Meoz
Features How it works Why Meoz Pricing FAQ Changelog
Start Pro trial Download
Features How it works Why Meoz Pricing FAQ Changelog Start Pro trial Download for Mac
Privacy

Privacy Policy

Version 2026-09-12 · Effective September 12, 2026. This is the current version, preserved at this versioned link; the short address /privacy points here.

1. Who we are and what this covers

Cam Chanh Tech operates Meoz. Contact us at support@meozai.comⓘ. This policy explains the Meoz macOS app, meoz.ai, and Meoz-operated services. It does not replace a third-party provider's own privacy notice.

2. Data that stays on your Mac

Your goals, schedules, focus history, journal entries, saved memory, local preferences, and API keys are stored on your Mac by default. Meoz does not capture or OCR arbitrary screen contents. Meoz does not sell personal data or use browsing history to build an advertising profile. We do not use your AI prompts or responses to train Meoz models.

3. When data leaves your Mac

Cloud AI is optional. When you choose an AI provider and use an AI feature, the request context needed for that feature—such as your prompt, relevant focus goal, or page/title context—goes to that provider. With a bring-your-own-key provider, it goes directly to the provider you selected. With Meoz Pro, it passes through Meoz's Cloudflare-hosted gateway to OpenRouter under a restricted provider policy: NovitaAI is preferred and DeepInfra is an availability fallback. It requires endpoints OpenRouter designates as Zero Data Retention (ZDR). ZDR is not a promise that no processing occurs: OpenRouter documents that an allowed endpoint may use transient, in-memory prompt caching. Meoz's application code does not intentionally persist AI prompts or responses in its own database, but OpenRouter and the selected provider may process the request under their own terms and privacy notices.

4. Pro license, payment, and service operations

To validate a Pro license and enforce the published fair-use limit, Meoz sends the license key to its service and to Lemon Squeezy for validation. Meoz stores a one-way derived identifier, validation result, and token-use counter in Cloudflare KV rather than storing the license key itself. Validity records expire after about one hour; token counters expire after 48 hours. Lemon Squeezy processes purchases, subscription and payment information under its own privacy notice.

5. Optional diagnostics and local error reports

Usage telemetry is off by default. If you turn it on, Meoz sends a daily, license-linked activity signal and the number of guardian interventions; it does not send URLs, browsing history, goals, page text, or journal entries. The service retains those counters for up to 30 days. After a crash, Meoz asks before sending a minimized diagnostic summary. The summary contains the app version, macOS version, exception category, and a one-way crash fingerprint; it does not include your license key or the raw crash report.

Meoz's own gateway automatically receives a random per-request identifier and a random rotating installation diagnostic identifier, plus app/build version, macOS version, and processor architecture. This exists only to correlate reliability failures between local and gateway logs. The installation identifier is generated locally, rotates every 30 days, can be reset in Settings, and is not derived from or linked to a license key, account, computer name, or hardware serial. Before logging it, the gateway transforms it with a secret-keyed one-way function; the raw identifier is not logged. Failed or degraded gateway requests are logged, while routine successful requests are sampled. These gateway diagnostic records do not contain page URLs, titles, focus goals, prompts, AI responses, license keys, or API keys and are retained only under Meoz's limited Cloudflare operational log policy.

The AI Judge error report is a separate, local and user-initiated support export. Meoz does not automatically upload or share it. You choose its date range, detail level, and save location. A technical report contains only recovery/error events and a site host. A readable-context report can additionally contain a page title and focus goal. A Full support bundle can additionally contain a sanitized page location (scheme, host, and safe path only), the non-secret AI request text, and limited runtime metadata such as selected provider, whether a credential is configured, and the entitlement state. Query strings, fragments, credentials, ports, license keys, API keys, authorization headers, cookies, response bodies, and raw crash reports are excluded from every report. The paired local context used to build this export stays on your Mac until you remove local Meoz data; you decide whether to share a saved report with support.

6. Permissions

Accessibility, Automation, Microphone, Speech Recognition, Calendar, and Location permissions are optional macOS choices. Meoz uses a permission only for the feature you enable. You can revoke each permission in macOS System Settings or turn the related feature off in Meoz.

7. Retention, security, and choices

Local data remains on your Mac until you delete it or remove Meoz data. We use reasonable technical measures to protect our service, but no system is perfectly secure. You can disable optional telemetry, decline a crash report, reset the rotating diagnostic reference, change permissions, stop using a cloud provider, and contact support@meozai.com with a privacy request. Do not send passwords, payment-card details, government identifiers, or other highly sensitive information in an AI request or support message.

8. Changes to this policy

We preserve this version at its immutable link. A material change creates a new dated version and Meoz asks you to acknowledge it before you continue to use the changed policy. The current version is always available at meoz.ai/privacy.

Meoz

Made with care for people who just want to focus.

Features Pricing FAQ Changelog Privacy Terms Support
© 2026 Meoz Go get your focus back.