Privacy Policy
Last updated:
Meylo is a private mood journal. This policy explains what we process, why, how long we keep it, who works with us, and the choices you keep at every step.
1. Who is responsible for your data
Meylo is published and operated by the company below, which acts as the data controller for the processing described in this policy.
Our contact details appear once JavaScript is enabled. We display them this way to protect them from automated harvesting.
For any question about your data, your rights or this policy, write to the address above. We answer within one month. For complex requests we may extend that period by two months, and we tell you why.
2. What this policy covers
This policy applies to everything published under the Meylo name:
- the public website, including the landing pages, the blog and these legal pages;
- the Meylo application on the web and on Android, including your account, your entries, your photos and the optional social features;
- it does not cover third-party sites or apps you open from Meylo, which have their own policies.
3. What we process
We only process what a feature actually needs. Depending on how you use Meylo, this can include:
- Account data — the email address, sign-in identifier and profile details attached to your account, or the anonymous identifier if you use Meylo as a guest.
- Journal entries — the date, the 1 to 5 rating, activities, emotions, stress level and the free-text notes you write.
- Photos — the images you attach to an entry, stored in your own private space in three sizes.
- Location — when you enable weather, the city you pick or the position your device provides, plus the coordinates needed to fetch weather and daylight data.
- Optional integrations — health and screen-time context, only when you connect them yourself.
- Social data — friend relationships, invitations, the entries you explicitly publish, reactions and story views.
- Messages — the content of conversations with friends, including reactions and read state when you leave read receipts on.
- Notification data — the push token of your device and your notification preferences.
- Technical data — what is needed to serve the app securely, such as the IP address handled by our providers, device and browser type, and error diagnostics.
- Correspondence — what you send us when you contact us, so we can answer you.
- Product suggestions — the message you send from the app settings, along with your email address, the app version and the device type, so we can understand and prioritise the request.
Mood entries say something about your state of mind, and notes are free text you may use to write about your health. We treat this content as sensitive by design: it is stored in your own space, it is never published without an explicit action from you, and precise location and screen-time context are moved into an owner-only document that friends can never read.
We do not build advertising profiles, we do not sell data, and we take no automated decision that produces legal effects for you.
4. Why we process it, and on what legal basis
Under the GDPR, every processing activity needs a legal basis. Here is ours:
| Purpose | Legal basis |
|---|---|
| Create your account, sign you in, and keep your data in sync across your devices | Performance of our contract with you |
| Store your entries, photos and notes, and produce your personal charts and recaps | Performance of our contract with you |
| Run the optional social features: friends, published entries, reactions and conversations | Performance of our contract, and your consent for each publication |
| Show weather, daylight and city context on an entry | Your consent, which you can withdraw in the settings |
| Produce an AI summary of a period when you request one | Your consent, given by requesting the recap |
| Send reminders and social notifications to your device | Your consent, given through the device permission and the notification settings |
| Measure how the public website is used, in aggregate | Your consent through the cookie banner |
| Keep the service available, prevent abuse, apply rate limits and investigate incidents | Our legitimate interest in a secure and working service |
| Answer your questions and handle your requests | Our legitimate interest in supporting our users |
| Collect and handle your ideas and improvement suggestions | Our legitimate interest in improving the service |
| Meet our legal obligations and defend legal claims | Legal obligation and our legitimate interest |
Where we rely on consent, you can withdraw it at any time, in the app settings or through the cookie manager. Withdrawal does not affect what was done before it.
5. AI recaps
Meylo can write a summary of a week, a month or a year from your entries. This feature only runs when you ask for it, and it uses OpenAI as a processor.
- Nothing is sent until you explicitly request a recap for a period.
- Only the entries of the chosen period are sent: ratings, activities, emotions, stress, your notes, and the weather or context saved with them.
- The request carries no account identifier. Your name, your email address, your photos and your messages are never included, so the provider receives the content of a period without being told whose it is.
- The request is sent with provider-side storage disabled, and under the OpenAI API terms we use the content is not retained beyond the request nor used to train their models.
- A recap is an editorial summary. It is not a diagnosis, and no decision is taken about you on its basis.
If you never request a recap, no entry ever leaves our infrastructure for this purpose.
6. What other people can see
Meylo is private by default. Nothing you write becomes visible to another person unless you take an explicit action.
- An entry is only visible to your friends after you publish it, and unpublishing removes it from their feed.
- A published entry exposes the city and the country only. Exact coordinates, how the location was obtained, and screen-time context stay private.
- Your past history is not public by default and follows the privacy settings of your profile.
- Conversations are visible to their participants. Deleting your account deletes the conversation for everyone in it.
- Solo mode turns off every sharing feature at once: your friends see a private-mode state, and your social data stays dormant rather than deleted.
We never sell your data, we never rent it, and we never hand it to advertisers.
7. Who processes data for us
We keep the list of providers short, and each one only receives what its job requires. They act on our instructions under a data processing agreement.
| Provider | What it does | Where |
|---|---|---|
Google Firebase | Authentication, database, photo storage, server functions and push notifications | European Union and United States |
Google Analytics 4 | Aggregate audience measurement on the public website, only with your consent | European Union and United States |
OpenAI | Generates an AI recap when you request one | United States |
Open-Meteo | Returns weather and daylight data for the coordinates of an entry | European Union |
Google Play | Distributes the Android application and handles its installation | European Union and United States |
City search and the conversion of a device position into a city name run entirely on your device, from a city index shipped with the app. No geocoding request ever leaves your device.
8. Transfers outside the European Union
Some of our providers process data in the United States, in particular for server functions, AI recaps and audience measurement.
These transfers are covered by the European Commission's standard contractual clauses and, where the provider is certified, by the EU-U.S. Data Privacy Framework. You can ask us for a copy of the safeguards that apply.
9. How long we keep it
We keep data only for as long as the purpose requires:
- Account and profile data: for as long as your account exists.
- Entries, photos and personal analytics: for as long as your account exists, or until you delete them.
- Conversations: until you or the other participant deletes them, or until either account is deleted.
- AI recaps: stored with your account until you regenerate or delete them. The technical logs of that feature are short-lived and removed with your account.
- Push tokens: until you turn notifications off, sign out, or the token expires.
- Provider backups: purged within 30 days of deletion, following our providers' rotation.
- Website audience measurement: 14 months at most, and only with your consent.
- Product suggestions: kept for 12 months from submission, then deleted automatically.
10. How we protect it
We apply technical and organisational measures proportionate to the risk:
- server-side access rules that scope every read and write to the account that owns the data;
- encryption in transit for all traffic, and encryption at rest by our infrastructure providers;
- a strict minimum of people with administrative access, through a separate internal tool protected by an explicit allowlist;
- data minimisation, including keeping precise location and context out of anything shared with friends.
No service can promise absolute security. If a breach is likely to result in a high risk to your rights, we notify you and the supervisory authority as the law requires.
11. Your rights
If you are in the European Economic Area or the United Kingdom you have the rights below, and we apply them to everyone regardless of location:
- Access — obtain confirmation that we process your data, and a copy of it.
- Rectification — correct data that is wrong or incomplete.
- Erasure — have your data deleted, which you can also trigger yourself at any time.
- Restriction — ask us to freeze a processing activity while a dispute is examined.
- Portability — receive your data in a machine-readable format. The app exports it directly.
- Objection — object to processing based on our legitimate interest.
- Withdrawal of consent — at any time, without affecting what was lawful before.
- Post-mortem instructions — define how your data should be handled after your death.
Write to the contact address below. We may ask you for elements confirming your identity when answering would otherwise expose someone else's data. Exercising your rights is free, unless a request is manifestly unfounded or excessive.
If you believe your rights are not respected, you can lodge a complaint with your national supervisory authority. Ours is the French CNIL.
12. Children
Meylo is not intended for children under 16, or under the lower age your country allows where local law permits it, such as 15 in France. We do not knowingly collect data from a child below that age. If you are a parent or guardian and believe your child created an account, contact us and we will delete it.
13. Cookies and local storage
The public website uses a small number of cookies, and audience measurement only runs after you accept it. The application also stores data locally on your device so it works offline. The details are in our cookie policy.
14. Changes to this policy
We update this policy when the product changes. The date at the top always reflects the current version. When a change materially affects your rights, we tell you in the app or by email before it applies.
15. Contact
For any privacy question, request or complaint, write to us. We answer every request.
Our contact details appear once JavaScript is enabled. We display them this way to protect them from automated harvesting.