Is Meloa safe?

Short answers to what people actually ask, in plain words. The binding statements are the privacy policy and the consumer health data notice. Nothing here overrides them.

Is it safe to connect Google Calendar to Meloa?

Meloa asks for two narrow Google permissions and nothing else: to read and write calendar events, and to list your calendars so you can pick one. It deliberately doesn't ask for the broad calendar permission, so it can't change your calendar's settings, its sharing, or who has access. Connecting is optional, the app works fully without it, and you can disconnect any time, which revokes the token with Google.

Where are my Google credentials stored, and are they encrypted?

The access and refresh tokens are encrypted with AES-256-GCM before they're written to the database, using a key kept outside it. That's stronger than database permissions alone: if a backup, an admin session or a service key were ever exposed, the tokens in it wouldn't work as Google credentials.

Can I add two-factor authentication to my Meloa account?

Yes. Turn on two-step verification with any authenticator app (TOTP) from Settings → Account, and save a one-time recovery code in case you lose the device. Passwords must be at least 12 characters, and Meloa checks them against known breach lists, so a password that's already leaked somewhere can't be used here.

Can my therapist see my Meloa data?

No. There is no clinician login, no dashboard, and no notification of any kind sent to a therapist. Meloa has no way to contact your therapist about you. The only way a therapist sees anything is if you generate a PDF yourself, choose which sections go into it, and hand it to them.

Can other Meloa users see my data?

No. Every record is sealed to the account that created it, enforced by the database itself rather than by the app remembering to ask, so one account cannot read another's calendar or health data. That holds even when someone else pays for your plan: every account stays private to the person who uses it, with no shared visibility of any kind.

Has Meloa ever had a security problem?

One, found and fixed on September 25, 2026. After someone publicly claimed Meloa had a backdoor, we tested the live app the way an attacker would: signed in as one account and tried to read, change or delete another account's records, on every table. Every attempt was refused. The test did find one real bug: a person could give their own account a paid plan without paying, by deleting and re-creating their own profile. It never exposed anyone's data. It was fixed the same day, and we found no sign that anyone had used it. Several smaller protections were tightened in the same pass. If anything ever affects your data, it will be written up here.

Do you sell my data, or use it to train AI models?

No to both. Meloa does not sell personal data and does not use your content to train AI models. AI-assisted features are switched off until you separately opt in, which is a distinct choice from paying for any plan.

What happens to my data if I delete my account?

Deleting your account schedules the deletion for 30 days later, and it completes within about a day of that date. You can cancel during that window, or choose to delete right away. It removes your calendar entries, your check-ins, any connected-calendar tokens, and, if you signed in with Apple, our record with Apple. You can also export everything you've logged before you go.

Is Meloa HIPAA compliant, and is it a medical device?

Meloa is a self-tracking app you use yourself. It isn't a medical device, isn't treatment, and doesn't diagnose anything. It isn't a HIPAA-covered entity, because it isn't a healthcare provider and doesn't bill insurance. Your data belongs to you rather than sitting in a clinical record. Exports are formatted to be handled as protected health information once they reach a clinician, which is where those obligations begin.

Does Meloa monitor me or alert anyone in a crisis?

No. Meloa does not watch your scores in real time and will never contact anyone on your behalf, including emergency services or your therapist. In a crisis the app directs you to call or text 988 in the US, or 911 for emergencies.

How do I report a security problem?

Email security@meloa.io. Please send the details there rather than posting them publicly, so the problem can be fixed before anyone else can use it. Every report goes to the person who wrote the code, and every one gets an answer. Security researchers can also find the contact in meloa.io/.well-known/security.txt.

Something unclear or wrong? Ask me directly. It goes to the person who wrote the code, and a question you had to ask usually means this page is missing an answer. Found a security problem? Send it to security@meloa.io.