Legal

Privacy Policy

Last updated: March 2026 · Effective immediately

Plain English Summary

  • We collect only what we need to run the service
  • We never sell your data to anyone
  • Your lead data is used only to generate your audit results
  • You can delete everything at any time
  • We comply with GDPR (EU) and CCPA (California)

1. Who We Are

Meytchi AI ("we", "us", "our") is a revenue recovery platform operated at meytchi.io. We help sales teams identify and re-engage dormant leads using artificial intelligence. For data protection enquiries, contact us at: vijay@meytchi.io

2. Data We Collect

Account data: When you register, we collect your name, email address, and optionally your company name. This is required to create and maintain your account. Lead data: When you upload a CSV or XLSX file, we process the data in that file (company names, contact names, email addresses, deal values, etc.) to generate audit results. This data is stored in your account and subject to automatic deletion after 14 days per our GDPR cron policy. Usage data: We collect standard server logs including IP addresses, browser type, pages visited, and actions taken within the platform. This is used for security, debugging, and improving the service. Payment data: Payments are processed by Stripe. We do not store your card details. We receive a confirmation of payment and the amount charged.

3. How We Use Your Data

• To provide the service: processing your lead files, generating Gold-Score™ audit results, and delivering AI-drafted emails • To manage your account: authentication, credits, billing history • To communicate with you: onboarding emails, support responses, service notifications • To improve the platform: aggregated, anonymised analytics on feature usage • To comply with legal obligations: fraud prevention, tax records, regulatory requirements We do not use your lead data to train AI models. We do not sell your data to third parties. We do not share your data with advertisers.

4. Legal Basis for Processing (GDPR)

For users in the European Economic Area, we process your data under the following legal bases: • Contract performance: processing necessary to deliver the service you signed up for • Legitimate interests: security monitoring, fraud prevention, service improvement • Legal obligation: compliance with tax, accounting, and regulatory requirements • Consent: marketing communications (you may withdraw consent at any time)

5. Data Retention

Account data is retained for the lifetime of your account. Lead data uploaded for audits is automatically purged after 14 days as part of our GDPR compliance cron job. If you delete your account, all associated data is removed from our systems within 24 hours. Billing records are retained for 7 years as required by financial regulations.

6. Data Sharing

We share data only with the following third-party processors, under contractual data protection agreements: • Supabase (database and authentication) — EU/US data centres • Vercel (hosting and edge network) — global CDN • Stripe (payment processing) — PCI DSS Level 1 certified • Resend (transactional email) — email delivery only • Groq (AI inference) — lead data sent for scoring, not retained by Groq We do not share your data with any other parties without your explicit consent.

7. Your Rights

Under GDPR and CCPA, you have the right to: • Access: request a copy of all personal data we hold about you • Rectification: correct inaccurate data • Erasure: request deletion of your data ("right to be forgotten") • Portability: receive your data in a machine-readable format • Objection: object to processing based on legitimate interests • Restriction: request we limit how we process your data To exercise any of these rights, email us at vijay@meytchi.io. We will respond within 30 days. You can also delete your account instantly from Settings → Danger Zone, which removes all your data immediately.

8. Cookies

We use only essential cookies required for authentication (session tokens) and security (CSRF protection). We do not use tracking cookies, advertising cookies, or third-party analytics cookies. No cookie consent banner is required as we only use strictly necessary cookies.

9. Security

We protect your data using: • TLS 1.3 encryption in transit • AES-256 encryption at rest • Row-level security in our database • Service-role access controls (your data is never exposed to other users) • Regular security reviews In the event of a data breach affecting your personal data, we will notify you within 72 hours as required by GDPR Article 33.

10. International Transfers

Your data may be processed in the United States and European Union. All international transfers are covered by Standard Contractual Clauses (SCCs) or adequacy decisions as required by GDPR Chapter V.

11. Children

Meytchi AI is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us immediately at vijay@meytchi.io.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified by email to registered users at least 7 days before they take effect. The date at the top of this page reflects the most recent update.

13. Contact & Complaints

For privacy questions or to exercise your rights: Email: vijay@meytchi.io Response time: within 30 days If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority (e.g. the ICO in the UK, or your EU supervisory authority).