Merosa
Privacy notice

Privacy

Effective date: August 8, 2026

Pre-release legal draft. This synchronized notice covers the Merosa application, website, early-access list, and private beta. It must be reviewed by qualified counsel before production launch.

Who operates Merosa

Merosa is operated by Jonathan Sumpter in North Carolina, United States. “Merosa,” “we,” and “us” refer to that service operation. Privacy questions and requests may be sent to privacy@joinmindbridgeapp.com.

Information we collect

Device-only information

Saved arsenal items, roles, goals, routines, concise-copy settings, low-stimulation settings, communication drafts, and local searches remain in account-scoped storage on the device unless a feature explicitly says otherwise. They are not included in the server export. The account-deletion flow offers an immediate device erase because the server cannot reach storage left on a device.

Future preference controls

The current diagnostics, research-invitation, and sensitive-notification-preview settings record future preferences only. This build has no optional diagnostics SDK, study-invitation delivery, or push-notification system. A future activation requires fresh disclosure and consent.

How we use information

How information is disclosed

We disclose information only as needed to operate Merosa, to processors acting under our instructions, to protect people or the service where legally permitted, in connection with a lawful business transition subject to appropriate safeguards, or when law requires it. Current or planned processors include Render for API/database/worker hosting, Cloudflare for website/edge/security/early-access storage, Postmark and Resend for transactional email, and Expo/EAS for app build and update tooling. Provider settings and contracts remain a production evidence gate.

Merosa does not sell personal information, use private health-related content for targeted advertising, or track people across other companies’ apps and websites. Merosa does not disclose consumer health data for advertising.

Community visibility

Community posts stay hidden until human review. An approved post may be shown to signed-in beta participants without the account email or account identifier. Authorized moderators can access the submitted content and moderation context. The community is not an emergency-monitoring service.

Crisis-resource activity

Merosa does not intentionally create an account history of which crisis links or telephone links you open. Your device, carrier, destination service, hosting provider, or operating system may process technical information under its own practices.

Retention

Your choices and rights

Within Merosa you can update privacy preferences, delete individual or grouped content where offered, request an account export, schedule account deletion, and erase device-local arsenal data. You may also request access, correction, deletion, or withdrawal of consent at privacy@joinmindbridgeapp.com. You can start account deletion from the app or the public account-deletion page. We may verify a request before acting. Rights vary by location.

For consumer health data, see the separate Consumer Health Data Privacy Policy.

Security and transfers

Merosa uses HTTPS, encrypted native credential storage, hashed passwords and tokens, access controls, bounded retention, and encrypted export objects. No service can guarantee absolute security. Information may be processed in the United States; international availability and transfer safeguards require review before broad release.

Adults only

Merosa accounts and the early-access program are intended for adults age 18 or older. Merosa is not directed to children and does not knowingly collect account information from children.

Changes

Material changes will receive a new effective date and, where required, a fresh in-app consent request. Historical acceptance records identify the policy version accepted.