← ncdLabs
Meridian
Privacy

What local-first means in Meridian

Meridian runs on hardware you control and keeps its own configuration and synchronized smart-home data there. Third-party integrations still follow the rules of the services they connect to.

Where Meridian runs

Desktop setup

Meridian runs on your computer and keeps its application data on that computer. Developer ID desktop builds can embed Meridian Runtime (meridiand) on the same machine.

Connected / whole-house setup

In Connected mode, the app syncs with a Meridian Runtime you host (embedded on desktop, or a remote runtime on your network). App Store builds on iOS and Mac App Store are client-only and connect to a runtime you provide.

Local vs Connected data

Standalone keeps observation and control on the device using local adapters and cached data; it does not require a running meridiand.

Connected stores account identity, provider configuration, resources, events, and related sync data in the runtime you connect to, and mirrors a working copy in the app’s local database for that signed-in user.

Account credentials (password or PIN hashes, session unlock, runtime tokens) stay in the device secure store (Keychain / equivalent). Passwords are never sent to Meridian servers as account passwords — Meridian is not a hosted cloud identity provider.

Account deletion

You can delete your Meridian account from the app: Settings → Account → Delete account, or from the profile menu. You must type your account email to confirm.

Deletion removes the account from this device (registry entry, secrets, and that user’s local database). In Connected mode, Meridian also deletes the matching runtime user and that user’s runtime data directory on the connected meridiand. After deletion you return to sign-in or create-account.

Deleting a Meridian account does not revoke third-party provider access by itself — disconnect providers in Meridian and revoke access in each provider’s account settings when needed.

Passkeys

Optional platform passkeys are registered with Meridian Runtime for passwordless sign-in. Passkey credentials for a user are stored by the runtime and removed when that runtime user is deleted. Production Associated Domains use passkeys.ncdlabs.com.

Diagnostics (Sentry)

When a Meridian release is built with a Sentry DSN configured, the app may send crash and error diagnostics (and related technical context) to Sentry to help improve reliability. Builds without a DSN do not initialize Sentry and do not send that telemetry. Diagnostics are separate from your smart-home configuration and device state stored locally or on your runtime.

Information used by integrations

To show and control connected equipment, Meridian may synchronize information such as provider account identifiers, device names, device identifiers, capabilities, state, rooms, locations, events, and alerts. The exact information depends on the provider and permissions you approve.

A local-first app cannot make a cloud-dependent device local. Home Assistant, Tuya, Amazon, Arlo, and other providers may still receive requests and data needed to operate their services.

Provider credentials

When a provider uses its own sign-in and consent page, authentication is handled by that provider. Meridian receives the tokens or connection information needed to maintain the link; it does not receive the password entered on the provider’s site.

For the exact Amazon permissions, storage details, revocation steps, and data categories, read the Amazon connection privacy notice.

Website analytics

The Meridian marketing pages use Google Analytics to measure page visits, screenshot opens, and download clicks. These website analytics do not include the smart-home configuration or device data stored by the Meridian app.

Your choices

Questions and corrections

This page explains the current product at a high level; provider-specific notices supply additional detail. For a privacy question or correction, email privacy@ncdlabs.com.

Last updated: September 18, 2026