Mezo
Privacy Policy
Version 1.2 · Effective
Mezo stores the meals, workouts, body measurements and photos you log, what you share with friends, the details on your account, and what is needed to keep you signed in. We use that data to run Mezo for you and for nothing else. We do not sell it, we do not show advertising, and we do not run third-party analytics.
1.Who we are
Mezo ("we", "us") operates the Mezo web app at https://usemezo.app and the API and MCP server behind it. For the purposes of the General Data Protection Regulation (GDPR) we are the controller of the personal data described in this policy.
Mezo is a hobby project, built and run by one person in the Netherlands in their spare time. It is not a company. Being small does not change your rights: everything in this policy applies in full.
Questions about this policy or about your data go to support@usemezo.app.
2.What this policy covers
This policy applies when you visit usemezo.app, create an account, use the app, connect an AI assistant or your own scripts to your account, or write to us. It does not cover services you connect to Mezo yourself, such as an AI assistant or a calendar app. Those have their own policies.
3.What we collect and why
We collect only what a feature needs. The table lists each kind of data, where it comes from, and what we do with it.
| Data | Where it comes from | Why we process it |
|---|---|---|
| Account: your name, email address and profile picture | You, when you sign up and edit your profile | To create and identify your account, to send sign-in codes, and to show your picture in the app |
| Public profile: username, a short bio, location and social links | You, if you choose to fill them in | To show your public profile page at usemezo.app/<username> |
| Preferences: language, time zone, time format, first day of the week, theme, privacy and notification choices | You, in the settings; the browser fills in language and time zone until you save them | To show dates, times and the interface the way you want them, and to apply your privacy choices |
| Health and activity data: meals, water, workouts, routines, body measurements, goals and the notes you attach to them | You, when you log them, or an assistant or script you have connected | To keep your log, show your progress, and produce the summaries Mezo is for |
| Progress photos | You, when you add them | To show your progress back to you. Only you can see them. Location and camera details are removed from the file when it is uploaded |
| Social activity: friends and friend requests, kudos, comments, chat messages and what you attach to them, challenges and calendar entries you share | You, and the friends you interact with | To run the social features: your feed, chat, challenges, leaderboards, comparisons and shared calendar entries |
| Calendar feed: a private link to your calendar entries | Created when you turn the feed on | To let the calendar app you subscribe with show your Mezo entries |
| Sign-in and security: IP address, browser or device type, session tokens, the one-time codes we send you, and counters of recent requests | Your browser or device, and our servers | To keep you signed in, to detect misuse, and to limit how often codes can be requested or guessed |
| Developer access: the API keys you create and the assistants you authorise, with their scopes and last use | You, in the developer settings or through an OAuth consent screen | To let your scripts and assistants act on your account, and to let you see and revoke that access |
| Correspondence: what you write to us, and our reply | You, by email or through the contact form | To answer you and to keep a record of what was agreed |
Health and activity data, and progress photos, are a special category of personal data under Article 9 of the GDPR. We process them only because you asked us to by logging them, which is your explicit consent. You can withdraw that consent at any time by deleting the entries or your account.
We do not use your data to train machine-learning models, and we do not profile you for advertising. An AI assistant you connect through MCP reads your data on your instruction; what it does with the result is governed by that assistant's own policy.
4.Our legal bases
Each thing we do with your data, and the article of the GDPR that allows it:
| Purpose | Legal basis |
|---|---|
| Running your account, keeping you signed in, the social features you use, and sending sign-in codes, security notices and the notification emails set in your notification settings | Performance of our contract with you (Article 6(1)(b)) |
| Storing meals, workouts, body measurements and progress photos | Your explicit consent (Article 9(2)(a)) |
| Preventing abuse: rate limiting, blocking repeated wrong codes, and keeping a short log of sign-ins | Our legitimate interest in keeping the service secure (Article 6(1)(f)) |
| Product news and offers by email | Your consent (Article 6(1)(a)); both are off until you switch them on |
| Keeping records we are required to keep, and answering lawful requests | Compliance with a legal obligation (Article 6(1)(c)) |
6.What your friends see
Friends are people you have accepted a friend request from, or who accepted yours. They can see:
- Your finished workouts in their feed: the name, date, duration, number of sets, total volume and the exercises, with the kudos and comments on them.
- Your training next to theirs when they compare, and your scores on the friends leaderboard and in challenges you join.
- The messages you send them in chat, and the routines, workouts and calendar entries you attach.
- Calendar entries you invite them to, and whether you joined theirs.
Turning off "Show your training on your profile" in the settings takes your workouts out of their feed, comparisons and leaderboards. Your meals, water, body measurements and progress photos are never shown to friends.
7.What is public
Once you choose a username, your profile page is visible to anyone with the link. It shows your name, picture, username, bio, location, social links and the routines you have shared.
Unless you turn off "Show your training on your profile" in the settings, it also shows your training: a calendar of the days you trained, your streak, your recent workouts as dates and totals, your top lifts and the muscles you train most. Your meals, water, body measurements, progress photos and email address are never on it.
Search engines are asked not to index your profile unless you turn on search indexing in the settings. You only appear in Discover and on the everyone leaderboard if you switch that on. Removing your username takes the page down.
A share link to a routine or a folder shows it, with your name and picture, to anyone who has the link, until you stop sharing it. An invite link to a calendar entry shows the entry, who hosts it and the names and pictures of everyone who has joined, to anyone who has the link.
9.Service providers
These providers process personal data on our behalf, under a data processing agreement:
| Provider | What they do for us | Where the data is |
|---|---|---|
| Vercel Inc. | Runs the web app and the API, and stores profile pictures and progress photos | Frankfurt, Germany |
| Supabase Inc. | Hosts the database | Frankfurt, Germany |
| Resend (Plus Five Five, Inc.) | Sends sign-in codes and notification emails | Ireland |
| ImprovMX | Forwards email sent to our support address to our inbox | Outside the European Economic Area |
We will update this list before we add a provider, and email you about the change if it affects where your data is stored.
10.Where your data is stored
Mezo is operated from the European Union. Our database, our servers and the files you upload are in Frankfurt, Germany. Some of our providers are companies based in the United States, and email forwarding happens outside the European Economic Area. Where data is, or could be, accessed from outside the EEA, we rely on the EU-US Data Privacy Framework where the provider is certified under it, and otherwise on the European Commission's Standard Contractual Clauses. You can ask us for a copy of the safeguards in place.
11.How long we keep it
We keep data for as long as the feature it serves needs it, and no longer:
| Data | Kept for |
|---|---|
| Your account, profile, preferences, and everything you logged, including progress photos | Until you delete it or your account. Deleting your account removes all of it at once, including your pictures. |
| Chat messages | Until the sender deletes them, or either of you deletes your account |
| Comments and kudos | Until they are removed, the workout is deleted, or the account that gave them is deleted |
| One-time sign-in codes | Five minutes, or until used or guessed wrong three times |
| Sessions, with their IP address and device type | Until you sign out, or seven days after you last used the session |
| Counters used for rate limiting, keyed by IP address or account | Cleared regularly, usually within a day |
| API keys | Until you delete them, or at most one year after creation |
| Assistant (OAuth) authorisations and their tokens | Until you disconnect the assistant in the developer settings |
| Email correspondence | Two years after the conversation ends |
| Server logs | Thirty days, then deleted |
Backups of the database are kept for thirty days and then overwritten. Data you deleted can survive in a backup for that long and is not restored from it.
12.How we protect it
- All traffic between your device and Mezo is encrypted with TLS.
- There are no passwords to leak. You sign in with a six-digit code sent to your email address; it expires after five minutes and is discarded after three wrong attempts.
- API keys are stored as hashes. We show you the full key once, when you create it, and cannot recover it afterwards.
- Sign-in and code endpoints are rate limited per IP address.
- Progress photos are served only to their owner, through our own servers.
- Access to production systems is limited to the people who operate Mezo, each with their own credentials.
If a security incident affects your data, we will tell you without undue delay, and the supervisory authority within 72 hours where the GDPR requires it.
13.Your rights
Under the GDPR you can ask us to:
- Tell you what personal data we hold about you, and give you a copy (access).
- Correct data that is wrong (rectification).
- Delete your data (erasure).
- Stop processing it, or limit what we do with it (restriction and objection).
- Give you your data in a machine-readable format, or send it to another provider (portability).
- Withdraw consent you gave earlier. This does not affect what was done before you withdrew it.
Most of this you can do yourself. Your name, email address, picture, profile and preferences are editable in the settings. Everything you logged can be edited or removed in the app. Deleting your account, under Profile, removes all of it.
For anything else, including a copy of your data, email support@usemezo.app from the address on your account. We answer within one month. If we cannot meet a request, we will tell you why.
You can also complain to a data protection authority. For us that is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), but you may contact the authority in the country where you live.
14.Children
Mezo is not meant for anyone under 16, and we do not knowingly hold data on them. If you believe a child has created an account, write to us and we will delete it.
15.Changes to this policy
When we change this policy we update the version and date at the top. If a change affects what we collect or why, we email every account holder before it takes effect. Earlier versions are available on request.
16.Contact
Mezo, support@usemezo.app, https://usemezo.app.