Skip to main content

DRAFT — not reviewed by a lawyer and not yet in effect. Bracketed fields must be completed by the operator. (Spanish translation pending review.)

Privacy notice

Who we are

Meeply is a product of NextRealm Interactive. Data controller: [LEGAL ENTITY NAME], [REGISTERED ADDRESS]. Privacy contact: [PRIVACY CONTACT EMAIL].

What Meeply is (and is not)

Meeply helps you keep medication routines, record what you report, and share chosen information with people you invite. It is not a medical device, does not give medical advice, does not verify that medication was taken, and is not an emergency or monitoring service.

Information we keep

Account: email address and authentication data (handled by our authentication provider, Supabase Auth).

Profile and preferences: display name, time zone, language, display and reminder settings.

Health-related information you enter: medication names or nicknames, optional strength/form/instructions exactly as you type them, optional photos, schedules, and your reports (taken, skipped, snoozed, corrections) with timestamps and who recorded them.

Care Circle: invitations (the email address you invite and a hashed token), connections, permissions, alert rules, alerts and check-in messages.

Devices: web push subscription endpoints and keys for devices where you turn on notifications.

Billing (if enabled): a Stripe customer ID and subscription status. Card details are handled by Stripe and never reach Meeply.

Security and operations: rate-limit counters, minimal audit events (what kind of action happened and by whom, without medication content), and delivery records (queued/attempted/accepted/failed/clicked where observable).

What we do not do

No advertising trackers. We do not sell personal information. We do not put medication names or health details in analytics, logs, Stripe metadata, invitation emails or (by default) lock-screen notifications.

We do not ask for demographics or diagnoses, and we do not perform pill identification, OCR or interaction checks.

Meep, the AI routine helper

Conversations with Meep are kept only in the open browser tab's memory. They are not saved on our servers or in browser storage, and they are cleared when you sign out, switch accounts or close the tab. Clearing a conversation never changes your medications or records.

Meep reads your records through the same permission checks as the rest of the app, only when you ask, and shows where each answer came from. Nothing is saved or sent until you confirm it.

The optional on-device AI model (Gemma 3 1B, open weights, Gemma Terms of Use) is downloaded from Hugging Face only after you agree, and is stored in this browser's cache until you remove it. Your messages to Meep are processed on your device; they are not sent to Meeply's servers or any AI provider. Downloading the model shares your device's network address with Hugging Face and the jsDelivr CDN, like any download. Routines you save sync to your Meeply account as usual.

Optional Cloud AI (off by default) is for devices that can't run the model, such as many phones. Only after you turn it on, each message you type to Meep (or the routine you describe) is sent to Cloudflare Workers AI, where an open-weight Gemma model drafts a reply. Your medication list, records and account details are not sent. Meeply does not store these messages or log their content; Cloudflare processes them under its own terms. You can turn Cloud AI off at any time.

Sharing with your Care Circle

Nobody can see your information unless you invite them, they sign in with the invited verified email address, accept, and you grant permissions. Status-only access shows medication nicknames and whether items are recorded around today. Details/history, alerts and recording on your behalf are separate permissions you control per person and per medication. You can remove access at any time; it ends immediately for new access, but information already seen or exported cannot be recalled.

Processors

Supabase (database, authentication, private file storage) — region: [SUPABASE REGION].

Hosting provider: [HOSTING PROVIDER AND REGION].

Web push services operated by your browser vendor (e.g. Apple, Google, Mozilla) receive encrypted notification payloads.

If you turn on Meep's on-device AI: Hugging Face (model files) and jsDelivr (runtime files) serve downloads to your browser. They receive no content you type.

If you turn on Meep's Cloud AI: Cloudflare Workers AI receives the messages you type to Meep to generate a reply.

Email provider (if enabled): [EMAIL PROVIDER]. Stripe (if billing is enabled).

Security

Data is transmitted over HTTPS. Database access is restricted with row-level security policies; private photos are stored in a private bucket and served through short-lived signed links. This is not end-to-end encryption. We do not claim HIPAA compliance or any certification.

If you turn on offline access, a copy of your current timeline is stored in this browser. Anyone with access to the device or browser profile may be able to see it; the optional privacy lock hides the screen but does not encrypt stored data.

Retention and deletion

You can export your data and delete your account in Settings. Deletion immediately stops reminders and sharing, then removes your records, photos and device subscriptions and cancels any subscription; progress is tracked and shown to you.

Backups maintained by our database provider may retain deleted data for up to [BACKUP RETENTION PERIOD] before being overwritten. Stripe retains billing records as required by law. Operational logs are kept for [LOG RETENTION PERIOD].

Your rights

Depending on where you live you may have rights to access, correct, export and delete your data, and to complain to a regulator: [APPLICABLE JURISDICTIONS AND REGULATOR CONTACTS].

Changes

Last updated: [DATE]. We will describe material changes in the app before they apply.