1. Who we are and how to reach us
Medori is a reminder app for utility bills and other recurring deadlines. This policy explains what it does with your data.
Medori is developed and operated independently, based in Ukraine.
For anything privacy-related — a question, a request, a complaint — write to support@medori.app.
2. What data we collect
Account data
The email address and user ID that Apple or Google give us when you sign in. That's it. Medori never collects or stores a password, because it never asks you for one.
Reminder content
Whatever you enter into your reminders: titles, categories, schedules (open and close dates, repeat interval), notes, links, expected amounts, meter readings, payment amounts, and your completion history.
If you attach a photo to a reminder, the photo itself stays on your device. Only a reference to the local file is stored and synced — the image is never uploaded.
Preferences
Only one preference leaves your device: your currency choice, which is stored on our servers alongside your profile so it follows you between devices.
Your language, theme, notification lead time, and quiet-hours settings are stored locally on your device only. They are never sent to Medori's servers.
Technical and device data
A push-notification token, so our servers can ask Apple or Google to deliver a reminder to your device at the right moment.
Standard request metadata — your IP address and a timestamp — generated whenever your device talks to Medori's servers, as with any internet service.
There is no advertising SDK, no analytics SDK, and no third-party tracker anywhere in the app.
3. Why we collect it, and the legal basis
- Performing our contract with you. Your reminder content, your account identity, and your push token exist so Medori can do the one thing you installed it for: hold your reminders and tell you about them on time.
- Legitimate interest. Technical and device data — request metadata — keeps the service reliable and secure, and lets us investigate abuse or failures.
- Consent. Notification delivery, where your device's own settings require you to grant permission. You can withdraw it at any time in your device settings, and Medori will stop sending notifications.
4. Where it's stored and who processes it
Your data lives first and foremost on your own device, in a local SQLite database. That is always true, whether or not you are signed in — Medori works offline by design.
If you are signed in, your content also syncs to a Supabase (PostgreSQL) database. Those rows are protected by row-level security, which means the database itself enforces that only your account can read your rows.
These are the only third parties involved, and each one has a defined role. Each name links to that company's own privacy policy:
- Supabase — hosts the database and the authentication service.
- Expo — delivers push notifications.
- Apple and Google — sign-in, push delivery (Apple), and in-app purchases.
- RevenueCat — tracks subscription status. RevenueCat receives a pseudonymous identifier tied to your Medori account, together with the receipt and product identifier that Apple or Google issue for each purchase — that is how it knows which plan you bought and whether it is still active.
Medori never sees or stores your card details. Apple and Google handle the payment directly, and Medori has no access to that data.
5. How long we keep it
We keep your data for as long as your account exists.
When you delete your account, it is immediately marked for deletion and stops being used to send you reminders. Thirty days later it is permanently and irreversibly erased — your account and all of its data.
If you sign back in during those 30 days, everything is restored. After that window closes, the data is gone and cannot be recovered.
6. Your rights (GDPR)
If the GDPR applies to you, you have the right to:
- access the personal data we hold about you;
- rectify it if it's wrong;
- erase it;
- port it — receive it in a portable form;
- restrict how we process it;
- object to processing based on legitimate interest;
- complain to your local supervisory authority.
Most of this you can do yourself, in the app's Settings — deleting your account erases everything, and your reminder data is on your device already. For anything else, write to support@medori.app.
7. Children
Medori is not directed at anyone under 16, and is not knowingly used by anyone under 16.
8. Security
Everything your device sends to our servers travels over TLS. On the server side, Supabase row-level security enforces that your rows are readable only by your account.
You can also turn on a device-level biometric lock — Face ID or your fingerprint — from within Medori, which adds a layer of local protection if someone else picks up your unlocked phone. It's optional and off until you enable it.
9. International transfers
Your data is stored on Supabase's EU-hosted infrastructure. Some of the processors we use — including RevenueCat, Apple, and Google — may process data outside the European Economic Area, and Medori itself is operated from Ukraine, outside the EEA.
Where that happens, we rely on the safeguards those processors provide — including their own Standard Contractual Clauses and Data Processing Agreements — to keep your data protected to a standard equivalent to the GDPR.
10. Changes to this policy
When this policy changes, the "last updated" date at the top of this page changes with it. For anything material, we'll also surface the change in the app rather than relying on you to re-read this page.