Privacy Policy

1. Controller, scope, and contact

Meykai determines why and how personal data is processed for this service and acts as the data controller. Privacy questions and data-rights requests can be sent to privacy@meykai.com. General support can be reached at support@meykai.com.

This policy applies when you visit a Meykai-controlled website, create or use an account, read content, start a trial or membership, submit feedback, or contact us. A third party's own notice applies when that third party acts as an independent controller—for example, Razorpay for payment processing or Google when you choose Google sign-in.

Meykai does not currently appoint a separate data-protection officer. If an EU representative is required under Article 27 GDPR, its identity and contact details must be added to this section. Server location alone does not establish an EU entity or replace that requirement.

2. Personal data we process

We collect data you provide, data generated when you use the service, and limited data received from service providers:

  • Account and identity data: display name, email address, authentication method, user ID, account timestamps, and—if you choose Google sign-in—basic identity information returned by Google.
  • Profile and onboarding data: role, experience or AI-familiarity level, learning goals, company context, industry, available learning time, plan intent, and optional company name.
  • Reader and learning data: chapters opened, saved position, last block, completion, active reading time, resume activity, search/library actions, and reader mode or accessibility settings.
  • On-device focus data: the Focus reader can calculate a rolling reading-speed estimate from the time content blocks remain in the focal area. Raw block samples and the resulting WPM baseline are processed and stored locally in your browser; the current product does not upload raw block-by-block WPM samples to the server.
  • Acquisition and essential event data: referrer origin and path, entry page, campaign/UTM values, signup method, anonymous visitor ID, broad viewport category, application revision, event name, page path, content ID, and event time.
  • Feedback and communications: feedback type, message, helpfulness, page/content context, reading mode, whether contact is allowed, support messages, and our internal resolution status or notes.
  • Billing and entitlement data: selected plan, trial and membership status, entitlement dates, Razorpay customer/subscription/payment identifiers, provider event IDs, payment status, and billing audit records. Meykai does not receive or store your full card, bank-account, or payment-instrument credentials.
  • Device, reliability, and security data: IP address and request metadata available to hosting/authentication providers, browser and broad device category, limited error message, route, runtime, error digest, first/last seen time, and security or anti-abuse records.

Do not submit passwords, full payment details, government identifiers, health data, or confidential employer/client information through feedback or support. Meykai does not intentionally request special-category data under Article 9 GDPR.

3. Why we process data and our lawful bases

GDPR requires a lawful basis for each purpose. Depending on the activity, we rely on contract, steps requested before a contract, legitimate interests, legal obligation, or consent.

Our legitimate interests include securing and operating the service, keeping a limited audit trail, understanding whether the product works, fixing defects, preventing fraud, and improving released content. We balance those interests against your rights by limiting event names, excluding sensitive request bodies and detailed passive telemetry, using row-level access controls, and allowing objections where the GDPR provides that right.

Where processing is based on consent, you may withdraw consent at any time. Withdrawal does not affect processing that was lawful before withdrawal.

4. Cookies, browser storage, and similar technologies

Meykai does not use third-party advertising cookies. The service currently uses the following first-party storage:

  • Authentication and security cookies: Supabase session cookies are used to keep you signed in, refresh your session, and protect account routes. These are necessary for the account service.
  • meykai_analytics_consent: a necessary first-party cookie that records “accepted” or “rejected” for 180 days so the site can respect your choice.
  • meykai_first_touch: an HTTP-only first-party cookie holding referrer, entry-page, and campaign attribution. It expires after 90 days and is not required for the reader to function.
  • meykai_beta_visitor_id: a random first-party local-storage identifier used to deduplicate and connect the limited landing and beta-funnel events described above. It remains until site data is cleared.
  • Reader storage: chapter progress, reader mode, lightweight-mode preference, Focus reading-speed baseline, and dismissed guidance are stored locally so the reader can resume and respect your settings.
  • Session storage: short-lived keys prevent duplicate event submission and cache browser capability checks until the tab or browser session ends.

Non-essential acquisition and anonymous analytics storage is disabled unless you select “Accept analytics.” You can refuse it without losing the free chapters or paid reader. You may change your choice below or clear site data in your browser. Blocking necessary authentication storage will prevent account sign-in; clearing reader storage can remove unsynchronised local progress and preferences.

5. Service providers, recipients, and international transfers

We disclose personal data only as needed to operate the service or meet legal obligations:

  • European hosting and infrastructure providers that run the website, application, network, database, backups, and operational logs.
  • Supabase for authentication, session management, database services, and account email workflows.
  • Razorpay for subscription authorisation, payment processing, fraud controls, refunds, and payment records. Razorpay may act as an independent controller for parts of its processing; see its Buyer Privacy Notice.
  • Google only if you choose Google sign-in. Google receives the OAuth request and processes sign-in data under its own terms and privacy notice.
  • Professional advisers, auditors, insurers, and authorities where reasonably necessary for legal advice, claims, compliance, fraud prevention, or a binding request.
  • A successor organisation in a merger, financing, restructuring, or asset transfer, subject to confidentiality and applicable notice requirements.

Primary hosting in Europe does not prevent all restricted transfers. Before transferring EEA/UK personal data to a country without an applicable adequacy decision, Meykai must use an appropriate Chapter V GDPR mechanism, such as the European Commission's Standard Contractual Clauses, together with supplementary measures where required. You may request information about the relevant safeguard at privacy@meykai.com.

We do not sell personal data or share it for cross-context behavioural advertising.

6. How long we keep data

We keep personal data no longer than needed for the purposes above, taking account of account status, legal obligations, security, disputes, and the ability to de-identify data.

A deletion request does not require deletion of records that must be retained for tax, payment, fraud-prevention, legal-claims, or regulatory purposes. Those records are restricted to the applicable purpose and deleted when the obligation ends.

7. Your EU/EEA and UK data-protection rights

Subject to the conditions and exemptions in applicable law, you may:

  • request access to your personal data and information about its processing;
  • correct inaccurate or incomplete data;
  • request erasure when the data is no longer needed or processing is unlawful;
  • request restriction of processing in specified circumstances;
  • receive data you provided in a structured, commonly used, machine-readable format where portability applies;
  • object to processing based on legitimate interests and object at any time to direct marketing;
  • withdraw consent where consent is the basis; and
  • lodge a complaint with your local supervisory authority. The European Data Protection Board lists EU/EEA supervisory authorities.

Email privacy@meykai.com to exercise a right. We may request proportionate information to verify identity. We will respond without undue delay and normally within one month; where the GDPR permits an extension, we will explain it within the initial month. Requests are normally free unless manifestly unfounded or excessive.

Meykai does not make decisions that produce legal or similarly significant effects based solely on automated processing. Reader Focus calculations can change presentation or surface guidance, but they do not determine access, price, employment, credit, or another legal right.

8. Security, children, changes, and contact

Security measures include encryption in transit, provider-managed encryption at rest where supported, session controls, least-privilege service credentials, row-level database access policies, environment separation, webhook verification, restricted administrative access, and limited operational logging. No online service can guarantee absolute security. If a personal-data breach is likely to create a risk to individuals, Meykai will notify the competent authority and affected individuals where required by law.

Meykai is intended for adults and is not directed to people under 18. If you believe a minor has provided personal data, contact us so the account and data can be reviewed.

We may update this policy when the product, providers, or law changes. Material changes will be highlighted in the product or by email where appropriate. The effective date above identifies the current version.