Privacy policy

Last updated on October 4, 2026

Introduction

Meelio is a local-first new tab page for focus. It works without an account: your tasks, notes, settings and everything else stay in your browser. Some features you can choose to turn on, such as sync, connected apps and the AI assistant, send data to our servers or to another service. This policy explains what each one sends, why, and how to stop it.

Who we are

Meelio is built by Zain Zafar . Questions about this policy go to support@meelio.io.

What stays on your device

Without an account, your tasks, notes, habits, settings, sounds and other workspace data are kept only in your browser's storage. We do not receive them. Clearing your browser data or uninstalling the extension deletes them.

Your account

You can create an account with an email and password, or sign in with Google. We keep your email address, your name and, if you sign in with Google, your profile photo. When you sign in with Google we only ask for your basic profile and email. We do not keep the tokens Google sends at sign-in. You stay signed in for up to a year so the app keeps working offline, until you sign out.

Sync

When you are signed in, your tasks, notes, settings and other workspace data are copied to our servers so they appear in each browser you use. They are stored in the European Union. Nightly backups are kept for 30 days and then deleted.

Google Calendar and Google Tasks

Connecting Google Calendar or Google Tasks is optional. You connect them in Settings, and Google asks for your permission first.

  1. What we access: with Google Calendar, read-only access to the events on your primary calendar. With Google Tasks, your task lists and the tasks in them.
  2. How we use it: to show your next events and today's agenda on your new tab, and to show your Google Tasks inside Meelio's Tasks app, where you can add a task and mark a task complete. Meelio never changes or deletes calendar events, and never deletes tasks or task lists.
  3. How it is stored: the access and refresh tokens Google gives us are stored encrypted on our servers. Events and tasks are fetched from Google when you open Meelio and are kept only in your browser. We do not store them on our servers.
  4. How it is protected: the access and refresh tokens are encrypted with AES-256-GCM before it is saved, and the encryption key is kept apart from the database, in our server settings. All data between your browser, our servers and Google travels over HTTPS. Events and tasks pass through our servers only to reach your browser and are not saved. Disconnecting deletes the tokens.
  5. Sharing: we do not sell this data, use it for advertising, or use it to train AI models. We do not send it to the AI assistant. No one at Meelio reads it, except when you ask us to for support, for security reasons, or when the law requires it. The only other companies that handle this data are our hosting and database providers, which store the encrypted tokens for us. We share it with no one else.
  6. Removing access: choose Disconnect in Settings, which deletes the stored tokens from our servers. You can also remove Meelio at myaccount.google.com/permissions .

Meelio's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy , including the Limited Use requirements.

Other connected apps

Todoist, Asana, ClickUp and GitHub work the same way: optional, connected in Settings, with the access token stored encrypted on our servers and deleted when you disconnect. We fetch your tasks or issues only to show them in Meelio.

AI assistant

When you ask the AI assistant something, we send your question to our AI provider, together with a short summary so the answer can use it: the titles and due dates of your open Meelio tasks, your note titles, and how long you focused today. When you use AI in a note, the text you selected is sent. Nothing is sent until you ask. Our AI provider may process this outside the European Union. It may not use it to train AI models, and keeps it only as long as needed to answer and to prevent abuse. Data from Google Calendar and Google Tasks is never sent.

You can also let your own AI assistant, such as Claude, read and manage your Meelio tasks by creating a token in Settings. We store only a scrambled copy of each token, and you can delete a token at any time.

Weather

To show the weather, we estimate your city from your IP address, or use the place you choose. We send those coordinates to Open-Meteo to get the forecast. We do not store your location. We keep recent forecasts for about a kilometre around a point for a short time, not linked to you, so nearby requests are faster.

Payments

Meelio Pro is sold through Lemon Squeezy, which handles your payment details. We never see your card. We receive your email and the status of your plan so we can turn Pro on.

Crash reports and usage

The app sends crash reports so we can fix bugs, with notes, tasks and personal details removed. It also sends usage counts, such as which apps are opened, never their content. You can turn off both in Settings, under Data & Privacy.

Extension permissions

  1. Storage: to keep your data in your browser.
  2. Tabs: to save and reopen tabs with Tab Stash.
  3. Declarative Net Request: to block the sites you choose in Site Blocker.
  4. Alarms and offscreen: to run the focus timer and play sounds when the new tab is closed.
  5. Optional: bookmarks, top sites, tab groups and notifications are requested only when you turn on a feature that needs them.

The meelio.io website

This website uses Google Analytics to understand traffic. This can include the page visited, where you came from, browser and device details, and approximate location. Google handles this data under its own privacy policy. You can block it with your browser settings or a content blocker. The Meelio app itself does not use Google Analytics.

Deleting your data

Disconnect any connected app in Settings. Sign out and clear your browser data, or uninstall the extension, to remove data from your device. To delete your account and everything on our servers, email support@meelio.io from your account's email address. We delete it within 30 days, and it leaves our backups within a further 30 days.

Changes to this policy

We post any change on this page and update the date at the top. Significant changes are also announced in the app.

Contact

Questions about this policy go to support@meelio.io.