Privacy Policy
Effective: April 16, 2026 · Merico, Inc.
Merico, Inc. and its affiliates ("Merico," "we," "our," or "us") are committed to protecting your privacy. This Privacy Policy explains how personal information is collected, used, and disclosed by the Human Signoff service. By accessing or using Human Signoff, you signify agreement to the collection, storage, use, and disclosure of personal information as described in this Privacy Policy and our Terms of Service.
1. Information We Collect and Its Purpose
Information you provide directly
We collect your name, email address, phone number, and other data you provide when registering for or using Human Signoff. This includes communications between you and Merico. Payment information (such as credit card details) is collected and processed directly by our third-party payment processor, Stripe, Inc. Merico does not receive or store your payment card information. See Stripe's Privacy Policy for details. By using Human Signoff, you consent to the recording, storage, and disclosure of such communications for service-related purposes.
Data collected through your use of Human Signoff
We collect information about how you use the service, including approval and rejection actions, audit log entries, agent action metadata, and other interactions with the service. When you authenticate an approval using biometrics (Face ID, Touch ID, Android Biometrics, or similar), all biometric processing occurs locally on your device via the operating system. Merico never receives, transmits, or stores raw biometric data such as fingerprints or facial geometry. We only receive a pass/fail authentication result and a timestamp. We may monitor and store usage data to protect your safety, assist with regulatory or law enforcement efforts, or protect our rights and property.
Information from third-party services
When you connect Human Signoff to third-party services such as GitHub, Slack, or other platforms, you authorize us to access those services on your behalf. We may receive agent action requests, approval metadata, and other data those services share based on the permissions you grant. We store OAuth tokens or API credentials necessary to maintain the connection; these are encrypted at rest and promptly removed from active systems when you disconnect the integration. Residual copies in backups are purged according to our standard backup retention schedule. The data we receive depends on your privacy settings with those third parties.
How we use this information
We use collected information to operate, maintain, and provide Human Signoff features and functionality; communicate with you via email and push notifications; and send service-related messages including account verification, feature updates, and security notices.
2. Cookies and Tracking Technologies
We and our third-party partners automatically collect usage information when you access Human Signoff, read emails, or otherwise engage with us. We collect this information through cookies, web beacons, and similar tracking technologies.
Information collected includes device and software details such as IP address, browser type, operating system, date and time stamps, and unique identifiers. We also collect usage data including pages visited, links clicked, access frequency, and other actions.
This data is used to remember your preferences, provide personalized content, identify you across devices, monitor service effectiveness, diagnose technical problems, and improve the service.
Our website also loads resources from third-party services that may receive visitor data on page load. These currently include Google Fonts (font delivery; Google may receive your IP address and browser information), Tally (waitlist form; Tally receives data you submit and standard request metadata), and Simple Icons via cdn.simpleicons.org (product logo delivery; the CDN may receive your IP address and browser information). See Google's Privacy Policy and Tally's Privacy Policy for details.
Most browsers allow you to change cookie settings, disable existing cookies, or automatically reject cookies. Note that disabling cookies may limit some functionality of Human Signoff.
3. Sharing of Your Information
We may share personal information in the following circumstances:
- With other companies owned or controlled by Merico, Inc., including subsidiaries and affiliates, who will use your information in accordance with this Privacy Policy.
- With third-party vendors and service providers that perform services on our behalf, including payment processing, web hosting, and analytics.
- With other parties in connection with company transactions such as mergers, acquisitions, or sale of assets.
- With third parties as required by law, subpoena, or if reasonably necessary to comply with legal obligations, enforce our Terms of Service, or protect our rights, property, or safety.
We may also share information in aggregated or anonymized form that does not reasonably identify you as an individual.
4. Control Over Your Information
Profile and data sharing settings
You may update your profile information and change data sharing preferences through your account settings.
Communication preferences
You can stop receiving promotional emails by clicking the "unsubscribe" link in such communications. You cannot opt out of service-related communications including account verification, transactional messages, feature changes, and security notices.
Modifying or deleting information
For questions about reviewing, modifying, or deleting your information, contact legal@merico.ai. We may not be able to modify or delete information in all circumstances.
5. Data Storage and Security
Information collected through Human Signoff may be stored and processed in the United States or any country where Merico, Inc. or its service providers maintain facilities. If you are located outside the United States, please note that we may transfer information to a jurisdiction that does not have the same data protection laws as your jurisdiction.
We use commercially reasonable physical, administrative, and technological safeguards to preserve the integrity and security of all information collected. However, no security system is impenetrable and we cannot guarantee absolute security. In the event of a breach of security, we will take reasonable steps to investigate and, where appropriate, notify affected individuals in accordance with applicable laws.
6. Data Retention
We retain different categories of data for different periods based on their purpose:
- Account data (name, email): retained while your account is active and for up to 30 days after deletion to allow recovery.
- Approval and audit logs: retained for the duration of your subscription plus 1 year, or longer if required by law or your organization's compliance needs.
- Biometric authentication results (pass/fail and timestamps only): retained alongside the associated audit log entry.
- Integration tokens and credentials: retained while the integration is active and promptly removed from active systems upon disconnection. Residual copies in backups are purged according to our standard backup retention schedule.
- Support communications: retained for up to 2 years after resolution.
- Billing records: retained as required by tax and accounting regulations (typically 7 years).
You may request deletion of your data at any time by contacting legal@merico.ai. Some data may be retained beyond your request where required by law, contractual obligation, or your organization's compliance requirements, as described in the retention periods above.
7. Children's Privacy
Human Signoff is not intended for users under the age of eighteen (18), and we do not knowingly collect or solicit any information from anyone under eighteen. If we learn that we have inadvertently collected personal information from a person under eighteen, we will delete that information as quickly as possible. If you believe we may have information from a person under eighteen, please contact legal@merico.ai.
8. Links to Other Websites and Services
Human Signoff may contain links to third-party websites and services. These websites have their own privacy policies, and we do not accept responsibility or liability for their practices. We recommend reviewing the privacy policies of any third-party sites you visit.
9. Contact Us
For questions about this Privacy Policy or Human Signoff, please contact legal@merico.ai.
10. Changes to This Privacy Policy
We may modify or update this Privacy Policy from time to time. When we make material changes, we will update the effective date at the top of this page. Continuing to use Human Signoff after changes are published means you consent to the updated policy.