MeYay AI Privacy Policy
Effective date: October 3, 2026
This policy explains what information MeYay AI collects, why, who it goes to, how long we keep it, and what you can do about it.
In this policy, "MeYay AI", "we", and "us" mean the operator of MeYay AI. You can reach us about privacy at venjoe@meyay.ai.
MeYay AI is offered to adults in the United States.
The short version
- What you type, and the apps built from it, are sent to an AI model through OpenRouter. We don't attach your account details, but anything you type is sent as you typed it. Don't put personal or sensitive information in your ideas. See AI model processing.
- We don't sell or share your personal information for advertising, and there are no analytics, advertising, or cross-site tracking tools on MeYay AI.
- We use only the cookies needed to run the service: to keep you signed in, to complete Google sign-in, to prevent abuse of free guest trials, and, during the invite-only beta, to remember an invitation code you entered. None is used for analytics or advertising. See Cookies and local storage.
- A guest trial is deleted after 7 days unless you sign in and keep it. You can delete it sooner yourself, in the browser you used for it.
- Apps you publish can be opened by anyone who has their address. A public app's address, including the name you chose for it, is also checked once a day with Google Web Risk. See Publishing your apps.
- You can delete an app, download your data, or delete your account yourself: an app from its history in the MeYay AI Studio, the rest from your account page.
- MeYay AI is for adults 18 and older, including guest trials.
Information we collect
Information you give us
- Your ideas and change requests. What you type into MeYay AI, exactly as you type it. The start of your first idea, up to 80 characters, becomes the app's title.
- Your conversations with the Coach. If you choose Help me think in the MeYay AI Studio instead of building your idea straight away, the Coach asks you a few questions about it. We store your idea, the Coach's questions, your answers, and the Coach's latest summary of what you want. If you change the summary, your change is sent to the Coach with your next answer, which writes a new summary; when you build, we store the summary as you left it.
- Account information from Google. When you sign in with Google, we receive your Google account identifier, your email address and whether Google has verified it, your name, and the address of your profile picture. We don't receive your Google password.
- Your age declaration. Whether you declared that you are 18 or older, the version of the question you answered, and when you answered it. This is a statement you make. We don't verify your identity or collect identity documents.
- Your agreement to our terms. When you tick the box agreeing to our terms, before a guest trial, when you create an account, or before you subscribe, we record which of those it was, the versions of the Terms of Service, this policy, and the Refund Policy at the time, whether you confirmed you are 18 or older, and when.
- Payment information, through Stripe. When you first choose to upgrade, we create a customer record for you at Stripe that holds only our internal identifier for your account, and it stays there whether or not you pay. If you subscribe, Stripe collects your email address, card, and billing details directly at checkout, including your billing address, which Stripe uses to work out the sales tax due and keeps with your customer record for later renewals. We receive references to your Stripe customer and subscription, your plan, your payment status, and when your billing period ends. Stripe also sends us notices of payments, refunds, and disputes, which we keep as we receive them. They can include your email address, name, billing address, and your card's brand, last four digits, and expiry date. We never receive or store your full card number.
- Your invitation. During the invite-only beta, the invitation code you enter. We don't keep the code; we compare a one-way hash of it with the codes we issued, and remember in a cookie which invitation it was (see Cookies and local storage).
- Your invitation request. During the invite-only beta, if you ask for an invitation: the Gmail address you give and when you asked. We email that address only if we let you in. When you then sign in with Google, we compare your Google account's verified address with the requests we approved, to let you in without a code.
- Messages and reports. What you send when you email us, including abuse reports and copyright notices.
- Reports about published apps. If you report an app with the form linked from every published app, we store which app you reported, a fingerprint of the version it was showing, the reason you chose, and what you wrote. The form doesn't ask who you are, and we store nothing about you with the report. Cloudflare still processes your IP address to deliver the form, as it does for every request.
Information created as you use MeYay AI
- Your applications. For every version, including drafts from builds that didn't pass our checks: the HTML source, a content fingerprint (hash), the request it was built from, the plan our AI agents wrote for it, a summary of what changed, and the results of automated code review, security checks, and browser testing. Browser testing records screenshots of your app on a desktop and a phone screen, and any errors or failed web addresses the test saw.
- Run records. For each time our agents build or change an app: which steps ran, which AI model was used, how many tokens were processed, what it cost, how long it took, how it ended, and whether it used an AI Credit. Run records don't contain what you typed or what the model wrote; those are stored with your applications.
- Usage and billing records. Your plan history, including any free Pro given during the beta, the AI Credits granted and used and why a build wasn't charged, and whether a successful payment from a signed-in adult has occurred. The last of these is a fraud-prevention signal. It is not verification of your age or identity.
- Publishing records. If you publish an app: whether it is unlisted or public, its address, which version it shows, and when you published it.
- Security records. A record when you declare your age, when a guest trial is moved into your account, when you ask to delete your account or cancel that request, when you publish an app or stop publishing it, when a published app becomes private because your Pro plan ended, and when our daily check finds one of your public apps listed as unsafe.
- Invitation request records. Whether we approved or declined your request and when, and whether we have emailed you. If we approve it, we issue an invitation for your Gmail address alone, recorded as the invitation records below describe.
- Invitation records. During the invite-only beta, for each invitation code we issue: a one-way hash of the code, how many accounts it can admit and has admitted, the plan it gives, when it expires or was revoked, and our short note of who it is for, such as a first name or a group. If your account was created with a code, or given free Pro, we record which invitation it was, when the free Pro was given, and when it ended. If we invited you, we also keep a note of who we gave the code to and when.
Information collected automatically
- Cookies and browser storage. The cookies, and the values in your browser's storage, listed in Cookies and local storage.
- Session details. When each session started, when it was last used, and when it expires or was ended. For a guest trial we also store your browser's user-agent string and a one-way hash of your IP address.
- Abuse-prevention signals for guest trials. We turn your IP address, the random id in your visitor cookie, and a combination of your browser's user-agent and language settings into one-way hashes using a secret key, and store only those hashes. They let us count how many trials come from the same place, so that free trials can't be abused. We don't store your IP address or the visitor id itself with them. We delete them once 24 hours have passed since the trial started.
- Abuse-prevention signal for invitation requests. In the same way, a one-way hash of your IP address, kept with your request, so we can limit how many requests come from the same place. We delete it once 24 hours have passed since the request.
- Network data handled by our hosting provider. Cloudflare, which hosts MeYay AI, processes your IP address and request information to deliver the service and protect it from attacks, and keeps logs of requests to our service for up to 7 days. See Copies held by our providers.
What we don't collect
We don't collect passwords, full payment card numbers, precise location, your contacts, identity documents, or biometric information. We don't use analytics, advertising, or cross-site tracking technologies.
Sensitive information
We don't ask for sensitive personal information, such as health information, government ID numbers, financial account details, or information about your race, religion, sex life, or immigration status, and we don't knowingly collect it. MeYay AI asks you not to include it in your ideas.
We can't stop you from typing it, though. If you do, it is handled like the rest of what you type: it is stored with your app and sent to the AI model. We use it only to build your app, never to infer anything about you. If you included sensitive information by mistake, you can delete it by deleting the app it is in (see How to make a request) or your account, or email us and we will help you remove it.
How we use information
We use information to:
- Provide MeYay AI. Turn your ideas into working applications, save their versions, go back to an earlier version, and run previews and tests.
- Keep your account working. Sign you in, remember your session, and move a guest trial into your account when you sign in.
- Run the invite-only beta. Decide on invitation requests, email the people we let in, and let them in when they sign in with Google.
- Meter and bill. Count AI Credits and changes, apply plan limits, and process subscriptions.
- Protect the service and its users. Prevent trial abuse and fraud, detect and respond to attacks, check apps before they are published and public apps once a day for malware and phishing warnings, and review abuse reports and copyright notices.
- Improve reliability. Diagnose failed builds and measure cost and quality, using run records rather than your identity.
- Meet legal obligations. Keep billing records, keep a record of the terms you agreed to, and respond to lawful requests.
We don't use your ideas or applications to train AI models, and we don't make automated decisions that produce legal or similarly significant effects about you.
AI model processing
Building an application means sending information to an AI model. MeYay AI reaches AI models through OpenRouter (OpenRouter, Inc., based in the United States), which passes each request to the company that runs the model. We let our requests go only to Microsoft Azure (Microsoft Corporation, based in the United States), which runs the model, and only to endpoints that OpenRouter lists as keeping nothing they are sent and not training on it.
- What is sent: your ideas and change requests exactly as you typed them, your conversations with the Coach, the plans our agents write, the source code of your application, and the review and test results needed to fix it. Anything you type, or put into an app, is sent as it is. If it includes a name, an email address, or other personal information, OpenRouter and Microsoft receive it.
- What we don't attach: your account details, such as your name, email address, Google account identifier, or payment details, any identifier for your account or trial, and your IP address. Our requests come from MeYay AI's own OpenRouter account, not from yours.
- Where it is processed: Microsoft runs the model in its Azure data centers, which can be in the United States or in other countries, such as those of the European Union.
- How long it is kept: OpenRouter doesn't store what is in our requests or in the model's answers. It keeps records about each request, such as its size and how long it took, without its content. It may also sort a small sample of requests into categories for its own statistics, keeping those categories anonymously and never linked to our account. Microsoft, as OpenRouter lists it, doesn't keep what it is sent.
- Model training: We don't use your ideas or apps to train AI models. We haven't allowed OpenRouter to use what we send it to improve its own product, and our requests go only to providers that OpenRouter lists as not training on them. Those listings are OpenRouter's best knowledge of each provider's terms, which we don't control.
Because of this, don't include personal information, other people's information, or anything confidential in your ideas or in the apps you ask us to build.
Who we disclose information to
We don't sell your personal information, and we don't share it for cross-context behavioral advertising.
We disclose information only in these situations:
| Recipient | Why | What they receive |
|---|---|---|
| Cloudflare | Hosting, databases, file storage, running our build pipeline, automated browser testing, request logs, and security | All information described in this policy, as our service provider. Its build pipeline keeps a working record of each build, including your idea or change request and the code generated, for 1 hour after the build finishes, or 1 day if it fails. See Copies held by our providers. |
| Forward Email | Email for meyay.ai: receiving and keeping the mail sent to venjoe@meyay.ai, sending our replies, and sending the emails about invitation requests |
Emails you send us, with your name, email address, and what you write, and our replies to you. If you ask for an invitation: your Gmail address, in our note to ourselves about your request and, if we approve it, in our email to you |
| Sign-in | Google knows you used your Google account to sign in to MeYay AI | |
| Google Web Risk | Checking that public apps, and the sites that serve published apps, aren't listed as unsafe, for example for malware or phishing | Once a day, the web addresses of public apps and of meyay.app and preview.meyay.app. A public app's address includes the name its creator chose. The requests carry no account details and no app source code, and we don't send the addresses of unlisted apps. See Checking published apps. |
| Microsoft Azure | Running the AI model, through OpenRouter | What you type, plans, source code, and test results, as described in AI model processing |
| OpenRouter | Passing our requests to the AI model | What you type, plans, source code, and test results, as described in AI model processing |
| Stripe | Payments and subscriptions | Our internal identifiers for your account and for your agreement to our terms, sent when you first choose to upgrade, and the email address and payment details you give Stripe directly at checkout |
We also disclose information:
- For legal reasons. To comply with law, legal process, or enforceable government requests, or to protect the rights, safety, and property of our users, the public, or MeYay AI. This includes passing a copyright notice or counter-notice, with the contact details in it, to the other side, as the law provides.
- In a business transfer. If MeYay AI is involved in a merger, acquisition, or sale of assets, information may transfer as part of that transaction. This policy continues to apply to it.
- When you publish an app. Anyone who opens a published app sees the app as you built it, and its address. See Publishing your apps.
- With your direction. When you ask us to.
Previews of your apps
Your apps open on a separate site, preview.meyay.app, not on meyay.ai, through a link that works for 15 minutes. MeYay AI sets no cookies there, and adds no analytics, advertising, or other tracking to your apps. Cloudflare still processes each request, including the IP address of whoever opens the app, to deliver it and protect the service.
Each app runs in its own sandbox there. What an app stores in your browser stays in that browser, and we don't receive it. It is tied to the exact file of each version: a new version starts with nothing stored, a version you restore finds what it stored before, and two apps whose files are exactly the same share it. Other apps can't read it.
Publishing your apps
With a Pro plan, you can publish an app so that other people can open it. Until you do, an app is private: only you can open it, through the previews above.
- Unlisted. The app opens at an address with a random name that can't be guessed, such as
https://k3j9m2q7….meyay.app. We don't list it anywhere, and we don't send its address to anyone. But anyone who has the address can open the app and pass the address on, and if it is posted somewhere public, search engines may find it. - Public. The app opens at an address with a name you choose, such as
https://timer.meyay.app. Anyone can open it, and search engines may list it. The name is part of the address everyone sees, and it can say who you are or what the app is about, so choose it with that in mind. We check public apps' addresses once a day with Google Web Risk; see Checking published apps.
A published app shows the version you chose, as it was built. It opens on its own site, at its address, not on meyay.ai. MeYay AI sets no cookies there, and adds no analytics, advertising, or other tracking. Each published app runs in its own sandbox, on its own site. What it stores in a visitor's browser stays in that browser, we don't receive it, and other apps can't read it. Around the app we show "Made with MeYay AI" and a link to report it. Cloudflare processes each request, including the IP address of whoever opens the app, to deliver it and protect the service.
Checks before publishing. Before an app is published, and each time you publish a newer version, our own systems check its code for things such as fields that ask for passwords or card numbers, or links that hide where they go. Nothing is sent to anyone else for this. If the app doesn't pass, it isn't published, and we tell you why.
What we keep. While an app is published, we keep whether it is unlisted or public, its address, which version it shows, and when you published it, with the app in your account. We also keep a security record each time you publish an app or stop publishing it. See How long we keep information.
When you stop publishing. The app stops opening at its address, normally at once; if that step fails, the hourly cleanup retries it. If stopping it finds that the address couldn't be stopped at once, MeYay AI tells you. The app stays in your account as a private app. Its address is released, so someone else could later publish an app with the same public name. Deleting a published app, or your account, stops it at its address, normally at once; if that step fails, the hourly cleanup retries it. Until then, the address may still open.
When your Pro plan ends. Publishing is part of Pro. Your plan ends, for example, at the end of the period you paid for if you cancel, when Stripe can't collect a renewal payment after its retries, or when free Pro from the beta ends, as our Terms of Service explain. Your published apps then become private at the hourly cleanup, normally within an hour; if there are unusually many to change, or a cleanup fails, it happens at a later one. They stop opening at their addresses, the addresses are released, and we keep a security record for each. Nothing else about the apps changes: they stay in your account, where you can open and download them, and change them within the free plan's allowance. If you subscribe again and publish an app again, an unlisted app gets a new address, and a public app can have its old name only if no one else has taken it.
Reports and removals. Anyone can report a published app, with the form it links to or by email. The form doesn't ask who is reporting; we store which app was reported, a fingerprint of the version it was showing, the reason chosen, and what was written. A report stays linked to the app, even if the app is deleted, until its owner's account is deleted. Then we remove the app's and the account's identifiers from it, but keep the fingerprint and what was written until the report's time runs out. We review every report. If we remove an app, it stops opening, normally at once; if that step fails, the hourly cleanup retries it, and it can't be published again. We can also block its content from being published in any other app, by keeping a fingerprint of it, as How long we keep information says.
An app is built to your instructions. If it asks the people who use it for information, or stores information in their browsers, that is part of your app, and you are responsible for it.
Checking published apps
A browser warning about one app could affect every app on meyay.app. So once a day we ask Google Web Risk whether the web addresses of meyay.app, preview.meyay.app, and every public app are listed as unsafe, for example for malware or phishing.
- What Google receives: those addresses, sent from MeYay AI's own Google Cloud account. The requests carry no account details and no app source code. A public app's address includes the name its creator chose, which can say who they are or what the app is about. And like anyone else, Google can open a public app itself.
- What it doesn't receive: the addresses of unlisted apps.
- What we do with the answer: if an address is listed, we record that with the app, and review the app ourselves. A listing alone doesn't remove an app, and we don't show the answer to people who open it.
- What happens to them at Google: see Copies held by our providers.
Cookies and local storage
MeYay AI sets only the cookies in this table, all on meyay.ai and all needed for the service to work. None is used for analytics or advertising. They are sent only to meyay.ai, only over secure connections, and the scripts on our pages can't read them.
| Cookie | What it's for | What it holds | How long it lasts |
|---|---|---|---|
meyay_session |
Keeps you signed in, or keeps your guest trial connected to you | A session identifier, signed so it can't be forged. On our side it points to your account or your trial. | 30 days after you last used MeYay AI when signed in; 7 days after your last visit for a guest trial, and it stops working once the trial is deleted. Deleted when you sign out, delete your account, or delete your guest trial. |
meyay_visitor |
Recognizes repeat guest-trial attempts from the same browser, so a free trial can't be claimed over and over by changing network address alone | A random identifier, signed. We store only a one-way hash of it. | 2 days. Set when you start a guest trial, or try to and are refused because of our limits. |
meyay_oauth |
Protects Google sign-in against forged or replayed requests | Random one-time values for that sign-in, signed | 30 minutes. Deleted when you return from Google. |
meyay_pending_registration |
Carries your Google details to the age question the first time you sign in | Your Google account identifier, email address and whether Google has verified it, name, and profile picture address. It is signed so it can't be changed, but it isn't encrypted. | 30 minutes. Deleted when you answer the age question. |
__Host-invite |
During the invite-only beta, remembers that this browser entered a valid invitation code, so that you can start a guest trial or create an account | Our identifier for that invitation, signed so it can't be forged. Never the code itself. | 30 days. Deleted when you create an account with it. It admits no one once the code is revoked, expires, or is used up. |
Local storage. The MeYay AI Studio stores two values in your browser's local storage: the identifier of the build you started most recently, and of the app version on screen. They let the Studio pick up where you left off if you reload the page. They are removed when you start over, sign out, delete your guest trial, or delete your account.
Session storage. If you type an idea and are then asked for an invitation code, the Studio keeps what you typed in that browser tab's session storage, so it is still there when you come back from the invitation page. It is removed as soon as the Studio puts it back, and when you close the tab.
We don't use cookies, local storage, pixels, or similar technologies for analytics or advertising.
How long we keep information
Deletions happen in a cleanup that runs every hour. Where the table says something is deleted at the cleanup, it is normally gone within a day of the time given. If there is an unusually large amount to delete, it can take a few days longer. Where a time is counted from when your account is deleted, it means the end of the 30 days described in When you delete your account.
| Information | How long | Why we keep it |
|---|---|---|
| Guest trial ideas, applications, screenshots, run records, and sessions | Until the trial's 7 days end, then deleted at the cleanup, unless you signed in and moved the trial into your account. If you delete the trial yourself before then, deleted at once, or at the next cleanup if something goes wrong partway. See How to make a request. | So you can come back to the trial, and keep it by signing in |
| Abuse-prevention signals for a guest trial | Deleted at the cleanup once 24 hours have passed since the trial started, whether you moved the trial into your account, deleted it yourself, or neither. Deleting a trial yourself doesn't delete them sooner. | Our trial limits count only the trials started in the last 24 hours, including any deleted since |
| The record that a guest trial existed: its identifier and when it started, ended, and was deleted, without its abuse-prevention signals | If you never moved the trial into an account, deleted at the cleanup together with its record of agreement to our terms, at the latest 2 years after the trial started. If you moved it into your account, kept with your billing records. | It ties the record of agreement, or the billing records, to the trial they are about |
| Your applications, including what you typed, test results, and screenshots | For as long as you have your account, unless you delete an app sooner. See How to make a request. | So you can open, change, download, and go back to them |
| Conversations with the Coach | One you built an app from is kept with that app and deleted with it. One you didn't build from is deleted at the cleanup 7 days after you last used it. Both go sooner if your trial is deleted, or when your account's deletion is finalised. | To carry the conversation from one question to the next and into the app you build from it. We can't tell when you have stopped, so one you didn't build from is kept 7 days |
| Publishing records: whether an app is unlisted or public, its address, which version it shows, and when it was published | While the app is published. Deleted when you stop publishing it. Deleted when you delete the app, normally at once; if that step fails, the hourly cleanup retries it. Deleted at the hourly cleanup after your Pro plan ends. If you delete your account, your apps stop, normally at once; if that step fails, the hourly cleanup retries it, and their addresses are kept until the deletion is finalised, so no one else can take them in the meantime. If we remove an app, we keep its address, and why we removed it, for as long as the app exists. | To show your app at its address, and to keep a removed app from coming back |
| Your account profile | For as long as you have your account | To sign you in and run your account |
| Sessions | Deleted at the cleanup after they expire or you sign out | To keep you signed in |
| Account download archives | The download works for 7 days after the archive is ready. The file is deleted at the cleanup after that. The record of your request, which holds no content, is deleted 30 days later. If you delete an app, the files of downloads you asked for before then are deleted, normally at once; if that step fails, the hourly cleanup retries it. If your account deletion is finalised first, both go then. | So you have time to download it |
| Billing records: plan history, AI Credit history, run records, the empty project records they refer to, your billing account record (your Stripe customer and subscription identifiers, subscription status, and whether a payment was confirmed), and what remains of your account record after deletion (your age statement and the dates you joined and left, without your name, email address, or Google identifier) | 7 years from when each record was made or last changed, including after your account is deleted, then deleted | For tax and accounting, and to answer questions and disputes about payments and AI Credits |
| Records of your agreement to our terms | See Records of your agreement below | To show which version of our terms applied to you and that you agreed to it, including to automatic renewal |
| Payment notices from Stripe | Deleted at the cleanup once they are 13 months old | To match payments, refunds, and disputes to your account, including a dispute that closes months after the payment |
| Invitation records: the codes' hashes, limits, and our notes on who they were for, which invitation each account came from, and our notes of who we gave each code to | Kept while the invite-only beta lasts, then deleted within 3 months after it ends, except the record that an account had free Pro, which stays with the account. Whatever of these is about an account is deleted with it, when the account's deletion is finalised. | To admit only invited people, to give them free Pro, and to answer questions about it |
| Invitation requests: your Gmail address, when you asked, our decision, and when we emailed you | While you are waiting, and after we approve it, kept while the invite-only beta lasts, then deleted within 3 months after it ends. Deleted with your account, when its deletion is finalised, if you joined through it. Deleted at the cleanup 30 days after we decline it. The IP hash kept with it goes 24 hours after the request. | To decide on your request, let you in, and not ask you twice |
| Security records | Deleted at the cleanup once they are 2 years old. If you delete your account, they are kept for the rest of that time without your name or email address. | To investigate misuse of accounts and of the service |
| A fingerprint of an app removed for abuse or copyright: a one-way hash of its content, and the reason | 3 years after the removal, then deleted | To stop the same content being put back |
| Reports sent with our form about a published app: which app, a fingerprint of the version it was showing, the reason chosen, and what was written | Until we have dealt with the report, then 2 years more, then deleted at the cleanup. The report stays linked to the app, even if the app is deleted, until its owner's account is deleted. Then we remove the app's and the account's identifiers from it, and keep the fingerprint of the version reported and what was written for the rest of that time. So the report isn't anonymous: the fingerprint can match the same content elsewhere. | To recognize the same problem, such as a repeat offender, if it comes back |
| Emails you send us, including abuse reports and copyright notices, our replies, and our notes of what we did about them | Until we have dealt with what they are about, then 2 years more. We delete them once a month, so they go within about a month after those 2 years end | To answer follow-up questions, and to recognize the same problem, such as a repeat infringer, if it comes back |
| Copies we keep as evidence | See Copies we keep as evidence below | To put back an app we removed, if a counter-notice asks us to, and to answer a disputed payment, a security incident, or a legal claim |
Records of your agreement
Each time you tick the box agreeing to our terms, we keep a record of it, as described in Information you give us. Each record is deleted at the cleanup after the time below:
- Before a guest trial you never moved into an account: 2 years after you agreed.
- When you created your account, before a guest trial you moved into it, and when you started a Pro checkout that didn't lead to a subscription, such as one you never completed: kept while you have your account, then deleted 2 years after your account is deleted. If another of your checkouts led to a subscription, they aren't deleted before that checkout's record.
- When you subscribed to Pro, meaning the checkout you agreed at was completed and the subscription it created started: kept while you have your account, then deleted once 3 years have passed since you agreed and 1 year has passed since your account was deleted. California law asks for a record of agreement to automatic renewal to be kept for at least 3 years, or 1 year after the contract ends if that is longer.
Each checkout is judged on its own. If your subscription ended and you later started another checkout but didn't complete it, the record of that checkout is kept as a checkout that didn't lead to a subscription, even though an earlier one did.
Copies we keep as evidence
Some things are kept as evidence after they are gone from MeYay AI:
- an app, with its screenshots, that we removed after a copyright notice, so that we can put it back if a counter-notice asks us to;
- what we send Stripe to answer a disputed payment;
- our copies of logs and records about a security incident;
- emails and records about a legal claim that has been made, or that we reasonably expect.
We keep them apart from MeYay AI, in an encrypted store on our own computer that only we can open, and use them only for the matter they are about. That computer's backups hold the store only in the same encrypted form, and something deleted from the store can stay in a backup for a time. Each is deleted 2 years after its matter is closed, like the emails about it, within about a month of that date. A removed app's copy is also kept for as long as the app stays removed, up to 3 years, if that is longer. Anything about a legal claim is kept until the claim ends, if that is later still. If you delete your account, or ask us to delete your information, while we hold such a copy, we keep it only for its matter or claim, and delete it when that time comes.
Copies held by our providers
Our providers hold some of the same information. What each keeps, for how long, and what happens when you delete your account:
- Cloudflare, which hosts MeYay AI:
- Build records. Cloudflare's build pipeline keeps a working record of each build: your idea or change request, the plan, and the code generated. We have set it to delete the record automatically 1 hour after the build finishes, or 1 day after it fails, which leaves time to find out why it failed. Because these records go so quickly, we don't delete them separately when a trial or account is deleted; one can outlast that deletion by up to a day. A download's record holds only your account's internal identifier and where the file is stored. It is deleted the same way, and also when your account's deletion is finalised, if that comes first. In rare cases, such as when that deletion fails, it is left to its 1 hour or 1 day.
- Build progress. While a build runs, Cloudflare keeps a record for us of the stages it has reached and when, and whether you cancelled it, so the Studio can show its progress. It holds nothing you typed and none of the code generated. We have set it to delete itself 1 day after the build ends. Like build records, it isn't deleted separately when a trial is deleted, and it can outlast that deletion by up to a day.
- Request logs. Our service's logs at Cloudflare record each request to MeYay AI, with details of the request, which can include your IP address and approximate location, and the error messages our code writes when something fails. We write those messages so they don't contain what you type or the code we generate. Cloudflare keeps these logs for up to 7 days, then deletes them, and doesn't let us change that period. We use them to find and fix problems and to investigate attacks. Cloudflare also uses request information to protect its own network, under its own policies.
- Database history. Cloudflare keeps a point-in-time history of our database so it can be restored after a failure. Information deleted from the database stays in that history for up to 30 days, then ages out. Cloudflare doesn't let us turn it off or shorten it. We don't keep other backups of the database.
- Stored files. When we delete a file, such as a version of your app, a screenshot, or a download archive, it can no longer be read, and we keep no earlier versions of it. The one exception is an app we remove after a copyright notice: we keep a copy of it outside MeYay AI, as Copies we keep as evidence describes.
- Forward Email, which handles our email: keeps the emails you send us, and our replies, in an encrypted mailbox that only we can open, until we delete them as the table above says. It doesn't keep a copy of mail it only passes on; its error logs hold a message's headers, not what it says, for up to 7 days. For each email we send, it keeps a record for about 30 days, and deletes what the email says as soon as it is delivered or can't be. It also keeps encrypted backups of the mailbox, for periods it sets, so a deleted message can stay in a backup for a time.
- Google Web Risk: receives the full web addresses we check through its Lookup API. Under Google's published Cloud terms, those addresses are Customer Data, which Google processes under its Cloud Data Processing Addendum. Google also collects technical records about use of Cloud services, but its published terms do not say whether those records include each Lookup address or set a fixed period for keeping Lookup addresses. The Addendum's deletion deadlines apply after a qualifying deletion instruction or the end of the Cloud service, not after each lookup; deleting your MeYay AI account does not itself delete Google's records.
- OpenRouter and Microsoft Azure: keep none of what we send them, as AI model processing describes. OpenRouter keeps only records about each request, without its content.
- Stripe: keeps your customer record and payment records. They are part of our billing records, so deleting your account doesn't delete them; it cancels your subscription at Stripe at once. Stripe also keeps payment records under the financial, tax, anti-fraud, and other laws that apply to payment providers, for periods it sets.
When you delete your account
- Right away: you are signed out everywhere, and all your projects are made private. An active Pro subscription is cancelled at Stripe at once, not at the end of the period; the Refund Policy explains what that means for refunds.
- For the next 30 days: everything else is kept, so you can change your mind. Your account page shows the date and time the 30 days end. Sign in with the same Google account to cancel the deletion or to download your data; you can't otherwise use MeYay AI during this time. If you cancel, your projects stay private and your subscription stays cancelled.
- After 30 days: at the cleanup after that time, your name, email address, Google identifier, and profile picture are removed from your account, your identity is removed from security records, and your applications, their versions, what you typed, test results, and screenshots are permanently deleted. What remains of each project is an empty record with no title or content, kept because billing records refer to it. After that, your account can't be restored.
- Kept: billing records, records of your agreement to our terms, payment notices from Stripe, security records, and the record of any guest trial you moved into your account, for the periods in How long we keep information, without your applications. A download archive you made is deleted at the cleanup after its 7 days. Deleted information leaves the database history within 30 days. A copy we keep as evidence is kept only for its matter, as Copies we keep as evidence says. What Cloudflare and Stripe hold, including your Stripe customer record, and what we know of what Google Web Risk keeps, is described in Copies held by our providers.
Your rights and choices
Wherever you live in the United States, you can:
- Know and access the personal information we hold about you, and how we use and disclose it.
- Download your applications and account information. See How to make a request.
- Correct information that is inaccurate. Most profile information comes from your Google account, and updating it there updates it here the next time you sign in.
- Delete your account and personal information, subject to the exceptions in How long we keep information.
- Opt out of sale, sharing, and targeted advertising. We don't do any of these, so there is nothing to opt out of.
We won't discriminate against you for exercising any of these rights. Nothing in this policy limits a right the law gives you.
How to make a request
- Signed in: go to your account page at meyay.ai/account. Download my data prepares a download, and Delete my account deletes your account, as described in When you delete your account. While a deletion is waiting, the same page offers Cancel deletion.
- What the download contains: a ZIP file with every version of every app as an HTML file that opens in a browser; for each version, what you typed for it, its plan and change summary, the results of code review, security checks, and browser testing, and the screenshots the test took; your conversations with the Coach, both those you built an app from and those you didn't; and your account records: profile, plan, AI Credit history, security records about you, and the terms you agreed to. A version we removed after a copyright notice or an abuse report is left out: the download lists it as removed, without its file or screenshots. It usually takes a few minutes. The link works for 7 days, and only your most recent download is offered. It doesn't include records held by our providers, which Copies held by our providers describes.
- To delete one app: in the MeYay AI Studio, open the app, choose History, then Delete this app, and confirm. You can't delete an app while a change to it is still being made.
- What deleting it does: the app leaves your apps at once. Its versions, what you typed for it, its plans, change summaries, test results, and screenshots are deleted, and a download of your data you asked for before then stops working, normally at once; if that step fails, the hourly cleanup retries it. If the app is published, it stops opening at its address, normally at once; if that step fails, the hourly cleanup retries it. If deleting the app finds that its address couldn't be stopped at once, MeYay AI tells you. The address is released. A report made about it with our form stays linked to its empty record, as How long we keep information says. What remains is an empty project record with no title or content, kept with your billing records because the run records of its builds refer to it, as How long we keep information says. The AI Credits and changes its builds used stay used. Deleted information leaves the database history within 30 days. An app can't be restored once it is deleted.
- By email: write to venjoe@meyay.ai. We check that a request comes from the person it is about before we act on it. If you can sign in, your account page is the quickest way to download your data or delete your account. For anything else we do by email that changes or deletes your information, or tells you what we hold about you, we write to the email address on your account, even if your request came from another address. To cancel Pro or for a refund, we may write instead to the email address you gave Stripe at checkout, where your receipts go. That email has a request code and says exactly what we will do. We act only on a reply from that address that quotes the code, within 14 days. Signing in to MeYay AI doesn't confirm a request made by email.
- If you can't use the email address on your account, for example because you no longer have it, tell us so, and tell us things we can check against what we already hold, such as the card brand, last four digits, amount, and date of a payment, or the name and billing address you gave Stripe. We ask for more before we send you a copy of your information, change it, or delete your account than before we answer a general question, and never for more than the request needs. We use what you tell us only to check the request. If we can't verify that the request is yours, we may decline it or do only part of it, and we will tell you why.
- Before we send a copy, change anything, or delete an account this way, we accept only details that someone who has merely seen your apps couldn't know, so an app's title or when you made it isn't enough. Such details are, for example, a payment's card brand, last four digits, amount, and date, or the words of changes you asked us to make to an app, which the app itself doesn't show. We first write to the email address on your account and wait 7 days, so that its holder can tell us if they didn't ask. We send a copy only to an email address you have shown us you control, by replying from it with a request code we send there. If what you can tell us doesn't let us be reasonably sure the account is yours, we can't send a copy, make the change, or delete the account this way, and we will tell you why; you can still do any of these by signing in with its Google account.
- If you used a guest trial: a trial isn't linked to your name or email address, and it is deleted with everything in it after its 7 days. Until then, you can see it in the browser you used, and you can delete it sooner there: in the MeYay AI Studio, choose Delete this trial, then confirm. That browser holds the trial's session, which is how we know the trial is yours, so it is the only way to delete a trial early.
- What deleting it does: the trial ends at once, that browser leaves it, and a build still running stops. Its apps, what you typed for them, their plans, test results, and screenshots, and its run records are deleted straight away, or at the next cleanup if something goes wrong partway. We keep only what How long we keep information lists for every trial: the record that the trial existed, the record of your agreement to our terms, and, until 24 hours after the trial started, its abuse-prevention signals, so deleting a trial doesn't make room for another under our daily limits.
- By email: we can't delete a trial early for you, even if you tell us an app's title and when you started it. Anyone who has seen an app could tell us the same, and deleting someone else's work can't be undone. If you no longer have the browser you used, your trial is deleted on its usual schedule, 7 days after it started. For the same reason, we won't send a trial's contents to anyone.
- Through an authorized agent: the agent must provide written permission from you, and we may still ask you to confirm the request with us directly, in one of the ways above.
We respond within 45 days. If we need longer, we will tell you why, and we will respond within 90 days.
Appeals
If we decline your request, you can appeal by replying to our decision or emailing venjoe@meyay.ai with "Appeal" in the subject line. We will respond within 60 days and explain the result. If you disagree with the outcome, you can contact your state attorney general.
Security
We protect information with encryption in transit, signed and server-validated sessions, limited access to production systems, and isolation of generated applications from your account.
Every application built for you runs on a separate domain from your account, so it can't read your session or account data.
No system is perfectly secure. If a breach affects your personal information, we will notify you as the law requires.
Children
MeYay AI is for adults 18 and older. Before a guest trial starts, and when an account is created, the person must confirm that they are 18 or older. Anyone who answers that they are under 18 can't create an account; we keep only a record that the answer was given, with nothing that identifies who gave it.
MeYay AI isn't directed to children, and we don't knowingly collect personal information from anyone under 18. If we learn that we have, we will delete it, as we do when an account is deleted, but without waiting the usual 30 days. What When you delete your account says is kept, such as the payment records we must keep, and our emails about the matter stay for the periods in How long we keep information.
If someone other than the account holder tells us, such as a parent, we check what they tell us. While we do, we suspend the account, so it can't be used and nothing more is collected, and we write to the account holder, who can tell us they are 18 or older. We don't delete anyone's work on a report we haven't been able to verify.
For a child under 13, we delete their information as soon as we know, and keep only what we need for each of these purposes, without the child's name or contact details:
- Accounting for payments and refunds: the billing records in How long we keep information, which name the account only by our internal identifier. We delete the contact details Stripe collected at checkout from our records, and ask Stripe to delete what it can.
- Showing what happened: the record of the age that was declared and the terms that were agreed to, and security records, for their periods in that table, also without the child's name or contact details.
- Repaying a refund: one email address to write to if a refund we owe fails, kept only until every such refund has gone through and can no longer fail, about 30 days after it succeeds.
- Our own record: a note of what we did, without details about the child, kept like our other emails.
If you believe a child has used MeYay AI, contact venjoe@meyay.ai.
Using MeYay AI outside the United States
MeYay AI is offered in the United States. If you use it from elsewhere, your information is processed in the United States, in other countries where Cloudflare operates, and in the countries where Microsoft runs the AI model.
Changes to this policy
When we change this policy, we will update the effective date above. If a change materially affects how we use information we already hold, we will email account holders at least 30 days before the change takes effect. A change takes effect at the start of its effective date, at 00:00 Central Time (America/Chicago).
Contact us
MeYay AI venjoe@meyay.ai