Privacy
What Meridian stores about you, why, and for how long.
Draft2 sections are drafts — plain language about what the product does, not yet reviewed by counsel. Everything else on this page describes how the product works today.
What we hold
Your email address and a hash of your password — never the password itself. The registration form asks for neither a name nor a country.
Your sessions: the client name, the network address and the expiry of each sign-in, listed on the Settings page so you can end one.
Your identity documents, once uploaded, and the reviewer’s decision.
Your simulated trading record: every order, fill, position and account event, on an append-only log.
Your payout destinations, stored in full and shown masked — the last four characters only.
An audit trail of every money movement and every administrative action on your account, with the network address it came from.
What we show others
The leaderboard uses an anonymous handle by default. Your email address, name and country are not shown on it, or to other traders.
How long we keep it
Identity documents are kept while you hold an account and deleted 30 days after your last account closes, whether they were approved or rejected. The deletion is recorded with its reason.
The trading record and the audit trail are append-only and are not deleted.
Payment processors
The challenge fee is paid on the processor’s own page, and a payout is sent through a processor. Meridian sends the processor the amount, the currency and a reference; what the processor collects from you on its page is governed by its own policy.
Your rights and how to exercise them
Draft — not yet reviewed by counselWhat you can see and end yourself: every session on your account is listed on the Settings page and can be ended there, which ends that sign-in everywhere. Your payout destinations are listed on the Payouts page, masked, and can be retired there; a retired destination stays on the record because a payout may refer to it.
Who can read your identity documents: an administrator only, and every read is written to the audit log. You cannot download a document again once it is uploaded.
Erasure: identity documents are deleted 30 days after your last account closes. The decision on them survives, holding only the outcome, when it was made, who made it and a fingerprint of what was reviewed that cannot be turned back into the document — never the document itself.
You cannot yet ask for a copy of your data, or for your account to be deleted, from inside the app. How to make either request is not described here yet.
Your public handle is drawn at registration from fixed word lists and is not derived from your email address. Nothing in the product changes it afterwards: the only parts of your sign-in details the product ever changes are your password and your second factor.
Cookies
One cookie: the session, set when you sign in and cleared when you sign out. It is not readable by scripts and is not used for anything but recognising your session.
Contact
Draft — not yet reviewed by counselYou can write to us at help@mct.money. We do not state a reply time.
Email from Meridian is sent only when an address is registered: a notice to that mailbox, in plain text.