Trust and security
Last updated 4 October 2026
Draft.This page is under legal review. Everything on it is true today; its wording may change.
When you use Meles, you're the controller of your users' data and Meles is your processor: we process it only on your instructions, under our data processing agreement. For your own team's accounts, Meles is the controller, as our privacy notice explains.
Where your data lives
In the United States. Our servers, database and file storage run at DigitalOcean in New York, and error reports are stored by Sentry in the United States.
Your users' browsers fetch our script and your campaigns' settings from DigitalOcean's content delivery network, which runs on Cloudflare's network worldwide and may set Cloudflare's bot-management cookie, __cf_bm. What your users send back goes to our servers in New York.
Security measures
Each measure says what shows it. Our code and its tests are private: ask at privacy@meles.app and we'll share the evidence with you under the DPA.
Hosted in the United States
The application, its database and its file storage run at DigitalOcean in New York (nyc3). Error reports are stored by Sentry in the United States.
Shown by: Declared in our infrastructure code, which is the only way anything is created.
Encrypted in transit and at rest
Every page and API call is served over HTTPS, with HSTS. The managed database encrypts its storage and its connections.
Shown by: The web server's configuration, and the database's terms, checked when it was chosen on 2026-09-20.
The application can't read a table
The application's database role may only run reviewed stored routines, each scoped to one organisation. It can't read or change a table directly, so one customer's request can't reach another's data.
Shown by: Checked on every change by the database's guardrail tests.
Keys are hashed, scoped and revocable
Secret API keys are stored only as hashes, carry only the scopes they were given, and can be revoked at once. Sites can require that each identified user is vouched for by your server, with an HMAC of their ID.
Shown by: Tested through the API and the MCP server on every change.
Sign-in through WorkOS
Dashboard sign-in is WorkOS AuthKit's. Meles keeps no passwords, and its session cookie is HttpOnly, Secure and SameSite.
Shown by: Our requirements and the session's tests.
Nobody configures a server by hand
Servers are configured only by our deployment pipeline, from code in our repository. Emergency access opens a temporary window that closes itself.
Shown by: The pipeline configures the server after every infrastructure change, and every release passes its health gate.
Backups, and a restore we've rehearsed
The database is backed up daily and can be restored to any moment in the last 7 days. A full restore was rehearsed on 2026-09-26 and was online in about 6 minutes.
Shown by: The restore runbook's rehearsal log.
Monitored, with alerts that page
The API is checked every minute from outside DigitalOcean, and an outage pages the founder's phone. Every new error is reported.
Shown by: Each alert was drilled, with its timings recorded.
Error reports carry no personal data
Error reports leave out users, IP addresses, cookies, headers, query strings and request bodies. Our embeddable script sends nothing to an error tracker.
Shown by: A test sends a request full of personal data and fails if any of it reaches the report.
Logs hold internal IDs only
Our logs never hold a name, an email address or anything a person typed: only our own internal ID numbers. They're kept until our next release.
Shown by: Tested on every change, for every kind of request.
Delete and export a person's data
You can delete or export everything Meles holds about one of your users, through the API or the MCP server. After a restore from backup, our runbook replays every deletion.
Shown by: Tested across every table that holds a person's data.
A breach runbook, walked
How we find, contain and assess a breach, and how we tell you about it.
Shown by: Walked as a tabletop exercise.
A retention window for raw events
Raw events and impressions are deleted once they're 180 days old, a month at a time; webhook and Slack delivery logs 30 days after their last attempt. Responses and answers are kept until you delete them.
Shown by: A daily job does it; tests plant old months and check it deletes them and keeps any month not yet fully counted in your results.
Planned security measures
- Logs kept for a stated period. Logs kept for a set number of days, searchable across releases, rather than until the next release.
- Your whole organisation, exported or deleted. An export of everything in your organisation, and its deletion at the end of the service.
- A restore rehearsed with real data. The restore rehearsal repeated against a database holding customers' data.
What we don't have yet
- No independent audit or certification, such as SOC 2 or ISO 27001. Our sub-processors' certifications are theirs, not ours.
- No independent penetration test.
- One person operates Meles today, so an alert reaches one phone.
How long we keep data
- Your users' people and answers: until you delete them, their site or your organisation.
- What your users do, and when campaigns were shown to them: 180 days, then deleted a month at a time.
- The log of each webhook and Slack delivery: 30 days after its last attempt.
- Which of your users were reached each month, for billing: until two months after the month ends.
- A site you delete: 30 days, during which you can restore it, then gone for good.
- When your organisation leaves Meles: Planned: 30 days, with an export if you ask in that time, then deleted.
- Backups: 7 days, so a deletion reaches every copy within a week.
- Our servers' logs: until our next release, usually hours to a few days, and never more than about 30 MB per server. They hold only our internal ID numbers.
- Error reports: 30 days, at Sentry.
- The record of each AI agent's tool calls: 28 days at most, with the call's arguments only as a keyed hash.
- Invitations to your organisation: 30 days after they're accepted, revoked or lapse.
- The record of each deletion or export request: for your organisation's life, holding internal ID numbers and a keyed hash of the person, never who they are.
Sub-processors
These are the vendors that receive data from Meles, and what each receives. Only DigitalOcean and Sentry receive your users' data; the others handle your team's accounts, our email and billing.
DigitalOcean
- What for
- Hosting: our servers, database, backups and file storage, and the network that delivers our script
- What it receives
- Everything Meles holds
- Where
- The United States (New York)
- Transfers from the EEA and the UK
- Certified to the EU-U.S. Data Privacy Framework, its UK Extension and the Swiss-U.S. Framework, with the EU standard contractual clauses and the UK Addendum as the fallback
- Its data processing terms
- DigitalOcean's DPA
Sentry
- What for
- Error reports from our servers and dashboard, and uptime checks
- What it receives
- Our internal ID numbers in error reports: never a name, an email address or an answer
- Where
- The United States
- Transfers from the EEA and the UK
- Certified to the EU-U.S. Data Privacy Framework, its UK Extension and the Swiss-U.S. Framework, with the EU standard contractual clauses and the UK Addendum as the fallback
- Its data processing terms
- Sentry's DPA
Resend
- What for
- Sends our email: invitations to join an organisation, notices to an organisation's owners, and the waitlist's
- What it receives
- Invitees', owners' and waitlist sign-ups' email addresses, and the emails we send them
- Where
- The United States
- Transfers from the EEA and the UK
- The EU standard contractual clauses and the UK Addendum; certified to the EU-U.S. Data Privacy Framework
- Its data processing terms
- Resend's DPA
Cloudflare
- What for
- Our domain's DNS, forwarding email sent to our addresses, and our status page
- What it receives
- Email you send to an address at meles.app, and the details of each visit to our status page, which Cloudflare logs for 3 days
- Where
- Cloudflare's network of data centres, worldwide
- Transfers from the EEA and the UK
- Certified to the EU-U.S. Data Privacy Framework and its UK Extension; the EU standard contractual clauses and the UK Addendum for any other transfer
- Its data processing terms
- Cloudflare's DPA
WorkOS
- What for
- Dashboard sign-in
- What it receives
- Your team's names, email addresses and sign-in sessions
- Where
- The United States
- Transfers from the EEA and the UK
- The EU standard contractual clauses and the UK Addendum
- Its data processing terms
- WorkOS's DPA
GitHub
- What for
- Holds the email addresses admitted to the private beta
- What it receives
- Those email addresses
- Where
- The United States, among other places
- Transfers from the EEA and the UK
- Certified to the EU-U.S. Data Privacy Framework; the EU standard contractual clauses
- Its data processing terms
- GitHub's DPA
Stripe
- What for
- Billing: checkout, subscriptions and invoices
- What it receives
- Your billing contact's details and payment method
- Where
- The United States, and Stripe's affiliates and sub-processors elsewhere
- Transfers from the EEA and the UK
- Certified to the EU-U.S. Data Privacy Framework, its UK Extension and the Swiss-U.S. Framework, with the EU standard contractual clauses and the UK Addendum as the fallback
- Its data processing terms
- Stripe's DPA
Changes. We tell your organisation's Owners by email 30 days before a new sub-processor starts, and you can object.
Destinations you connect aren't our sub-processors. A Slack connection sends a campaign's name, its scores and its open-text answers to the channel you choose, and a webhook sends the events you subscribe it to, to the address you give. They go where you send them, under your own terms with Slack or the receiver.
The data processing agreement
Our DPA is part of our terms, so accepting them accepts it. It includes the EU standard contractual clauses and the UK Addendum for transfers to the United States. If you need a countersigned copy, email privacy@meles.app.
If something goes wrong
If a breach affects your data, we email your organisation's Owners without undue delay, and within 72 hours of finding it: what happened, which data, what we've done and what you may need to do. We keep a record of every breach, however small.
To report a vulnerability or a suspected breach, email privacy@meles.app.