Skip to content

Mezo

Privacy Policy

Version 1.2 · Effective

Mezo stores the meals, workouts, body measurements and photos you log, what you share with friends, the details on your account, and what is needed to keep you signed in. We use that data to run Mezo for you and for nothing else. We do not sell it, we do not show advertising, and we do not run third-party analytics.

Download as PDF

1.Who we are

Mezo ("we", "us") operates the Mezo web app at https://usemezo.app and the API and MCP server behind it. For the purposes of the General Data Protection Regulation (GDPR) we are the controller of the personal data described in this policy.

Mezo is a hobby project, built and run by one person in the Netherlands in their spare time. It is not a company. Being small does not change your rights: everything in this policy applies in full.

Questions about this policy or about your data go to support@usemezo.app.

2.What this policy covers

This policy applies when you visit usemezo.app, create an account, use the app, connect an AI assistant or your own scripts to your account, or write to us. It does not cover services you connect to Mezo yourself, such as an AI assistant or a calendar app. Those have their own policies.

3.What we collect and why

We collect only what a feature needs. The table lists each kind of data, where it comes from, and what we do with it.

DataWhere it comes fromWhy we process it
Account: your name, email address and profile pictureYou, when you sign up and edit your profileTo create and identify your account, to send sign-in codes, and to show your picture in the app
Public profile: username, a short bio, location and social linksYou, if you choose to fill them inTo show your public profile page at usemezo.app/<username>
Preferences: language, time zone, time format, first day of the week, theme, privacy and notification choicesYou, in the settings; the browser fills in language and time zone until you save themTo show dates, times and the interface the way you want them, and to apply your privacy choices
Health and activity data: meals, water, workouts, routines, body measurements, goals and the notes you attach to themYou, when you log them, or an assistant or script you have connectedTo keep your log, show your progress, and produce the summaries Mezo is for
Progress photosYou, when you add themTo show your progress back to you. Only you can see them. Location and camera details are removed from the file when it is uploaded
Social activity: friends and friend requests, kudos, comments, chat messages and what you attach to them, challenges and calendar entries you shareYou, and the friends you interact withTo run the social features: your feed, chat, challenges, leaderboards, comparisons and shared calendar entries
Calendar feed: a private link to your calendar entriesCreated when you turn the feed onTo let the calendar app you subscribe with show your Mezo entries
Sign-in and security: IP address, browser or device type, session tokens, the one-time codes we send you, and counters of recent requestsYour browser or device, and our serversTo keep you signed in, to detect misuse, and to limit how often codes can be requested or guessed
Developer access: the API keys you create and the assistants you authorise, with their scopes and last useYou, in the developer settings or through an OAuth consent screenTo let your scripts and assistants act on your account, and to let you see and revoke that access
Correspondence: what you write to us, and our replyYou, by email or through the contact formTo answer you and to keep a record of what was agreed

Health and activity data, and progress photos, are a special category of personal data under Article 9 of the GDPR. We process them only because you asked us to by logging them, which is your explicit consent. You can withdraw that consent at any time by deleting the entries or your account.

We do not use your data to train machine-learning models, and we do not profile you for advertising. An AI assistant you connect through MCP reads your data on your instruction; what it does with the result is governed by that assistant's own policy.

5.Cookies and local storage

Mezo sets no advertising or tracking cookies and loads no third-party analytics. The cookies and browser storage it does use are all needed for the app to work:

  • A session cookie that keeps you signed in. It is HTTP-only and expires after seven days without use.
  • A cookie remembering whether the sidebar was open or collapsed.
  • Your chosen colour scheme, kept in the browser so the page does not flash on load.
  • The plates you set up in the plate calculator.
  • While you sign in, the email address you entered, until the tab is closed, so the code screen knows where the code went.

Because none of these are used for tracking, no cookie banner is shown. Clearing them signs you out and resets those choices; nothing else is lost.

6.What your friends see

Friends are people you have accepted a friend request from, or who accepted yours. They can see:

  • Your finished workouts in their feed: the name, date, duration, number of sets, total volume and the exercises, with the kudos and comments on them.
  • Your training next to theirs when they compare, and your scores on the friends leaderboard and in challenges you join.
  • The messages you send them in chat, and the routines, workouts and calendar entries you attach.
  • Calendar entries you invite them to, and whether you joined theirs.

Turning off "Show your training on your profile" in the settings takes your workouts out of their feed, comparisons and leaderboards. Your meals, water, body measurements and progress photos are never shown to friends.

7.What is public

Once you choose a username, your profile page is visible to anyone with the link. It shows your name, picture, username, bio, location, social links and the routines you have shared.

Unless you turn off "Show your training on your profile" in the settings, it also shows your training: a calendar of the days you trained, your streak, your recent workouts as dates and totals, your top lifts and the muscles you train most. Your meals, water, body measurements, progress photos and email address are never on it.

Search engines are asked not to index your profile unless you turn on search indexing in the settings. You only appear in Discover and on the everyone leaderboard if you switch that on. Removing your username takes the page down.

A share link to a routine or a folder shows it, with your name and picture, to anyone who has the link, until you stop sharing it. An invite link to a calendar entry shows the entry, who hosts it and the names and pictures of everyone who has joined, to anyone who has the link.

8.Who we share data with

We do not sell personal data and we do not share it with advertisers. The data leaves our systems only in these cases:

  • Service providers that host Mezo, store its files and handle its email, on our instructions. They are listed in the next section.
  • Assistants and scripts you authorise. An API key or an OAuth consent lets that client read or write the parts of your account covered by its scopes, until you revoke it in the developer settings.
  • A calendar app you subscribe with, through your calendar feed link, until you turn the feed off.
  • Friends, visitors to your public profile, and people with a share link, as described above.
  • Gravatar, run by Automattic Inc. in the United States. If you have not uploaded a picture, our servers ask Gravatar for the one registered to your email address, sending a one-way hash of it. Your email address itself is not sent, and your browser never contacts Gravatar.
  • Open Food Facts. When you search for a food or scan a barcode that Mezo does not know yet, our servers send the search text or barcode to Open Food Facts. Nothing that identifies you is sent with it.
  • Authorities, when the law requires it and after we have checked that the request is valid.
  • A successor, if Mezo is acquired or merges. This policy would continue to apply to your data, and we would tell you before anything changed.

9.Service providers

These providers process personal data on our behalf, under a data processing agreement:

ProviderWhat they do for usWhere the data is
Vercel Inc.Runs the web app and the API, and stores profile pictures and progress photosFrankfurt, Germany
Supabase Inc.Hosts the databaseFrankfurt, Germany
Resend (Plus Five Five, Inc.)Sends sign-in codes and notification emailsIreland
ImprovMXForwards email sent to our support address to our inboxOutside the European Economic Area

We will update this list before we add a provider, and email you about the change if it affects where your data is stored.

10.Where your data is stored

Mezo is operated from the European Union. Our database, our servers and the files you upload are in Frankfurt, Germany. Some of our providers are companies based in the United States, and email forwarding happens outside the European Economic Area. Where data is, or could be, accessed from outside the EEA, we rely on the EU-US Data Privacy Framework where the provider is certified under it, and otherwise on the European Commission's Standard Contractual Clauses. You can ask us for a copy of the safeguards in place.

11.How long we keep it

We keep data for as long as the feature it serves needs it, and no longer:

DataKept for
Your account, profile, preferences, and everything you logged, including progress photosUntil you delete it or your account. Deleting your account removes all of it at once, including your pictures.
Chat messagesUntil the sender deletes them, or either of you deletes your account
Comments and kudosUntil they are removed, the workout is deleted, or the account that gave them is deleted
One-time sign-in codesFive minutes, or until used or guessed wrong three times
Sessions, with their IP address and device typeUntil you sign out, or seven days after you last used the session
Counters used for rate limiting, keyed by IP address or accountCleared regularly, usually within a day
API keysUntil you delete them, or at most one year after creation
Assistant (OAuth) authorisations and their tokensUntil you disconnect the assistant in the developer settings
Email correspondenceTwo years after the conversation ends
Server logsThirty days, then deleted

Backups of the database are kept for thirty days and then overwritten. Data you deleted can survive in a backup for that long and is not restored from it.

12.How we protect it

  • All traffic between your device and Mezo is encrypted with TLS.
  • There are no passwords to leak. You sign in with a six-digit code sent to your email address; it expires after five minutes and is discarded after three wrong attempts.
  • API keys are stored as hashes. We show you the full key once, when you create it, and cannot recover it afterwards.
  • Sign-in and code endpoints are rate limited per IP address.
  • Progress photos are served only to their owner, through our own servers.
  • Access to production systems is limited to the people who operate Mezo, each with their own credentials.

If a security incident affects your data, we will tell you without undue delay, and the supervisory authority within 72 hours where the GDPR requires it.

13.Your rights

Under the GDPR you can ask us to:

  • Tell you what personal data we hold about you, and give you a copy (access).
  • Correct data that is wrong (rectification).
  • Delete your data (erasure).
  • Stop processing it, or limit what we do with it (restriction and objection).
  • Give you your data in a machine-readable format, or send it to another provider (portability).
  • Withdraw consent you gave earlier. This does not affect what was done before you withdrew it.

Most of this you can do yourself. Your name, email address, picture, profile and preferences are editable in the settings. Everything you logged can be edited or removed in the app. Deleting your account, under Profile, removes all of it.

For anything else, including a copy of your data, email support@usemezo.app from the address on your account. We answer within one month. If we cannot meet a request, we will tell you why.

You can also complain to a data protection authority. For us that is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), but you may contact the authority in the country where you live.

14.Children

Mezo is not meant for anyone under 16, and we do not knowingly hold data on them. If you believe a child has created an account, write to us and we will delete it.

15.Changes to this policy

When we change this policy we update the version and date at the top. If a change affects what we collect or why, we email every account holder before it takes effect. Earlier versions are available on request.

16.Contact

Mezo, support@usemezo.app, https://usemezo.app.