Privacy Policy

Effective: September 6, 2026

Your privacy is fundamental to how we build and operate MeraChat, a product of Infergent Labs Private Limited. This policy explains how we collect, use, store, and protect your personal information.

1. Information We Collect & How We Use It

1.1 Information We Collect:

  • Account Information: Name, email address, and profile picture from OAuth providers (Google, GitHub, etc.)
  • Content Data: Your inputs (prompts), AI-generated outputs (responses), conversation history, and timestamps
  • Usage Data: Token consumption, model selections, feature usage, and interaction patterns
  • Technical Data: IP address, browser type, device information, operating system, and access times
  • Location Data: Approximate location (city/region level) derived from your IP address for service optimization, security, and compliance purposes. We do not collect precise GPS location.
  • Payment Information: Billing address and payment method details (processed securely by our payment providers)
  • Content Reports: When you report AI-generated content as harmful, offensive, inaccurate, or otherwise problematic, we collect the report category, optional details you provide, and a reference to the reported message to improve content safety

1.2 How We Use Your Information:

  • To provide, maintain, and improve our services
  • To personalize your experience and remember your preferences
  • To process transactions and manage subscriptions
  • To monitor usage, enforce limits, and prevent abuse
  • To communicate with you about service updates, security alerts, and support
  • To comply with legal obligations and protect our rights
  • To analyze trends and improve our AI services (in anonymized form)
  • To review reported content and improve the safety and quality of AI-generated responses

1.3 Data Security: We implement industry-standard security measures including encryption in transit (TLS) and at rest, secure access controls, and regular security audits. However, no method of transmission over the internet is 100% secure.

1.4 Data Sharing: We do not sell your personal data. We share data only with: (a) AI providers to process your requests, under contractual data protection obligations appropriate to that sharing, (b) service providers who assist our operations under similar contractual obligations, (c) when required by law, and (d) with your explicit consent.

1.4.1 Aggregated and De-Identified Data: We may create aggregated or de-identified data from the information described above — data that has been stripped of anything that could reasonably identify you. Once data is aggregated or de-identified in this way, it is no longer personal data, and we may use, retain, and share it for any lawful business purpose, including research, benchmarking, and improving our services, without further restriction under this policy.

1.5 Your Privacy Rights: Depending on your location, you may have the following rights regarding your personal data:

  • Right to Access: Request a copy of the personal data we hold about you
  • Right to Rectification: Request correction of inaccurate personal data
  • Right to Erasure: Request deletion of your personal data (subject to legal requirements)
  • Right to Data Portability: Receive your data in a structured, machine-readable format
  • Right to Object: Object to processing of your personal data for certain purposes
  • Right to Restrict Processing: Request limitation of processing in certain circumstances
  • Right to Withdraw Consent: Withdraw consent where processing is based on consent

To exercise any of these rights, please contact us at support@merachat.ai. We will respond to your request within 30 days.

1.6 International Data Transfers: Your data may be transferred to and processed in countries other than your country of residence, including India where our servers are located. We ensure appropriate safeguards are in place for such transfers in compliance with applicable data protection laws.

1.7 Children's Privacy: While our app may be rated for all ages on app stores (e.g., 3+ on Google Play), the use of our AI services requires a minimum age. Our services are not intended for unsupervised use by children. The following age requirements apply:

  • Users must be at least 13 years old to use our services (or 16 years old in the European Economic Area, or 18 years old in India).
  • Our services are not available to anyone in India under 18. Elsewhere, users under 18 must have parental or legal guardian supervision and consent to use the services.
  • We do not knowingly collect personal data from children below the applicable minimum age without parental consent.

If we become aware that we have collected personal data from a child without appropriate consent, we will take steps to delete such information promptly. If you believe a child has provided us with personal data, please contact us immediately.

1.8 Changes to This Policy: We may update this privacy policy from time to time to reflect changes in our practices, services, or legal requirements. We will provide at least 30 days' advance notice of material changes via email or through prominent notice in our services, in the same manner described in our Terms of Service. Non-material changes may take effect immediately upon posting. The "Effective" date at the top of this page indicates when this policy was last updated, and we maintain an archive of previous versions available on request.

2. Data Collection & Retention

2.1 Conversation Storage: Your conversations are stored securely in our encrypted database. We retain this data to provide you with conversation history, enable search functionality, and allow data export.

2.2 Data Retention: We retain your data for as long as your account is active or as needed to provide services. Upon account deletion:

  • All conversations and messages are deleted from our active systems within 30 days. A copy may briefly persist in encrypted backups until those backups are cycled out in the ordinary course, after which it is also deleted.
  • Account information is anonymized or deleted
  • Aggregated, anonymized analytics data may be retained for service improvement
  • Data required for legal compliance may be retained as necessary

2.3 Data Export: You can export all your conversation data at any time from the Settings page in JSON or Markdown format. We support your right to data portability.

2.4 Cookies and Tracking: We use the following types of cookies and tracking technologies:

  • Essential Cookies: Required for authentication, session management, security, and basic functionality. Cannot be disabled.
  • Preference Cookies: Remember your settings, preferences, and customizations.
  • Analytics Cookies: Help us understand how users interact with our services. We use this data to improve our services.

We do not use third-party advertising or marketing cookies. Most browsers allow you to control cookies through settings. Note that disabling essential cookies may prevent you from using certain features.

2.5 Model Training: We do not use your conversations to train AI models. We improve our services using aggregated and de-identified data (Section 1.4.1) and by reviewing content that has been reported or flagged for safety, as described in our Terms of Service. Webpage content read by the MeraChat browser extension is never used to train AI models. See Section 8.1.1.

2.6 Do Not Track: Our services currently do not respond to "Do Not Track" browser signals because there is no industry standard for this feature. We recommend managing cookies through your browser settings.

2.7 Data Retention After Account Termination: After account termination, we may retain certain data as required by law, for legitimate business purposes (such as fraud prevention), or as necessary to fulfill our legal obligations. Aggregated or anonymized data may be retained indefinitely.

2.8 Incognito Conversations: MeraChat offers an incognito mode, which you turn on from the conversation header. While it is on, the exchange is not written to our database: it does not appear in your history, cannot be searched or exported, and is gone when you leave it. This includes anything the browser extension reads for you during an incognito conversation, which is held only for as long as the request takes to answer and then expires. Your account details, usage counts, and the technical logs described in Section 1.1 are still recorded, because we need them to run the service and bill it — incognito mode governs conversation storage, not the fact that you used MeraChat.

3. Third-Party AI Services

3.1 AI Providers: Our service integrates with third-party AI models from providers including OpenAI (GPT models), Anthropic (Claude), Google (Gemini), DeepSeek, xAI (Grok), Inception (Mercury), MiniMax, Mistral AI, Z.ai (GLM models), and others. When you use our service, the following data may be shared with these providers to generate responses:

  • Your text prompts and messages
  • Relevant conversation history needed for contextual responses
  • File attachments or images you include in your messages
  • Audio recordings when you use speech-to-text (voice input) features
  • The content of web pages you ask the MeraChat browser extension to read, including a picture of the visible page where it has no readable text (Section 8.1)

We do not share your name, email address, account information, or other personal identifiers with AI providers. This sharing is necessary to provide the service you have asked for: when you send a message, you direct us to pass it to the AI provider whose model you selected.

3.2 Third-Party Terms: Your use of AI features may be subject to additional terms from our AI providers. Each provider has their own privacy policy and data handling practices:

3.3 Data Minimization: We only share the minimum data necessary with AI providers — specifically your text prompts and relevant conversation context needed to generate responses. We do not share your account information, email address, or metadata with AI providers unless required for the service.

3.4 No Third-Party Sales: We do not sell, rent, or trade your personal information or conversation data to third parties for marketing or advertising purposes.

3.5 Third-Party Data Processing: When you use AI models from third-party providers, your Input may be processed on servers located in various countries including the United States (OpenAI, Anthropic, Google, xAI, Inception), the European Union (Mistral AI, which is established in France), Singapore (MiniMax), and China (DeepSeek, Z.ai). Each provider handles data according to their own policies and applicable laws.

3.6 Third-Party Links: Our services may contain links to third-party websites, services, or content. We are not responsible for the privacy practices, content, or availability of these third-party services. Your use of third-party services is at your own risk and subject to their terms.

3.7 Service Integrations: We may offer integrations with third-party services (such as file storage, productivity tools, etc.). When you enable such integrations, you authorize us to access and use data from those services as necessary to provide the integration functionality.

4. Security

4.1 Our Security Measures: We implement industry-standard security measures to protect your data, including encryption in transit (TLS) and at rest, secure authentication, regular security audits, and access controls. However, no method of transmission over the Internet or electronic storage is 100% secure.

4.2 Your Security Responsibilities: You are responsible for:

  • Maintaining the confidentiality of your account credentials
  • Using strong, unique passwords and enabling two-factor authentication where available
  • Notifying us immediately if you suspect unauthorized access to your account
  • Not sharing your account with others
  • Logging out from shared or public devices

4.3 Security Vulnerabilities: If you discover a security vulnerability in our services, please report it responsibly to support@merachat.ai. Do not exploit or publicly disclose vulnerabilities before giving us reasonable time to address them.

4.4 Data Breach Notification: In the event of a data breach affecting your personal information, we will notify you and relevant authorities as required by applicable law, in the manner and timeframe that law requires. Where required, that notification will describe the nature of the breach, the affected data categories, and steps you can take to protect yourself.

5. Legal Basis for Processing (GDPR)

Under the General Data Protection Regulation (GDPR), we process your personal data based on the following legal bases:

  • Performance of Contract (Article 6(1)(b)): Processing necessary to provide our services, including account creation, conversation processing, and subscription management.
  • Legitimate Interest (Article 6(1)(f)): Processing for analytics, service improvement, security, fraud prevention, and abuse detection, where our interests do not override your rights.
  • Consent (Article 6(1)(a)): Processing based on your explicit consent, such as optional integrations or communications you choose to enable. You may withdraw consent at any time by disabling the relevant feature or contacting us.
  • Legal Obligation (Article 6(1)(c)): Processing necessary to comply with applicable laws, regulations, or legal proceedings.

5.1 Data Protection Officer: For GDPR-related inquiries, you may contact us at support@merachat.ai. We will respond to your request within 30 days.

5.2 Right to Lodge a Complaint: If you are in the EEA, you have the right to lodge a complaint with your local data protection authority if you believe your data has been processed unlawfully.

6. India — Digital Personal Data Protection Act (DPDPA)

Infergent Labs Private Limited, the company that owns and operates MeraChat, acts as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (DPDPA). As a user ("Data Principal"), you have the following rights:

  • Right to Access: Obtain a summary of your personal data and processing activities.
  • Right to Correction and Erasure: Request correction of inaccurate data or deletion of your personal data.
  • Right to Grievance Redressal: Submit complaints regarding data processing to our grievance contact.
  • Right to Nominate: Nominate another individual to exercise your rights in case of death or incapacity.

6.1 Consent: We process your personal data based on your consent, which is obtained at the time of account creation. You may withdraw consent at any time by deleting your account or contacting us, though this may affect your ability to use our services.

6.2 Children's Data: Our services are not available to anyone in India under 18 years of age. We do not knowingly process the personal data of children in India, and if we learn that we have done so we will delete it promptly.

6.3 Grievance Officer: For any grievances related to your personal data processing, please contact our Grievance Officer at support@merachat.ai. We will acknowledge your grievance within 48 hours and resolve it within 30 days.

7. California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):

  • Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you, the sources of collection, the business purposes, and the categories of third parties with whom we share it.
  • Right to Delete: You may request deletion of your personal information, subject to certain exceptions.
  • Right to Correct: You may request correction of inaccurate personal information.
  • Right to Opt-Out of Sale/Sharing: We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising.
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights.

7.1 Categories of Personal Information Collected: Identifiers (name, email), internet activity (usage data, conversations), geolocation data (approximate, from IP), and commercial information (subscription and payment data).

7.2 No Sale of Personal Information: We have not sold personal information in the preceding 12 months and do not intend to do so.

7.3 How to Exercise Your Rights: To submit a request, email us at support@merachat.ai. We will verify your identity and respond within 45 days. You may also designate an authorized agent to submit requests on your behalf.

8. MeraChat Browser Extension

This section describes the MeraChat browser extension for Google Chrome, which opens MeraChat in Chrome's side panel. The extension is a thin shell around the MeraChat web application: the panel loads merachat.ai in a frame, and everything you do inside it is handled exactly as described in the sections above. This section covers only what is specific to the extension.

8.1 Reading the Page You Are On: When you ask MeraChat about the page you are viewing — for example "summarise this page" — the extension reads the text of that one tab and sends it to our servers so the AI can answer. This happens only when you ask. The extension does not read pages in the background, does not read your other tabs, and does not follow where you browse or how long you spend on any page. It reads nothing until a request you made requires it. The address and title of a page you do ask about are received and kept with that conversation, as described in Section 8.1.1.

8.1.1 What Is Sent and Kept: When a page is read we receive its rendered text, its address, and its title. These become part of that conversation and are retained with it, under the same terms as anything else you send us (Sections 1 and 2). Page content is not used to train AI models — this is a commitment in our Terms of Service (Section 5.5.1). If you delete the conversation, the page content goes with it. In an incognito conversation (Section 2.8) it is never written to our database at all: it is held only for as long as the request takes to answer and then expires.

8.1.2 Pages With No Readable Text: Some pages have no text to read — a map, a design tool, a scanned document, or anything drawn rather than written. When that happens, and only then, the extension captures a picture of the visible part of that one tab and sends it so the AI can answer. That picture is not stored. It is passed to the AI model to answer your question and then discarded; we keep only a note that a picture was taken, and of which page. It is never saved to our file storage and never appears as an attachment on your message.

8.1.3 Pages MeraChat Will Not Read: Some pages are refused even if you ask. The rule is that MeraChat will not read a page where you are entering a secret: sign-in pages, payment and checkout pages, and password managers. It refuses these by their address and also by noticing a password, card or one-time-code field on the page, wherever it is hosted. When a page is refused, no content from it is sent to us — you are told which page was refused and why. Beyond these, whole categories of site are refused as well, described in Section 8.1.3.1. Webmail is not refused: your inbox is your own content and you asked about it. Think before asking about a page that shows financial, medical, or other sensitive information: its content is sent to the AI provider you selected (Section 3). This is a set of rules rather than a judgement about every site on the web, so treat it as a floor and not a guarantee.

8.1.3.1 Structural Safeguards: Alongside the refusals described in Section 8.1.3, three further measures apply. Category refusals: the extension carries a built-in list, shipped inside the extension itself rather than fetched from us, of site categories it will not read at all — banking sites, cryptocurrency exchanges, government identity portals such as Aadhaar and DigiLocker, patient health portals, and pages whose address indicates a money transfer. On these the refusal happens in your browser, so no page content is read and none is sent. The site's name is sent — its domain, not the full address of the page — because the assistant has to be able to tell you which site it declined and why; it is recorded with that conversation in the same way as the rest of it (Sections 1 and 2). The list matches sites by the shape of their address, which means it is a floor and not a census: it will not recognise every bank or clinic in the world, and it may occasionally refuse a public page on a site it recognises. The categories named here are indicative, and the underlying list is updated from time to time without separate notice to you. Asking first: some pages are allowed but likely to show your own financial or health records — the income-tax, GST and provident-fund portals, and pharmacy or clinic accounts. On these the extension asks you in the panel before anything is read, and you may tell it not to ask again for that site. That choice is stored in your browser, not with us. Reduced-surface reading: the extension collects only text that is actually rendered on the page, so content the page has removed from display is not collected and not sent. This is a reduction in what is exposed, not a filter for every technique — text that is rendered but made hard to see remains readable, which is what the measure below is for. Untrusted-content handling: page content is treated as data and never as instructions. We screen it for text that appears to be addressed to the AI assistant rather than to you, and where such text is found the assistant is instructed to disregard it and to tell you it was present, so that you can judge it yourself. These are risk-reduction measures and not guarantees. Prompt injection is an unsolved problem across the industry, and we do not represent that MeraChat is immune to it.

8.1.3.2 Requests from Website Operators: If you operate a website and would prefer that the MeraChat extension not read pages on your domain, you may ask us to add it to the list described in Section 8.1.3.1. Write to us at support@merachat.ai from an address at the domain concerned, or otherwise demonstrate that you are authorised to act for it. We will acknowledge your request within 48 hours and tell you our decision within 30 days, on the same footing as the grievance process in Section 6.3. We expect to honour most such requests. We do not undertake to honour all of them: we may decline a request that we cannot verify as coming from the operator, or one that seeks to restrict a user from reading information that is public and lawfully available to them. Changes to that list take effect with the next published version of the extension, so a decision to add a domain reaches users when Chrome delivers that update rather than immediately. Adding a domain prevents future reading; it does not by itself remove page content already held in a user's conversation, which is deleted when that user deletes the conversation or exercises the rights in Section 1.5.

8.1.4 User Responsibility: The extension reads a page only when you ask it to, and reads only that page. You choose which pages to direct it at.

  • User Assurances: By using the extension to read, summarize, or analyze any webpage, you warrant and represent that you have the lawful right, authorized access, and necessary permissions (including compliance with the target website's Terms of Service) to process that webpage content.
  • Prohibition of Mass Scraping: You are strictly prohibited from using MeraChat for automated, systematic, or industrial-scale data harvesting, web scraping, or crawling that violates Section 43 of the Indian Information Technology Act, 2000.
  • Indemnification: You initiate each request, and you are responsible for the pages you direct the extension at. You agree to indemnify and hold harmless Infergent Labs Private Limited from any third-party claims, legal notices, or penalties arising from your unauthorized processing of restricted, proprietary, or private portal data.

8.1.5 Site Access and Why It Is Broad: Chrome asks for permission to "read and change all your data on all websites" because the extension cannot know in advance which page you will ask about, and Chrome offers no way for a side panel to request access to one page at the moment you ask. You can restrict this at any time in Chrome's extension settings under Site access. Note that restricting it also signs you out of the panel, because the same permission is what lets the panel see that you are logged in to merachat.ai.

8.2 Text You Choose to Send: The extension adds one item to Chrome's right-click menu, "Ask MeraChat about this", which appears only when you have selected text. Choosing it places that text into the panel's message box, unsent, so you can add your own question or delete it. Selected text reaches our servers only if you then send the message yourself. Nothing is captured automatically. Selecting text is one of two ways page content reaches us; the other is asking MeraChat about the page you are on, described in Section 8.1. Neither happens without an action you take.

8.3 Local Storage on Your Device: The extension keeps a small amount of data in Chrome's own extension storage, on your device. None of it is sent to us, and none of it is a record of pages you have visited. It is:

  • Text you selected, held briefly on its way from the right-click menu into the panel. Deleted as soon as the panel receives it.
  • Which tabs currently have the panel open, and which conversation belongs to each — this is what makes Section 8.5.1 work. It holds tab numbers and MeraChat conversation identifiers; it does not hold page addresses, titles, or content.
  • A single number recording that you have seen the "Before you start" notice, so it is not shown to you every time.

The first two live in session storage and are cleared entirely when you close your browser. The third lives in local storage and persists until you uninstall the extension; it is stored per browser rather than per account, so installing the extension on another machine will show you the notice again. The extension keeps no other data on your device and no persistent local record of your activity.

8.4 Signing In: The extension has no login of its own and never handles your password. It uses the merachat.ai session already present in your browser, so if you are signed in on the web you are signed in the panel, and signing out on the web signs you out of the panel. Authentication happens on merachat.ai in an ordinary browser tab, not inside the extension.

8.5 Data Handled Through the Panel: Conversations you hold in the side panel are treated the same as conversations on the website. This includes your account information (Section 1.1), your prompts and the AI responses, usage data, and technical data such as your IP address. Messages sent from the panel are recorded as originating from the extension so that we can understand how the panel is used.

8.5.1 Each Tab Has Its Own Conversation: The panel keeps a separate conversation for each browser tab, so switching tabs switches the conversation rather than carrying one across everything you look at. This is a privacy measure as much as a convenience: it stops a page you asked about at your bank and a page you asked about on a stranger's blog from being pooled into a single stored record. The map of which tab owns which conversation is kept on your device only (Section 8.3) and is cleared when you close your browser; the conversations themselves are stored under your account as normal, and you can find them in your history.

8.6 Analytics: The panel loads the MeraChat web application, and Google Analytics runs within it as it does on the website, collecting usage and interaction data as described in Section 1.1. It does not collect information about other pages or tabs.

8.7 Third-Party AI Providers: Messages you send from the panel are processed by the same AI providers listed in Section 3, under the same terms. The extension does not introduce any additional third party.

8.8 Incognito — Two Different Things: The word is used for two features that are unrelated, and it is worth separating them.

8.8.1 MeraChat Incognito: The panel header carries MeraChat's own incognito toggle, the same one the website has. Turning it on means the conversation is not stored — see Section 2.8. Page content the extension reads during an incognito conversation is never written to our database; it is held only long enough to answer the request and then expires. While incognito is on, the panel's conversation list and "new chat" are unavailable, because there is nothing being saved to list.

8.8.2 Chrome Incognito Windows: A different thing, and Chrome's, not ours. Chrome disables extensions in Incognito unless you explicitly allow them, and Incognito keeps a separate session. The panel will therefore show you as signed out in a Chrome Incognito window even when you are signed in normally.

8.9 Removing the Extension: Uninstalling the extension from Chrome removes it and clears everything it stored on your device, both the session and local storage described in Section 8.3. It does not delete your MeraChat account or your conversation history — to delete those, exercise the rights described in Section 1.5 or contact us at support@merachat.ai.

9. Contact Information

If you have questions, concerns, or feedback about our privacy practices, please contact us:

Infergent Labs Private Limited

Email:

support@merachat.ai

For privacy-related requests under GDPR or other data protection laws, we will respond within 30 days. For urgent security matters, please include "URGENT" in your subject line.

For our full Terms of Service, please visit our Terms of Service page.

© 2026 Infergent Labs Private Limited. MeraChat is a product of Infergent Labs Private Limited. All rights reserved.

Privacy Policy | MeraChat