legal
Privacy Policy
last updated · september 19, 2026
The short version
- We do not train on your data. Not on the text you send, not on the text we return, and not in anonymised or aggregated form.
- We do not store your content. The text in a request is held in memory only while we generate the response, then discarded. It is never written to our database or our logs.
- What we do keep is what running a prepaid account requires: who you are, your balance, and how many tokens each request used — plus a request ID and how the request went, so we can answer questions about it without its text.
1. Who we are
meraGPT is operated by Okyasoft Pte Ltd, a company registered in Singapore (“we”, “us”). We run meragpt.com and the meraGPT API (together, the “Service”). This policy explains what information we handle when you use the Service and what we do with it.
2. The content of your requests
When you call the API or use the playground, the text you send travels over an encrypted connection to our application servers and on to the servers that run our models. It is held in memory for as long as it takes to generate the response, and is then discarded. Our inference servers do not cache prompts between requests.
We do not write request or response text to our database, we do not record it in our logs, and we do not use it to train, evaluate or improve any model. Because it is not retained, it is not available to our staff either. Automated checks that run on a response before we return it — for example, confirming that facts were preserved — happen in memory on that same request and are discarded with it.
No third-party AI provider receives your content. The models are our own, and we run them ourselves.
If you reach us through an aggregator such as OpenRouter, we receive the request from them and handle it exactly as described here. What the aggregator itself does with your data is governed by its own policies.
3. What we collect
- Account. When you sign in with Google we receive your name, email address and profile picture, and the identifiers Google uses to sign you in.
- Billing. Payments are processed by Stripe. We never see or store your card number. We keep your Stripe customer reference, your balance, and a ledger of purchases, usage charges and refunds. If you turn on auto top-up we also keep Stripe’s reference to the saved payment method, along with your threshold and monthly cap.
- API keys. We store a one-way hash of each key and its first few characters so you can recognise it. The full key is shown to you once, when it is created.
- Usage records. For each request: the time, the model, which key was used, the number of input and output tokens, the cost, the latency, and an error code if it failed. This is what we bill from and what your dashboard shows. It contains no request text.
- Playground without an account. To enforce the free daily allowance we keep a salted one-way hash of your IP address with the date and a count of requests and tokens. We never store the IP address itself, and the hash cannot be reversed into one.
- Operational logs. Status codes, timings and token counts, so we can keep the Service running. No request text.
- Request records. Each API request gets an ID, returned to you with the response. Against it we keep the model, token counts, cost, latency, any error, and how the request was processed — for a restyle, which paragraphs were rewritten or left unchanged and why, identified by position and word count. This is what lets you ask us about a specific response. It never includes the text you sent or the text we returned.
- Website analytics. Aggregate page-view statistics. See our Cookie Policy.
4. How we use it
To provide the Service, sign you in, meter and bill your usage, enforce rate limits and prevent abuse, answer support requests, and meet our legal obligations. We do not sell your information and we do not use it for advertising.
5. Who we share it with
Only the providers we need to run the Service, each processing data on our behalf: Vercel (application hosting), Neon (database), Stripe (payments), Google (sign-in), and the cloud infrastructure providers that host the servers running our models, none of which retain your content. We may also disclose information where the law requires it, or to a successor if meraGPT is acquired, in which case this policy continues to apply.
6. Where it is processed
We and our providers may process information in countries other than your own, including the United States. Where the law requires it, those transfers rely on appropriate safeguards such as standard contractual clauses.
7. How long we keep it
Request content is not kept at all. Account information is kept while your account is open. Your ledger and usage records are kept for as long as billing, tax and accounting obligations require, and deleted after that.
8. Your rights
You can ask us to access, correct, export or delete your information, or object to how we use it, by emailing hello@meragpt.com. We respond within 30 days. Deleting your account removes your profile, keys and billing settings. Ledger entries we are legally required to keep are retained until that obligation ends.
9. Security
All traffic is encrypted in transit. API keys are stored only as hashes and IP addresses only as salted hashes. Access to production systems is restricted to the people who operate them. No system is perfectly secure, but we design so that the most sensitive thing you give us — your content — is never stored in the first place.
10. Children
The Service is not directed to anyone under 18 and we do not knowingly collect information from them.
11. Changes
We will update the date at the top of this page when this policy changes, and email account holders before any change that materially affects how their information is handled.
12. Contact
Questions about this policy: hello@meragpt.com.