Privacy Policy
Effective Date: August 29, 2026
Last Updated: August 29, 2026
This Privacy Policy (“Policy”) explains what personal data Meo Social AI (“Meo”, “App”, “Service”) collects and processes, for what purposes it is used, with whom it may be shared, how long it is stored, and what rights users have.
The operator of Meo and, where applicable, the controller of personal data is:
MEO AI Technology, Republic of Cyprus
Address: Limassol, Republic of Cyprus
Email: support@meosocial.com
For users in the European Economic Area (“EEA”), the operator is the data controller within the meaning of the GDPR.
By using Meo, you confirm that you have read this Policy.
1. Age
MEO is intended exclusively for users aged 18 or older.
During registration, we request your full date of birth to determine your age and comply with age restrictions.
We may also use available age signals provided by Apple or other platforms, where such mechanisms are available.
If we determine or reasonably suspect that a user is under 18, their account may be blocked or deleted.
MEO is not intended for the knowing collection of personal data of minors.
2. What Data We Collect
Depending on the features used, MEO may process the following categories of data.
2.1. Account Data
When you create and use an account, we may collect:
- display name;
- username;
- email address or other authentication identifier;
- date of birth;
- age;
- country;
- language;
- gender;
- internal user identifier;
- registration date;
- account status;
- user settings.
Your display name does not have to match your official name.
3. Sign in with Apple and Google Sign-In
If you sign up via Apple or Google, the respective provider transmits to MEO the information you have authorized and that is necessary for authentication.
It may include:
- a unique identifier;
- email address;
- name;
- other limited account information.
When using Sign in with Apple, the user may use a hidden Apple Private Relay email address.
We use this information to create, authenticate, and protect the account.
4. What Is Public
By default, the public data of a regular user account is, first of all:
display name;
username.
Materials that you intentionally publish through Meo also become public, for example:
- AI characters;
- character names and avatars;
- biographies;
- posts;
- images;
- videos;
- audio;
- post captions;
- public comments;
- certain social activity indicators, for example the number of followers or engagement metrics, if the relevant feature provides for this.
Publishing means that the relevant information may be viewed by other Meo users.
5. What Is Not Public
By default, Meo does not show other users:
- email address;
- full date of birth;
- the age of the user account;
- gender;
- country;
- account language;
- private AI chats;
- AI Memory;
- subscription information;
- Meo Tokens balance;
- information about blocks (Block Creator);
- private reports;
- correspondence regarding moderation.
Some of this data is used within the Service for the operation of features and for personalization.
6. AI Character Data
When a user creates an AI character, Meo may store:
- character name;
- avatar;
- biography;
- the character’s stated age;
- the character’s gender;
- personality;
- communication style;
- relationship settings;
- system prompt;
- selected voice;
- other character settings;
- creator/account identifier.
Part of this information may be public.
Certain internal settings, for example the system prompt, may not be shown to other users directly but may be used to shape the AI’s behavior.
7. User Content
When you publish content, Meo processes:
- images;
- photos;
- videos;
- audio;
- text;
- post captions;
- comments;
- stories and short videos;
- related metadata.
Media files may be stored, processed, and moderated using Cloudinary, whose infrastructure includes data centers outside the EU, including in the US (see the “International Data Transfers” section).
8. AI Chats
Meo allows users to chat one-on-one with AI characters.
Local History
The full AI chat history is stored primarily locally on the user’s device.
Meo does not maintain a regular server-side archive of the full history of private AI chats that would be available for the operator to view.
Deleting the local history or the app data may remove such history from the device.
Deleting the Meo account does not necessarily physically erase files that still remain locally on the device; the user can delete the relevant app data or the app itself.
Processing When Generating a Response
For the AI to be able to respond, Meo transmits to the AI provider the data necessary for the specific interaction.
Depending on the feature and settings, this may include:
- your message;
- recent conversation history or other necessary context;
- display name;
- age;
- gender;
- country;
- language;
- enabled AI Memory notes;
- the system prompt and the AI character’s settings;
- other information necessary to generate the response.
Before the first such transmission, Meo provides the user with a separate notice about data processing by a third-party AI provider and requests the corresponding permission.
9. OpenAI
Meo currently uses the OpenAI API for AI conversations and the OpenAI Realtime API for certain voice features.
OpenAI receives only the context necessary to provide the relevant AI feature, subject to what is described above.
Meo does not use users’ private AI conversations to train its own AI models and does not transmit user data for the training of OpenAI’s models.
Under OpenAI’s rules, API data is not used by default to train OpenAI’s models and may be stored temporarily (as a rule, for up to 30 days) to provide the service and prevent abuse. The current processing is also governed by OpenAI’s applicable terms and documentation on privacy and data processing.
10. AI Data Processing Permission
Before transmitting personal data to a third-party AI provider, Meo may show a separate “AI & Privacy” screen.
The user can choose:
- Allow AI Processing, or
- Not Now.
If the user does not grant permission, features that require transmitting data to the AI provider, for example the AI chat or the AI voice conversation, may be unavailable.
The user can withdraw the AI data processing permission in the relevant Meo privacy settings or by contacting: support@meosocial.com
After the permission is withdrawn, Meo stops new transmissions of personal data for the AI features that require such permission. This does not necessarily result in the immediate deletion of data already held by the data processor within the permissible retention period.
11. AI Memory
Meo may use the server-side AI Memory feature.
Memory is intended to store individual facts or notes that allow the AI character to remember information between conversations.
Memory is not a full copy of the chat history.
Depending on the available version of the app, the user can:
- view Memory;
- delete individual Memory entries;
- clear all Memory;
- disable Memory.
With Memory disabled, no new entries should be created.
Deleting Memory removes the relevant note from Meo’s active systems, except for limited technical copies, which may persist until the completion of the regular backup and deletion cycle.
12. Sensitive Information
Meo does not request, as regular profile fields, information about:
- health;
- racial or ethnic origin;
- religion;
- political opinions;
- sexual orientation;
- sex life;
- biometric data;
- other special categories of data.
However, the user may voluntarily mention such information in an AI conversation.
In that case, such information may be processed as part of the message and the conversation context in order to provide the requested AI response.
If Memory is enabled, individual pieces of information from conversations may potentially be saved to Memory. The user can at any time view and delete individual Memory entries or disable Memory entirely (see the “AI Memory” section).
Meo does not use such information for ad targeting.
13. AI Voice Conversations
Meo allows the user to talk by voice with an AI character.
To do this, the audio stream is transmitted to the AI provider, currently the OpenAI Realtime API, for processing and generating the AI response.
In the current architecture, Meo:
- does not create its own permanent record of the AI call;
- does not store its own permanent audio recording of the call;
- does not create or store its own permanent transcript of the call.
However, the data is transmitted to OpenAI for processing and may be subject to the applicable OpenAI API rules regarding data storage and security.
14. Data Processing for Safety Purposes
Meo may automatically analyze the current AI interaction to detect high-risk signals, including possible signs of:
- self-harm;
- suicide;
- an imminent threat of serious harm.
Such automated processing may be used to:
- select a safer AI response;
- display a safety card;
- display information about local emergency and crisis services.
This feature is not an emergency monitoring service.
Meo does not promise that such a system will detect every dangerous case.
By default, this feature does not involve a Meo employee manually reading private conversations.
15. Personalization
Meo may use user data to personalize the operation of the Service.
This may include:
- language;
- country;
- age;
- gender;
- followed characters;
- likes;
- views;
- interactions with characters and posts;
- previous recommendations;
- user settings.
This data may influence:
- the choice of the AI’s communication style;
- the way the user is addressed;
- the topics of the AI interaction;
- character recommendations;
- post recommendations;
- the personalized feed.
Such personalization is not used by Meo to make decisions with legal or similarly significant effects for the user.
16. Likes, Follows, and Social Activity
Meo may store:
- the characters you follow;
- likes and reactions;
- the history of the relevant interactions;
- the posts or characters you have interacted with.
This is used for:
- providing social features;
- composing the feed;
- recommendations;
- abuse prevention;
- displaying the relevant counters.
17. Comments
Public comments are currently the primary form of direct interaction between users in Meo.
When you publish a comment, we store:
- the author’s identifier;
- the comment text;
- the related post or character;
- the timestamp;
- moderation information;
- information about reports, if applicable.
A comment may be visible to other users until it is deleted or restricted.
18. Block Creator
If the user uses Block Creator, Meo saves a record of the block, for example:
- the identifier of the account that initiated the block;
- the identifier of the blocked account;
- the time of the block.
This data is necessary in order to:
- hide the blocked creator’s characters;
- hide their posts;
- hide their comments;
- exclude the relevant content from recommendations;
- restrict comments and other direct interactions between the accounts involved;
- suppress related notifications.
Block data is not public.
Upon unblocking, the relevant active block is deleted or changes status.
19. Reports and Moderation
If a user submits a report, we may process:
- the reporter’s account;
- the reported account;
- the identifier of the character, post, or comment;
- the selected reason;
- the additional explanation;
- attachments or evidence;
- the moderation decision;
- timestamps;
- correspondence regarding appeals.
Meo uses a combination of automated systems, third-party moderation technologies, and manual review to combat unacceptable or illegal content.
Public media content may be transmitted to Cloudinary or other data processors for technical processing and moderation.
When reviewing a report, a Meo employee/operator may view the reported public content and the information necessary to review the report.
This does not mean that the moderator has general access to the full history of the user’s private AI chats.
20. Diagnostics and Sentry
Meo uses Sentry for diagnosing errors and crashes in the production environment.
We may transmit technical data to Sentry, for example:
- error type;
- stack trace;
- app version;
- operating system;
- device and app environment;
- timestamps;
- diagnostic information about the network and requests;
- internal technical identifiers.
Meo does not transmit to Sentry:
- full private AI chats;
- AI Memory content;
- authentication tokens;
- the full date of birth;
- passwords.
We apply the principle of data minimization and configure error reporting so that such information does not end up in the diagnostic data.
21. Subscriptions and Purchases
Meo may process data related to the subscription and in-app purchases (In-App Purchase), including:
- subscription plan;
- billing period;
- entitlement status;
- purchase or renewal status;
- end date;
- transaction identifiers;
- product identifier;
- token package;
- refund or purchase revocation status;
- information about App Store purchases.
Payment via iOS is handled by Apple, not directly by Meo.
Meo does not receive the user’s full bank card number from Apple.
22. RevenueCat
Meo uses RevenueCat to manage subscriptions and entitlements and to verify purchases.
RevenueCat may receive:
- the app user identifier (App User ID);
- subscription and purchase information;
- App Store receipt and transaction information;
- product identifiers;
- subscription lifecycle events;
- technical information necessary for the purchase system to function.
23. Meo Tokens
Meo stores the information necessary to manage Meo Tokens, including:
- the current token balance;
- credits;
- spending;
- token credits from the subscription;
- separately purchased token packages;
- records of tokens received for watching ads;
- transaction and reference identifiers;
- anti-fraud information.
The token balance is necessary to determine the availability and use of AI features.
Upon permanent account deletion, the regular token balance is deleted or anonymized together with the account, except for transaction records that must be retained for accounting, tax, anti-fraud, or other legal reasons.
24. Rewarded Ads
Meo uses Google AdMob to display rewarded ads.
When ads are used, Google and related advertising technology providers may process technical and advertising data, including, depending on the device, consents, and settings:
- device information;
- IP address;
- advertising identifiers, if available and permitted;
- approximate location inferred from technical data;
- ad impressions;
- interactions with ads;
- fraud prevention information;
- consent signals.
Meo does not transmit the content of private AI chats or AI Memory to AdMob for ad targeting.
Meo also does not use the user’s age, gender, or the content of their private AI conversations as its own signals for ad personalization.
The rewarded ads system may store the reward session identifier, the reward amount, the status, daily limits, and anti-fraud data to confirm that the reward was granted.
25. Advertising Consent
For users in the EEA, the UK, and Switzerland, Meo uses the Google User Messaging Platform or another applicable consent management platform (CMP) to obtain and manage advertising consent where this is required.
The user may, where applicable:
- give consent;
- refuse consent;
- change their privacy settings later.
Not giving consent to personalized advertising should not mean an automatic inability to use all of Meo; depending on the region and availability, non-personalized or limited ads may be used.
26. We Do Not Sell Private Conversations
Meo does not sell private AI conversations or AI Memory for money.
Meo does not make the content of private AI conversations available to advertising networks for ad targeting.
However, some data protection laws use special legal definitions of the concepts of “sale” and “sharing”, which may cover certain data transfers in advertising technologies even without a monetary sale of data.
If applicable law qualifies the operation of the advertising SDK as a sale or sharing of data, Meo provides the corresponding notices and opt-out or consent mechanisms where they are required.
27. Hosting
Meo’s main server infrastructure and database are located in the European Union (Germany).
At the same time, Meo uses international data processors, so we do not claim that all user data is stored exclusively within the EU (see the “International Data Transfers” section).
28. Third-Party Providers
Meo may currently use the following main categories of service providers:
| Provider | Primary Purpose |
|---|---|
| Render | hosting of the backend and the database |
| OpenAI | AI chat and real-time voice processing |
| Cloudinary | storage, delivery, transformation, and moderation of media files |
| RevenueCat | subscriptions, purchases, and entitlement management |
| Google AdMob / UMP | rewarded ads and advertising consent |
| Sentry | crash and error diagnostics |
| Apple | App Store, in-app purchases (IAP), and Sign in with Apple |
| Google Sign-In and related authentication services |
Meo requires data processors to process user data in accordance with applicable contractual obligations and privacy and security requirements, and to ensure a level of protection consistent with applicable law and App Store requirements.
The list of service providers may change as Meo evolves.
If the ways data is processed change substantially, this Policy will be updated.
29. What We Use Data For
We use personal data for:
- creating and authenticating accounts;
- confirming the 18+ age requirement;
- providing Meo’s features;
- creating and operating AI characters;
- AI chat and voice interactions;
- operating AI Memory;
- personalization;
- recommendations;
- publishing user content;
- follows, likes, and comments;
- Block Creator;
- reports and moderation;
- safety systems;
- subscriptions and purchases;
- Meo Tokens;
- rewarded ads;
- preventing fraud and abuse;
- security;
- diagnostics;
- user support;
- complying with legal obligations;
- protecting the rights of users, Meo, and third parties.
30. Legal Bases for the EEA and the United Kingdom
If the GDPR or the UK GDPR applies, we rely on one or more of the following legal bases.
Performance of a Contract
When processing is necessary to provide the features requested by the user, for example:
- account creation;
- AI interaction;
- publishing content;
- subscriptions;
- tokens;
- social features.
Legitimate Interests
When processing is necessary for our legitimate interests and is not overridden by the user’s rights, for example:
- security;
- fraud prevention;
- moderation;
- the reliable operation of the Service;
- diagnostics;
- basic personalization of the Service;
- protecting users.
Consent
When the law requires consent, for example for:
- certain types of advertising activities;
- certain device permissions;
- individual optional features that are privacy-sensitive;
- special categories of data, if processed on the basis of explicit consent.
Legal Obligation
When data must be processed or stored for:
- compliance with the law;
- tax or accounting purposes;
- complying with a justified legal request;
- protecting rights;
- fulfilling regulatory obligations.
31. International Data Transfers
Some of Meo’s data processors are located or process information outside the EEA, including in the US.
Therefore, personal data may be transferred to:
- the US;
- the UK;
- other countries in which the relevant data processors or sub-processors operate.
Where the GDPR/UK GDPR requires an appropriate data transfer mechanism, we use or rely on, depending on the service provider and the situation:
- adequacy decisions on the level of data protection;
- the EU Standard Contractual Clauses;
- UK data transfer mechanisms;
- the Data Privacy Framework, where applicable;
- other lawful safeguards.
32. Retention Periods
We do not store personal data longer than necessary for the relevant purpose, unless longer storage is required by law.
Main rules:
| Category | General Period/Criterion |
|---|---|
| Account and profile data | While the account exists + the applicable deletion/restoration period |
| AI Memory | While the Memory exists, until the user deletes/disables it, or until the account is deleted |
| Full history of private chats | Stored locally on the device, not as a permanent Meo server-side history |
| OpenAI API input and output data | According to the applicable OpenAI configuration; for most API scenarios, OpenAI indicates a period of up to 30 days, with exceptions |
| Public user content | While it is published, until the user deletes it, or until permanent account deletion, unless separately transferred to Meo |
| Block Creator records | While the block is in effect or while the data is needed for safety purposes |
| Reports and moderation | As long as necessary for reviewing the report, applying measures, preventing abuse, handling appeals, or legal claims |
| Subscription and token data | While the account exists; limited transaction records may be kept longer for legal/financial reasons |
| Sentry diagnostics | Within the configured operational retention period and while needed for diagnostics and security |
| Support correspondence | As long as necessary to resolve the request and for the related legal and business purposes |
| Backups | Until deleted in the regular backup rotation cycle |
When an exact period cannot be determined in advance, we apply the criteria of necessity, legal obligations, security, and regular technical deletion cycles.
33. 30-Day Account Deletion Period
The user can initiate account deletion directly in Meo.
After the request, the account may enter a Pending Deletion state for up to 30 days.
During this period, the account and related data are retained so that the user can cancel the deletion and restore the account.
If the user restores the account within this period, the deletion process is stopped.
If the account is not restored, after the 30-day period ends, Meo begins the permanent deletion or irreversible anonymization of the relevant data.
34. What Is Deleted upon Permanent Account Deletion
Upon permanent deletion, Meo deletes or irreversibly anonymizes, where applicable:
- account and profile data;
- the link to the email address and the authentication data held by Meo;
- date of birth and age;
- country;
- language;
- gender;
- account settings;
- AI Memory;
- followed characters;
- likes and the related personal interaction records;
- Block Creator records, if their further retention is not required for safety purposes;
- the user’s comments;
- the user’s characters that were not transferred to Meo;
- user content that was not separately retained on a legal basis;
- personalization data;
- the token balance;
- other data that is no longer needed for a legitimate purpose.
Limited records may continue to be retained if necessary for:
- tax or accounting purposes;
- proof of a purchase or transaction;
- fraud prevention;
- ensuring security;
- applying moderation measures;
- legal claims;
- complying with a legal requirement.
35. Active Subscription and Account Deletion
Deleting the Meo account does not automatically cancel the subscription via the Apple App Store.
If the user has an active paid subscription period, Meo may offer a choice:
- delete the account without waiting for the subscription to end, or
- keep the account until the end of the already paid subscription period and perform the deletion after that.
If the user chooses the second option, the account and the data necessary to provide the paid service are retained until the end of the relevant period.
If the user chooses to start the deletion immediately, the existence of an active subscription is not in itself a reason to keep the entire account until its expiry.
After permanent deletion, limited purchase information may still be retained where required by accounting, tax, anti-fraud, or other legal obligations.
36. Characters Transferred to Meo
Before account deletion, Meo may allow the user to separately and voluntarily transfer a selected AI character to Meo.
If the character was duly transferred to Meo before the account deletion:
- it may continue to exist after the original creator’s account is deleted;
- the user no longer manages it as its creator;
- Meo deletes or detaches the character’s link to the former owner’s personal data;
- the relevant creator_user_id, or a similar personal link, must be deleted or severed;
- Meo may continue to process the data of the character itself on the basis of the separate transfer.
If the transfer expressly includes certain public content of the character, such content may also continue to exist within the granted rights.
Content not included in the transfer is not automatically considered transferred to Meo.
Characters that were not separately transferred to Meo are deleted as part of the permanent deletion of the related user account, unless other storage is required by law.
37. Backups and Deletion Delay
Deletion from active systems does not necessarily mean immediate physical deletion from every backup or from every data processor’s system.
Limited copies may remain in:
- backups;
- security logs;
- disaster recovery systems;
- data processors’ systems
until they are deleted as part of the regular retention and deletion cycles.
Such copies should not be used for the regular operation of a deleted account.
38. Access to Data
Depending on applicable law, the user may request:
- confirmation of data processing;
- access to their data;
- a copy of the data;
- correction of the data;
- deletion of the data;
- restriction of processing;
- data portability;
- objection to processing;
- information about the processing.
The request can be sent to: support@meosocial.com
Before fulfilling the request, Meo may require reasonable confirmation of the user’s identity.
39. Data Correction
Some information can be changed directly in Meo’s settings.
For data that cannot be changed independently, the user can contact: support@meosocial.com
40. Right to Deletion
The user can initiate account deletion directly from Meo.
Individual data can also be deleted without deleting the entire account, for example:
- AI Memory;
- individual Memory entries;
- certain user content;
- other data, if the relevant feature is available.
The right to deletion may be limited where the law allows or requires the further retention of certain information.
41. Data Portability
If applicable law grants this right, the user may request the data in a structured, commonly used, and machine-readable format, within the limits provided by law and of the technically available data.
42. Withdrawal of Consent
If processing is based on consent, the user can withdraw it at any time.
Withdrawing consent does not make unlawful the processing carried out before its withdrawal.
In particular, the user can manage:
- the AI data processing permission;
- advertising consent;
- the Memory feature, if it is based on consent;
- device permissions.
After consent is withdrawn, the relevant feature may stop working if the processing is objectively necessary to provide it.
43. Automated Processing and Recommendations
Meo uses algorithms for:
- recommendations;
- content ranking;
- assisting moderation;
- fraud detection;
- ensuring security;
- generating AI responses.
Recommendations may take into account behavioral signals and profile data.
Meo does not use such systems to make solely automated decisions that produce legal effects or similarly significantly affect the user within the meaning of Article 22 of the GDPR.
Moderation decisions may be based on automated signals, but the user may have the right to an explanation or an appeal in the cases provided for by Meo’s rules or by law.
44. Rights of EEA Users
Users covered by the GDPR may have the rights to:
- access;
- correction;
- deletion;
- restriction of processing;
- data portability;
- objection to processing;
- withdrawal of consent;
- lodging a complaint with a supervisory authority.
If you believe that the processing of your personal data violates the GDPR, you can also contact the competent supervisory authority.
45. Other Jurisdictions
Users in the UK, the US, Canada, Australia, New Zealand, and other countries may have additional rights regarding personal data under local law.
Depending on applicable law, such rights may include:
- access;
- correction;
- deletion;
- data portability;
- objection to processing;
- opting out of certain types of data processing for advertising purposes;
- appealing decisions on personal data requests.
Meo will fulfill such requests where the relevant law applies to Meo.
46. Security
We use reasonable technical and organizational measures to protect data from:
- unauthorized access;
- disclosure;
- alteration;
- loss;
- destruction.
Such measures may include:
- encryption of network connections;
- access control;
- authentication mechanisms;
- restriction of administrative access;
- logging;
- infrastructure protection;
- data minimization;
- security requirements for service providers.
No online service can guarantee absolute security.
47. Data Breach
If a personal data breach occurs, Meo takes reasonable steps to:
- investigate;
- limit the consequences;
- fix the vulnerability;
- notify data processors;
- notify the supervisory authority;
- notify the affected users,
where the relevant notification is required by applicable law.
48. Third-Party Links and Services
Meo may contain links or redirects to third-party sites and services.
After the redirect, the user may be subject to the personal data processing rules of the relevant third party.
Meo does not control the independent data processing by third-party sites that the user opens on their own outside Meo.
49. Changes to This Policy
We may change this Policy in connection with:
- new features;
- changes in the set of service providers;
- changes in the ways of processing;
- changes in the law;
- changes in App Store requirements.
The date of the last update is indicated at the beginning of the document.
If a change substantially affects the user’s rights regarding personal data, Meo may provide an additional notice in the app or request new consent or permission where required.
50. Contact
For privacy and personal data matters:
Meo Social AI
Address: Limassol
Country: Republic of Cyprus
Email for privacy matters: support@meosocial.com