Privacy Policy

Meresay · Effective date: July 16, 2026 · Applies to the Meresay Android app

Meresay sends short inspirational sentences to your phone as notifications. We built it to need as little of your data as possible. This policy explains, in plain language, exactly what we collect, why, and what we never do.

The short version

1. What we collect

When you install and use Meresay, we collect and store the following. This is the complete list.

DataWhat it isWhy we need it
Anonymous user ID A random identifier created by Firebase Anonymous Authentication when you first open the app. It is not linked to your name, email, or any real-world identity. To keep your preferences and delivery history together without requiring an account.
Push notification token A device token issued by Firebase Cloud Messaging (FCM), Google's push notification service. To deliver notifications to your device. Without it the app cannot function.
Device details Your device's platform (Android), app and OS version, language setting (e.g. en-US), and timezone (e.g. Europe/Berlin). To send messages in your language and inside your chosen daily time window (not at 3am), and to keep the app working across versions.
Notification preferences How many messages per day you want and during which hours. To schedule deliveries the way you asked for them.
Delivery history A log of which messages were scheduled and sent to you, and when. To show your message history in the app and avoid sending you the same message twice.
Likes and dislikes If you like or dislike a message, we store that reaction (one per message). To show the messages you've liked, and to notice content that isn't landing well.
Content reports If you report a message, we store the report reason you chose and which message it was about. To review and remove content that shouldn't have been published.

2. What we do not collect or do

3. Who processes your data

We run our service on Google Cloud. The following providers act as our processors, only on our instructions:

No other third party receives your data. We may disclose data if legally compelled to (for example, by a valid court order), but the data described above contains no real-world identity to disclose.

4. How long we keep data

Your data is kept for as long as your anonymous user record exists. If you delete your data (section 5), it is removed from our production database immediately; residual copies in encrypted database backups expire on the backup rotation schedule (currently within 7 days). Stale devices that can no longer receive notifications are marked inactive and stop being sent to.

5. Deleting your data, and your rights

Because your data is anonymous, deletion is simple and requires no identity verification beyond the device itself:

Depending on where you live (for example under the EU/UK GDPR or the CCPA/CPRA), you may have rights to access, correct, delete, or port your data, to object to or restrict processing, and to not be discriminated against for exercising these rights. You can exercise any of them via meresay@gaar.dev. Because we cannot identify you from the data we hold, some rights (like access requests) may require the anonymous user ID from your device. Our legal bases under the GDPR are performance of a contract (delivering the service you asked for) and legitimate interest (keeping the service safe and functional). You also have the right to complain to your local data protection authority.

6. AI-generated content disclosure

The inspirational sentences delivered by Meresay are drafted with the assistance of artificial intelligence and are reviewed by a human editor before publication. An automated safety review also screens each item. Every message can be reported from within the app; reports are reviewed by a human. This disclosure is also shown in the app under Settings → About.

7. Children

Meresay is not directed at children under 13 (or the higher minimum age in your country), and we do not knowingly collect data from them. The app collects no identity data with which we could distinguish a child; if you believe a child's device data should be removed, contact meresay@gaar.dev.

8. Security

Data is encrypted in transit (TLS) and at rest. Access to production systems is restricted and logged. No system is perfectly secure, but the data we hold is deliberately minimal and contains no real-world identity, which limits what any breach could expose.

9. International transfers

Our servers are located in the United States (Google Cloud, us-central1). If you use Meresay from outside the US, the data described in section 1 is transferred to and processed in the US under our processors' standard safeguards (including Google's standard contractual clauses for GDPR purposes).

10. Changes to this policy

If we change this policy, we will update the effective date above and, for material changes, notify you in the app before the change takes effect. We will never retroactively expand what we collect without telling you.

11. Contact

Meresay
Email: meresay@gaar.dev