Trust and security

Draft.This page is under legal review. Everything on it is true today; its wording may change.

When you use Meles, you're the controller of your users' data and Meles is your processor: we process it only on your instructions, under our data processing agreement. For your own team's accounts, Meles is the controller, as our privacy notice explains.

Where your data lives

In the United States. Our servers, database and file storage run at DigitalOcean in New York, and error reports are stored by Sentry in the United States.

Your users' browsers fetch our script and your campaigns' settings from DigitalOcean's content delivery network, which runs on Cloudflare's network worldwide and may set Cloudflare's bot-management cookie, __cf_bm. What your users send back goes to our servers in New York.

Security measures

Each measure says what shows it. Our code and its tests are private: ask at privacy@meles.app and we'll share the evidence with you under the DPA.

  • Hosted in the United States

    The application, its database and its file storage run at DigitalOcean in New York (nyc3). Error reports are stored by Sentry in the United States.

    Shown by: Declared in our infrastructure code, which is the only way anything is created.

  • Encrypted in transit and at rest

    Every page and API call is served over HTTPS, with HSTS. The managed database encrypts its storage and its connections.

    Shown by: The web server's configuration, and the database's terms, checked when it was chosen on 2026-09-20.

  • The application can't read a table

    The application's database role may only run reviewed stored routines, each scoped to one organisation. It can't read or change a table directly, so one customer's request can't reach another's data.

    Shown by: Checked on every change by the database's guardrail tests.

  • Keys are hashed, scoped and revocable

    Secret API keys are stored only as hashes, carry only the scopes they were given, and can be revoked at once. Sites can require that each identified user is vouched for by your server, with an HMAC of their ID.

    Shown by: Tested through the API and the MCP server on every change.

  • Sign-in through WorkOS

    Dashboard sign-in is WorkOS AuthKit's. Meles keeps no passwords, and its session cookie is HttpOnly, Secure and SameSite.

    Shown by: Our requirements and the session's tests.

  • Nobody configures a server by hand

    Servers are configured only by our deployment pipeline, from code in our repository. Emergency access opens a temporary window that closes itself.

    Shown by: The pipeline configures the server after every infrastructure change, and every release passes its health gate.

  • Backups, and a restore we've rehearsed

    The database is backed up daily and can be restored to any moment in the last 7 days. A full restore was rehearsed on 2026-09-26 and was online in about 6 minutes.

    Shown by: The restore runbook's rehearsal log.

  • Monitored, with alerts that page

    The API is checked every minute from outside DigitalOcean, and an outage pages the founder's phone. Every new error is reported.

    Shown by: Each alert was drilled, with its timings recorded.

  • Error reports carry no personal data

    Error reports leave out users, IP addresses, cookies, headers, query strings and request bodies. Our embeddable script sends nothing to an error tracker.

    Shown by: A test sends a request full of personal data and fails if any of it reaches the report.

  • Logs hold internal IDs only

    Our logs never hold a name, an email address or anything a person typed: only our own internal ID numbers. They're kept until our next release.

    Shown by: Tested on every change, for every kind of request.

  • Delete and export a person's data

    You can delete or export everything Meles holds about one of your users, through the API or the MCP server. After a restore from backup, our runbook replays every deletion.

    Shown by: Tested across every table that holds a person's data.

  • A breach runbook, walked

    How we find, contain and assess a breach, and how we tell you about it.

    Shown by: Walked as a tabletop exercise.

  • A retention window for raw events

    Raw events and impressions are deleted once they're 180 days old, a month at a time; webhook and Slack delivery logs 30 days after their last attempt. Responses and answers are kept until you delete them.

    Shown by: A daily job does it; tests plant old months and check it deletes them and keeps any month not yet fully counted in your results.

Planned security measures

What we don't have yet

How long we keep data

Sub-processors

These are the vendors that receive data from Meles, and what each receives. Only DigitalOcean and Sentry receive your users' data; the others handle your team's accounts, our email and billing.

  • DigitalOcean

    What for
    Hosting: our servers, database, backups and file storage, and the network that delivers our script
    What it receives
    Everything Meles holds
    Where
    The United States (New York)
    Transfers from the EEA and the UK
    Certified to the EU-U.S. Data Privacy Framework, its UK Extension and the Swiss-U.S. Framework, with the EU standard contractual clauses and the UK Addendum as the fallback
    Its data processing terms
    DigitalOcean's DPA
  • Sentry

    What for
    Error reports from our servers and dashboard, and uptime checks
    What it receives
    Our internal ID numbers in error reports: never a name, an email address or an answer
    Where
    The United States
    Transfers from the EEA and the UK
    Certified to the EU-U.S. Data Privacy Framework, its UK Extension and the Swiss-U.S. Framework, with the EU standard contractual clauses and the UK Addendum as the fallback
    Its data processing terms
    Sentry's DPA
  • Resend

    What for
    Sends our email: invitations to join an organisation, notices to an organisation's owners, and the waitlist's
    What it receives
    Invitees', owners' and waitlist sign-ups' email addresses, and the emails we send them
    Where
    The United States
    Transfers from the EEA and the UK
    The EU standard contractual clauses and the UK Addendum; certified to the EU-U.S. Data Privacy Framework
    Its data processing terms
    Resend's DPA
  • Cloudflare

    What for
    Our domain's DNS, forwarding email sent to our addresses, and our status page
    What it receives
    Email you send to an address at meles.app, and the details of each visit to our status page, which Cloudflare logs for 3 days
    Where
    Cloudflare's network of data centres, worldwide
    Transfers from the EEA and the UK
    Certified to the EU-U.S. Data Privacy Framework and its UK Extension; the EU standard contractual clauses and the UK Addendum for any other transfer
    Its data processing terms
    Cloudflare's DPA
  • WorkOS

    What for
    Dashboard sign-in
    What it receives
    Your team's names, email addresses and sign-in sessions
    Where
    The United States
    Transfers from the EEA and the UK
    The EU standard contractual clauses and the UK Addendum
    Its data processing terms
    WorkOS's DPA
  • GitHub

    What for
    Holds the email addresses admitted to the private beta
    What it receives
    Those email addresses
    Where
    The United States, among other places
    Transfers from the EEA and the UK
    Certified to the EU-U.S. Data Privacy Framework; the EU standard contractual clauses
    Its data processing terms
    GitHub's DPA
  • Stripe

    What for
    Billing: checkout, subscriptions and invoices
    What it receives
    Your billing contact's details and payment method
    Where
    The United States, and Stripe's affiliates and sub-processors elsewhere
    Transfers from the EEA and the UK
    Certified to the EU-U.S. Data Privacy Framework, its UK Extension and the Swiss-U.S. Framework, with the EU standard contractual clauses and the UK Addendum as the fallback
    Its data processing terms
    Stripe's DPA

Changes. We tell your organisation's Owners by email 30 days before a new sub-processor starts, and you can object.

Destinations you connect aren't our sub-processors. A Slack connection sends a campaign's name, its scores and its open-text answers to the channel you choose, and a webhook sends the events you subscribe it to, to the address you give. They go where you send them, under your own terms with Slack or the receiver.

The data processing agreement

Our DPA is part of our terms, so accepting them accepts it. It includes the EU standard contractual clauses and the UK Addendum for transfers to the United States. If you need a countersigned copy, email privacy@meles.app.

If something goes wrong

If a breach affects your data, we email your organisation's Owners without undue delay, and within 72 hours of finding it: what happened, which data, what we've done and what you may need to do. We keep a record of every breach, however small.

To report a vulnerability or a suspected breach, email privacy@meles.app.