Skip to content
Merito

Privacy Policy

Last updated: July 14, 2026

1. Scope and Who We Are

1.1. This Policy applies to the Merito platform at merito.eb1mentor.com and associated subdomains, applications, tools, and features (the "Service"), operated by Mind Arc LLC ("Merito," "we," "us," "our").

1.2. It covers individuals who use the Service directly (Free and Pro users), attorneys and law-firm members who use the Counsel Product, and individuals whose case data is shared into a Firm's workspace ("Represented Users").

1.3. Why immigration data gets extra care. Case documents in an immigration matter can include sensitive personal information about you and others. We limit who can access this data, minimize how it is processed, and design our tools to read structured, purpose-built data rather than passing raw files around unnecessarily (see Section 4).


2. Information We Collect

We collect the following categories of information:

2.1. Account information. Your name, email address, password (stored in hashed form), plan type, and settings.

2.2. Case content. Documents, files, text, notes, and other materials you upload or create in connection with a case, and the structured data we derive from them (see Section 4).

2.3. USCIS receipt numbers. If you use case-status features, we collect the USCIS receipt number(s) you provide. Receipt numbers are stored in encrypted form and are used to retrieve and display case-status information for you.

2.4. Profile information. Optional professional or biographical details you choose to add to support your use of the tools.

2.5. Billing information. When you make a payment, our payment processor (Stripe) collects and processes your payment-card details. We do not receive or store your full card number. We retain limited billing records (for example, plan, amount, date, and a payment reference) for accounting and compliance.

2.6. Usage and analytics data. Information about how you interact with the Service — pages viewed, features used, device and browser information, approximate location derived from IP, and event data — collected through our analytics provider (PostHog) and our infrastructure.

2.7. Communications. Emails and support messages you exchange with us, sent and delivered through our email provider (Resend).

2.8. Cookies and similar technologies. See Section 8.

We do not intentionally collect special categories of data beyond what your case content may contain, and we do not ask for information we do not need to provide the Service.


3. How We Use Your Information

We use your information to:

3.1. provide, operate, and secure the Service, including building the structured Case File and running the tools you choose to use;

3.2. process payments, manage subscriptions and Credits, and maintain financial records;

3.3. send you transactional messages (for example, account, security, and billing notices) and, where you have opted in, product updates;

3.4. detect, prevent, and respond to fraud, abuse, security incidents, and violations of our Terms;

3.5. understand and improve the Service through aggregated, de-identified usage analysis; and

3.6. comply with legal obligations and enforce our agreements.

We do not sell your personal information, and we do not use your case content to train, fine-tune, or develop any AI or machine-learning model (see Section 4).


4. How Case Documents Are Processed (and the No-Training Commitment)

4.1. Case File, not raw files. When you add documents, we build a structured "Case File" — a purpose-built representation of the relevant information — once. Our tools then read from that structured Case File rather than repeatedly reading your raw source files. This minimizes how widely raw documents are handled.

4.2. AI processing vendor. To power AI-assisted features, portions of your structured case data are processed by our AI vendor, Anthropic, through its commercial API.

4.3. No training on your data. We do not use your case content to train, fine-tune, or develop any AI model, and, under the commercial terms governing our use of Anthropic's API, your inputs and outputs are not used to train Anthropic's models. Your case data is processed only to generate the outputs you request.

4.4. Outputs are drafts. As explained in our Terms and Disclaimer, AI outputs are drafts and educational materials for your review, not predictions or legal advice.


5. Free Tools and the RFE Decoder — What We Don't Keep

5.1. Some tools are designed to process input without retaining it.

5.2. RFE Decoder. When you paste or upload a Request-for-Evidence letter into the RFE Decoder, the letter itself is not stored. It is held only in memory for the duration of your request, analyzed, and then discarded. Only the structured decode result is stored for you; the original letter text is not written to any database or storage system.

5.3. For tools of this kind, we may record a fully de-identified usage-statistics entry that is not linked to you, your account, your case, or your session, solely to understand overall tool usage. That entry contains no case content and cannot reasonably be used to identify you.


6. Who We Share Information With

We share information only with the service providers ("processors") that help us operate the Service, and only as needed for them to perform their function. Our current processors are:

  • Supabase — database, authentication, and file storage.
  • Anthropic — AI processing (subject to the no-training commitment in Section 4).
  • Vercel — application hosting; handles the traffic required to serve the Service.
  • Inngest — background-job orchestration, including jobs that build your Case File and run scheduled tasks.
  • Stripe — payment processing (we do not store full card numbers).
  • Resend — transactional and opt-in email delivery.
  • PostHog — product analytics.
  • Internet Archive — where you use archiving features, we submit URLs you designate to the Internet Archive's "Save Page Now" service to create a public, time-stamped archive of that web page. Do not archive a page you do not wish to be publicly archived.

6.1. Each processor is bound by contractual obligations to protect the information they process for us and to use it only to provide their service.

6.2. We do not sell your personal information and do not share it for cross-context behavioral advertising.

6.3. Legal and safety disclosures. We may disclose information if required by law, subpoena, or legal process, or where we reasonably believe disclosure is necessary to protect our rights, users, or the public, or to investigate fraud or security issues.

6.4. Business transfers. If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.


7. Counsel Product — Firm Access to Case Data

7.1. What this means for Represented Users. If you are represented by an attorney or law firm that uses Merito's Counsel Product, and your case is shared into that Firm's workspace, the Firm and its authorized members can access the shared case's documents, structured Case File, and tool outputs. This access is a core function of the Counsel Product and is controlled by access rules within the Firm's workspace.

7.2. The Firm's own obligations. Your relationship with the Firm is governed by your separate agreement with that Firm. The Firm is responsible for its own confidentiality, professional-responsibility, and data-handling obligations toward you and for obtaining any consents it needs. Mind Arc LLC provides the technology; it does not control the Firm's use of your data within the bounds of the Service.

7.3. Questions about Firm access. If you have questions about who at a Firm can see your data, contact the Firm directly. You can also contact us at legal@eb1mentor.com.


8. Cookies and Analytics

8.1. We use essential cookies required to operate the Service (for example, to keep you signed in and to secure the Service) and analytics cookies (through PostHog) to understand how the Service is used.

8.2. You can control cookies through your browser settings; disabling essential cookies may prevent parts of the Service from working.

8.3. Where required by law (for example, for users in the EU/UK), we will obtain consent for non-essential cookies through a consent mechanism before setting them.


9. Data Retention and Deletion

9.1. Retention while your account is active. We keep your Account and case content for as long as your Account is active or as needed to provide the Service.

9.2. Deletion — 14-day grace period, administrative review, then permanent deletion. You can request deletion of your Account from your settings. Your Account then enters a 14-day grace period, during which you can cancel and restore it. After the grace period, your request is reviewed by an administrator before deletion executes — a safeguard against errors in the deletion process itself, not a review of your reasons for leaving. Once approved, your Account and case content are permanently and irreversibly deleted. Our internal deletion record for this event does not retain your case content.

9.3. Exceptions to deletion. After deletion, we retain only:

  • (a) Financial and transactional records required for tax, accounting, audit, or legal-compliance purposes;
  • (b) De-identified, aggregated statistics not linked to you; and
  • (c) Comments or notes you left on other users' cases, which are anonymized rather than deleted — your authorship is unlinked and your name is displayed as "Deleted user" — so the other user retains the context of their own case. The comment text is preserved; your identity as its author is removed.

9.4. Represented Users. If your data was shared into a Firm's workspace, deleting your own Account may not remove copies of shared materials held within the Firm's workspace; contact the Firm regarding data it controls.


10. Your Privacy Rights

10.1. General. You may access, correct, export, or delete your information. Deletion is self-serve from your Account settings (Section 9). For access, correction, or export requests, contact us at legal@eb1mentor.com; we will verify your identity before acting.

10.2. EU/UK/EEA (GDPR). If you are in the EU, UK, or EEA, you have rights to access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your supervisory authority. Our legal bases for processing are: performance of our contract with you (providing the Service), our legitimate interests (securing and improving the Service, preventing abuse), your consent (for opt-in communications and non-essential cookies), and compliance with legal obligations.

10.3. California (CCPA/CPRA). If you are a California resident, you have rights to know, access, correct, and delete your personal information, and to not be discriminated against for exercising them. We do not sell or share your personal information for cross-context behavioral advertising. You may exercise these rights as described in Section 10.1.

10.4. Other U.S. states. Residents of other states with applicable privacy laws may have similar rights; we honor them where they apply.

10.5. Authorized agents. You may use an authorized agent to submit a request where the law permits, subject to verification.


11. Future Feature — Outcome Library and Pattern Intelligence (Consent Framework)

11.1. Not yet live. This section describes a feature that is planned but not yet in operation. We include it so you understand our intended approach before it launches. We will update this Policy and, where required, obtain consent before it goes live.

11.2. What it will do. The Outcome Library will let designated administrators upload real case-outcome records (for example, approvals, denials, and RFE cycles) and derive non-predictive "pattern" observations from them (for example, "in N tracked outcomes involving a given entity, a given objection was resolved by a given kind of evidence"). These observations will never be presented as approval rates, probabilities, or predictions.

11.3. Consent source required. Every uploaded outcome record must be tagged with a consent source: the administrator's own case, a case the attorney/client has expressly consented to share, or a public record (for example, a published decision). Records without a valid consent basis are not eligible.

11.4. Human-reviewed anonymization. Before any record can be used, it goes through a redaction process: an automated pass removes fixed-format identifiers (for example, receipt numbers and addresses), and a reviewer must review and approve the redaction — including flagged names and employers — on a dedicated screen. Only records a human reviewer has explicitly approved are ever used to derive patterns.

11.5. No personal data in patterns. Derived patterns are structured, de-identified observations and do not surface the underlying personal data. Each pattern shown to users displays how many observations support it and how fresh they are, and indicates when observations are limited.


12. International Data Transfers

12.1. We are based in the United States, and our processors may process data in the United States and other countries. If you access the Service from outside the United States, your information will be transferred to and processed in the United States, where data-protection laws may differ from those of your country.

12.2. Where required, we rely on appropriate safeguards for international transfers (for example, Standard Contractual Clauses) with processors that receive personal data from the EU/UK/EEA. [Transfer mechanism to be confirmed by counsel — see Attorney Review notes.]


13. Security

13.1. We use technical and organizational measures designed to protect your information, including encryption in transit, encryption of sensitive fields at rest (for example, USCIS receipt numbers), access controls that restrict case data to those authorized to see it, and separation of raw documents from the structured data our tools read.

13.2. No system is perfectly secure. We cannot guarantee absolute security, and you are responsible for safeguarding your account credentials. If we become aware of a security incident affecting your information, we will notify you and any authorities as required by law.


14. Children's Privacy

The Service is not directed to children under 18, and we do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact us at legal@eb1mentor.com and we will delete it.


15. Changes to This Policy

We may update this Policy from time to time. If we make material changes, we will provide notice by a reasonable means (for example, by email or a prominent in-Service notice) before the changes take effect. The "Last Updated" date reflects the current version. Your continued use after the effective date constitutes acknowledgment of the updated Policy.


16. Contact

Mind Arc LLC Privacy inquiries: legal@eb1mentor.com


Privacy Policy — Merito