Meredic
Products Research Company
Get early access
Products Research Company Get early access
Back to Meredic

Legal

Privacy Policy, Terms of Service, product-specific terms, and Responsible Disclosure for Meredic Research, Inc. These documents govern your use of our website, our products (including Cura), and our engagement with security researchers.

On this page
Privacy Policy Terms of Service Product Terms Responsible Disclosure
Effective June 14, 2026 v1.1
01 — Privacy Policy

Privacy Policy

Meredic Research, Inc. ("Meredic", "we", "our", "us") takes privacy seriously. This policy explains what information we collect across our websites and applications (together, our "Services") — including meredic.com and our products such as Cura — how we use it, and the controls you have over it. Individual products may have additional, product-specific terms set out under Product Terms below.

§ 1

Information we collect

Our website (meredic.com) is a public informational site: it does not operate user accounts, collect payment information, or run persistent user sessions. Our applications (such as Cura) do involve accounts and connected data; the specifics of what each product collects and how it is handled are set out under Product Terms below, which supplement this policy. From the website we may collect the following categories of information:

  • Contact inquiries. If you submit an enterprise inquiry via the contact form, we collect your name, email address, and the message you provide. This information is used solely to respond to your inquiry.
  • Usage data. We may collect anonymised technical data (browser type, referring URL, pages visited, approximate geographic region) through privacy-respecting analytics. We do not use cookies that track individuals across sites.
  • Server logs. Our hosting infrastructure may retain standard server access logs for up to 30 days for security and operational purposes.

§ 2

How we use your information

We use information we collect to:

  • Respond to enterprise inquiries and evaluate potential engagements.
  • Understand aggregate website usage to improve our content.
  • Detect and prevent abuse, fraud, or security threats.
  • Comply with applicable legal obligations.

We do not sell, rent, or share personal information with third parties for their marketing purposes. We do not use personal information to serve behavioural advertising.


§ 3

Data retention

Contact inquiry data is retained for as long as necessary to manage the relevant business relationship, and then deleted or anonymised. We review retention periodically and align practices to applicable law, including the Korean Personal Information Protection Act (PIPA) and, where applicable, the GDPR.


§ 4

Your rights

Depending on your jurisdiction, you may have rights to access, correct, delete, or port personal information we hold about you, and to object to or restrict certain processing. To exercise any of these rights, contact us at the address below. We will respond within 30 days.


§ 5

International transfers

Meredic is incorporated in South Korea. If you are located in the European Economic Area or United Kingdom, please be aware that any personal information you provide may be transferred to and processed in South Korea, which may have different data protection laws than your jurisdiction.


§ 6

Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be indicated by an updated effective date at the top of this page. Continued use of the website after changes are posted constitutes acceptance of the revised policy.

Privacy enquiries

For privacy-related questions or to exercise your rights, contact our team at privacy@meredic.com.
Meredic Research, Inc. · South Korea

02 — Terms of Service

Terms of Service

By accessing meredic.com you agree to these Terms of Service. If you do not agree, please do not use the website. These terms govern use of our public website only; separate agreements govern any enterprise engagement or deployment.

§ 1

Use of the website

You may access and use this website for lawful, informational purposes only. You agree not to:

  • Attempt to gain unauthorised access to any part of the website or its underlying infrastructure.
  • Scrape, crawl, or systematically extract content in a manner that disrupts the operation of the website or places unreasonable load on our servers.
  • Reproduce, republish, or distribute Meredic's proprietary content (including research papers, technical specifications, and marketing copy) without prior written consent.
  • Use the website to transmit malware, spam, or any harmful code.

§ 2

Intellectual property

All content on this website — including but not limited to text, architecture descriptions, benchmark data, branding, and design — is the proprietary intellectual property of Meredic Research, Inc. or its licensors, and is protected by applicable intellectual property laws.

Research publications listed on this website are subject to the licence terms stated in the individual publication. Where no licence is stated, all rights are reserved.


§ 3

Disclaimer of warranties

This website and its content are provided "as is" and "as available" without warranty of any kind, express or implied, including without limitation any implied warranty of merchantability, fitness for a particular purpose, or non-infringement.

Meredic does not warrant that the website will be uninterrupted, error-free, or free of viruses or other harmful components. Technical specifications and performance figures stated on the website reflect conditions at time of publication and may change.


§ 4

Limitation of liability

To the fullest extent permitted by applicable law, Meredic and its officers, directors, employees, and agents shall not be liable for any indirect, incidental, special, consequential, or punitive damages arising out of your access to or use of (or inability to access or use) this website or its content.


§ 5

Third-party links

This website contains links to third-party websites, including Latent Research (latnt.xyz). These links are provided for convenience only. Meredic does not control, endorse, or assume responsibility for the content, privacy practices, or availability of any third-party website.


§ 6

Governing law

These Terms of Service are governed by and construed in accordance with the laws of the Republic of Korea, without regard to its conflict of law provisions. Any dispute arising in connection with these terms shall be subject to the exclusive jurisdiction of the courts located in South Korea.


§ 7

Changes to these terms

We reserve the right to modify these Terms of Service at any time. Updated terms will be posted on this page with a revised effective date. Your continued use of the website following such changes constitutes acceptance of the updated terms.

Legal enquiries

For questions about these terms, contact us at legal@meredic.com.

03 — Product Terms

Product Terms

Some products have additional, product-specific terms that apply in addition to the Privacy Policy and Terms of Service above. Where a product supplement conflicts with those documents in respect of that product, the supplement controls. As we release more products — such as Syneuro and Binary — each will appear here as its own supplement.

Cura

Ambient AI life manager · Android beta
§ 1

What Cura is

Cura gathers information from services you choose to connect, writes a calm daily brief, and helps you keep a schedule and a small set of custom panels. Cura is built on four commitments, which are product principles and contractual undertakings:

  • Glass box, not black box. Every line in your brief and every panel decision traces back to the source signal that produced it.
  • Visible, reversible boundaries. You can always see what Cura can see, per source, and disconnect any source in one step without breaking the app.
  • Propose, confirm, act. Cura proposes; you confirm; only then does it act, log the action, and offer an undo. Cura does not take actions on your behalf without your confirmation.
  • Local-feeling by default. Sensitive raw data is distilled before it leaves your device wherever feasible, and only the distilled signal is sent on.

§ 2

Information Cura processes

  • Account data. Cura uses passwordless email sign-in. We store your email address and basic account metadata to operate your account.
  • Connected-source data. When you connect a source, Cura accesses only the data covered by the scopes you grant. At launch this means your Google Calendar (read access). Additional Google Workspace sources (such as Tasks, Gmail metadata, or Drive) are off by default and are accessed only if and when you connect them and grant the relevant scope.
  • Content you create. Schedule blocks, to-dos, routines, panels, diary entries, and your settings.
  • Device signals. Where you enable them, on-device signals are distilled locally; only the resulting signal — not the underlying raw content — is stored or transmitted.
  • Operational logs. A per-user audit log records each read of your data and each action you accept, so you can review what Cura did and why.

Sensitive categories (health, finance, precise location) are not collected in the current version.


§ 3

How Cura uses your data & AI processing

Cura uses your data only to provide the service to you: to generate your brief, build and update your panels, and surface proposed actions for your confirmation. To produce the brief and panels, distilled signals are processed by Google's Gemini models through the Gemini API, called from our secured server environment. We do not use your personal data to train foundational models, and we do not sell, rent, or share your personal data with third parties for their marketing purposes.

Google user data accessed through Cura is used and transferred in accordance with the Google API Services User Data Policy, including its Limited Use requirements. Cura requests the minimum scopes needed for a feature and only at the point you enable it.


§ 4

Security

Your data is isolated per user by row-level access controls, so you can only ever read or write your own rows. Credentials and API keys are held only in our secured server environment and are never embedded in the app. Connections to connected services use OAuth; we store access and refresh tokens securely and never see your passwords for those services.


§ 5

Your controls, retention & deletion

You can disconnect any source at any time from the app, which stops further access under that source. You can delete individual content, and you can delete your account, which removes your personal data and disconnects your sources. We retain your data for as long as your account is active and delete or anonymise it after account deletion, except where we must retain limited records to meet legal obligations. To request deletion or export, use the in-app controls or contact us at the address below.


§ 6

Beta software

Cura is currently offered as beta software and may change, contain errors, or be interrupted. It is provided "as is" without warranties of any kind, and you should not rely on it as the sole record of time-critical commitments. The limitation of liability in our Terms of Service applies to your use of Cura.


§ 7

Eligibility

Cura is not directed to children. You must be at least the age of digital consent in your jurisdiction to create an account.

Cura privacy & support

For questions about Cura, to exercise your data rights, or to request deletion, contact privacy@meredic.com.
Meredic Research, Inc. · South Korea

04 — Responsible Disclosure

Responsible Disclosure

Meredic operates in regulated environments where security is non-negotiable. We welcome responsible security research and are committed to working openly with researchers who identify vulnerabilities in good faith.

§ 1

Scope

This policy applies to security vulnerabilities affecting:

  • The meredic.com website and any subdomains.
  • The Cura application and its backend APIs and endpoints operated by Meredic.
  • Publicly exposed APIs or endpoints operated by Meredic.
  • Configuration or infrastructure issues that expose non-public data.

This policy does not apply to vulnerabilities in third-party services we use, or to defects in Meredic products deployed within a customer's private infrastructure — those should be reported through your enterprise support channel.


§ 2

How to report

Send a written description of the vulnerability to security@meredic.com. Encrypt your report using our PGP key (available on request) if the details are sensitive. Include:

  • A clear description of the issue and its potential impact.
  • Steps to reproduce, including URLs, payloads, or proof-of-concept code where relevant.
  • Your name or handle, and whether you wish to be credited if we publish an advisory.

§ 3

Our commitments

In exchange for responsible disclosure, Meredic commits to:

  • Acknowledge receipt of your report within two business days.
  • Provide an initial assessment of severity and planned remediation within ten business days.
  • Keep you informed of progress and notify you when the issue is resolved.
  • Not pursue legal action against researchers who act in good faith and comply with this policy.
  • Credit researchers (with their consent) in any public advisory we issue.

§ 4

Responsible research guidelines

We ask researchers to:

  • Avoid accessing, modifying, or deleting data beyond what is necessary to demonstrate the vulnerability.
  • Not perform denial-of-service testing or automated high-volume scanning.
  • Not disclose the vulnerability publicly until we have had a reasonable opportunity to remediate it (typically 90 days from acknowledgement, extendable by mutual agreement).
  • Not use the vulnerability for personal gain or to access customer data.

§ 5

Bug bounty

Meredic does not currently operate a formal bug bounty programme with monetary rewards. We may offer recognition and acknowledgement for significant findings at our discretion. We are evaluating a formal programme and will update this policy if one is introduced.

Report a vulnerability

Email security@meredic.com with a full description of the issue. For sensitive reports, request our PGP key in your first message.

We aim to acknowledge all reports within two business days.

Meredic

An applied AI research lab, building from architecture to product. Makers of Cura.

Products
  • Cura
Research
  • Publications
  • Benchmarks
  • Disclosures
  • Latent ↗
Company
  • About
  • Careers
  • Press
  • Contact
© 2026 Meredic Research, Inc. Korea · South
Responsible disclosure Privacy Terms Product terms