MeeFins Brand Logo
MEE-FINS
Back to DashboardLast Updated: August 26, 2026
GDPR & Privacy Statement

Privacy Policy & GDPR Compliance

Learn how MeeFins protects your privacy, operates on a secure remote server, and guarantees your rights under the General Data Protection Regulation (GDPR).

Our Core Privacy & Security Guarantees

Secure Remote Server

Hosted on firewall-protected remote servers with TLS/SSL encryption and HTTP-only cookie tokens.

Full GDPR Compliance

Complete support for data access, rectification, erasure, portability, and restriction under EU GDPR law.

Zero Commercial Sale

Your data is strictly processed for language exchange sessions and never sold to third parties.

1

Secure Remote Server Hosting & Infrastructure

MeeFins services, databases, and authentication endpoints are hosted on a secure remote server infrastructure equipped with enterprise-grade security standards:

  • End-to-End Transport Encryption: All data in transit between your browser and our secure remote servers is encrypted using standard TLS/SSL (HTTPS) protocols.
  • Protected Remote Storage: User accounts, hashed credentials, slot bookings, and custom vocabulary decks are stored on hardened, firewall-protected remote server environments.
  • Secure WebRTC Rooms: 1-on-1 video and audio practice sessions run on dedicated, isolated LiveKit media servers without persistent video cloud recording.
2

General Data Protection Regulation (GDPR) Compliance

MeeFins fully adheres to the European Union General Data Protection Regulation (GDPR). We process personal data strictly under lawful bases (Article 6 GDPR) for contract performance to deliver peer-to-peer language exchange services.

  • Lawful Basis & Purpose Limitation: Data is collected exclusively to authenticate users, manage language exchange slots, connect LiveKit rooms, and store study flashcards.
  • Data Minimization: We store only the minimum essential information required to operate your account and study tools.
  • No Commercial Exploitation: Personal data is never sold, leased, or monetized for advertising or tracking purposes.
3

Your GDPR Data Subject Rights

Under GDPR, as a data subject, you possess the following explicit rights regarding your personal information processed on MeeFins:

  • Right of Access (Article 15 GDPR): The right to request confirmation of whether your personal data is being processed and to receive a copy of your account profile, scheduled slots, and flashcards.
  • Right to Rectification (Article 16 GDPR): The right to update or correct inaccurate or incomplete profile information (such as display name, avatar URL, or timezone).
  • Right to Erasure / Right to be Forgotten (Article 17 GDPR): The right to request permanent deletion of your account, meeting logs, ratings, and custom vocabulary collections.
  • Right to Restriction of Processing (Article 18 GDPR): The right to request temporary restriction of your data processing under specific dispute circumstances.
  • Right to Data Portability (Article 20 GDPR): The right to receive an export of your created vocabulary decks and account activity in a structured, machine-readable format.
  • Right to Object (Article 21 GDPR): The right to object to data processing activities based on legitimate interests.
4

Information We Collect

We collect only the essential categories of personal information needed for platform operations:

  • Account Data: Email address, display name, profile picture URL, timezone setting, and encrypted password hash (or GitHub OAuth identifier).
  • Learning & Practice Data: Custom vocabulary collections, word lists, scheduled 1-on-1 language exchange slot records, meeting history, and partner ratings.
  • Technical Session Data: Ephemeral LiveKit room credentials and secure HTTP-only JWT cookies (access_token and refresh_token).
5

Cookies & Session Security

MeeFins uses secure HTTP-only cookies to manage authentication tokens (access_token and refresh_token). HTTP-only cookies cannot be accessed via browser JavaScript, safeguarding your session against Cross-Site Scripting (XSS) attacks. Cookies automatically expire upon session timeout or logout.

6

Third-Party Service Providers

We engage trusted third-party technology providers strictly to fulfill operational features:

  • LiveKit Media Server: Handles real-time WebRTC audio and video streaming during language exchange meetings without cloud stream recording.
  • GitHub OAuth: Provides optional single sign-on authentication when logging in with your GitHub account.
7

GDPR Data Controller & Contact Information

If you wish to exercise any of your GDPR rights, request data export or account deletion, or ask privacy questions, please contact our Data Controller at:

Need to review our Terms & Conditions?Read Terms & Conditions