This notice is required by Washington's My Health My Data Act and Nevada's consumer health data law, and we apply it to everyone who uses Meloa, wherever they live. It describes, specifically and separately from our general Privacy Policy, how Meloa LLC ("we," "us," "our") collects, uses, and shares your consumer health data — information that identifies your past, present, or future physical or mental health status. If anything here conflicts with the general Privacy Policy on how health data specifically is handled, this notice controls.
Categories of consumer health data we collect, and why
Distress ratings (SUDS logs)
0–100 anxiety scores, and optional somatic/cognitive/anticipatory/autonomic breakdowns, tied to specific events or logged ad hoc.
Purpose: Compute your baseline anxiety trend and detect patterns like the Anticipation Gap shown on your Record page.
Baseline mental health assessments
General anxiety, social anxiety and depression self-report scores: check-ins adapted from the GAD-7 and PHQ-9, plus a short social-anxiety check-in written for Meloa.
Purpose: Track how your baseline anxiety and mood shift over weeks or months, shown as longitudinal trend lines on your Record page.
Daily anxiety logs
One whole-day 0–100 rating and optional notes, per day.
Purpose: Shade calendar day cells and provide a coarse day-level view distinct from individual event ratings.
Medications & adherence logs
Medication name, dosage, frequency, schedule, and whether each scheduled dose was taken, skipped, or partial.
Purpose: Power daily adherence check-ins and the medication adherence trend line on your Record page.
Event anxiety ratings & cognitive profile
Per-event 1–10 anxiety ratings; time-blindness level, rejection sensitivity, and checking-compulsion score you provide during onboarding or intake.
Purpose: Drive pre-event lockout timing, post-event decompression buffers, and OCD-safeguard schedule locking defaults.
Breathing & guided relax session history
Session type, duration, and completion status for breathing exercises and guided relax audio.
Purpose: Show your own session history; not used for anything beyond your own account.
Intake questionnaire responses
Executive-function, schedule-preference, and baseline-anxiety answers from onboarding.
Purpose: Set your initial app defaults (spoon budget, buffer lengths, category defaults); retaken any time to re-tune them.
Period start dates (optional)
The first day of each period, only if you turn on period tracking and log it yourself. Never inferred from your mood or anything else. Plus one setting: how many days before an estimated period you'd like more room.
Purpose: Let your own record show what the days before and during your period do to your anxiety numbers, using the same statistics as every other pattern. The estimate of your next period, from your own logged dates, is used only to honor the room setting you chose — never to tell you how a week will go.
Sleep logs
The hours of sleep you log for a night.
Purpose: Show how sleep and your ratings move together.
Fears you track
The fears you name, the ratings you give them, and the moments you faced one: how high it got, whether you stayed, left or avoided it, and a short note if you wrote one.
Purpose: Show how a fear changes over time.
Journal entries and photos you attach
What you write in the journal, and any photo you add to an entry or an event.
Purpose: Kept so you can read them back. An entry is sent to Talu only when you ask him to reflect on it.
Things that help
Acts such as a walk, a shower or a call, including ones you add yourself, with how long they took and the ratings you give before and after.
Purpose: Show which ones help you.
Hard dates, and the people and places in your life
Dates that are hard for you and the notes you write about them; the names of people and places you add, with a phone number if you give one; and whether a tool helped you.
Purpose: Give those days more room, and keep the people you can reach close at hand.
Routines
The routines you set up, their steps, and the days you finished them.
Purpose: Place your routines in your day and show which days they were done.
Predictions
The rating you expected before an event or task, what you were afraid would happen if you wrote it down, and predictions for things you ended up not doing.
Purpose: Show what you expected next to what happened.
Forwarded emails and held texts
Messages you choose to hand to Talu, with the sender and the text. They can mention your health or someone else's.
Purpose: Wait for you on the Talu tab until you are ready. Held texts are deleted 30 days after they arrive. Forwarded emails are kept until you delete them or your account.
Facts Meloa has worked out about you (your working profile)
One-sentence conclusions with a pointer to their source: "anticipation runs hottest around work things," "you finish focus tasks in the morning," "you told us phone calls are a trigger." Never a predicted score, a diagnosis, or a risk level.
Purpose: Size buffers, pick calmer windows, and let Talu refer to things you have actually done. Every fact is visible on your facts page, where you can hide, correct, or delete it. See the section below.
What Meloa learns about you
Meloa keeps a working profile: a set of facts it has worked out from what you log, so it can size buffers, pick calmer windows, and let Talu refer to things you have actually done. Every fact has a source you can see — the check-ins, ratings, events, tasks, or answers it came from. Facts come from three places:
- Computed from your numbers and dates. This is arithmetic over your own record and involves no outside service.
- Distilled from things you wrote: the notes beside a rating, prep notes on an event, notes on a task or a day, any journal entry you asked Talu to reflect on, and what you said in a chat with Talu, read once when the chat closes. Distilling uses Google Gemini, runs only if you have turned on AI-assisted features, and is part of the Premium plan.
- Stated by you, on the “What Meloa knows about you” page.
Your journal is not read to build this profile. An entry is read once, only when you press “Ask Talu to reflect” on it. Entries you have not asked about are never sent anywhere and never used to learn about you. Chats with Talu are not stored. Three things can be kept, each by your choice: a reply you save to your journal; a reply you report, which sends that reply and your message just before it to the Meloa team; and, on Premium, up to three short notes taken from what you said when a chat closes. Talu’s own replies are not read for the notes, and nothing is read from a chat where a crisis resource was shown. You can decline the notes as you close a chat, and see or delete each one on your facts page.
The profile never contains a predicted score, a diagnosis, or a risk level. Meloa’s whole approach depends on your own before-and-after numbers, and a number a model made up would poison that record.
You can see every fact, hide any fact so nothing uses it, correct it, or delete it, at Record → What Meloa knows about you. Deleting your account deletes the profile with everything else, and your data export includes it.
Who we share it with, and why
We do not share your consumer health data with anyone beyond what's listed below, and never for advertising or to build profiles about you for other companies.
Supabase
Database hosting and authentication — stores every category above.
Shared: Always, as our infrastructure provider, to operate the Service you asked for. Not optional and not a consent choice — the app cannot function without a database.
Google Gemini (Google Cloud AI)
Talu's AI features are provided by Google's Gemini, a third-party AI service: task breakdown, planning from a description, paste and photo import, chat, weekly reflections, journal reflections you request, and (on Premium) distilling the notes you write into facts on your working profile. What is sent: text you type, paste or dictate; task and event details, including the anxiety ratings you give them; photos you choose; and your distress (0–100) and daily anxiety ratings, with the notes beside them when you chat with Talu, or as weekly averages when you ask for a weekly reflection. Also sent when you chat with Talu: your routines, reminders, milestones, the things that help you with their ratings, and the names of places you saved. Your sleep logs, the fears you track, the names and schedule of your medications and, if you track your period, where today falls in your cycle and the body symptoms you logged for today are sent only if you turn on "Let Talu see sleep, fears and medications". Medication amounts are never sent. A held text or forwarded email is sent only if you choose to use it with Talu. On Premium, what you said in a chat is read once when the chat closes, to write up to three short notes. Emails, phone numbers and likely names are removed from text before it is sent. Photos are sent as they are.
Shared: Only while "AI-assisted features" is on in Settings → Privacy, and only on accounts belonging to someone 18 or over. It is off by default at every age, nothing is sent while it is off, and you can turn it off there at any time. Meloa itself is available from age 13, but Gemini's own terms require adult users, so on an account whose date of birth is under 18 the switch cannot be turned on and nothing is ever sent — buying a paid plan does not change that. Task Breakdown still works without it via a non-AI heuristic fallback.
OpenAI (text-to-speech)
Talu's spoken voice. What is sent: the replies Talu writes to you in chat, which can mention your events, tasks and how you've been feeling. Your own messages are never sent. The reply is turned into audio and returned to your device; Meloa stores none of it, and OpenAI does not use it to train its models.
Shared: Only after you turn on Talu's voice in a chat and agree on the screen that names OpenAI, only while "AI-assisted features" is also on, and only on accounts belonging to someone 18 or over. It is off by default, is never used for a crisis reply, and you can withdraw it anytime in Settings → Privacy.
PostHog
Product analytics — named, deliberate events (e.g. "onboarding_completed") with your account ID, never free-text health data, never autocapture of form inputs.
Shared: Only when you've turned on "Product analytics" in Settings → Privacy. Off by default, and never sent if your browser sends a Global Privacy Control signal.
Stripe
Billing — payment and subscription-tier information only. Never receives health data.
Shared: Only if you buy something on our website: a plan, a Group Plan, or a pack of Talu actions.
Apple
Purchases made in the iPhone app, Sign in with Apple, and delivering notifications to the iPhone app. Apple receives the token your iPhone issued for Meloa and the words of each notification, such as a reminder that a check-in is waiting. Notifications do not carry your ratings or the titles of your events.
Shared: Only if you use the iPhone app and buy there, sign in with Apple, or turn notifications on.
Your browser's push service
Delivers notifications on the web. It is run by the maker of your browser and receives the encrypted notification.
Shared: Only if you turn notifications on in a browser.
Google Maps (Places and Routes)
Address suggestions as you type a location, and travel-time estimates between addresses you saved. An address can be a clinic or another place that says something about your health.
Shared: Only when you type in a location field or ask for a travel estimate. Never your device's location.
Cloudflare (Turnstile)
A check that tells a person from an automated script when you sign up, sign in, reset your password or delete your account. It reads browser and device signals. It does not receive your health data.
Shared: On those four screens.
Resend
Email delivery, and receiving emails you forward to your Talu address.
Shared: Your email address and the content of each email. The weekly summary, if you get it, includes figures from your record, such as your average rating before and after events. A reply you report is sent to the Meloa team by email. Emails you forward pass through Resend on their way to your account.
Vercel
Application hosting — every request to Meloa passes through it in transit.
Shared: In transit only, encrypted; Vercel does not store your health data.
Sentry
Error reports when something in the app breaks.
Shared: Technical details of the failure. Form contents and logged values are not attached to a report.
We do not sell your consumer health data
Meloa does not sell consumer health data, and has never sold it, to any third party — not to data brokers, advertisers, or anyone else. If that were ever to change, the law requires (and we would provide) a separate, signed authorization naming the buyer, the specific purpose, and an expiration date — not a routine consent pop-up. We have no plans to introduce this.
No location-based tracking near healthcare facilities
Meloa never receives your device's location. In the iPhone app, if you turn on “Notice when I arrive”, your iPhone watches for the places you put on your own hard events, around the time of each one, and shows you one notification when you get there. That happens on your iPhone. Meloa does not learn where you are and does not use it for advertising. Places of health care are left out: if an event's title or place reads like a doctor, a dentist, a clinic, a hospital, a pharmacy or a therapist, your iPhone is never asked to watch for it. It is off unless you turn it on. The other location-related features work from addresses you type in yourself: address suggestions for event locations, saved places you choose to add (like Home), and optional travel-time estimates between them. None of these read your device's location, and the addresses you save are visible only to you and deletable at any time in Settings.
Your consent and how to withdraw it
Collecting your consumer health data requires your affirmative, opt-in consent, given at signup (or, for accounts created before this notice existed, the first time you sign back in). Sharing it with Google Gemini or PostHog requires a second, separate opt-in — both are off until you turn them on. Two more are separate opt-ins of their own, and both are also off until you turn them on: Talu's voice, which sends the replies Talu writes to OpenAI, and “Let Talu see sleep, fears and medications”, which adds those three to what Gemini receives when you chat.
You can withdraw the sharing opt-ins at any time from Settings → Privacy, with immediate effect. Because the collection of this data is what the core product does, withdrawing consent to collection itself means closing your account — see Delete Account in the same section. You choose between deleting right away and a 30-day wait that you can cancel. After the wait, your account and everything in it are deleted from our database, usually within a day. We cancel any subscription billed through Stripe, remove your analytics profile from PostHog, and end our access to your Google or Apple account. Stripe keeps its own payment records as the law requires.
You can also download a full, machine-readable copy of everything listed above at any time from the same section of your profile settings.
Contact
Questions about this notice, or requests to access, correct, or delete your consumer health data, can be sent to support@meloa.io.