What we collect, and why.
Merenyo ("we," "us") is a task-capture and auto-scheduling app. This page explains what personal data we collect when you use it, why, and how to get it deleted. If anything here is unclear, email hello@merenyo.com and we'll answer directly.
Information we collect
To run your account:
- Account info: your email address, and a password (stored as a one-way hash, never in plain text) — or, if you sign in with Google, your Google account's email, name, and a stable account identifier instead of a password.
- The content you give the app: task names, details, deadlines, priorities, and the time blocks you set up. This is the actual product — it has to be stored to work.
- Schedule preferences: your timezone, your default day window, and notification/digest settings.
- Billing information, if you upgrade: we never see or store your card number. Paddle (our payment processor and merchant of record) handles that directly, and also handles sales tax/VAT on our behalf; we only keep a customer/subscription reference so we know your plan and can cancel it on request.
- A push notification token, if you enable notifications — an opaque identifier from your device/browser used to deliver reminders, not personal information on its own.
- Basic crash and usage data via Firebase Analytics (all platforms) and Firebase Crashlytics (mobile only) — which screens get used and what breaks, not the content of your tasks.
- Google Calendar (optional): if you connect your Google Calendar, we read your event details — titles, times, descriptions, and any meeting links — so you can see what's on your calendar without leaving Merenyo. This data is fetched periodically and kept only in memory to keep your schedule current; it is not permanently stored in our database. This access is read-only — Merenyo never creates, edits, or deletes anything on your Google Calendar. You can disconnect at any time from Settings, which immediately stops any further access.
What we don't do
- We don't sell your data to anyone, ever.
- We don't read your tasks to serve you ads or train anything — the scheduler is a deterministic formula, not an AI model trained on user data.
- We don't share your task content with third parties, except the infrastructure providers below, strictly to run the service.
How we protect it
- Encrypted in transit: every connection to Merenyo — the app, the API, Google's servers — is HTTPS/TLS. Nothing is sent in plain text.
- Encrypted at rest: your data is stored in a managed Postgres database (via Fly.io) and, for backups, in Tigris object storage — both encrypt data at rest by default. Your password is never stored at all, only a one-way hash that can't be reversed back into the original.
- Google Calendar data specifically: read via a read-only scope that can't modify or delete anything on your calendar. Event data is fetched over an encrypted connection, held only in memory long enough to compute your schedule, and never written to our database or logs — a server restart clears it, and disconnecting from Settings stops all further access immediately.
- Access is restricted: only the infrastructure providers listed below process your data, each strictly to run the service they're engaged for — no one else gets access, and nothing is sold.
We're a small, indie-run product, not a large security team — but these are standard, non-negotiable practices, not aspirational ones.
Who else processes it
Running Merenyo means a few infrastructure providers handle data on our behalf, under their own security commitments:
- Google Firebase — authentication, app hosting, push notifications, crash/analytics.
- Paddle — payment processing and merchant-of-record services for the paid plan.
- Fly.io — hosts our backend server and database.
- Tigris — stores encrypted database backups (kept 14 days, then automatically deleted).
None of these providers get to use your data for their own purposes beyond providing the service we've engaged them for.
How long we keep it
For as long as your account exists. Deleting your account (from the Account screen, in-app — no email required) permanently removes your tasks, time blocks, and profile immediately; it's not recoverable. Database backups age out and are deleted automatically after 14 days, so a copy of deleted data can briefly persist there before that window closes.
Your rights
You can see everything the app knows about you by using it — there's no hidden data. You can:
- Export nothing you don't already see — there's no separate data dump today, since the app itself is the full view of your data.
- Correct your name, email, or any task/block content directly in the app, any time.
- Delete your account and everything in it, permanently, from the Account screen.
- Ask us anything about what we hold, by emailing hello@merenyo.com.
Children's privacy
Merenyo isn't directed at children under 13, and we don't knowingly collect data from them. If you believe a child has created an account, email us and we'll remove it.
Changes to this policy
If this policy changes in a meaningful way, we'll update the date at the top of this page. Continuing to use Merenyo after a change means you accept the update.
Contact
Questions, requests, or concerns: hello@merenyo.com.