Privacy Policy

Last Updated: July 15, 2026 · Notice version 2026-07-15

Introduction

Welcome to Merak ("we," "our," or "us"). We are committed to protecting your privacy and handling your data in an open and transparent manner. This Privacy Policy explains how we collect, use, store, and protect your information when you use the Merak mobile application and related services.

By using Merak, you agree to the collection and use of information in accordance with this policy.

1. Information We Collect

1.1 Information You Provide

Account Information

When you create an account, we collect:

1.2 Information We Generate

Learning Progress Data

As you use the app, we automatically collect:

Learner-Submitted Text and Support

When you choose a feature that accepts text, we collect the text needed to provide it, including path-chat messages, free-form answers, content reports, and support feedback. Do not include information you do not want processed as part of that request.

Usage Analytics

We collect:

Diagnostics Data

To maintain app quality, we automatically collect:

1.3 Information We Do NOT Collect

2. How We Use Your Information

2.1 Core Functionality

2.2 Service Improvement

2.3 Communication

2.4 We Will Never

3. AI-Generated Content and Learning Models

Learning content in Merak is generated by AI. Artificial-intelligence models turn topics into paths, write the learning material, and evaluate some learner responses. Automated quality checks run before content reaches the app, and human review is targeted rather than universal. When you use path chat or submit a free-form answer, the text and the minimum curriculum context needed for that request may be sent to Groq, OpenRouter, and a model provider selected through OpenRouter. We exclude direct account identifiers from model input.

How a path is built. A Merak path is not a single prompt to a chatbot. Merak first retrieves source material for the topic and fixes it as the evidence set for that build; it plans the factual content as a ledger of individual claims; it renders cards and questions against those claims; it re-checks grounded claims against the evidence set; and it submits the finished material to two independent model families acting as a review jury, neither of which wrote it. A failed check regenerates the specific card, question or claim that failed rather than the whole course. Every build runs inside fixed time, call and cost limits and fails closed.

What that means for your data. Merak keeps no permanent corpus of retrieved source material; the evidence set for a build is acquired for that build. The search and model requests made during a build are derived from the topic and objectives of the path being generated — which, for a path you asked for, includes the topic text you typed. Direct account identifiers are excluded from those requests.

Web search during generation. Retrieving that source material is a web search, and it runs on every course Merak builds. The search is carried out through OpenRouter's search tool by Perplexity, or by Exa if the primary search is unavailable; a single build can reach both. Those companies receive the search query — built from the topic, the objectives, and the specific factual claims being checked — and not your account. Merak holds no account with either company and reaches them only through OpenRouter. Searches are capped at 12 per course, and social networks, forums and aggregator sites are excluded in the request itself.

4. Tracking and Advertising

We do not use advertising tracking. Merak does not participate in ad networks, does not use tracking pixels, and does not share data with advertising services. We do not use the Apple Identifier for Advertisers (IDFA) or any cross-app tracking technology.

Our iOS app does not use cookies. Your authentication token is stored securely on your device using the iOS Keychain.

Because Merak does not use cross-app advertising tracking, the App Tracking Transparency (ATT) prompt is not required or shown.

5. How We Store and Protect Your Data

5.1 Data Storage

5.2 Security Measures

5.3 Data Retention

6. Data Sharing and Third Parties

6.1 Third-Party Services We Use

6.2 Apple

When you download and use Merak through the Apple App Store, Apple may collect certain data in accordance with their own privacy policy, including app usage data, crash logs, and performance metrics via TestFlight or App Store. This data is governed by Apple's Privacy Policy.

6.3 Legal Disclosure

We may disclose your information if required by law, such as in response to valid legal process, to protect our rights, to prevent fraud, or in connection with a merger or acquisition (users will be notified).

7. Your Rights and Choices

7.1 Access Your Data

Create a portable JSON export from Settings → Request My Data when signed in to a permanent account. The app verifies the file's integrity before presenting the iOS share sheet. The export covers Merak's primary account, profile, learning, progress, rewards, reports, support, entitlement, and transaction records. Processor-held diagnostics and analytics require the manual rights process described on Merak Support.

7.2 Correct Your Data

You can update your display name directly in the app. Your username is generated by Merak and cannot be changed. For other corrections, use Merak Support.

7.3 Delete Your Data

Delete your account through the app when signed in: Settings → Account → Delete Account. Guest journeys can be cleared from this device in Settings. During beta, use the current request instructions on Merak Support for any manual account request.

When the in-app deletion transaction succeeds, Merak removes the authentication account and primary application records linked through that account. Processor logs, legally retained transaction records, and disaster-recovery copies may remain until their applicable retention cycle expires. Use Merak Support if you need a processor-specific rights request or a deletion problem investigated.

7.4 Control Notifications

Manage notification preferences in iOS Settings → Merak → Notifications, or within the app under Settings → Notifications.

8. Children's Privacy

The current controlled pilot is available only to people who confirm they are 13 years or older. Merak stores the version of that confirmation and does not ask for a date of birth. If you believe a person under 13 is using the pilot, use Merak Support so access and deletion can be investigated.

The pilot is invite-only. Merak stores the hashed one-time invitation record, your admission status, admission sequence number, and any later revocation status. The plaintext invitation code is not retained. These admission records are included in account export and removed or de-identified through account deletion rules.

Product experiments are disabled for the current controlled pilot. If a later release enables experiments, Merak will store stable assignment and actual exposure as separate records and will not place raw prompts, answers, support messages, or direct contact details in experiment context.

9. International Users

Merak is operated by a developer based in Turkey and uses providers that may process data in other countries. Where required, international transfers must rely on an applicable legal mechanism rather than consent language alone.

9.1 European Users (GDPR)

If you are located in the European Economic Area (EEA), you have the following rights under the General Data Protection Regulation:

Legal Bases for Processing: Consent (account creation), contract performance (providing the learning service), legitimate interests (service improvement, fraud prevention), and legal obligation.

Data Controller: Merak

9.2 California Users (CCPA)

If you are a California resident, you have the right to:

To exercise these rights, use the in-app account tools or the current request instructions on Merak Support.

10. Changes to This Policy

We may update this policy. Material changes will receive a new notice version and an appropriate in-app or service notice before they apply. Where consent is the legal basis, a material purpose change requires a new choice rather than assumed acceptance.

11. Contact Us

Privacy: Use Settings → Request My Data in the app when signed in. During beta, use the current request instructions on Merak Support for manual privacy requests.

Support: Merak Support

Response Time: During beta, manual privacy requests are handled through the current support instructions and applicable legal timelines.

Summary (TL;DR)