Privacy Policy

Meliya — meliya.org. Last updated 9 August 2026.

Meliya is a learning app for children and families, with polls and quizzes alongside the lessons. This policy describes exactly what the running service stores, why, and how to have it removed. It describes the software as built, not an intention.

Our promise

We do not sell, rent, or share your personal information, and we never use it for anything other than running Meliya and delivering the features you use — your account, your learning, and keeping the app safe. There is no advertising, no third-party ad tracking, and no analytics brokers. We do not build advertising or behavioural profiles of anyone, and we especially never do so for children. Your content is never used to train AI models. We collect the minimum we need, and you can ask for a copy of it or have it deleted at any time (see Contact).

You agree to this policy when you create or sign in to a Meliya account, and we ask you to accept it before you can use an account. You can read it here at any time, and if it changes materially we ask you to review and accept it again.

You can use Meliya without an account

Browsing polls and voting require no account and no sign-in. If you never sign in, we never learn your name or email address.

What is collected

DataWhenWhy
Email address, display name, profile picture, and an account identifier from whichever of Google, Facebook or X you use Only if you sign in with that provider To create your account, show who you are, and decide what you are allowed to do. You can sign in with more than one of these at once — see "Linked accounts" below
Email address and a securely hashed password Only if you create an account with an email and password instead To let you sign in without a third-party provider. The password itself is never stored — only a one-way cryptographic hash that cannot be reversed back into it. A verification link is emailed to confirm you own the address before the account can be used
Your votes and the polls you create When you vote or post To count results and show them back to everyone
A one-way hash of your IP address and browser user-agent When you vote To limit repeat voting and abuse. The hash is salted and your actual IP address is not stored alongside it. If your profile does not already supply a country, your IP address is separately used, live and only for that moment, to resolve an approximate country for the anonymous aggregate statistics below — the address itself is still never stored, only the resulting country
Sign-in session cookie Only if you sign in To keep you signed in. It is HTTP-only, so page scripts cannot read it
Your theme choice and which polls you have voted on As you use the app Stored in your browser's local storage, on your device. It is not sent to the server
First and last name, on your profile Only if you choose to add them, from "Edit profile" Optional, and shown only to you — never to anyone else, and never used in the anonymous aggregate statistics described below
Gender, country, state/province, city, and birth year/month, on your profile Only if you choose to add them, from "Edit profile" Every field is optional and can be cleared at any time. Gender, country, and birth year/month are also used, in coarsened form, to compute the anonymous aggregate statistics described in "Anonymous aggregate statistics" below. State/province and city are shown only to you and are not currently used in those statistics
A photo you choose to upload as your profile picture Only if you upload one, from "Edit profile" (currently limited to staff and trusted accounts while this is new — see below) Stripped of any location or camera data it carried (EXIF, including GPS) and resized before it is ever stored. It is checked by an automated safety model before it is shown to anyone; anything the model is not clearly confident about is held for a person to review first rather than published or rejected automatically. You can switch away from it, or back to your sign-in provider's picture, at any time from "Edit profile"
Your device's approximate position, momentarily Only if you press “Detect” on your profile, and only if you then allow your browser's location prompt To suggest your country, state/province and city so you do not have to type them. The coordinates are sent to Meliya's own server, matched against a list of place names that Meliya holds itself, and discarded — they are never written to the database, never sent to any other company, and no mapping or geocoding service is involved. The suggestion appears in the three ordinary fields on the form, and nothing is saved unless you press Save. If you never press “Detect”, none of this happens

If you sign in with Google, Facebook or X, we request only your basic profile and email address (X does not provide an email address at all, even if you grant one — that is a limit of X's own sign-in system, not a choice of ours). Meliya never receives your password on any of these services, and asks for no access to Gmail, Drive, Contacts, your Facebook friends, or your X posts and follows.

Anonymous aggregate statistics

Meliya shows how different groups voted on a poll — for example, whether one age group leaned a different way than another. This section describes exactly how it works.

What is not collected

Content generated by AI

Many polls on Meliya are generated by AI models running on private hardware, and are labelled “AI made this” so you can tell them apart from polls written by people. Polls submitted by people are checked by an automated moderation model before publication, and may be reviewed by a person. Your content is not used to train any AI model.

Where the data lives

Meliya runs on privately-operated hardware in Canada, reached through Cloudflare, which routes traffic and sees the usual connection metadata. AI models run locally on that same private hardware; poll content is not sent to any third-party AI provider.

How long it is kept

Your choices

Where the place names come from

The country, state/province and city suggestions on your profile come from GeoNames, used under the Creative Commons Attribution 4.0 licence. The list is stored on Meliya's own server, so searching it and matching a detected position against it involve no request to GeoNames or to anyone else.

Children and families

Meliya is a learning app for children, and it is designed to be set up and overseen by a responsible adult — a parent, guardian, caregiver or teacher.

Signing up. You must be at least 13 to create your own account. We ask for your date of birth when you register, and we do not create an account for anyone who tells us they are under 13 — instead we ask them to have a parent or teacher add them as a learner.

Younger learners. A child under 13 does not sign up on their own. A responsible adult adds the child as a learner on the adult's own account, confirms they are that child's parent, guardian or teacher, and consents on the child's behalf. For a learner managed this way we keep as little as possible — a first name or nickname, and an approximate age so lessons are age-appropriate — and the child has no separate login, password or email of their own.

Your control. The responsible adult can review a learner's information and ask us to delete it at any time (see Contact). Removing a child deletes their learning profile and all of its data. If you believe a child under 13 has created an account without a parent or teacher, contact us and we will remove it.

Consent is recorded. When a parent, guardian or teacher adds a child, they confirm their relationship and consent, and we store that confirmation with the date — so there is always a record of who authorised a child's participation. A 13–17 learner who holds their own account must put a parent or guardian's email on file.

How we keep children safe

Meliya is built so that everything a child sees is checked, nothing about them is sold or used to target them, and a responsible adult is always in the loop.

Changes

If this policy changes materially, the date above changes, and we ask you to review and accept the updated policy the next time you use your account.

Contact

For any privacy request, including access or deletion, contact [email protected].