Meridian Consent Privacy Notice — Login with Amazon
This Consent Privacy Notice describes what you authorize when you connect your Amazon account to Meridian using Login with Amazon, and how ncdLabs ("we," "us," or "our") collects, uses, stores, and shares that information.
Meridian is a local-first operations platform. When you use Login with Amazon in Meridian, most data stays on your device and is not sent to ncdLabs servers.
Part I — Consent
1. What you are authorizing
Meridian uses Login with Amazon so you can link your Amazon account and control Alexa Smart Home devices from the app. If you continue on Amazon's sign-in screen, you allow Meridian to request the following permissions:
Meridian does not receive your Amazon password. Authentication is handled entirely by Amazon. Meridian does not use your Amazon data for advertising, sale to third parties, or profiling.
2. Your choices
- Cancel on Amazon's consent screen if you do not want to connect.
- Disconnect later in Meridian: Providers → Amazon Alexa → Disconnect.
- Revoke access in your Amazon account settings at any time.
- Delete local data by removing Meridian's application data from your device or using Meridian's data export/purge options where available.
3. Agreement
By connecting your Amazon account to Meridian, you authorize ncdLabs to access the permissions listed in Section 1 solely to provide Alexa Smart Home integration inside Meridian. Data is stored locally on your device unless you use a remote runtime you configure. You confirm that you have read and understand this Consent Privacy Notice.
Part II — Privacy Notice
4. Scope
This notice applies to the Amazon account connection feature in Meridian (the "Alexa integration"). It is displayed on Amazon's consent screen when you authorize Meridian to access your Amazon account.
5. Information we receive from Amazon
When you sign in with Amazon and grant permission, Meridian may receive the following through Amazon's Login with Amazon and Alexa APIs, depending on the permissions you approve:
Profile information (profile scope)
- Amazon customer identifier (user ID)
- Name associated with your Amazon account
- Email address associated with your Amazon account
We use this information only to confirm which Amazon account is linked to your Meridian profile and to display connection status in the app.
Alexa Smart Home access (alexa::ask:skills:readwrite scope)
- Alexa Smart Home endpoint identifiers
- Device friendly names and display categories
- Device capabilities (for example, power or brightness control)
- Current device state (for example, on/off, brightness level)
We use this information to discover Alexa-connected devices, show their status in Meridian, and send control commands you initiate in Meridian back to Alexa.
6. How we use your information
We use Amazon-related information only to:
- Complete the Login with Amazon authorization flow
- Maintain your Amazon account connection
- Discover and display Alexa Smart Home devices in Meridian
- Read device state and send device control commands you request
- Refresh access tokens so the connection remains active
- Show connection status and troubleshooting information in the app
7. Where information is stored
Meridian is designed to run locally on your computer or device.
-
OAuth tokens (refresh tokens and short-lived access tokens) are stored in your
local Meridian runtime data directory in
alexa-config.json, within your per-user tenant folder. - Device names, states, and metadata discovered from Alexa are stored locally in Meridian's database on your device.
-
Sign-in flow: Meridian opens Amazon's sign-in page in your system browser.
After you approve access, Amazon redirects to a callback URL on your local Meridian runtime
(default:
http://127.0.0.1:7420/api/v1/alexa/auth/callback).
Unless you configure Meridian to connect to a remote runtime you control, this information is not transmitted to ncdLabs-hosted servers.
8. How information is shared
We share information only as needed to operate the integration:
| Recipient | What is shared | Why |
|---|---|---|
| Amazon | OAuth authorization requests, token refresh requests, Alexa Smart Home API calls | To authenticate you and operate the Alexa integration |
| Your device | All stored tokens and synced device data | Local storage required for Meridian to function |
We do not sell your personal information. We do not share Amazon account data with data brokers.
If you use a self-hosted or team-shared Meridian runtime, administrators of that runtime may have access to stored provider configuration on that system. Treat shared runtime hosts like any system that stores credentials.
9. Data retention
- Amazon connection data is retained on your device until you disconnect the Amazon account in Meridian or delete your Meridian data.
- When you choose Disconnect in Meridian, local OAuth tokens and Alexa provider configuration are removed from your device.
- Disconnecting in Meridian does not by itself revoke Meridian's access at Amazon. To fully revoke access, you may also remove Meridian's authorization in your Amazon account settings.
10. Your rights
Depending on where you live, you may have additional rights to access, correct, or delete personal information. Because Meridian stores data locally, you can usually fulfill these requests directly on your device. For questions, contact us using the information in Section 14.
11. Security
We take reasonable measures to protect information handled by Meridian:
- OAuth tokens are stored in runtime-side configuration on your device, not in the client SQLite database.
- API communication with Amazon uses HTTPS.
- Meridian uses a local bearer token to authenticate client requests to your runtime.
You are responsible for securing the device and user account where Meridian runs.
12. Children's privacy
Meridian and the Amazon connection feature are not directed to children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children through Login with Amazon.
13. Third-party services
Login with Amazon and Alexa services are provided by Amazon.com, Inc. and its affiliates. Your use of Amazon services is also governed by Amazon's own policies, including:
We are not responsible for Amazon's privacy or security practices.
14. Contact us
If you have questions about this Consent Privacy Notice or Meridian's use of Login with Amazon, contact:
ncdLabs
Email: privacy@ncdlabs.com
15. Changes to this notice
We may update this Consent Privacy Notice from time to time. When we do, we will revise the "Last updated" date at the top of this document. Material changes will be reflected in the hosted version used for Amazon's Consent Privacy Notice URL.