Privacy Policy

Last updated: 12 June 2026

1. What we collect

Account data you provide at registration: name, work email, organisation, city, country, phone number, account type and — for clinician accounts — speciality and procedures (used for the vetting workflow).
Usage events: which product surfaces you use (e.g. a dashboard view, a news view, an export — downloads record which document) with a timestamp. These events carry no IP address, page URL or device fingerprint, and are retained for 365 days, after which they are automatically deleted. They are used only for operating and improving the Service (e.g. renewal conversations); staff usage is excluded from aggregates.
Operational server logs: request logs and sign-in events (including IP address and browser user-agent) are retained for a limited period in our hosting provider's log pipeline, and used for security forensics and troubleshooting only.
Billing data: handled by Stripe; we store your subscription state and card brand/last-four only — never full card numbers.

2. Cookies

We use essential cookies only: two httpOnly authentication cookies that keep you signed in. There are no advertising, analytics or third-party tracking cookies, and no tracking pixels.

3. Processors we use

Stripe (payments and invoicing), Resend (transactional email), Railway (application and database hosting), and Sentry (error monitoring; reports may include account identifiers but are not used for profiling). Each processes data on our behalf under their own data-processing terms. We do not sell personal data, and we do not share it with advertisers.

4. Emails

We send transactional email (verification, password reset, billing-adjacent notices) and — only where you opt in via saved searches — alert and digest emails, each carrying one-click unsubscribe. We do not send marketing email to account holders without consent.

5. Your rights

You can access and correct your profile from the account page, export the datasets your plan includes, and delete your account yourself (account page → danger zone). Deletion anonymises your personal data immediately — name and email are replaced with tombstones — while non-personal records required for audit and finance are retained. Sign-in sessions are revoked and any subscription is cancelled at period end. For any other request (including data portability or complaints), contact support@mervo.io and we will respond within 30 days. You may also lodge a complaint with your local supervisory authority.

6. Security and retention

Passwords are stored only as modern memory-hard hashes (argon2); access is enforced server-side on every request; data is encrypted in transit. Account data is retained for the life of the account; usage events for 365 days; security tokens expire and are purged automatically; database backups are retained on a rolling schedule.

7. Changes; contact

Material changes to this policy will be notified via the Service or email before they take effect. Privacy questions and requests: support@mervo.io.