Merora Privacy Policy

Version of 6 October 2026

This policy explains what personal data Merora processes, why, who receives it and what your rights are.

1. Who processes your data

The controller of your personal data is Ekodist ARG s.r.o., company ID (IČO) 11677899, VAT ID CZ11677899, registered office Nuselská 143/31, 140 00 Prague 4, Czech Republic, registered in the Commercial Register kept by the Municipal Court in Prague, section C, file 352774.

For anything related to your personal data, write to riccardo@merora.app.

2. What data we process and why

Account

  • Data: email address and password. The password is stored only in a form from which it cannot be recovered. If you sign in with Apple or Google, the identifier of your account with that service and the details it shares with us: email address (Apple may give us a hidden relay address), and possibly your name and profile picture.
  • Why: so you can sign in and have your reminders on every phone where you sign in.
  • Legal basis: performance of a contract, i.e. the Terms of Use (Art. 6(1)(b) GDPR).

Reminders, places and labels

  • Data: reminder text, time, recurrence, status (done, snoozed), label, place and a record of when the reminder went off. For reminders created by voice or from a sentence, also the original sentence. For places: name, address, coordinates and radius. For labels: name and colour.
  • Why: this is the service itself: storing your reminders and alerting you at the right moment.
  • Legal basis: performance of a contract.

Profile and settings

  • Data: time zone, app language, your answer in the introduction about what you want to use Merora for, the date you completed the introduction, your consent to tips by email and your consent to AI sentence parsing, each together with the date it last changed.
  • Why: correct reminder times, language, tailored examples and a record of your consent.
  • Legal basis: performance of a contract. For the record of consent, our legitimate interest in being able to prove that consent exists (Art. 6(1)(f) GDPR).

Location

  • Merora uses your phone’s location only for place-based reminders, and only if you allow location access in the system.
  • Your saved places are monitored by iOS directly on the phone. We only send our server the fact that the phone reported arriving at or leaving a saved place, and when. We do not store your continuous location or a history of your movements.
  • When you choose “Use my location” for a place, the coordinates of that place are saved.
  • Legal basis: performance of a contract.

Dictation and sentence parsing

  • Speech-to-text is handled by Apple’s speech recognition in iOS. Apple may process the audio on its servers under its own policies. We do not receive or store the audio.
  • Sentence parsing: we send the text of the sentence to OpenAI’s GPT-4o language model through the OpenRouter service, together with the names of your saved places and labels, your time zone and the current time. The model works out the task, time and place, and we save the result as a reminder. We do not send the model your account identifier, email address or the location of your places.
  • Consent: we send a sentence for parsing only with your explicit consent. The app asks for it before your first sentence. You can withdraw it at any time in Settings → AI sentence parsing. After that, no sentence is sent to OpenAI and you add reminders manually.
  • Daily limit: each account can have at most 30 sentences parsed per day. For this, we store with your account how many parses and how many language-model tokens you used that day. Records older than 30 days are deleted.
  • Legal basis: for speech-to-text, performance of a contract; for sentence parsing, your consent (Art. 6(1)(a) GDPR).
  • The text you type into the address search is sent to the Nominatim service of the OpenStreetMap Foundation. With “Use my location”, we send it your coordinates so it can return the address. If Nominatim does not respond, Apple’s geocoding in iOS looks up the address from the coordinates.
  • Legal basis: performance of a contract.

Diagnostics and errors

  • Diagnostics: records of how reminders work (for example, when the phone reported arriving at a place and how the app responded). They may also contain the text of the reminders and the names of the places they relate to. We keep them with your account and delete records older than 30 days every day.
  • App errors and crashes are sent to Sentry: a description of the error, device model, system and app version, IP address, your account identifier and email, and a log of your recent steps in the app, which may include parts of your content such as reminder text. Sentry keeps them for at most 90 days.
  • Server logs: requests to our server create records with your account identifier, IP address, time and type of request. For sentence parsing, they also contain the text of the sentence and the language model’s answer. These records are deleted automatically after at most 7 days.
  • Why: to find and fix errors and keep Merora reliable and secure.
  • Legal basis: legitimate interest (Art. 6(1)(f) GDPR).

Usage statistics

  • Data: how you use the app: when you open it, which screens and introduction steps are shown, when you create, edit, complete, snooze or delete a reminder and what kind it is (time-based, place-based, recurring, with a label), whether it was created by voice or by typing, whether and how quickly you tap a notification or the daily question, when you add a place or a label and what you change in the settings. Also your choices in the app (language, loud alerts, daily question, consents), the status of permissions for notifications, location and alarms, how you signed up, the app and system version and the phone model.
  • Identifiers: your account identifier and a random identifier the app creates when it is installed.
  • What we never send: reminder text, dictated or typed sentences, search text, names, addresses or locations of places, your email address or name. PostHog discards the IP address and does not use it to determine location.
  • Why: to see whether and how Merora is used, for example whether people add more reminders after the introduction and whether the daily question helps them, and to improve it accordingly.
  • Statistics are processed by the PostHog service on servers in the EU (Germany).
  • Turning it off: in Settings → Usage statistics. Once it is off, the app sends no statistics. The setting applies to this phone, even if you sign out.
  • Legal basis: legitimate interest in improving the app (Art. 6(1)(f) GDPR). You can object to it, fastest by turning statistics off.

Tips and news by email

  • Only with your consent, given in the introduction or in Settings → Notification Settings. We will then occasionally send tips and news about Merora to your email address.
  • You can withdraw your consent at any time in the same setting or through the link in any email.
  • Legal basis: consent (Art. 6(1)(a) GDPR).

Waitlist on the website

  • Data: email address, website language, time of sign-up and the version of the consent text shown with the form.
  • Why: to let you know when Merora launches and occasionally send you news and tips.
  • Before a sign-up is saved, the Cloudflare Turnstile service checks that the form is not being sent by a bot. To do this, it processes your IP address and technical details about your browser and device.
  • You can unsubscribe through the link in any email or by writing to riccardo@merora.app.
  • Legal basis: consent (Art. 6(1)(a) GDPR). The bot check is based on our legitimate interest in protecting the form from abuse.

When you contact us

  • We use your email address and message to reply. Email sent to @merora.app addresses is forwarded by Cloudflare to a Gmail mailbox provided by Google, and we reply from it through the Resend email service.
  • Legal basis: legitimate interest.

The merora.app website

  • The website runs on the Cloudflare network. When you visit it, your IP address and technical details about your browser are processed to deliver the page and protect it from attacks.
  • We measure visits with Cloudflare Web Analytics, without cookies. We only see aggregate numbers, such as how many times a page was viewed, not individual visitors.
  • The website does not use cookies for analytics or advertising. If you choose a language manually, only your browser remembers it.
  • Legal basis: legitimate interest in operating, securing and improving the website.

Notifications and alarms

Notifications, alarms and the daily question are scheduled by the app directly on your phone. We do not use remote (push) notifications and send nothing anywhere to schedule them. How you respond to them may appear in the usage statistics.

Payments

Merora is currently free. If we introduce paid features, payments will be processed by Apple through the App Store, and we will update this policy.

3. Who receives your data

Your data is processed by the following providers, each only to the extent needed for its service:

Provider Purpose Data location
Supabase, Inc. database, sign-in, server, waitlist EU (Ireland)
OpenRouter, Inc. and OpenAI sentence parsing USA
Functional Software, Inc. (Sentry) error reports EU (Germany)
PostHog, Inc. app usage statistics EU (Germany)
Cloudflare, Inc. website, bot protection for the form, website statistics, email forwarding global network, USA
Plus Five Five, Inc. (Resend) sending email EU (Ireland)
OpenStreetMap Foundation address search United Kingdom
Apple Sign in with Apple, speech recognition, maps, address search, App Store under Apple’s policies
Google Sign in with Google, mailbox for email you send us (Gmail) under Google’s policies

We entrust your data only to providers that protect it at least as well as this policy describes.

We do not sell your data, do not use it for advertising and do not track your activity in other apps or on the web. We disclose data to authorities only where the law requires us to.

4. Transfers outside the EU

Supabase, OpenRouter, OpenAI, Functional Software (Sentry), PostHog, Cloudflare, Plus Five Five (Resend) and Google are companies based in the USA. Even where some of them store data in the EU, access from the USA cannot be ruled out. Transfers rely on the standard contractual clauses approved by the European Commission, or on the EU–US Data Privacy Framework where the recipient is certified. For the United Kingdom, the European Commission’s adequacy decision applies.

5. How long we keep your data

  • Account, reminders, places, labels and profile: until you delete your account. A reminder, place or label you delete is deleted right away.
  • Deleting your account: in the app via Settings → Delete account. This deletes your account and all data linked to it, including diagnostics and usage statistics, and also disconnects Sign in with Apple at Apple. Data may remain in our providers’ backups until those backups are overwritten.
  • Diagnostics: 30 days. Usage statistics: 1 year. Error reports in Sentry: at most 90 days. Server logs: at most 7 days. Daily count of sentence parses: 30 days.
  • Consent to emails: until you withdraw it or delete your account.
  • Consent to AI sentence parsing: until you withdraw it or delete your account.
  • Waitlist: until you unsubscribe.
  • Email you send us: as long as we need it to deal with your request, at most 3 years.

6. Your rights

You have the right to:

  • access your data and get a copy,
  • have inaccurate data corrected,
  • have your data erased (fastest by deleting your account in the app),
  • restrict processing,
  • data portability,
  • object to processing based on legitimate interest,
  • withdraw your consent at any time. This does not affect processing before the withdrawal.

Write to us at riccardo@merora.app and we will reply within one month. If you believe we handle your data unlawfully, you can lodge a complaint with the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Prague 7, www.uoou.gov.cz) or with the supervisory authority in your EU country.

7. Security

Data is transferred encrypted (HTTPS) and each account can see only its own data. Access to personal data is limited to those who need it to run Merora.

8. Children

Merora is not intended for children under 15.

9. Changes to this policy

We will update this policy when the way we handle data changes. The current version is always available here. We will let you know about significant changes in the app or by email.