Privacy Policy
Last updated: 29 May 2026
Data controller: Merra Ai Ltd (Company No. 16470710)
Contact: privacy@trymerra.ai
1. About this policy
This policy explains what personal data Merra collects, why, what we do with it, and what your rights are. It’s written in plain English. If anything’s unclear, email privacy@trymerra.ai.
This policy covers Merra Practice — the consumer interview-practice product at trymerra.ai. Separate terms apply to our business product (Merra for Companies) when it relaunches.
2. Who we are
Merra Ai Ltd is the data controller for your personal data when you use Merra Practice. We’re a UK company (Co. No. 16470710), registered office 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom.
3. What data we collect
Account data
- Name (optional)
- Email address
- Password hash (we never see your actual password) or Google OAuth ID
- Account creation date
Practice content
- Audio and video of your practice interviews
- Transcripts generated from those recordings
- Scores, evaluations, and feedback
- Uploaded content (CVs, job descriptions) — when you choose to use Job Mode or Roast Mode
Payment data
Handled by Stripe. We see: last 4 digits of your card, card type, billing country, transaction ID. We never see or store your full card number or CVC.
Usage data and ad measurement
- Pages visited, features used, errors encountered (via PostHog)
- Conversion data from Google Ads — which ad brought you to Merra and whether you signed up or paid (via Google Ads)
- Only collected if you accept optional cookies
Session recordings
Replay of your interactions with the site (clicks, scrolls, form usage — with sensitive fields masked). Collected via PostHog only if you accept optional cookies.
Device and technical data
- Browser type, operating system
- IP address (used to estimate approximate location for fraud prevention; not stored long-term)
4. Why we use it and our legal basis
| What | Why | Legal basis (UK GDPR) |
|---|---|---|
| Account + practice content | Provide the service | Contract |
| Payment data | Process payments, comply with tax law | Contract + legal obligation |
| Transactional emails (receipts, renewal reminders, password resets) | Necessary parts of the service | Contract |
| Analytics (PostHog) | Understand what's working, improve the product | Consent |
| Session recordings (PostHog) | Diagnose UX issues, improve flows | Consent |
| Marketing emails | Tell you about new modes and features | Consent (opt-in only) |
| Security, anti-fraud, abuse prevention | Keep the service safe | Legitimate interest |
You can withdraw consent for any consent-based processing at any time — see Section 9.
5. AI — how we use your data
Merra is an AI product. Two things happen with your content, and they’re separate:
1. Real-time feedback (third-party AI providers)
Merra currently uses OpenAI for reasoning and ElevenLabs for voice. They process your interview content in real time to generate your feedback. Our contracts with these providers prohibit them from training their own models on your content.
2. Improving Merra’s own models
We use your practice content — interview audio, transcripts, scores, evaluations, and CV/JD uploads — to train and fine-tune Merra’s own AI models. The goal is better feedback, smarter interview simulations, and a product that learns what actually helps people prepare well.
You can opt out at any time in your account settings — one toggle, takes effect immediately for any future use of your content. Content that’s already been used in a completed training cycle can’t always be removed from a finished model, but we won’t include you in anything new going forward.
When we use your content for training:
- We use it inside Merra only. We don’t sell it, share it, or use it to train anyone else’s models.
- We remove direct identifiers (name, email, account ID) before training where technically possible.
- We use it only to improve Merra Practice — not for advertising, not for any kind of decision-making about you as an individual.
- You can also request deletion of your past contributions by emailing privacy@trymerra.ai.
Legal basis: Legitimate interest (UK GDPR Art. 6(1)(f)). We have a legitimate interest in improving our service, and we’ve assessed that this doesn’t override your rights given the safeguards above and your ability to opt out at any time. You can object via the settings toggle, or by emailing privacy@trymerra.ai.
Anonymised metrics (always on)
We also use anonymised, aggregated metrics (e.g. “X% of users finish their first interview”, “average score by interview type”) to track how the product is performing. This data can’t be traced back to you.
6. How long we keep your data
- Account: until you delete it, then up to 30 days
- Interview audio and video: 12 months by default, or until you delete it — whichever is sooner. You can delete individual recordings at any time from your dashboard.
- Transcripts, scores, and feedback: 12 months by default, or until you delete them
- Uploaded CVs and JDs: until you delete them, or 12 months
- Payment records: 7 years (UK tax law requires this)
- Analytics data: 12 months
- Backups: rotated within 90 days
- Training contributions: if your content has been used in a completed AI training cycle, that contribution may persist in trained models even after you delete the source content or opt out. We won’t include you in new training runs going forward.
7. Who we share your data with
We share data with the following sub-processors, who handle it on our instructions and under contract:
| Provider | Purpose | Location |
|---|---|---|
| AWS / Vercel | Hosting, storage | UK / EU |
| Stripe | Payments | UK / EU / US (with safeguards) |
| OpenAI | AI reasoning for feedback | US (with safeguards) |
| ElevenLabs | Voice generation | US (with safeguards) |
| PostHog | Analytics and session recording (consent-only) | EU |
| Brevo | Transactional emails (receipts, password resets, renewal reminders) | EU |
| Google (Google Ads) | Ad conversion measurement (consent-only) | US (with safeguards) |
We don’t sell your data. We don’t share it with advertisers.
We may share data if required by law (e.g. court order), to investigate fraud or abuse, or as part of a business sale or merger (you’d be told before this happens).
8. International transfers
Some sub-processors (OpenAI, ElevenLabs, Google, parts of Stripe’s infrastructure) operate outside the UK/EU. When we transfer your data to them, we use UK GDPR-approved transfer mechanisms:
- Standard Contractual Clauses (SCCs) combined with the UK International Data Transfer Addendum
- Transfer impact assessments where required
9. Your rights (UK GDPR)
You have the right to:
- Access — get a copy of your personal data
- Rectification — correct anything that’s wrong
- Erasure — delete your data (“right to be forgotten”)
- Restriction — pause processing
- Portability — get your data in machine-readable form
- Object — object to processing based on legitimate interest
- Withdraw consent — for analytics, marketing, and any other consent-based processing
- Complain to the ICO at any time (see Section 14)
To exercise any of these: email privacy@trymerra.ai. We’ll respond within 30 days. There’s no charge.
Most of these you can also do yourself in your account settings: delete individual recordings or transcripts, delete your account, export your data, and manage cookie and marketing preferences.
10. Users under 16
Minimum age to use Merra: 16. When you sign up, you confirm you meet this age requirement. We don’t knowingly collect data from anyone under 16.
If you’re a parent or guardian and believe a child under 16 has signed up, email privacy@trymerra.ai and we’ll delete the account.
11. Cookies
We use a small number of cookies. See our Cookie Policy for details and to manage your preferences.
PostHog (analytics, session recording) and Google Ads (conversion tracking) only run if you’ve accepted optional cookies. If you’ve selected “Essential Only”, no analytics, session recording, or ad-conversion data is collected.
12. Security
- Encryption: TLS in transit, AES-256 at rest
- Access: role-based access for staff, principle of least privilege, all admin actions logged
- Monitoring: automated security scanning, anomaly detection
- Backups: encrypted, restoration tested
- Vendor security: all sub-processors must meet our security standards
If we discover a personal-data breach that’s likely to affect you, we’ll notify you and the ICO within 72 hours, as required by UK GDPR.
Security concerns: security@trymerra.ai.
13. Changes to this policy
We may update this policy. For material changes (e.g. new sub-processors, new data categories, changes to retention), we’ll email you in advance. For minor changes (e.g. clarifying wording), we’ll update the “Last updated” date at the top.
14. Complaints
If you’re unhappy with how we’ve handled your data, please email privacy@trymerra.ai first — we’ll try to resolve it.
You also have the right to complain to the Information Commissioner’s Office (ICO) at any time, without contacting us first:
- Website: ico.org.uk
- Phone: 0303 123 1113
- Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, SK9 5AF
15. Contact
Merra Ai Ltd
71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom
- privacy@trymerra.ai — privacy questions, rights requests
- security@trymerra.ai — security issues
- support@trymerra.ai — general support