Privacy policy
What ExportFlow collects, who receives it, how long it is kept, and how to have it deleted. This policy covers the ExportFlow web application at exportflow.app and the ExportFlow Android application.
Last updated 2026-10-06.
Who we are
MeerTech Limited is the data controller for everything described here. Registered at Abuja, Nigeria.
Privacy questions, requests for a copy of your data, and deletion requests go to privacy@meertech.tech. You can also delete your workspace yourself — see deleting your account.
What we collect, and why
Everything ExportFlow holds about you is something you typed or a file you chose. There is no background collection of any kind: no location, no contacts, no device or advertising identifiers, no analytics, no crash reporting, no advertising.
To give you an account
- Your email address and a password. The address identifies you when you sign in. The password is never stored — we keep only a scrypt hash of it, and the original is not recoverable from that, by us or by anyone else.
- Your organisation’s name. Every record belongs to an organisation, and it is the name your reports are issued under.
The Android app never reads the accounts configured on your phone. The address is one you type.
To verify your shipments
- The documents you upload or photograph. Bills of lading, invoices, packing lists, certificates — whatever you add to a shipment. These are commercial documents and they routinely contain other people’s details: consignee names and addresses, bank references, values.
- What you tell us about the shipment. Your reference, the exporting company, the commodity and its code, origin and destination, the port, weights, package counts, consignee, planned departure, and any measurements you declare.
- What you confirm each document says. The verification step asks you to confirm the values read from your documents, and we keep your answers with the reading they came from.
What we generate from it
Extracted field values, verification runs and their findings, compliance assessments and the passages they rest on, preflight plans, and an audit trail of what was checked when. These are derived from the above and are kept with it.
Who else sees it
To extract the fields from a document, page one of it is sent to a vision-model provider — Alibaba Cloud (Model Studio), processing in Singapore. It is a processor acting on our instructions and it does not use your documents for its own purposes.
When you run a compliance assessment, a question built from the shipment’s details (such as its commodity, HS code, origin and destination) is sent to the same provider’s language model, together with the published regulations it is checked against.
This is the most significant disclosure on this page, which is why it is not in a list further down. If that is not acceptable for a particular document, do not upload it: ExportFlow still works with values you type by hand, and says so on the confirmation step.
Other than that:
- Our hosting and storage providers. The service and your documents run on infrastructure we rent in Singapore (DigitalOcean). They hold the data; they do not use it.
- Nobody else. We do not sell data, we do not share it for advertising, and there is no analytics or attribution vendor in either application.
- Except where the law requires it, or to establish or defend a legal claim.
Where it is kept, and how it is protected
- In transit. HTTPS everywhere. The Android app has exactly one network destination and it is the ExportFlow API; a release build cannot talk to an unencrypted address at all.
- On our servers. Each organisation’s rows are separated by row-level security in the database, so one customer’s query cannot return another’s data even if the application asked it to. Uploaded files are scanned for malware before they are stored, and an upload that could not be scanned is refused rather than stored unscanned.
- On your phone. The Android app keeps a local copy of what it has fetched, encrypted with SQLCipher under a key generated on the device and held in the Android Keystore. If the keystore is unavailable, the app refuses to store anything rather than storing it unprotected. Signing out destroys the key and the file.
- Your session. Signing in issues a token that expires after fourteen days and can be revoked. On the web it is held in an httpOnly cookie that no script on the page can read; on the phone it is in the device keystore, never in the app’s own storage.
How long we keep it
Until you delete it. There is no automatic expiry, and that is deliberate rather than an oversight: a verification run is evidence about a shipment that may be disputed months later, and a product that quietly deleted the report you relied on would be worse than one that keeps it.
The consequence is that deleting is your decision and we have made it immediate — see below.
Your rights
You can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, or object to what we are doing with it. Write to privacy@meertech.tech and we will answer.
Deletion you can do yourself, immediately. In the Android app it is under Account; in the web application it is on the deletion page. It removes the organisation, its members, every shipment and document, every uploaded file, and every report and assessment computed from them. It cannot be undone and there is no recovery window — when it returns, the data is gone.
Changes to this policy
If we change what we collect or who receives it, we will change this page and the date at the top of it. The version you are reading is the one in force.
One thing this policy is not
It is not a statement about what ExportFlow concludes about your shipments. ExportFlow reports evidence of inconsistency and the presence of known failure modes; it never asserts that goods meet a specification. What it can and cannot check is on the coverage register, which is public for the same reason this page is.