Privacy and data protection
Privacy Policy
Effective and last updated: 17 July 2026
This policy explains how Meykai handles personal data across the public website, account creation, free chapters, the Meykai reader, Core memberships, billing, support, and beta feedback. It is written to provide the transparency expected by the EU General Data Protection Regulation (GDPR) and equivalent UK requirements.
1. Controller, scope, and contact
Meykai determines why and how personal data is processed for this service and acts as the data controller. Privacy questions and data-rights requests can be sent to privacy@meykai.com. General support can be reached at support@meykai.com.
This policy applies when you visit a Meykai-controlled website, create or use an account, read content, start a trial or membership, submit feedback, or contact us. A third party's own notice applies when that third party acts as an independent controller—for example, Razorpay for payment processing or Google when you choose Google sign-in.
Meykai does not currently appoint a separate data-protection officer. If an EU representative is required under Article 27 GDPR, its identity and contact details must be added to this section. Server location alone does not establish an EU entity or replace that requirement.
2. Personal data we process
We collect data you provide, data generated when you use the service, and limited data received from service providers:
- Account and identity data: display name, email address, authentication method, user ID, account timestamps, and—if you choose Google sign-in—basic identity information returned by Google.
- Profile and onboarding data: role, experience or AI-familiarity level, learning goals, company context, industry, available learning time, plan intent, and optional company name.
- Reader and learning data: chapters opened, saved position, last block, completion, active reading time, resume activity, search/library actions, and reader mode or accessibility settings.
- On-device focus data: the Focus reader can calculate a rolling reading-speed estimate from the time content blocks remain in the focal area. Raw block samples and the resulting WPM baseline are processed and stored locally in your browser; the current product does not upload raw block-by-block WPM samples to the server.
- Acquisition and essential event data: referrer origin and path, entry page, campaign/UTM values, signup method, anonymous visitor ID, broad viewport category, application revision, event name, page path, content ID, and event time.
- Feedback and communications: feedback type, message, helpfulness, page/content context, reading mode, whether contact is allowed, support messages, and our internal resolution status or notes.
- Billing and entitlement data: selected plan, trial and membership status, entitlement dates, Razorpay customer/subscription/payment identifiers, provider event IDs, payment status, and billing audit records. Meykai does not receive or store your full card, bank-account, or payment-instrument credentials.
- Device, reliability, and security data: IP address and request metadata available to hosting/authentication providers, browser and broad device category, limited error message, route, runtime, error digest, first/last seen time, and security or anti-abuse records.
Do not submit passwords, full payment details, government identifiers, health data, or confidential employer/client information through feedback or support. Meykai does not intentionally request special-category data under Article 9 GDPR.
3. Why we process data and our lawful bases
GDPR requires a lawful basis for each purpose. Depending on the activity, we rely on contract, steps requested before a contract, legitimate interests, legal obligation, or consent.
| Purpose | Data | GDPR basis |
|---|---|---|
| Create and secure your account; authenticate you; provide Chapters 1–3 and paid access. | Account, authentication, profile, device, and entitlement data. | Steps before entering a contract and performance of our contract with you. Security processing is also based on our legitimate interests. |
| Operate the reader, remember settings, save progress, and resume learning. | Reader preferences, progress, completion, active reading time, and locally stored reading-speed baseline. | Performance of our contract and our legitimate interest in providing a reliable, usable service. |
| Process trials, subscriptions, renewals, cancellations, and payment support. | Plan, entitlement, billing contact, provider identifiers, status, and transaction audit data. | Performance of our contract and compliance with accounting, tax, fraud-prevention, and consumer-law obligations. |
| Understand acquisition and the minimum product funnel. | Referrer and UTM values, entry page, anonymous visitor ID, broad viewport category, and essential product events. | Consent where required for non-essential device storage; otherwise our legitimate interest in measuring and improving the service. |
| Review feedback, answer support requests, and improve content. | Feedback text, helpfulness, page/content context, contact choice, and correspondence. | Our legitimate interests; consent where you separately ask us to contact you or publish an attribution. |
| Protect the service, investigate abuse, and diagnose failures. | IP address and request metadata held by infrastructure providers, limited error messages, route, runtime, application revision, and security records. | Our legitimate interests in security, service integrity, and legal claims; legal obligation where applicable. |
Our legitimate interests include securing and operating the service, keeping a limited audit trail, understanding whether the product works, fixing defects, preventing fraud, and improving released content. We balance those interests against your rights by limiting event names, excluding sensitive request bodies and detailed passive telemetry, using row-level access controls, and allowing objections where the GDPR provides that right.
Where processing is based on consent, you may withdraw consent at any time. Withdrawal does not affect processing that was lawful before withdrawal.
4. Cookies, browser storage, and similar technologies
Meykai does not use third-party advertising cookies. The service currently uses the following first-party storage:
- Authentication and security cookies: Supabase session cookies are used to keep you signed in, refresh your session, and protect account routes. These are necessary for the account service.
meykai_analytics_consent: a necessary first-party cookie that records “accepted” or “rejected” for 180 days so the site can respect your choice.meykai_first_touch: an HTTP-only first-party cookie holding referrer, entry-page, and campaign attribution. It expires after 90 days and is not required for the reader to function.meykai_beta_visitor_id: a random first-party local-storage identifier used to deduplicate and connect the limited landing and beta-funnel events described above. It remains until site data is cleared.- Reader storage: chapter progress, reader mode, lightweight-mode preference, Focus reading-speed baseline, and dismissed guidance are stored locally so the reader can resume and respect your settings.
- Session storage: short-lived keys prevent duplicate event submission and cache browser capability checks until the tab or browser session ends.
Non-essential acquisition and anonymous analytics storage is disabled unless you select “Accept analytics.” You can refuse it without losing the free chapters or paid reader. You may change your choice below or clear site data in your browser. Blocking necessary authentication storage will prevent account sign-in; clearing reader storage can remove unsynchronised local progress and preferences.
6. How long we keep data
We keep personal data no longer than needed for the purposes above, taking account of account status, legal obligations, security, disputes, and the ability to de-identify data.
| Record | Normal retention rule |
|---|---|
| First-touch attribution cookie | 90 days, matching the cookie expiry. |
| Anonymous browser identifier | Until you clear site data. Associated server-side launch events are normally kept for up to 24 months, then deleted or irreversibly aggregated. |
| Account, profile, entitlement, and reader progress | For the life of the account. On a verified deletion request, active records are deleted or de-identified, subject to a short operational period and legal exceptions. |
| Local reader settings and progress | On your device until you clear site data, reset the setting, or remove it through available product controls. |
| Feedback and support correspondence | Until resolved and normally for up to 24 months afterwards, unless needed longer for a continuing issue or legal claim. |
| Product events and production errors | Normally up to 24 months for product events and 12 months after resolution for errors, unless a shorter period is sufficient or a longer period is required for security or claims. |
| Billing, subscription, tax, and payment audit records | For the period required by applicable accounting, tax, payment, and anti-fraud laws—commonly 7–10 years depending on the record and jurisdiction. |
| Backups | Rotated on the infrastructure provider’s schedule. Deleted data may remain in protected backups for a limited period before automatic overwrite and is not restored except for disaster recovery. |
A deletion request does not require deletion of records that must be retained for tax, payment, fraud-prevention, legal-claims, or regulatory purposes. Those records are restricted to the applicable purpose and deleted when the obligation ends.
7. Your EU/EEA and UK data-protection rights
Subject to the conditions and exemptions in applicable law, you may:
- request access to your personal data and information about its processing;
- correct inaccurate or incomplete data;
- request erasure when the data is no longer needed or processing is unlawful;
- request restriction of processing in specified circumstances;
- receive data you provided in a structured, commonly used, machine-readable format where portability applies;
- object to processing based on legitimate interests and object at any time to direct marketing;
- withdraw consent where consent is the basis; and
- lodge a complaint with your local supervisory authority. The European Data Protection Board lists EU/EEA supervisory authorities.
Email privacy@meykai.com to exercise a right. We may request proportionate information to verify identity. We will respond without undue delay and normally within one month; where the GDPR permits an extension, we will explain it within the initial month. Requests are normally free unless manifestly unfounded or excessive.
Meykai does not make decisions that produce legal or similarly significant effects based solely on automated processing. Reader Focus calculations can change presentation or surface guidance, but they do not determine access, price, employment, credit, or another legal right.
8. Security, children, changes, and contact
Security measures include encryption in transit, provider-managed encryption at rest where supported, session controls, least-privilege service credentials, row-level database access policies, environment separation, webhook verification, restricted administrative access, and limited operational logging. No online service can guarantee absolute security. If a personal-data breach is likely to create a risk to individuals, Meykai will notify the competent authority and affected individuals where required by law.
Meykai is intended for adults and is not directed to people under 18. If you believe a minor has provided personal data, contact us so the account and data can be reviewed.
We may update this policy when the product, providers, or law changes. Material changes will be highlighted in the product or by email where appropriate. The effective date above identifies the current version.