1. Who this applies to
This policy covers anyone with a Meco account (a "caregiver") and, by extension, the people a caregiver enrolls as trusted visitors or as the person Meco is set up to recognize (a "patient" or "Meco member"). A patient doesn't typically create their own account — the caregiver who enrolls them is responsible for having their consent, or the legal authority to act on their behalf. See §6.
2. What we collect
An account holder's name and email, handled by our authentication provider, Clerk. For each trusted person a caregiver enrolls: a name, relationship, a short memory cue, a face descriptor (a numerical representation of facial geometry, not a photograph) and a small thumbnail, and optionally a voiceprint. For each recorded visit: an audio-derived transcript, speaker labels, and an AI-generated summary. Journal entries and care notes a caregiver or patient chooses to write. Settings such as speech language and calendar-sync preferences.
3. Where processing actually happens
Face matching — both enrollment and recognition — runs in the caregiver's own browser via face-api.js; only the resulting descriptor and thumbnail are saved, never a raw video stream. Voice matching runs on a small local server, not a third party. Everything else that needs an external provider (AssemblyAI or Deepgram for transcription, Google Gemini for summaries, Google Calendar for optional sync) is proxied through Meco's own server — provider credentials never reach the browser, and the browser never talks to those providers directly.
4. How we use it
Solely to run the features you're using: recognizing an enrolled person, transcribing and summarizing a visit, keeping a journal, syncing a calendar if you've turned that on. We don't use this data for advertising, we don't sell it, and we don't use it to train models outside of the third-party processors' own standard processing of a given request (see §5).
5. Third-party processors
Clerk (authentication), Appwrite (account-scoped data storage), AssemblyAI and Deepgram (speech-to-text), Google Gemini (visit summaries), and Google Calendar (optional). Each processes only what a given feature requires, under their own respective privacy terms, and only when you're actively using the feature that needs them.
6. Consent for enrolled people
A face descriptor and a voiceprint are biometric data belonging to the person enrolled — not the caregiver doing the enrolling. Meco does not verify consent for you; it's the caregiver's responsibility to have a real conversation with that person first, or to be acting within their legal authority as a caregiver, before enrollment.
7. Retention & deletion
Nothing is kept indefinitely by default, and nothing removes itself automatically — that's a decision left to the account holder. Any enrolled person, transcript, journal entry, or care note can be deleted the same way it was created, at any time, from within the app. Deleting your account removes the data associated with it.
8. Your rights
You can access, export, or delete your data at any time through the app itself, without needing to submit a request. If you'd rather reach us directly, see §11.
9. Security
Data in transit is encrypted (HTTPS). Authentication and storage rely on Clerk's and Appwrite's own security practices. No system is perfectly secure, and we can't guarantee absolute security — only that we haven't cut corners we could reasonably avoid.
10. Changes to this policy
If this policy changes in a way that meaningfully affects what we collect or how we use it, we'll update the date above and, where practical, note it in the app.