Meeds
Overview Research Pricing About us Shop Download App
Sign in Sign up Open Meeds
Overview Research Pricing About us Shop
Download App
Sign in Sign up Open Meeds

Legal

Privacy Policy

How Meeds handles personal and consumer health information.

Effective
July 11, 2026
Last updated
July 11, 2026

On this page

1. Information We Collect 2. How We Use Information 3. Legal Bases (EEA/UK Users) 4. How We Share Information 5. Meeds and HIPAA 6. Data Retention 7. Your Rights and Choices 8. Consumer Health Data (Washington MHMDA, Nevada SB 370, and Similar Laws) 9. Security 10. International Data Transfers 11. Children 12. Do Not Track and Opt-Out Preference Signals 13. Changes to This Policy 14. Contact Us
On this page
1. Information We Collect 2. How We Use Information 3. Legal Bases (EEA/UK Users) 4. How We Share Information 5. Meeds and HIPAA 6. Data Retention 7. Your Rights and Choices 8. Consumer Health Data (Washington MHMDA, Nevada SB 370, and Similar Laws) 9. Security 10. International Data Transfers 11. Children 12. Do Not Track and Opt-Out Preference Signals 13. Changes to This Policy 14. Contact Us

This Privacy Policy describes how Meeds Research Inc. ("Meeds," "we," "us") collects, uses, and shares personal information when you use our websites, web application, mobile applications, and related services (the "Service").

The short version:

  • You own your health data. We use it to run the Service for you — nothing else.
  • We do not sell your personal information. We do not share it for targeted advertising. We do not use your health information to train AI models.
  • You can delete your data and your account at any time.
  • Meeds is a consumer wellness product, not a healthcare provider, and is generally not subject to HIPAA (explained below).

This Policy also serves as our Consumer Health Data Privacy Policy for purposes of the Washington My Health My Data Act, Nevada SB 370, and similar laws (see Section 8).

1. Information We Collect

Information you provide:

  • Account information — name, email address, phone number, date of birth, password (stored in hashed form by our authentication provider), and profile details you choose to add.
  • Health information you submit — messages and questions you send to the AI, documents you upload (such as lab reports and health records), and health values, conditions, medications, supplements, or metrics you enter or confirm. Values extracted from your documents by AI are saved to your health profile only after you confirm them.
  • Payment information — processed by our payment processors (Stripe for web purchases; Apple for App Store purchases). We do not receive or store full payment-card numbers. We receive limited information such as subscription status, plan, and transaction identifiers.
  • Communications — messages you send us (for example, support requests).

Information collected automatically:

  • Usage information — features used, AI requests made (including counts against usage limits), timestamps, and interaction events.
  • Device and technical information — IP address, device type, operating system, browser type, app version, language, and identifiers used for security and abuse prevention (including device-attestation and app-integrity signals, and anti-fraud identifiers used to enforce free-tier limits).
  • Cookies and similar technologies — used for authentication, session management, security, and remembering preferences. We do not use third-party advertising cookies. Our sign-in and abuse-prevention systems use Google reCAPTCHA Enterprise, whose use is subject to the Google Privacy Policy and Terms of Service.

Information from third parties:

  • If you sign in with a third-party identity provider (for example, Apple or Google sign-in), we receive the information you authorize that provider to share (such as name and email address).
  • Subscription status and transaction confirmations from Stripe or Apple.

We do not knowingly collect information from anyone under 18 (see Section 11).

2. How We Use Information

We use personal information to:

  1. Provide the Service — operate your account, generate AI responses to your requests, analyze documents you upload, maintain your health profile, and sync your data across your devices;
  2. Process payments and manage subscriptions;
  3. Enforce usage limits and prevent fraud and abuse — including using IP addresses, device signals, and related identifiers to enforce free-tier limits and detect circumvention;
  4. Secure the Service — authenticate requests, detect and block attacks, investigate incidents, and maintain logs;
  5. Communicate with you — service announcements, security alerts, billing notices, support responses, and (with your consent where required) product updates you can opt out of;
  6. Improve the Service — debug, measure aggregate feature usage, and understand performance. We use aggregated or de-identified data for analytics; where we use de-identified data, we commit to not attempting to re-identify it;
  7. Comply with law — meet legal obligations and respond to lawful requests (see Section 4);
  8. Enforce our terms — including our Terms of Use.

AI processing and model training. Your messages, documents, and health profile context are transmitted to our AI infrastructure provider (Google Cloud Vertex AI) to generate responses. Under our configuration and Google Cloud's terms, this data is not used by Google to train its models, and we do not use your health information or conversations to train AI models either. We do not review your conversations except (a) as needed to investigate abuse, security incidents, or legal violations, (b) to provide support you request, or (c) as required by law.

3. Legal Bases (EEA/UK Users)

If you are in the European Economic Area or the United Kingdom, we process your personal data on these legal bases: contract (providing the Service you signed up for); consent (processing health data, which is special-category data under GDPR Art. 9 — you consent by submitting it for the purpose of receiving the Service, and you may withdraw consent at any time by deleting the data or your account); legitimate interests (security, fraud and abuse prevention, service improvement using aggregate data); and legal obligation (tax, accounting, lawful requests).

4. How We Share Information

We do not sell personal information. We do not share personal information for cross-context behavioral (targeted) advertising. We have not done either in the preceding 12 months.

We share personal information only with:

  1. Service providers (processors) acting on our instructions under contractual confidentiality and data-protection obligations:
    • Google Cloud / Firebase — hosting, database, authentication, storage, and AI processing (Vertex AI);
    • Stripe — payment processing for web purchases;
    • Apple — App Store distribution and in-app purchases (Apple acts independently for payment data under its own privacy policy);
    • Infrastructure providers for email delivery, error monitoring, and security.
  2. Legal and safety — if we reasonably believe disclosure is required by law, regulation, legal process, or governmental request; or necessary to protect the rights, property, or safety of Meeds, our users, or the public; or to detect, prevent, or address fraud, abuse, or security issues. Where legally permitted, we will attempt to notify you of legal demands for your health data.
  3. Business transfers — in connection with a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred, subject to this Policy's commitments; we will notify you of any change in ownership or in the uses of your personal information.
  4. With your direction — when you explicitly ask us to share something (for example, exporting your data).

We do not share your health information with data brokers, advertisers, insurers, or employers.

5. Meeds and HIPAA

Meeds is a direct-to-consumer wellness service. We are not a healthcare provider, health plan, or healthcare clearinghouse, and in providing the Service to you we are generally not a "covered entity" or "business associate" under the Health Insurance Portability and Accountability Act (HIPAA). This means the health information you submit to Meeds is generally not protected by HIPAA; it is instead protected by this Privacy Policy, our contracts with our service providers, and applicable consumer-privacy laws. If you obtained a document from your healthcare provider and upload it to Meeds, HIPAA continues to apply to your provider's copy — not to the copy you give us.

6. Data Retention

  • Account and health data — retained while your account is active. When you delete specific content (for example, a conversation or a health value), it is deleted from our production systems and purged from backups on their normal rotation cycle.
  • Account deletion — when you delete your account, we delete your personal information from production systems within 30 days, and from backups within their standard rotation period thereafter, except where retention is required by law (for example, transaction records for tax purposes) or needed to enforce agreements or resolve disputes, in which case data is retained only as long as necessary for that purpose and then deleted.
  • Security and abuse logs — retained for a limited period appropriate to detecting and investigating abuse, then deleted or de-identified. Anti-abuse identifiers used to enforce free-tier limits may be retained after account deletion to prevent limit-circumvention.
  • Aggregated/de-identified data — may be retained indefinitely; it does not identify you.

7. Your Rights and Choices

Depending on where you live, you may have some or all of the following rights, and we extend the core rights below to all users regardless of location:

  • Access / know — obtain a copy of the personal information we hold about you and information about how we process it;
  • Delete — delete specific content or your entire account and associated data;
  • Correct — fix inaccurate personal information (you can edit most information directly in the app);
  • Portability — receive your data in a portable format;
  • Withdraw consent — for processing based on consent (including health data), withdraw at any time by deleting the relevant data or your account;
  • Opt out of marketing — use the unsubscribe link in any marketing email; service and billing emails will still be sent;
  • Non-discrimination — we will not deny you the Service, charge a different price, or provide a different quality of service because you exercised a privacy right (though features that require certain data cannot function without it).

How to exercise rights: in-app account settings, or email info@meeds.com. We will verify requests using your account credentials or reasonable alternative means, respond within the time required by applicable law (generally 30–45 days), and permit authorized agents to act for you where the law provides. If we deny a request, you may appeal by replying to our decision; we will respond to appeals within the legally required period, and you may also contact your state Attorney General or (in the EEA/UK) your data-protection authority.

State-specific notes (California and similar): we do not sell or "share" (for targeted advertising) personal information, so no "Do Not Sell or Share" opt-out is needed; we do not use or disclose sensitive personal information beyond the purposes permitted under CPRA § 7027(m), so no Right to Limit is required; and we honor the rights to know, delete, correct, and portability described above. Categories collected are listed in Section 1; purposes in Section 2; disclosures in Section 4.

8. Consumer Health Data (Washington MHMDA, Nevada SB 370, and Similar Laws)

This section supplements this Policy for "consumer health data" as defined under the Washington My Health My Data Act, Nevada SB 370, and similar state laws.

  • Categories of consumer health data we collect: health conditions, symptoms, and concerns you describe; lab results, biomarkers, and measurements you upload or enter; medications and supplements you record; bodily functions or vital signs you record; health-related inferences the Service derives from the foregoing to provide responses to you; and associated identifiers linking that data to your account.
  • Sources: you (directly), and documents you choose to upload.
  • Purposes: solely to provide, secure, and improve the Service for you, as described in Section 2. We collect and use consumer health data with your consent, only to provide the services you request.
  • Sharing: only with the processors listed in Section 4(1), under binding contracts, for the purposes above; and as described in Sections 4(2)–(4). We do not sell consumer health data, and we will not do so without the separate, signed authorization those laws require. We do not use consumer health data for advertising. We do not process it for geofencing, and we do not use geofencing around healthcare facilities.
  • Your rights: withdraw consent, access, and delete your consumer health data, and appeal a refusal, as described in Section 7. Washington residents may raise unresolved concerns with the Washington Attorney General; Nevada residents with the Nevada Attorney General.

9. Security

We use administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit (TLS) and at rest, access controls on production systems, server-side authorization for all data writes, request authentication and app-integrity verification, secrets management, and monitoring for anomalous activity. No system is perfectly secure; we cannot guarantee absolute security. If a breach affecting your personal information occurs, we will notify you and regulators as required by law. Please use a strong, unique password and protect your credentials.

10. International Data Transfers

Meeds is operated from the United States, and your information is processed and stored in the United States (and other locations where our service providers operate), which may have different data-protection laws than your jurisdiction. Where required, we rely on appropriate safeguards for international transfers, such as the European Commission's Standard Contractual Clauses as implemented by our service providers.

11. Children

The Service is not directed to, and may not be used by, anyone under 18. We do not knowingly collect personal information from anyone under 18. If we learn we have collected personal information from a person under 18, we will delete it. If you believe a minor has provided us information, contact info@meeds.com.

12. Do Not Track and Opt-Out Preference Signals

Because we do not sell personal information or share it for targeted advertising, there is nothing for opt-out preference signals (such as Global Privacy Control) to opt you out of; we treat all users as opted out by default. Our Service does not respond differently to "Do Not Track" browser signals.

13. Changes to This Policy

We may update this Policy from time to time. We will post the updated Policy with a new "Last updated" date and, for material changes — including any new category of data collection, new sharing, or new purpose for consumer health data — we will provide prominent notice (such as email or in-app notice) and obtain consent where required by law before the change applies to previously collected data.

14. Contact Us

Meeds Research Inc.
Meeds
#1539
700 El Camino Real Suite 120
Menlo Park, CA 94025
United States
info@meeds.com

EEA/UK users: you may lodge a complaint with your local supervisory authority. If we are required to designate an EU/UK representative, their contact details will be listed here.

Meeds

Personal Health Intelligence

Download on the App Store

Product

Getting Started Release Notes Download App Pricing

Company

About us Research Beta Shop

Support

FAQ Request a Feature Report a Bug Contact

Legal

Terms of Use Privacy Policy

© Meeds Research Inc. 2026