Merlin

Privacy

What is stored, where, who else sees any of it, and for how long. Paragraphs marked ⚑ are for a lawyer to read before this is relied on.

Who runs this instance ⚑

This instance of Merlin is run by its operator, reachable at the address on the letters it sends. The operator is the controller of the data described here.

What is stored

Your address, a name if you gave one, a photo if you uploaded one, and a hashed password. For every brand: what you recorded about it, every file you uploaded, every piece made and every picture rendered, every publication and its numbers, every proposal Merlin wrote and whether you took it, and a log of what was done and by whom. For every generation: what it cost, as the model's API reported it. Sessions are kept so you can see where you are signed in and end one.

Where

The database is a managed cluster and the files are in object storage, both at DigitalOcean, in the region the operator chose. Nothing is stored in your browser but the session cookie and a few page preferences.

Who else sees any of it

Every third party Merlin sends anything to, and what, and when:

Nobody else. Merlin has no analytics, no advertising and no tracking of you.

For how long ⚑

As long as the account exists. Deleting the account from Settings removes the address, the name, the photo and the password at once, and every brand it owns with everything in it; what you did on other people's brands stays on those brands, attributed to a removed account. Files in object storage are removed with the record that owned them. Backups of the database are kept by the managed cluster for the period it states, and a deleted account is gone from them when they age out.

Your rights ⚑

You can export every brand you own as a file from the brand's context page, at any time. You can delete the account yourself. For anything else — a copy of what is held about you, a correction — write to the operator at the address above.

Last changed 12 September 2026.