Privacy Policy
Last updated: September 2026 · Applies to Merlin Builder and Merlin Organizations
1. Who We Are
Merlin Software ("Merlin," "we," "us") operates Merlin Builder and Merlin Organizations and the related websites and APIs (the "Services"). This policy explains what we collect, why, and the choices you have. It applies across all Merlin products and domains (merlinthedog.ai, merlinthedog.com, merlinthedog.io, merlinsoft.io, mrln.to).
2. Information We Collect
- Account information — email address and display name, managed through our authentication provider (Logto).
- Payment information — processed by Stripe; we never store full card numbers. We retain billing records (plan, invoices, usage charges).
- Content you create — prompts, project descriptions, generated applications and code, tasks and instructions given to AI agents, uploaded files, and knowledge-base entries.
- Usage and technical data — generation/credit consumption, storage use, feature interactions, logs, IP addresses, and device/browser information used for security and operations.
- Credentials you supply — API keys or tokens you provide for third-party services (for example your own AI-provider or GitHub keys) are stored encrypted and used only to perform the actions you configure.
- Integration data — if you connect platforms such as Discord, Telegram, or GitHub, we process the messages and events those integrations send us in order to provide the feature.
3. How We Use Information
We use information to provide, secure, and improve the Services; to meter usage and process payments; to communicate with you about your account (transactional email such as approvals, low-balance notices, and receipts); to prevent abuse and enforce our Terms; and to comply with legal obligations. We do not sell your personal information, and we do not use your prompts, code, or generated content to train AI models.
4. AI Processing
Prompts, relevant project context, and agent instructions are sent to our AI model providers (Anthropic and OpenAI, or a provider whose API key you supply) to generate responses. These providers process the data under their own terms; under our current API agreements they do not use API traffic to train their models. Prompts and outputs are stored so we can provide version history, billing, and audit features.
5. Data Security
Personally identifiable information (including email addresses and names) is encrypted with AES-256-GCM before storage. Third-party credentials you supply are stored with envelope encryption. All traffic is encrypted in transit (TLS). Authentication is delegated to Logto; deployed user applications run in isolated containers. No system is perfectly secure — please use a strong, unique password and keep your API tokens confidential.
6. Cookies
We use a small number of first-party cookies:
- Session cookies — keep you signed in (httpOnly).
- theme — remembers your light/dark preference.
- merlin_last_app — remembers which Merlin product you last used so the home page can take you back to it.
We do not use third-party advertising or cross-site tracking cookies.
7. Third-Party Processors
We share data with service providers only as needed to run the Services:
- Logto — authentication and single sign-on
- Stripe — payments and billing
- Anthropic / OpenAI — AI model processing
- Cloudflare — DNS for our domains
- Infrastructure and email providers — hosting and transactional email delivery
Each processor handles data under its own privacy policy and our agreements with them. We may also disclose information if required by law or to protect the rights, safety, or property of Merlin or others.
8. Data Retention & Deletion
Account data is retained while your account is active. After account deactivation, personal data is retained for 30 days (so you can change your mind) and then permanently deleted. Billing records and audit logs may be retained for up to 12 months, or longer where required for tax, legal, or security purposes. Deployed applications and their data are removed when you delete them or your account.
9. Your Rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. You can exercise these rights by contacting us via the contact page; we will respond within the timeframe required by applicable law. We do not discriminate against you for exercising privacy rights.
10. Children
The Services are not directed to children under 13 (or the higher minimum age in your jurisdiction), and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact us and we will delete it.
11. International Users
The Services are operated from the United States. If you use them from other regions, you understand your information will be processed in the United States, where data-protection laws may differ from those in your jurisdiction.
12. Changes to This Policy
We may update this policy from time to time. Material changes will be posted to this page with an updated date, and where appropriate announced in-product. Continued use of the Services after changes take effect constitutes acceptance.
13. Contact
Privacy questions or requests: reach us via the contact page.