Privacy policy

What we store, and what never leaves your machine

Your repositories are read on your machine and stay there. The app tracks nothing you do inside it. What we do hold is a technical report when it crashes, a licence record and, on this website, basic analytics.

"We" is CraftAtom Technologies (craftatom.com), the company behind Meridian and the controller of everything described below.

Your code

Meridian runs locally against your disk. Your repositories, diffs and history are read on your machine and stay there. The app records nothing about what you do in it: no feature tracking, no record of the repositories you open or the commands you run.

Crash reports

Meridian sends crash reports to Sentry so faults get found and fixed, which is what keeps the app stable for everyone. Almost nobody stops to report a crash, so this is usually the only way we learn one happened. A report carries technical, non-identifying information: the error and the stack trace that produced it, the app version, your macOS version and processor architecture, plus the same hashed device identifier that licensing uses, which tells one machine's crashes apart from another's.

File paths are stripped before the report leaves your machine: a path under your home directory, or on an external volume, is reduced to the file's name alone, so your username and your folder structure are not included. The text of a report carries no file contents, diffs, branch names, commit messages or credentials.

Crashes that kill the app outright are the exception, because a program in that state cannot describe what happened to it. Those reports attach a snapshot of the app's memory taken at the moment it died, which is the only thing that makes the cause identifiable afterwards. That snapshot is working memory, so it can hold fragments of whatever was on screen or being processed at the time, which may include part of a file or a diff. It is read to locate the crash and used for nothing else, and it is not indexed or searchable.

Reports are processed by Sentry on our behalf and are deleted on their standard retention schedule. Nothing is sent unless something actually goes wrong.

Licensing

Activating a licence stores the licence key, your email address, the order id, activation timestamps, a hashed device identifier and the device label you choose. The app also runs a licence check when it opens and once a day, which sends the hashed device identifier, the app and macOS versions, the processor architecture and your licence or trial status.

The trial

Extending the trial stores your email address and its verification state, nothing else.

Updates

The app checks api.gitmeridian.com for new versions. That request carries your licence key, so we can tell whether a release falls inside your update window, and nothing else beyond what any HTTP request carries.

Payments

Paddle processes checkout as merchant of record; card details never reach us. We receive your email address and order id in order to issue your licence key. Paddle's own privacy policy covers what they hold.

Email

We email your licence key and the trial confirmation link. Nothing else unless you ask for it.

This website

The pages are static. We keep anonymised analytics about how the site is used, such as which pages get read and which links get clicked, and we use it to make the site clearer. It is aggregate and not tied to you. There are no advertising trackers on this site; if that ever changes, this page will say so and you will be asked first.

The one third-party script anywhere on the site is Paddle's, on the checkout page, which is what draws their payment form. It loads on that page and nowhere else.

Your theme choice is stored in your own browser. Fonts load from Google Fonts, so Google receives the standard request data for those files.

Removal

Email support@gitmeridian.com to have your data deleted. We keep the minimum needed to honour active licences.