Privacy Policy
Last updated: June 27, 2026
Overview
Norium ("Norium", "we", "us", or "our") builds Meridian, an intermittent fasting app for iPhone (the "App"), and operates this website (together, the "Services"). This Privacy Policy explains what information we collect, how we use and share it, and the choices and rights you have. By using the Services, you agree to the practices described here.
Information We Collect
We collect the following categories of information:
Account information
When you create a Meridian account, we collect your email address and authentication credentials (such as a password or sign-in token), so your data can sync across your devices.
App content
Information you enter in the App, including fasting schedules, fast start/end times, goals, and notes. This content is synced to our servers so it is available across your devices and backed up if you reinstall the App.
Health data
If a future version of the App integrates with Apple Health (HealthKit), and you choose to enable that integration, we may read or write data such as weight, sleep, or activity to support in-app features. See Health Data below for how this is handled.
Device and diagnostic information
Technical information such as device model, operating system version, app version, language settings, and, if we enable crash reporting or analytics tools in the App, crash logs and aggregate usage data (such as which screens are used and how often).
Communications
If you contact us for support or feedback, we collect the contents of your message and the email address you used to send it.
Website information
Like most websites, our hosting provider automatically logs standard server information (such as IP address, browser type, and pages visited) for security and operational purposes.
How We Use Information
We use the information we collect to:
- Provide, operate, and sync the App across your devices
- Maintain your account and authenticate you
- Respond to support requests and feedback
- Monitor, diagnose, and fix bugs or crashes
- Understand aggregate usage to improve the App and website
- Detect, prevent, and address fraud, abuse, or security issues
- Comply with legal obligations
We do not sell your personal information, and we do not use your fasting or health data to serve you advertising.
Legal Basis for Processing
If you are located in the European Economic Area or UK, we rely on the following legal bases to process your information: performance of a contract (to provide the Services you sign up for), consent (for example, when you grant Health data permissions), and legitimate interests (for example, to keep the Services secure and working correctly). Where we rely on consent, you may withdraw it at any time.
Health Data
Any Apple Health (HealthKit) integration in the App is optional and only activates if you explicitly grant permission through iOS. Health data accessed this way is used solely to power the relevant in-app feature (for example, displaying your weight trend alongside your fasting history).
We do not use HealthKit data for advertising or marketing purposes, and we do not share HealthKit data with third parties such as advertisers, data brokers, or analytics companies, consistent with Apple's HealthKit guidelines. You can revoke Health permissions at any time in iOS Settings → Privacy & Security → Health.
How We Share Information
We may share information with:
- Service providers who host our infrastructure, provide authentication, or support crash reporting and analytics on our behalf, bound by confidentiality and data protection obligations
- Legal and safety purposes, if required to comply with law, legal process, or to protect the rights, property, or safety of Norium, our users, or others
- Business transfers such as a merger, acquisition, or sale of assets, in which case information may be transferred as part of that transaction
We do not sell or rent your personal information to third parties.
Data Storage & Security
Account and synced App content are stored on secure cloud infrastructure with encryption in transit and at rest, and access to production data is restricted to authorized personnel who need it to operate the Services. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
Data Retention
We retain account and App content for as long as your account is active, or as needed to provide the Services. If you delete your account, we delete or anonymize your personal information within a reasonable period, except where we are required to retain it for legal, security, or legitimate business purposes (such as fraud prevention).
Your Rights & Choices
Depending on your location, you may have the right to:
- Access the personal information we hold about you
- Correct inaccurate information
- Request deletion of your account and associated data
- Export your data in a portable format
- Object to or restrict certain processing
- Withdraw consent (for example, by revoking Health permissions)
You can exercise most of these directly within the App (account and data deletion), or by contacting us at support@norium.io. We will respond within the timeframe required by applicable law.
California Privacy Rights
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the CPRA, gives you the right to know what personal information we collect, request deletion of it, correct it, and opt out of any sale or sharing of personal information. We do not sell or share personal information as defined under the CCPA/CPRA. You can submit a request using the contact information below.
EEA & UK Privacy Rights
If you are located in the European Economic Area or United Kingdom, you have rights under the GDPR or UK GDPR, including the rights described above, and the right to lodge a complaint with your local data protection authority.
International Data Transfers
We may process and store information in countries other than the one in which you reside. Where we transfer personal information internationally, we take steps intended to provide an adequate level of protection, such as standard contractual clauses, where required by applicable law.
Children's Privacy
The Services are not directed to children under 13 (or the relevant minimum age in your jurisdiction), and we do not knowingly collect personal information from children under that age. If you believe a child has provided us with personal information, please contact us so we can delete it.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes to the Services or for legal, operational, or regulatory reasons. We will update the "Last updated" date above, and where changes are material, we will provide additional notice (such as an in-app notice).
Contact Us
If you have questions about this Privacy Policy or want to exercise any of the rights described above, contact us at support@norium.io.