Privacy Policy
Introduction
Welcome to MeteorWish. We respect your privacy and are committed to protecting your personal data. This privacy policy explains how we collect, use, and safeguard your information when you use our AI assistant service.
MeteorWish is designed with privacy at its core — conversations are ephemeral by default, and only the memories you actively choose to save are stored.
Data Controller
MeteorWish is the data controller responsible for your personal data. If you have any questions about this privacy policy or our data practices, please contact us.
Data We Collect
We collect and process the following categories of personal data:
Account Information
- Email address (required for account creation)
- Nickname (optional, for personalization)
- Authentication data (password hash or OAuth tokens)
Usage Data
- Memories you actively save (text, images, audio)
- Usage metrics (API calls, feature usage for billing)
Technical Data
- IP address and device information
- Browser type and language preferences
Legal Basis for Processing
We process your personal data based on the following legal grounds under GDPR Article 6:
- Contract Performance: Processing necessary to provide our services to you
- Consent: Where you have given explicit consent for specific processing
- Legitimate Interests: For security, fraud prevention, and service improvement
- Legal Obligation: Where required by applicable laws
How We Use Your Data
- To provide and maintain our AI assistant service
- To process your subscription and payments
- To communicate with you about your account
- To improve our service and develop new features
Data Sharing
We share your data with the following third-party service providers:
- Google: OAuth authentication (if you sign in with Google)
- Stripe: Payment processing for subscriptions
- OpenAI / Anthropic: AI model providers to process your queries (data is not logged)
- Cloudflare: Cloud storage for your saved media files
Data Retention
We retain your data for the following periods:
- Account data: Retained while your account is active, deleted within 30 days after account deletion
- Conversations: NOT stored — this is our core privacy feature
- Memories: Retained until you delete them or your account
Your Rights
Under GDPR, you have the following rights regarding your personal data:
- Right of Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate personal data
- Right to Erasure: Request deletion of your personal data
- Right to Data Portability: Receive your data in a portable format
- Right to Object: Object to certain types of processing
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent
How to Exercise Your Rights
To exercise any of your rights, please contact us at [email protected]. We will respond to your request within 30 days. In some cases, we may need to verify your identity before processing your request.
International Data Transfers
Your data may be transferred to and processed in countries outside your country of residence. We ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission.
Data Security
We implement appropriate technical and organizational security measures to protect your personal data, including encryption in transit and at rest, access controls, and regular security assessments.
Children's Privacy
Our service is not intended for users under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us.
Changes to This Policy
We may update this privacy policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the 'Last updated' date.
Contact Us
If you have questions about this privacy policy or wish to exercise your rights, please contact us:
Privacy Inquiries
Email: [email protected]
You also have the right to lodge a complaint with your local data protection authority if you believe we have not complied with applicable data protection laws.