Privacy Policy

Version of 24.08.2026

This document describes exactly what the system stores about you and your work, who that data is passed to, and how to retrieve or delete it. It is written from how the system actually works rather than from a template: every statement below matches what the code does.

1. Who processes the data

The controller is MERXION SOLUTION S.R.L. (IDNO 1026023039848), Chișinău, Moldova. Processing follows Law of the Republic of Moldova No. 133/2011 on personal data protection. Questions, data exports and deletion: [email protected].

2. Your account

Login, password (stored only as a hash — not even we can recover it), name, job title, description, photo, gender, work and personal email, work and personal phone. If you signed in with Google, we additionally store the email address and the Google account identifier. If two-factor protection is enabled, its key is stored encrypted.

3. Your work content

Tasks, comments, chat and direct messages, files and images, checklists together with the photos attached to them, invoices and documents, and conversations with the AI assistant. This is your company's data: it is visible to company members according to their permissions and is isolated from other companies' data at the database level.

4. Meeting recordings

If you use meetings, we store the audio recording of the conversation, its full transcript split by speaker and time, a short summary, decisions and suggested tasks with quotes. The audio sits on our own server rather than in the cloud, and is served only to the meeting's participants. Transcription is performed by an external service — see section 7.

5. What is stored on your device

Cookies — strictly necessary only; no ad or tracking cookies:

CookiePurposeLifetime
__Secure-next-auth.session-tokenLogin session (secured, not readable by page scripts)Until sign-out
__Host-next-auth.csrf-tokenForm anti-forgery protectionSession
__Secure-next-auth.callback-urlReturn to the right page after loginSession
NEXT_LOCALESelected interface language1 year

Besides cookies, the app keeps a copy of your data in the browser to open fast and work on poor connections: profile, colleagues, projects, tasks, chats, theme and last login. The copy is cleared on sign-out. Checklist answers with photos may be stored on the device temporarily while offline.

6. Technical records

Every sign-in creates a device record: type, browser, operating system and IP address — so that you can see your active sessions and end the ones that are not yours. The full browser string is not stored. We keep a log of actions on data (who changed what) and a log of security events. The failed sign-in counter stores the IP not in plain form but as an irreversible fingerprint.

7. Who the data is passed to

We do not sell data or share it for advertising. Only services essential to operation receive it:

ServiceWhat it receivesWhere
maibAmount, currency and payer IP on card payment. Card details are entered on the bank side and never reach usMoldova
CloudinaryPhotos, attachments, avatarsEU / US
DeepgramMeeting and voice-command audio for speech recognitionUS
Groq · Anthropic · Cerebras · MistralAI assistant prompts, transcript fragments, invoice files for recognitionUS / EU
TelegramNotifications if you connected the botOutside EU
Zoho MailEmail recipient addressEU
CloudflareAll site traffic passes through its protectionUS / global

Some of these services are located outside Moldova and the European Union.

8. Access for programs and bots

You can connect an AI agent or a bot to your company's data using a personal access key. Such a key acts on your behalf and within the limits of your permissions: the task board, and for managers the financial summary of invoices and subscriptions as well. Keys are issued and revoked in the settings; a revoked key stops working immediately.

9. How long we keep it

Data is kept for as long as your account and your company exist. Sign-in records, the action log and security events are kept for the entire lifetime of the account and are not cleared automatically. Payment records are kept longer than the rest: they are primary financial documents, and they are needed to resolve disputed charges. Meeting recordings and files are deleted together with the company.

10. Your rights

You may obtain a copy of your data, correct it, restrict processing or delete your account. Deletion is available without signing in to the app — on the account deletion page; before you confirm, we show exactly what will disappear and what will remain with the company. For everything else, write to [email protected].

Go to account deletion →

11. Protection

The connection to the site is encrypted. Passwords are stored as hashes; two-factor keys and the contents of your personal vault are stored encrypted. The database has no outside access. Different companies' data is separated at the database level, not only in the interface.

12. Password vault

The logins, passwords and notes you keep in your personal vault are encrypted on your device before they reach us: we store only the ciphertext and the wrapped keys, and the key that opens an entry never leaves your device. No one at Merxion can read what is in your vault, and neither can anyone who obtains a copy of our database. This protection has a cost worth knowing: if you lose the key, the entries are gone — we cannot recover or reset them for you. The vault is deleted together with your account, immediately and irreversibly.

13. Changes

If this document changes, the new version will appear on this page with a new date. We will show substantial changes in the app.

Controller and contacts

MERXION SOLUTION S.R.L.
IDNO 1026023039848
str. Nicolae Testemitanu 19/B, ap. 1408, Chisinau, MD-2025, Moldova