1. Who we are
Merit is operated by Namruth Paspulety. The app runs on a Hetzner server we rent. For paid checkout, Paddle.com Market Ltd is the merchant of record and is an independent controller of the payment data it needs to charge you, collect tax, and send receipts.
2. What we collect
Account identifiers from the sign-in method you choose: Google or GitHub. Interview messages you type. Files you upload (PDF, Word, or text). Evidence you confirm in the vault. CVs you generate. A session cookie so you stay signed in. Billing state we receive from Paddle after you subscribe (subscription id, status, and the user id we sent with checkout). Server logs such as IP address and user-agent, used to keep the box up and to investigate abuse.
3. What we do not collect
No microphone. No speech-to-text. No contacts. No location. No advertising ID beyond what Google attaches to its own sign-in. We do not store card numbers. Paddle handles the card.
4. How we use it
To run your account, run the interviewer, store the vault, export CVs you request, meter interview usage, and recognise a paid subscription. We do not sell your data. We do not use it to train a public model of our own. We do not run ads on the product.
5. Processors
- Hetzner Online — the server and disk in Helsinki where the app and vault files live.
- Google or GitHub — only if you choose that sign-in.
- Paddle — checkout, receipts, tax, refunds, customer portal.
- A language-model provider we have configured (currently DeepSeek; we may also use OpenAI, Anthropic, or Google Gemini) — interview text is sent so the interviewer can ask a follow-up. Do not put secrets in the chat that you do not want a model provider to see.
- Cloudflare — DNS and HTTPS for meritcv.com.
6. Where it lives
Your vault is a private SQLite file on our Hetzner disk, isolated from other accounts. It is not mixed into anyone else’s record. Interview text may leave that disk when it is sent to the model provider. Payment data lives with Paddle.
7. How long we keep it
Until you delete the account. Deleting signs you out, revokes sessions, and removes your tenant directory. Paddle keeps the billing records it is required to keep as merchant of record, even after you leave Merit. Server logs rotate on the box.
8. Your rights
You can export a CV you confirmed, and you can delete the account from the signed-in app. Depending on where you live, you may also have rights to access, correct, or object. Email [email protected] and we will handle it. If you are in the EEA or UK you may complain to your local data protection authority.
9. Cookies
The app sets a session cookie after you sign in. That cookie is necessary to keep you logged in. The marketing site does not use an analytics cookie. Paddle checkout may set cookies Paddle needs to complete payment.
10. Children
Merit is not directed at children under 16. Do not create an account for a child.
11. Contact
Privacy: [email protected]. Product and billing: [email protected]. Also see contact, terms, and refunds.