Discord GitHub icon

Privacy Policy

Last Updated: September 14, 2026

Meru is built so that your mail stays between you and Google. This policy explains the small amount of data that does reach us, why we have it, how long we keep it, and what you can ask us to do with it. If anything here is unclear, email us and we will explain it.

1. Who we are

Zoid Ltd (“Zoid”, “we”, “us”) makes Meru and is the controller of the personal data described in this policy. We are registered in England and Wales, company number 14931728, with a registered office at 167-169 Great Portland Street, 5th Floor, London, England, W1W 5PF.

You can reach us at tim@meru.so. We are a very small company and are not required to appoint a data protection officer, so that address reaches the person who handles these requests.

2. What this policy covers

It covers the Meru desktop app for macOS, Windows and Linux, the website at meru.so, the customer portal at portal.meru.so, our API at api.meru.so and api.meruapp.io, and the emails we send you.

What Meru never sends us. Meru shows Gmail in a browser session on your own device. Your messages, attachments, contacts, Google credentials and anything you type in Gmail travel between your device and Google, and nowhere else. Meru does not use the Gmail API and asks for no Google permission over your mail. We cannot read your mail, because we never receive it. If you sign in to the portal with Google, we ask only for the openid, email and profile scopes, which give us your name, email address and profile picture.

Your use of Gmail itself is between you and Google, under Google’s privacy policy. Meru is not affiliated with or endorsed by Google. Gmail and Google are trademarks of Google LLC.

3. What we collect and why

Every install and the free trial

On first launch, every install of Meru starts a 14-day Meru Pro trial automatically. To do that, the app sends us a device identifier: a SHA-256 hash of your operating system’s machine ID. The hash cannot be turned back into the original identifier, and it stays the same if you reinstall.

We store that hash, whether the trial is running, when it expires, an approximate country, and timestamps. The country comes from the country header Cloudflare adds to the request based on your IP address; we do not store the IP address itself.

While the app is open and the trial has not expired, it re-checks with us about every 3 hours. Once the trial has ended, a free copy of Meru makes no further calls to our servers at all.

Meru Pro licenses

If you buy Meru Pro, we store your device hash, your license key, the times it was activated and last validated, a device label (generated for you, and renameable in the app’s settings), the device limit on your license, and the email address used for the purchase. The app validates the license with us each time it launches.

Your portal account

If you create an account at portal.meru.so, we store your name and email address, whether the address has been verified, a profile image if you sign in with Google, the sign-in tokens Google gives us, a Stripe customer ID created when you sign up, and records of your sessions, which include your IP address and your browser’s user agent.

You sign in with Google, or with a magic link or one-time code sent to your email address by Resend. There are no passwords, so we never hold one. In the portal you can see your licenses and devices, remove a device, import a license, and buy licenses or extra device slots.

There is no self-serve account deletion or data export yet. Until there is, email tim@meru.so and we will do either by hand.

Buying Meru Pro

Purchases run through Stripe Checkout with Stripe Managed Payments, which may appear to you as “Link” or “Onelink”. Stripe is the merchant of record: it collects the payment, works out and remits VAT, sales tax or GST where it supports this, converts the price into your local currency, sends your receipt and invoice, handles payment disputes and payment support, and can issue refunds within 60 days.

We never see or hold your card details. What reaches us is your email address, a purchase reference, the amount, and the tax location. Stripe handles your payment data under its own privacy policy and purchase terms.

Emails we send

We send email through Resend: your license key when you buy, one follow-up message about 7 days after a first purchase, and sign-in links and codes for the portal.

First-time buyers are also added to our product updates list. Every one of those emails has an unsubscribe link. You can also opt out by replying or by writing to tim@meru.so, and we will take you off the list.

Support

When you email us for help, we have your email address, whatever you tell us in the message, and any attachments you send.

Updates and downloads

Meru checks for a new version when it launches and about every 3 hours after that, by asking GitHub for the latest release. Version history comes from api.github.com, and the download buttons on meru.so send you to GitHub. GitHub sees your IP address when your app or browser asks it for a file, as it does for any download.

Chrome extensions, a Pro feature, are downloaded from Google’s Chrome Web Store update service, which likewise sees your IP address.

If a license or trial check fails with a network error, the app requests a page from captive.apple.com to work out whether you are behind a captive portal or simply offline.

There is no analytics, advertising, tracking, crash reporting or telemetry in the app, on the website or in the portal. Our fonts are served from meru.so itself rather than a third-party font network.

Under UK data protection law we rely on three grounds.

Contract. Running your trial, issuing and validating your license, managing your devices, giving you a portal account, and answering support about a purchase. Without this data we cannot give you the product you asked for.

Legitimate interests. Keeping trials to one per device; preventing fraud and abuse, including license sharing and chargeback fraud; keeping our servers secure and working; and sending product updates to people who have bought Meru. We have weighed these against your interests, and you can object to any of them (section 8).

Legal obligation. Keeping purchase and tax records for as long as UK tax and accounting law requires.

5. Who we share data with

We do not sell personal data, and we do not share it for advertising. We use these processors and services.

WhoWhat forWhereSafeguard
StripePayments, tax, receipts, refundsUS, EUDPF or UK Addendum
ResendSending our emailsUSDPF or UK Addendum
CloudflareHosting our API, site and logsUSDPF or UK Addendum
PlanetScale on AWSOur databaseUS EastDPF or UK Addendum
GitHubUpdate checks and downloadsUSDPF or UK Addendum
GooglePortal sign-in, extension downloadsGlobalOwn terms

Google acts as an independent controller for sign-in and for the Chrome Web Store, under its own privacy policy rather than our instructions. Section 6 explains the safeguards named above.

Cloudflare keeps request logs for us as part of hosting. When a Stripe webhook fails, our server error logs may contain purchase details such as a name, email address and billing address. Those logs are kept briefly for debugging and then discarded, and we are working on keeping purchase details out of them.

We may also share data where the law requires it, or to establish or defend a legal claim.

6. Where your data goes

We are in the UK, and most of the services above are in the United States. Where a vendor is certified under the UK Extension to the EU-US Data Privacy Framework, we rely on that. Where it is not, we rely on the UK International Data Transfer Addendum to the EU standard contractual clauses. Email tim@meru.so and we will send you a copy of the terms that apply to a given vendor.

7. How long we keep it

DataHow long
Trial recordsIndefinitely, so one device cannot start a second trial
License and device recordsLife of the license, plus 12 months
Portal sessions30 days after the session expires
Support email24 months
Purchase records6 years, for tax and accounting
Product updates listUntil you opt out
Server error logsBriefly, for debugging

Trial records are the one thing we keep without a time limit. A trial row is a hash, a country and some dates, and deleting it would hand the same device a second free trial, which is the whole reason the row exists.

8. Your rights

You can ask us to give you a copy of your data, correct it, erase it, restrict how we use it, or send it to you or another provider in a portable form. Email tim@meru.so. We do not charge for this, and we answer within one month.

You can object to anything we do on the ground of legitimate interests. Tell us what you object to and we will stop, unless we can show compelling grounds that override your objection or we need the data for a legal claim. If you object to product update emails, there is nothing to weigh: we will stop sending them.

Two things are worth knowing before you ask us to erase data. Erasing your license and device records ends the license, because the app then has nothing to validate against. And records of your payment are held by Stripe as merchant of record rather than by us, so deleting those is a request to Stripe through Link support; we will point you to the right place and help where we can.

9. Complaints

If you are unhappy with how we have handled your data, email tim@meru.so. We will acknowledge your complaint within 30 days and answer it without undue delay.

You can also complain to the UK regulator, the Information Commissioner’s Office, at ico.org.uk. You do not have to come to us first.

10. Cookies and local storage

The portal sets one strictly necessary cookie, which keeps you signed in. Without it the portal cannot work.

Your appearance preference, light or dark, is stored in your browser’s local storage on meru.so and on your device in the app, so your choice survives a reload.

Meru’s settings and each account’s Gmail session data stay on your device. “Reset app” in settings clears them.

We set no analytics or advertising cookies and embed no third-party trackers.

11. Children

Meru is for people aged 18 and over. We do not knowingly collect data from anyone younger. If you believe a child has given us data, email tim@meru.so and we will delete it.

12. Changes to this policy

We update this policy when the product or the law changes. The date at the top shows when we last did. If a change materially affects how we use your data, we will tell you at least 30 days beforehand by email or in the app. Earlier versions are available on request.

13. Contact

Email tim@meru.so for anything in this policy, including a request to exercise your rights.

Zoid Ltd
167-169 Great Portland Street
5th Floor
London
W1W 5PF
England

Registered in England and Wales, company number 14931728.