Privacy Policy
Meliya — meliya.org. Last updated 9 August 2026.
Meliya is a learning app for children and families, with polls and quizzes alongside the lessons. This policy describes exactly what the running service stores, why, and how to have it removed. It describes the software as built, not an intention.
Our promise
We do not sell, rent, or share your personal information, and we never use it for anything other than running Meliya and delivering the features you use — your account, your learning, and keeping the app safe. There is no advertising, no third-party ad tracking, and no analytics brokers. We do not build advertising or behavioural profiles of anyone, and we especially never do so for children. Your content is never used to train AI models. We collect the minimum we need, and you can ask for a copy of it or have it deleted at any time (see Contact).
You agree to this policy when you create or sign in to a Meliya account, and we ask you to accept it before you can use an account. You can read it here at any time, and if it changes materially we ask you to review and accept it again.
You can use Meliya without an account
Browsing polls and voting require no account and no sign-in. If you never sign in, we never learn your name or email address.
What is collected
| Data | When | Why |
|---|---|---|
| Email address, display name, profile picture, and an account identifier from whichever of Google, Facebook or X you use | Only if you sign in with that provider | To create your account, show who you are, and decide what you are allowed to do. You can sign in with more than one of these at once — see "Linked accounts" below |
| Email address and a securely hashed password | Only if you create an account with an email and password instead | To let you sign in without a third-party provider. The password itself is never stored — only a one-way cryptographic hash that cannot be reversed back into it. A verification link is emailed to confirm you own the address before the account can be used |
| Your votes and the polls you create | When you vote or post | To count results and show them back to everyone |
| A one-way hash of your IP address and browser user-agent | When you vote | To limit repeat voting and abuse. The hash is salted and your actual IP address is not stored alongside it. If your profile does not already supply a country, your IP address is separately used, live and only for that moment, to resolve an approximate country for the anonymous aggregate statistics below — the address itself is still never stored, only the resulting country |
| Sign-in session cookie | Only if you sign in | To keep you signed in. It is HTTP-only, so page scripts cannot read it |
| Your theme choice and which polls you have voted on | As you use the app | Stored in your browser's local storage, on your device. It is not sent to the server |
| First and last name, on your profile | Only if you choose to add them, from "Edit profile" | Optional, and shown only to you — never to anyone else, and never used in the anonymous aggregate statistics described below |
| Gender, country, state/province, city, and birth year/month, on your profile | Only if you choose to add them, from "Edit profile" | Every field is optional and can be cleared at any time. Gender, country, and birth year/month are also used, in coarsened form, to compute the anonymous aggregate statistics described in "Anonymous aggregate statistics" below. State/province and city are shown only to you and are not currently used in those statistics |
| A photo you choose to upload as your profile picture | Only if you upload one, from "Edit profile" (currently limited to staff and trusted accounts while this is new — see below) | Stripped of any location or camera data it carried (EXIF, including GPS) and resized before it is ever stored. It is checked by an automated safety model before it is shown to anyone; anything the model is not clearly confident about is held for a person to review first rather than published or rejected automatically. You can switch away from it, or back to your sign-in provider's picture, at any time from "Edit profile" |
| Your device's approximate position, momentarily | Only if you press “Detect” on your profile, and only if you then allow your browser's location prompt | To suggest your country, state/province and city so you do not have to type them. The coordinates are sent to Meliya's own server, matched against a list of place names that Meliya holds itself, and discarded — they are never written to the database, never sent to any other company, and no mapping or geocoding service is involved. The suggestion appears in the three ordinary fields on the form, and nothing is saved unless you press Save. If you never press “Detect”, none of this happens |
If you sign in with Google, Facebook or X, we request only your basic profile and email address (X does not provide an email address at all, even if you grant one — that is a limit of X's own sign-in system, not a choice of ours). Meliya never receives your password on any of these services, and asks for no access to Gmail, Drive, Contacts, your Facebook friends, or your X posts and follows.
Anonymous aggregate statistics
Meliya shows how different groups voted on a poll — for example, whether one age group leaned a different way than another. This section describes exactly how it works.
- Only from what is already in this policy. No new data is collected for this. It draws only on the gender, country and birth year/month already described above, and only for votes cast while those fields are filled in.
- Coarsened at the moment you vote. Your exact birth year and month become a wide age band (for example "25–34"), and your country becomes just the country — never a state/province or city. This coarsened snapshot is stored on the vote itself, separately from your profile, and statistics are computed only from that snapshot — never by looking up your live profile.
- Not retroactive. Because the snapshot is taken at the moment of voting, editing or clearing a field on your profile afterwards changes what is captured on your future votes but does not alter statistics already computed from past ones.
- Never shown for a small group. A breakdown only appears once a poll has at least 50 votes in total, and even then, any group of voters smaller than 25 people is hidden rather than shown as a small number — and if hiding one group in a chart would let someone work out its size by subtraction, the whole chart for that poll is hidden, not just the small piece. This threshold cannot be configured below 10 people under any circumstances.
- One dimension at a time. A breakdown can show age group, gender, or country — never a combination such as "women aged 25–34 in Canada" — which is another way small, identifiable groups are avoided.
- Country may come from your connection, not just your profile. If you have not set a country on your profile — including if you are not signed in at all — Meliya resolves an approximate country from your IP address at the moment you vote, then discards the address immediately; only the resulting country is kept, on the vote itself, the same way a profile-supplied country would be. This lookup runs against a table Meliya holds itself, so your IP address is never sent to another company. It is never exact — VPNs, mobile carriers and corporate networks routinely place people in the wrong city or even the wrong country — so treat it as a rough, population-level signal, never a fact about one voter. This is the only new use of your IP address beyond the abuse-prevention hash described above: it still never uses the momentary "Detect" location described above, and never plots an individual voter on a map — only country-level totals.
- No new categories of data. Political, religious, health, or similarly sensitive data remains uncollected, as stated throughout this policy.
What is not collected
- No advertising or third-party tracking, and no analytics service.
- No background or continuous location tracking, no contacts, and no files. Meliya never asks your device for its position unless you press “Detect” on your own profile, and even then the coordinates are used once to suggest a place name and are not stored. Location Meliya keeps: the country, state/province and city sitting in your profile — each one optional, each one editable by hand, and each one clearable at any time — and, on a vote itself, a country approximated from your connection when your profile does not supply one (see “Anonymous aggregate statistics” above). Your IP address itself is never stored either way.
- No plaintext or reversible passwords. If you create an account with a password instead of Google, Facebook or X, only a salted one-way hash is stored — the same industry-standard approach used by ASP.NET Core's own identity system.
- No political, religious, health, or similarly sensitive data of any kind.
- Your data is never sold, rented, or shared with advertisers.
Content generated by AI
Many polls on Meliya are generated by AI models running on private hardware, and are labelled “AI made this” so you can tell them apart from polls written by people. Polls submitted by people are checked by an automated moderation model before publication, and may be reviewed by a person. Your content is not used to train any AI model.
Where the data lives
Meliya runs on privately-operated hardware in Canada, reached through Cloudflare, which routes traffic and sees the usual connection metadata. AI models run locally on that same private hardware; poll content is not sent to any third-party AI provider.
How long it is kept
- Account details — until you delete your account.
- Polls and votes — kept while published, since results are cumulative.
- Abuse-prevention hashes — kept as long as the associated vote.
- Backups — retained for 30 days, then deleted automatically.
Your choices
- Sign out at any time; the session cookie is dropped.
- Link or use more than one sign-in method — Google, Facebook, X, or an email and password — from the "Linked accounts" section of "Edit profile". They all reach the same account when the email matches.
- Choose your profile picture from "Edit profile" — your sign-in provider's picture, an uploaded photo of your own (see above), or a pick from a set of AI-generated illustrations. Switching away from an uploaded photo does not delete the stored file, but it is no longer shown anywhere.
- Edit or clear your profile at any time from "Edit profile" — name, gender, country, state/province, city, and birth year/month are each optional and each independently removable, and nothing about them is shown to other users. Clearing a field stops it from being captured on any vote you cast afterwards; see "Anonymous aggregate statistics" above for why it does not change statistics already computed from earlier votes.
- Ask for a copy of the data associated with your account.
- Ask for deletion of your account and personal details. Note that polls and vote counts other people have interacted with may remain, with your name removed from them.
- Clear local storage in your browser to remove your theme and vote history from your device.
Where the place names come from
The country, state/province and city suggestions on your profile come from GeoNames, used under the Creative Commons Attribution 4.0 licence. The list is stored on Meliya's own server, so searching it and matching a detected position against it involve no request to GeoNames or to anyone else.
Children and families
Meliya is a learning app for children, and it is designed to be set up and overseen by a responsible adult — a parent, guardian, caregiver or teacher.
Signing up. You must be at least 13 to create your own account. We ask for your date of birth when you register, and we do not create an account for anyone who tells us they are under 13 — instead we ask them to have a parent or teacher add them as a learner.
Younger learners. A child under 13 does not sign up on their own. A responsible adult adds the child as a learner on the adult's own account, confirms they are that child's parent, guardian or teacher, and consents on the child's behalf. For a learner managed this way we keep as little as possible — a first name or nickname, and an approximate age so lessons are age-appropriate — and the child has no separate login, password or email of their own.
Your control. The responsible adult can review a learner's information and ask us to delete it at any time (see Contact). Removing a child deletes their learning profile and all of its data. If you believe a child under 13 has created an account without a parent or teacher, contact us and we will remove it.
Consent is recorded. When a parent, guardian or teacher adds a child, they confirm their relationship and consent, and we store that confirmation with the date — so there is always a record of who authorised a child's participation. A 13–17 learner who holds their own account must put a parent or guardian's email on file.
How we keep children safe
Meliya is built so that everything a child sees is checked, nothing about them is sold or used to target them, and a responsible adult is always in the loop.
- Every piece of learning content is screened. Lessons, quizzes and the companion's messages that AI helps produce pass an automated child-safety check that is fail-closed — anything not clearly safe and age-appropriate is withheld rather than shown. AI content is generated on Meliya's own private hardware, never sent to a third-party AI provider, and is additionally reviewed by our moderation pipeline (and, where needed, by a person) before it reaches a learner.
- No ads, no tracking, no profiling of children. There is no advertising, no third-party analytics, and no behavioural or advertising profile — for anyone, and never for a child. A child's data is used only to run their lessons and show their own progress.
- Data minimisation for a child. A parent-managed child has only a first name or nickname and an approximate age — no email, password or login of their own. We collect nothing about a child beyond what their learning needs.
- A responsible adult oversees them. Parents, guardians and teachers can follow a child's activity and progress. Encouragement notes are one-way (adult → child); a child cannot exchange free-text messages with strangers, and open child-to-child messaging is not part of the app.
- Teachers act under their own responsibility. A teacher adds students to a class under a recorded attestation, can see each student's progress (never their answers), and can post one-way announcements. Teachers cannot see or touch any class or student that is not their own.
- Anyone can report content, and we act on it. Community-shared courses and other user content can be reported with one tap; reports go to a moderation queue, and content found to be unsafe is hidden and removed. Community courses are also gated by the same fail-closed safety check before they are ever shown.
- You are in control. A responsible adult can review or delete a child's data at any time (see Contact).
Changes
If this policy changes materially, the date above changes, and we ask you to review and accept the updated policy the next time you use your account.
Contact
For any privacy request, including access or deletion, contact [email protected].