Trust & Security

How MeSquared protects your personal data

πŸ”’ 256-bit SSLπŸ›‘οΈ OAuth 2.0πŸ“– Read-Only Access🚫 We Never Sell DataπŸ”‘ No Passwords Stored

Our Data Promise

MeSquared exists to simplify your life β€” not to monetize your data. We access only what's needed to power your dashboard, we never share it with third parties, and you can delete everything at any time.

What We Access & Why

IntegrationWhat We AccessPermissionWhat We Can't Do
Google CalendarEvent titles, times, locationsRead OnlyCreate, edit, or delete events
iCloud CalendarEvent titles, times, locationsRead OnlyModify any calendar data
SpotifyPlaylists, podcasts, now playingRead OnlyDelete playlists or modify your library
Google MapsLocation search, nearby placesAPI OnlyTrack your location or movements

How We Protect Your Data

πŸ”

Encryption

  • βœ“All data transmitted over HTTPS with TLS 1.3
  • βœ“OAuth tokens encrypted before database storage
  • βœ“Passwords hashed with bcrypt β€” we cannot read them
  • βœ“API keys stored server-side only, never in browser
πŸ”‘

Authentication

  • βœ“OAuth 2.0 for all integrations β€” your credentials go directly to Google/Spotify, not through us
  • βœ“Tokens auto-rotate β€” expired tokens refreshed, old ones invalidated
  • βœ“Revoke access any time from your integration settings
πŸ›‘οΈ

Infrastructure

  • βœ“Hosted on Vercel with automatic SSL certificates
  • βœ“Supabase PostgreSQL with Row Level Security
  • βœ“Rate limiting on all endpoints
  • βœ“No personal data in browser storage
πŸ“Š

Audit Trail

  • βœ“All data access logged with timestamp and action type
  • βœ“Audit logs available upon request
  • βœ“No employee accesses your raw integration data

What We Never Do

  • βœ•Never sell your data β€” to anyone, for any reason
  • βœ•Never share your data with advertisers or third parties β€”
  • βœ•Never store payment information β€” Stripe handles all billing
  • βœ•Never track your location β€” we use event locations, not GPS
  • βœ•Never access more than we need β€” all scopes are read-only
  • βœ•Never use your data to train AI models β€” your profile is yours
  • βœ•Never retain data after deletion β€” when you delete, it's gone

Your Rights

  • βœ“Access: Request a copy of all data we have about you
  • βœ“Delete: Request complete deletion of your account and all data
  • βœ“Export: Download your profile, preferences, and connected data
  • βœ“Revoke: Disconnect any integration instantly from settings
  • βœ“Audit: Request a log of when and how your data was accessed

To exercise any of these rights, email privacy@me-squared.ai

AI & Your Energy Profile

  • βœ“Your Energy Profile is generated by AI using birth data you provide
  • βœ“Birth data is used only during generation β€” it is not stored in plaintext
  • βœ“Your reading is saved to your account only β€” no one else can see it
  • βœ“The shareable Energy Type card shows only your type name β€” no personal details
  • βœ“AI recommendations include safety classifiers for wellness content

Questions?

If you have any questions about how we handle your data:

Email: privacy@me-squared.ai

Last updated: May 2026