← MeridianDesk

MeridianDesk: Privacy Notice

Last updated: July 15, 2026

Publisher: Aubora SAS (a company in formation), France.
Contact: contact@aubora.co

How MeridianDesk handles data. In short: everything stays on the prescriber's Mac.

1. Purpose of this notice. This notice explains how the MeridianDesk application handles data on the prescriber's Mac. MeridianDesk is local-only software: it runs on the prescriber's computer and is designed so that patient data never leaves that computer.

2. Data handled by the application. MeridianDesk imports a data file that a patient has exported from the Meridian application. That file may contain identifiable health information relating to the patient. The application reads this file, recomputes an estimated pharmacokinetic curve for review, and displays the result. MeridianDesk is read-only with respect to the patient's own data: it cannot alter, add to, or delete data on the patient's phone.

3. Where data is stored. Imported files and the application's working data are stored locally on the prescriber's Mac, within the user's Application Support directory and related local storage. No copy is created on any server controlled by Aubora.

4. No transmission to Aubora or to third parties. MeridianDesk does not transmit patient data, imported files, or computed results to Aubora or to any third party. The processing takes place entirely on the prescriber's Mac.

5. No analytics or telemetry. MeridianDesk collects no analytics, no usage telemetry, no tracking identifiers, and no behavioral data. Aubora receives no reporting about how, when, or by whom the application is used.

6. The prescriber is the data controller. Because the prescriber decides to import identifiable patient data onto their own Mac and to process it for the purposes of a consultation, the prescriber is the data controller for that data within the meaning of the General Data Protection Regulation (GDPR). Aubora provides the software only; it does not receive or process the patient data and is therefore neither the controller nor a processor of that data. The prescriber remains bound by their professional secrecy obligations and by applicable data-protection law, including, in France, the Code de la santé publique.

7. Special-category data. Health data is a special category of personal data under Article 9 of the GDPR and benefits from reinforced protection. The prescriber, as controller, is responsible for identifying an appropriate legal basis and an applicable condition for processing such data, and for handling it in accordance with law and professional rules.

8. Rights of the data subjects. Patients hold the rights granted by data-protection law, including the rights of access, rectification, erasure, restriction, and objection, subject to the conditions and limits set by law. Because Aubora holds no patient data, Aubora cannot act on any such request. The prescriber, as controller and holder of the data, is responsible for receiving and answering these requests directly.

9. Retention and deletion. The prescriber controls how long imported files and computed results are kept. Deleting a patient file through the ordinary means of the operating system, or through the application where it offers this, removes that file from the prescriber's Mac. Aubora keeps no copy and therefore performs no retention on the prescriber's behalf.

10. Security recommendations. The prescriber is responsible for the security of the device on which patient data is stored. Aubora recommends enabling FileVault full-disk encryption, protecting the Mac user account with a strong password, keeping the operating system up to date, and limiting physical and logical access to the device.

11. Optional calendar access. If, and only if, the prescriber enables the "patients seen today" feature, MeridianDesk reads the Mac's local calendar solely to match patient names. This access is local: no calendar content is stored by the application or transmitted to Aubora or to any third party.

12. International transfers. Because processing takes place locally on the prescriber's Mac and no data is sent to Aubora or to any third party, MeridianDesk performs no transfer of patient data, including any transfer outside the European Union or the European Economic Area.

13. Supervisory authority. A patient who considers that their data has been handled unlawfully may contact the competent supervisory authority. In France, that authority is the Commission nationale de l'informatique et des libertés (CNIL).

14. Publisher and contact. MeridianDesk is published by Aubora SAS (société en formation), Paris, France. For questions about the application, contact contact@aubora.co. Questions from patients about the handling of their own data should be addressed to the prescriber, who is the data controller.