MeYay AI

MeYay AI Privacy Policy

Effective date: October 3, 2026

This policy explains what information MeYay AI collects, why, who it goes to, how long we keep it, and what you can do about it.

In this policy, "MeYay AI", "we", and "us" mean the operator of MeYay AI. You can reach us about privacy at venjoe@meyay.ai.

MeYay AI is offered to adults in the United States.

The short version

Information we collect

Information you give us

Information created as you use MeYay AI

Information collected automatically

What we don't collect

We don't collect passwords, full payment card numbers, precise location, your contacts, identity documents, or biometric information. We don't use analytics, advertising, or cross-site tracking technologies.

Sensitive information

We don't ask for sensitive personal information, such as health information, government ID numbers, financial account details, or information about your race, religion, sex life, or immigration status, and we don't knowingly collect it. MeYay AI asks you not to include it in your ideas.

We can't stop you from typing it, though. If you do, it is handled like the rest of what you type: it is stored with your app and sent to the AI model. We use it only to build your app, never to infer anything about you. If you included sensitive information by mistake, you can delete it by deleting the app it is in (see How to make a request) or your account, or email us and we will help you remove it.

How we use information

We use information to:

We don't use your ideas or applications to train AI models, and we don't make automated decisions that produce legal or similarly significant effects about you.

AI model processing

Building an application means sending information to an AI model. MeYay AI reaches AI models through OpenRouter (OpenRouter, Inc., based in the United States), which passes each request to the company that runs the model. We let our requests go only to Microsoft Azure (Microsoft Corporation, based in the United States), which runs the model, and only to endpoints that OpenRouter lists as keeping nothing they are sent and not training on it.

Because of this, don't include personal information, other people's information, or anything confidential in your ideas or in the apps you ask us to build.

Who we disclose information to

We don't sell your personal information, and we don't share it for cross-context behavioral advertising.

We disclose information only in these situations:

Recipient Why What they receive
Cloudflare Hosting, databases, file storage, running our build pipeline, automated browser testing, request logs, and security All information described in this policy, as our service provider. Its build pipeline keeps a working record of each build, including your idea or change request and the code generated, for 1 hour after the build finishes, or 1 day if it fails. See Copies held by our providers.
Forward Email Email for meyay.ai: receiving and keeping the mail sent to venjoe@meyay.ai, sending our replies, and sending the emails about invitation requests Emails you send us, with your name, email address, and what you write, and our replies to you. If you ask for an invitation: your Gmail address, in our note to ourselves about your request and, if we approve it, in our email to you
Google Sign-in Google knows you used your Google account to sign in to MeYay AI
Google Web Risk Checking that public apps, and the sites that serve published apps, aren't listed as unsafe, for example for malware or phishing Once a day, the web addresses of public apps and of meyay.app and preview.meyay.app. A public app's address includes the name its creator chose. The requests carry no account details and no app source code, and we don't send the addresses of unlisted apps. See Checking published apps.
Microsoft Azure Running the AI model, through OpenRouter What you type, plans, source code, and test results, as described in AI model processing
OpenRouter Passing our requests to the AI model What you type, plans, source code, and test results, as described in AI model processing
Stripe Payments and subscriptions Our internal identifiers for your account and for your agreement to our terms, sent when you first choose to upgrade, and the email address and payment details you give Stripe directly at checkout

We also disclose information:

Previews of your apps

Your apps open on a separate site, preview.meyay.app, not on meyay.ai, through a link that works for 15 minutes. MeYay AI sets no cookies there, and adds no analytics, advertising, or other tracking to your apps. Cloudflare still processes each request, including the IP address of whoever opens the app, to deliver it and protect the service.

Each app runs in its own sandbox there. What an app stores in your browser stays in that browser, and we don't receive it. It is tied to the exact file of each version: a new version starts with nothing stored, a version you restore finds what it stored before, and two apps whose files are exactly the same share it. Other apps can't read it.

Publishing your apps

With a Pro plan, you can publish an app so that other people can open it. Until you do, an app is private: only you can open it, through the previews above.

A published app shows the version you chose, as it was built. It opens on its own site, at its address, not on meyay.ai. MeYay AI sets no cookies there, and adds no analytics, advertising, or other tracking. Each published app runs in its own sandbox, on its own site. What it stores in a visitor's browser stays in that browser, we don't receive it, and other apps can't read it. Around the app we show "Made with MeYay AI" and a link to report it. Cloudflare processes each request, including the IP address of whoever opens the app, to deliver it and protect the service.

Checks before publishing. Before an app is published, and each time you publish a newer version, our own systems check its code for things such as fields that ask for passwords or card numbers, or links that hide where they go. Nothing is sent to anyone else for this. If the app doesn't pass, it isn't published, and we tell you why.

What we keep. While an app is published, we keep whether it is unlisted or public, its address, which version it shows, and when you published it, with the app in your account. We also keep a security record each time you publish an app or stop publishing it. See How long we keep information.

When you stop publishing. The app stops opening at its address, normally at once; if that step fails, the hourly cleanup retries it. If stopping it finds that the address couldn't be stopped at once, MeYay AI tells you. The app stays in your account as a private app. Its address is released, so someone else could later publish an app with the same public name. Deleting a published app, or your account, stops it at its address, normally at once; if that step fails, the hourly cleanup retries it. Until then, the address may still open.

When your Pro plan ends. Publishing is part of Pro. Your plan ends, for example, at the end of the period you paid for if you cancel, when Stripe can't collect a renewal payment after its retries, or when free Pro from the beta ends, as our Terms of Service explain. Your published apps then become private at the hourly cleanup, normally within an hour; if there are unusually many to change, or a cleanup fails, it happens at a later one. They stop opening at their addresses, the addresses are released, and we keep a security record for each. Nothing else about the apps changes: they stay in your account, where you can open and download them, and change them within the free plan's allowance. If you subscribe again and publish an app again, an unlisted app gets a new address, and a public app can have its old name only if no one else has taken it.

Reports and removals. Anyone can report a published app, with the form it links to or by email. The form doesn't ask who is reporting; we store which app was reported, a fingerprint of the version it was showing, the reason chosen, and what was written. A report stays linked to the app, even if the app is deleted, until its owner's account is deleted. Then we remove the app's and the account's identifiers from it, but keep the fingerprint and what was written until the report's time runs out. We review every report. If we remove an app, it stops opening, normally at once; if that step fails, the hourly cleanup retries it, and it can't be published again. We can also block its content from being published in any other app, by keeping a fingerprint of it, as How long we keep information says.

An app is built to your instructions. If it asks the people who use it for information, or stores information in their browsers, that is part of your app, and you are responsible for it.

Checking published apps

A browser warning about one app could affect every app on meyay.app. So once a day we ask Google Web Risk whether the web addresses of meyay.app, preview.meyay.app, and every public app are listed as unsafe, for example for malware or phishing.

Cookies and local storage

MeYay AI sets only the cookies in this table, all on meyay.ai and all needed for the service to work. None is used for analytics or advertising. They are sent only to meyay.ai, only over secure connections, and the scripts on our pages can't read them.

Cookie What it's for What it holds How long it lasts
meyay_session Keeps you signed in, or keeps your guest trial connected to you A session identifier, signed so it can't be forged. On our side it points to your account or your trial. 30 days after you last used MeYay AI when signed in; 7 days after your last visit for a guest trial, and it stops working once the trial is deleted. Deleted when you sign out, delete your account, or delete your guest trial.
meyay_visitor Recognizes repeat guest-trial attempts from the same browser, so a free trial can't be claimed over and over by changing network address alone A random identifier, signed. We store only a one-way hash of it. 2 days. Set when you start a guest trial, or try to and are refused because of our limits.
meyay_oauth Protects Google sign-in against forged or replayed requests Random one-time values for that sign-in, signed 30 minutes. Deleted when you return from Google.
meyay_pending_registration Carries your Google details to the age question the first time you sign in Your Google account identifier, email address and whether Google has verified it, name, and profile picture address. It is signed so it can't be changed, but it isn't encrypted. 30 minutes. Deleted when you answer the age question.
__Host-invite During the invite-only beta, remembers that this browser entered a valid invitation code, so that you can start a guest trial or create an account Our identifier for that invitation, signed so it can't be forged. Never the code itself. 30 days. Deleted when you create an account with it. It admits no one once the code is revoked, expires, or is used up.

Local storage. The MeYay AI Studio stores two values in your browser's local storage: the identifier of the build you started most recently, and of the app version on screen. They let the Studio pick up where you left off if you reload the page. They are removed when you start over, sign out, delete your guest trial, or delete your account.

Session storage. If you type an idea and are then asked for an invitation code, the Studio keeps what you typed in that browser tab's session storage, so it is still there when you come back from the invitation page. It is removed as soon as the Studio puts it back, and when you close the tab.

We don't use cookies, local storage, pixels, or similar technologies for analytics or advertising.

How long we keep information

Deletions happen in a cleanup that runs every hour. Where the table says something is deleted at the cleanup, it is normally gone within a day of the time given. If there is an unusually large amount to delete, it can take a few days longer. Where a time is counted from when your account is deleted, it means the end of the 30 days described in When you delete your account.

Information How long Why we keep it
Guest trial ideas, applications, screenshots, run records, and sessions Until the trial's 7 days end, then deleted at the cleanup, unless you signed in and moved the trial into your account. If you delete the trial yourself before then, deleted at once, or at the next cleanup if something goes wrong partway. See How to make a request. So you can come back to the trial, and keep it by signing in
Abuse-prevention signals for a guest trial Deleted at the cleanup once 24 hours have passed since the trial started, whether you moved the trial into your account, deleted it yourself, or neither. Deleting a trial yourself doesn't delete them sooner. Our trial limits count only the trials started in the last 24 hours, including any deleted since
The record that a guest trial existed: its identifier and when it started, ended, and was deleted, without its abuse-prevention signals If you never moved the trial into an account, deleted at the cleanup together with its record of agreement to our terms, at the latest 2 years after the trial started. If you moved it into your account, kept with your billing records. It ties the record of agreement, or the billing records, to the trial they are about
Your applications, including what you typed, test results, and screenshots For as long as you have your account, unless you delete an app sooner. See How to make a request. So you can open, change, download, and go back to them
Conversations with the Coach One you built an app from is kept with that app and deleted with it. One you didn't build from is deleted at the cleanup 7 days after you last used it. Both go sooner if your trial is deleted, or when your account's deletion is finalised. To carry the conversation from one question to the next and into the app you build from it. We can't tell when you have stopped, so one you didn't build from is kept 7 days
Publishing records: whether an app is unlisted or public, its address, which version it shows, and when it was published While the app is published. Deleted when you stop publishing it. Deleted when you delete the app, normally at once; if that step fails, the hourly cleanup retries it. Deleted at the hourly cleanup after your Pro plan ends. If you delete your account, your apps stop, normally at once; if that step fails, the hourly cleanup retries it, and their addresses are kept until the deletion is finalised, so no one else can take them in the meantime. If we remove an app, we keep its address, and why we removed it, for as long as the app exists. To show your app at its address, and to keep a removed app from coming back
Your account profile For as long as you have your account To sign you in and run your account
Sessions Deleted at the cleanup after they expire or you sign out To keep you signed in
Account download archives The download works for 7 days after the archive is ready. The file is deleted at the cleanup after that. The record of your request, which holds no content, is deleted 30 days later. If you delete an app, the files of downloads you asked for before then are deleted, normally at once; if that step fails, the hourly cleanup retries it. If your account deletion is finalised first, both go then. So you have time to download it
Billing records: plan history, AI Credit history, run records, the empty project records they refer to, your billing account record (your Stripe customer and subscription identifiers, subscription status, and whether a payment was confirmed), and what remains of your account record after deletion (your age statement and the dates you joined and left, without your name, email address, or Google identifier) 7 years from when each record was made or last changed, including after your account is deleted, then deleted For tax and accounting, and to answer questions and disputes about payments and AI Credits
Records of your agreement to our terms See Records of your agreement below To show which version of our terms applied to you and that you agreed to it, including to automatic renewal
Payment notices from Stripe Deleted at the cleanup once they are 13 months old To match payments, refunds, and disputes to your account, including a dispute that closes months after the payment
Invitation records: the codes' hashes, limits, and our notes on who they were for, which invitation each account came from, and our notes of who we gave each code to Kept while the invite-only beta lasts, then deleted within 3 months after it ends, except the record that an account had free Pro, which stays with the account. Whatever of these is about an account is deleted with it, when the account's deletion is finalised. To admit only invited people, to give them free Pro, and to answer questions about it
Invitation requests: your Gmail address, when you asked, our decision, and when we emailed you While you are waiting, and after we approve it, kept while the invite-only beta lasts, then deleted within 3 months after it ends. Deleted with your account, when its deletion is finalised, if you joined through it. Deleted at the cleanup 30 days after we decline it. The IP hash kept with it goes 24 hours after the request. To decide on your request, let you in, and not ask you twice
Security records Deleted at the cleanup once they are 2 years old. If you delete your account, they are kept for the rest of that time without your name or email address. To investigate misuse of accounts and of the service
A fingerprint of an app removed for abuse or copyright: a one-way hash of its content, and the reason 3 years after the removal, then deleted To stop the same content being put back
Reports sent with our form about a published app: which app, a fingerprint of the version it was showing, the reason chosen, and what was written Until we have dealt with the report, then 2 years more, then deleted at the cleanup. The report stays linked to the app, even if the app is deleted, until its owner's account is deleted. Then we remove the app's and the account's identifiers from it, and keep the fingerprint of the version reported and what was written for the rest of that time. So the report isn't anonymous: the fingerprint can match the same content elsewhere. To recognize the same problem, such as a repeat offender, if it comes back
Emails you send us, including abuse reports and copyright notices, our replies, and our notes of what we did about them Until we have dealt with what they are about, then 2 years more. We delete them once a month, so they go within about a month after those 2 years end To answer follow-up questions, and to recognize the same problem, such as a repeat infringer, if it comes back
Copies we keep as evidence See Copies we keep as evidence below To put back an app we removed, if a counter-notice asks us to, and to answer a disputed payment, a security incident, or a legal claim

Records of your agreement

Each time you tick the box agreeing to our terms, we keep a record of it, as described in Information you give us. Each record is deleted at the cleanup after the time below:

Each checkout is judged on its own. If your subscription ended and you later started another checkout but didn't complete it, the record of that checkout is kept as a checkout that didn't lead to a subscription, even though an earlier one did.

Copies we keep as evidence

Some things are kept as evidence after they are gone from MeYay AI:

We keep them apart from MeYay AI, in an encrypted store on our own computer that only we can open, and use them only for the matter they are about. That computer's backups hold the store only in the same encrypted form, and something deleted from the store can stay in a backup for a time. Each is deleted 2 years after its matter is closed, like the emails about it, within about a month of that date. A removed app's copy is also kept for as long as the app stays removed, up to 3 years, if that is longer. Anything about a legal claim is kept until the claim ends, if that is later still. If you delete your account, or ask us to delete your information, while we hold such a copy, we keep it only for its matter or claim, and delete it when that time comes.

Copies held by our providers

Our providers hold some of the same information. What each keeps, for how long, and what happens when you delete your account:

When you delete your account

Your rights and choices

Wherever you live in the United States, you can:

We won't discriminate against you for exercising any of these rights. Nothing in this policy limits a right the law gives you.

How to make a request

We respond within 45 days. If we need longer, we will tell you why, and we will respond within 90 days.

Appeals

If we decline your request, you can appeal by replying to our decision or emailing venjoe@meyay.ai with "Appeal" in the subject line. We will respond within 60 days and explain the result. If you disagree with the outcome, you can contact your state attorney general.

Security

We protect information with encryption in transit, signed and server-validated sessions, limited access to production systems, and isolation of generated applications from your account.

Every application built for you runs on a separate domain from your account, so it can't read your session or account data.

No system is perfectly secure. If a breach affects your personal information, we will notify you as the law requires.

Children

MeYay AI is for adults 18 and older. Before a guest trial starts, and when an account is created, the person must confirm that they are 18 or older. Anyone who answers that they are under 18 can't create an account; we keep only a record that the answer was given, with nothing that identifies who gave it.

MeYay AI isn't directed to children, and we don't knowingly collect personal information from anyone under 18. If we learn that we have, we will delete it, as we do when an account is deleted, but without waiting the usual 30 days. What When you delete your account says is kept, such as the payment records we must keep, and our emails about the matter stay for the periods in How long we keep information.

If someone other than the account holder tells us, such as a parent, we check what they tell us. While we do, we suspend the account, so it can't be used and nothing more is collected, and we write to the account holder, who can tell us they are 18 or older. We don't delete anyone's work on a report we haven't been able to verify.

For a child under 13, we delete their information as soon as we know, and keep only what we need for each of these purposes, without the child's name or contact details:

If you believe a child has used MeYay AI, contact venjoe@meyay.ai.

Using MeYay AI outside the United States

MeYay AI is offered in the United States. If you use it from elsewhere, your information is processed in the United States, in other countries where Cloudflare operates, and in the countries where Microsoft runs the AI model.

Changes to this policy

When we change this policy, we will update the effective date above. If a change materially affects how we use information we already hold, we will email account holders at least 30 days before the change takes effect. A change takes effect at the start of its effective date, at 00:00 Central Time (America/Chicago).

Contact us

MeYay AI venjoe@meyay.ai