Meka

Privacy

Last updated September 25, 2026.

This notice explains what information Meka processes, why it is used, how it is protected, and the choices available to you when you use the service.

1. Who this notice applies to

This notice applies to visitors, registered users, free-preview users, and paid users of Meka. During MVP testing, Meka acts as the service operator responsible for the personal information described in this notice.

2. Information Meka processes

Meka may process account information such as your email address and authentication details; project information such as your Vision Lock, prompts, queued instructions, generated application content, checkpoints and project history; and technical information needed to operate and secure the service.

Technical information may include browser or device identifiers, IP-related information, timestamps, request frequency, generation events, error information, and security or abuse-prevention signals.

3. How Meka uses your information

Meka uses information to create and manage accounts, generate and edit applications, preserve project history and checkpoints, provide previews and publishing features, enforce free and paid usage limits, diagnose failures, improve reliability, secure the service, prevent misuse, and respond to user requests.

4. AI generation

When you ask Meka to build or edit an application, relevant project content is sent to an AI model provider so the requested output can be generated. This may include your project brief, queued instructions, and the current generated application code where necessary to perform an edit.

Meka aims to send only the context needed for the requested generation. Users should avoid entering secrets, passwords, payment-card information, highly sensitive personal information, or other data that is unnecessary for the build.

5. Abuse prevention and free usage

To protect Meka from repeated exploitation of free usage allowances, automated abuse, and circumvention of usage limits, Meka may process account identifiers, a first-party device or browser identifier, hashed IP-related information, generation timing and frequency, and indicators of similarity between recent generation requests.

Similarity checks are used as one signal among several. They are not treated as proof that two accounts belong to the same person. A request may be slowed, blocked, or reviewed when several signals indicate likely misuse.

6. Cookies and device identifiers

Meka may place a first-party device identifier in your browser so the service can recognize repeated use of the free preview and protect against abuse. This identifier is used for service protection and is not intended for advertising.

7. Service providers

Meka relies on specialist service providers to operate the product. These currently include Supabase for authentication and database services, Vercel for application hosting and deployment, GitHub for source-code infrastructure, and OpenAI for AI generation. These providers process information only as needed to provide the relevant service to Meka and are subject to their own security and privacy obligations.

8. Legal bases

Where the GDPR or similar law applies, Meka processes information when necessary to provide the service you request, to comply with legal obligations, and for legitimate interests such as securing the service, preventing abuse, maintaining reliability, and protecting fair access to Meka. Where consent is legally required, Meka will request it separately.

9. Data minimisation and retention

Meka aims to collect and retain only what is reasonably necessary for the relevant purpose. Account and project information may be retained while your account remains active and for a reasonable period afterwards where needed for security, dispute resolution, legal obligations, or backup integrity.

Abuse-prevention data is designed to be more limited. Technical identifiers are transformed or hashed where practical, and persistent abuse-event records are periodically removed when they are no longer needed for fair-use and security purposes.

10. International data transfers

Some service providers may process information outside your country of residence. Where required, Meka relies on appropriate contractual, organizational, or legal safeguards for such transfers.

11. Security

Meka uses technical and organizational safeguards intended to protect account, project, and usage data. No online service can guarantee absolute security, but Meka is designed to limit unnecessary access, keep sensitive infrastructure credentials server-side, and separate user projects through access controls.

12. Your rights and choices

Depending on where you live, you may have rights to request access to, correction of, deletion of, restriction of, or portability of your personal information, and to object to certain processing. You may also have the right to complain to your local data-protection authority.

Requests can be made through the contact channel provided by Meka in the service. Meka may need to verify your identity before acting on a request.

13. Age requirements

Meka is intended for users who meet the minimum age required to use online services independently in their jurisdiction. Where a user is below that age, access to Meka should only occur with any parental or guardian authorization required by applicable law. If Meka becomes aware that personal information has been collected in circumstances that do not meet those requirements, it will take reasonable steps to address the situation.

14. Sale of personal information

Meka does not sell users' personal information to advertisers. Meka's product and infrastructure decisions are not based on selling user project data for advertising purposes.

15. Changes to this notice

This notice may be updated as Meka's product, payment system, hosting, security controls, or legal obligations evolve. Material changes will be reflected on this page and the last-updated date will be revised.

TermsBack to Meka