Privacy
Pre-release legal draft. This synchronized notice covers the Merosa application, website, early-access list, and private beta. It must be reviewed by qualified counsel before production launch.
Who operates Merosa
Merosa is operated by Jonathan Sumpter in North Carolina, United States. “Merosa,” “we,” and “us” refer to that service operation. Privacy questions and requests may be sent to privacy@joinmindbridgeapp.com.
Information we collect
- Account data: email address, account identifier, language, onboarding status, policy versions, consent timestamps, verification state, and security/session records.
- Health-related and support data you choose to enter: structured check-ins, mood, energy, sensory load, support needs, Personal Support Plan selections, voluntary beta outcome scores, and private beta comments.
- Community and feedback data: community posts, report reasons, moderation state, beta-feedback categories, impact, frequency, and assistive-technology selections.
- Operational data: export and deletion requests, status-email preferences, readiness records, delivery records, and limited server/security logs. Hosting and security providers may process IP addresses and request metadata even when Merosa does not place those values in a user profile.
- Early-access data: email, consent version, signup source, status, and signup time.
Device-only information
Saved arsenal items, roles, goals, routines, concise-copy settings, low-stimulation settings, communication drafts, and local searches remain in account-scoped storage on the device unless a feature explicitly says otherwise. They are not included in the server export. The account-deletion flow offers an immediate device erase because the server cannot reach storage left on a device.
Future preference controls
The current diagnostics, research-invitation, and sensitive-notification-preview settings record future preferences only. This build has no optional diagnostics SDK, study-invitation delivery, or push-notification system. A future activation requires fresh disclosure and consent.
How we use information
- Provide accounts, personalized app functions, check-ins, support plans, community, exports, deletion, and service communications.
- Protect accounts, enforce retention, investigate abuse, moderate submitted content, and maintain service reliability.
- Evaluate voluntary private-beta feedback and outcomes without using private mental-health content for advertising or marketing.
- Comply with law and respond to valid rights, safety, and security requests.
How information is disclosed
We disclose information only as needed to operate Merosa, to processors acting under our instructions, to protect people or the service where legally permitted, in connection with a lawful business transition subject to appropriate safeguards, or when law requires it. Current or planned processors include Render for API/database/worker hosting, Cloudflare for website/edge/security/early-access storage, Postmark and Resend for transactional email, and Expo/EAS for app build and update tooling. Provider settings and contracts remain a production evidence gate.
Merosa does not sell personal information, use private health-related content for targeted advertising, or track people across other companies’ apps and websites. Merosa does not disclose consumer health data for advertising.
Community visibility
Community posts stay hidden until human review. An approved post may be shown to signed-in beta participants without the account email or account identifier. Authorized moderators can access the submitted content and moderation context. The community is not an emergency-monitoring service.
Crisis-resource activity
Merosa does not intentionally create an account history of which crisis links or telephone links you open. Your device, carrier, destination service, hosting provider, or operating system may process technical information under its own practices.
Retention
- Check-ins use the user-selected 7-, 30-, or 90-day retention period.
- Community posts and beta feedback are retained for no more than 90 days unless a documented legal or safety hold applies.
- Encrypted export objects expire after 24 hours and are destroyed after a completed one-time download.
- Account deletion has a 14-day cancellation period, after which eligible account data is erased or anonymized. A non-sensitive erasure receipt may be retained to prove completion.
- Transactional email content, service logs, backups, and security records follow provider and operational retention schedules documented in the data inventory and confirmed before production.
Your choices and rights
Within Merosa you can update privacy preferences, delete individual or grouped content where offered, request an account export, schedule account deletion, and erase device-local arsenal data. You may also request access, correction, deletion, or withdrawal of consent at privacy@joinmindbridgeapp.com. You can start account deletion from the app or the public account-deletion page. We may verify a request before acting. Rights vary by location.
For consumer health data, see the separate Consumer Health Data Privacy Policy.
Security and transfers
Merosa uses HTTPS, encrypted native credential storage, hashed passwords and tokens, access controls, bounded retention, and encrypted export objects. No service can guarantee absolute security. Information may be processed in the United States; international availability and transfer safeguards require review before broad release.
Adults only
Merosa accounts and the early-access program are intended for adults age 18 or older. Merosa is not directed to children and does not knowingly collect account information from children.
Changes
Material changes will receive a new effective date and, where required, a fresh in-app consent request. Historical acceptance records identify the policy version accepted.