1. Who we are
Merak Keystone Corp., a Delaware corporation ("Merak", "we", "us"), provides the Merak application and the getmerak.com website (the "Service"). This policy explains what data we collect, why, who receives it, and the choices you have. It applies to the app, the website, and our communications with you.
For any privacy question or request, email privacy@getmerak.com.
2. Data we collect
We collect user data. The categories are:
- Account data. Name, email address, username, password (stored as a salted hash when you use password sign-in), avatar, timezone, and profile details.
- Workspace content. Goals, signals, tasks, chat messages with the AI agent, comments, documents, and files you upload.
- Connected-service data. Data the Service retrieves from third-party services you or your organization connect, within the access you grant. Depending on what you connect, this can include code repository content, issues, messages, documents, and monitoring data.
- Credentials for connected services. OAuth tokens and API keys you provide. Secret values are stored in a dedicated secrets manager; product records store references and redacted metadata.
- AI interaction data. Prompts, agent instructions, model outputs, and artifacts produced by agent runs.
- Operational telemetry. Error reports, browser performance measurements collected under a pseudonymous user reference, and identity-free external MCP reliability events, with sampling and masking applied. Server logs include IP addresses and request metadata.
- Product analytics (only if you opt in). Feature-usage events under a pseudonymous analytics token, and, only with a separate opt-in, masked session replay.
- Support and signup data. Emails you send us and information you submit on the waitlist.
We collect this data when you provide it, when you connect services, when your organization's members use shared workspaces, and automatically when you use the Service.
3. How we use data
We use data to operate the Service: to authenticate you, run the workspaces and agent workflows you configure, store and display your content, secure the Service, prevent abuse, provide support, measure reliability and performance, and meet legal obligations. Opt-in product analytics is used to understand feature usage.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not run third-party advertising cookies or trackers.
4. AI processing
The Service is built on artificial-intelligence models operated by third parties. When you use AI features, your prompts and relevant workspace context are sent to a model provider to generate the response or run the agent workflow. Our current default providers are OpenAI (general inference) and Anthropic (media analysis). If your organization configures its own model provider or API key, those calls go to that provider under your agreement with them.
We do not train our own foundation models on your content. Each model provider processes data under its own terms.
5. Cookies and similar technologies
The app uses a small number of first-party cookies:
| Cookie | Purpose | Type |
|---|---|---|
| wos-session | Keeps you signed in | Essential |
| merak-workos-return | Short-lived sign-in flow state | Essential |
| _dd_s | Performance-monitoring session (Datadog) | Operational telemetry |
The app also uses browser storage (localStorage and sessionStorage) for preferences such as theme and layout, for sign-in state in some configurations, and, after you opt in to product analytics, for a pseudonymous analytics device identifier.
The getmerak.com website uses cookieless, aggregate visit measurement (Vercel Analytics) and sets no advertising or analytics cookies.
Our sites do not respond to browser Do Not Track signals. The controls we honor are described in Section 6.
6. Your choices
- Product analytics is off by default. You can turn it on or off at Settings, Account, Privacy. Session replay is a separate opt-in and stays off unless you enable it.
- Operational telemetry opt-out. You can opt out of routine browser performance monitoring and routine external MCP success telemetry at Settings, Account, Privacy. Bounded error, security, and service logs that are strictly necessary to run the Service stay on. This opt-out takes precedence over product analytics consent for external MCP events.
- Connected services. You can disconnect a connected service in the product or revoke access with the provider at any time.
7. Who receives data
- Subprocessors. Vendors that help us run the Service (hosting, storage, compute, authentication, model inference, monitoring, email). We share the current list on request; email privacy@getmerak.com.
- Customer-directed connections. When you connect a third-party service or configure your own model provider, data flows to that party at your direction, under your agreement with them. These are your choices, not our subprocessors.
- Your organization. Content in a shared workspace is visible to that workspace's members according to its roles and permissions.
- Legal and corporate. We may disclose data when required by law, and in connection with a merger, acquisition, or sale of assets, with notice where required.
8. Retention and deletion
Retention depends on the data category:
- Account data is kept while your account exists.
- Workspace content is kept until you or your organization delete it.
- Temporary artifacts from agent runs, such as sandbox workspace archives and staged media uploads, are deleted on short automatic schedules (about one day).
- Deleted files can persist briefly in storage versioning and backups before permanent removal.
- Telemetry and analytics data are retained under each provider's settings.
Deletion controls:
- Personal workspace erasure. At Settings, Account, Privacy you can permanently erase your personal workspace. This requires a recent sign-in and a typed confirmation. It deletes your personal workspace records, queues deletion of the associated stored files, and disconnects your analytics identifier from future events.
- Company workspace deletion. A company owner can delete the company workspace. This deletes the company's records and queues deletion of its stored files.
- Everything else. For account deletion or any request these controls do not cover, email privacy@getmerak.com and we will handle it. Deletion from backups and third-party telemetry systems can take longer than deletion from the live product.
9. Your rights
Depending on your state, you may have rights to access, correct, delete, or obtain a copy of your personal information. We honor reasonable requests of this kind from any user, regardless of which state law applies. Email privacy@getmerak.com from your account email address so we can verify the request. We will not discriminate against you for exercising these rights. Because we do not sell or share personal information for advertising, there is no sale or sharing to opt out of.
10. Security
We apply organization-scoped authorization checks before protected operations, store connected-service secrets in a dedicated secrets manager, encrypt data in transit, encrypt stored files at rest, and run agent workloads in isolated runtimes with restricted network egress. No system is perfectly secure; report concerns to security@getmerak.com.
11. Children
The Service is a business tool for adults 18 and older. We do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, email privacy@getmerak.com and we will delete it.
12. Where data is processed
We are a United States company and process data in the United States.
13. Changes
We may update this policy. For material changes we will ask you to acknowledge the new version in the app, and the version and effective date at the top of this page will change.
14. Contact
Merak Keystone Corp.
privacy@getmerak.com