MeritLink — The Proof of Talent Protocol

Legal

Subprocessors

Last updated 19 August 2026

To run MeritLink we rely on a small number of third-party providers. Each processes data only on our instructions and under contract. This page lists them, and the Privacy Policy points here rather than naming them inline, so that changing a provider does not mean reissuing the policy.

This list is published while the platform is still being built. It reflects the stack we intend to run and will be rewritten against what is actually deployed before launch.

1. Current subprocessors

ProviderWhat it doesData it processesRegion
ContaboVirtual servers running the application and the databaseAll service data at rest, including account, billing and assessment recordsEuropean Union
CloudflareDNS, content delivery and image storageTraffic metadata, IP addresses, and images served or uploadedGlobal network
Google (Firebase Authentication)Sign-in and account authenticationEmail address, and the sign-in identifier issued by the provider. No passwords are ever created or storedUnited States
CrossmintEmbedded wallet creation and credential mintingEmail address, authentication identifier and public wallet address. Identity documents only if a financial-compliance check is triggered, which ordinary use does not doUnited States
StripePayment processing for credit top-upsName, email address and payment details. We never receive full card numbersUnited States and European Union
GoogleSign-in providerEmail address and account identifierGlobal
Google (Gemini)Automated evaluation of assessmentsSubmitted code and text, audio transcripts, and derived session signalsGlobal
OpenAI (Whisper)Speech transcription for spoken formatsAssessment audioUnited States
Client-Side Biometric Engine (@vladmandic/human)Local in-browser liveness detection and facial descriptor extraction (Zero Cloud Subprocessors)Processed 100% locally in the candidate's browser via WebGL/WASM. Only a one-way normalized mathematical vector is stored; no raw facial photos or video streams are ever transmitted to third-party cloud servers.Local Browser / On-Premises PostgreSQL

2. What we deliberately do not collect

Identity consistency is handled by face enrolment and liveness rather than by document verification. No provider on this page receives a passport, a driving licence or any other identity document from us, because we never ask you for one.

The one exception is described in Section 1 of the Privacy Policy: if a financial-compliance check is ever triggered, the wallet provider collects those documents directly and holds them itself. Ordinary use of the Service does not trigger it.

3. What runs on your device instead

The camera runs before an assessment, not during it. There is no continuous recording and no camera-based supervision while you answer: the integrity signals collected during an attempt are behavioural — window focus, and pasted rather than typed text — and no video reaches us or any provider on this page.

4. Changes to this list

We update this page when a provider is added, removed or replaced, and change the date above. The Privacy Policy always points to the current version rather than reproducing it, so a change here does not alter the policy itself.

Business customers who need advance notice of subprocessor changes should ask for it in their agreement with us.

5. Contact

Questions about this list: privacy@meritlink.pro.