Draft for legal review. Not yet in effect. Last updated: September 28, 2026.
meibo (meibo.io) is a private directory for schools and clubs, run by Fennec Studio LLC ("we", "us"). This policy explains what information meibo holds, who can see it, who else handles it, and how long we keep it.
1. Who decides what
Each directory belongs to its owner: usually a parent-teacher group, a school office or a club's organiser. The owner decides who can see the directory and who can add entries to it, and approves entries before they are listed. For what a directory holds, we act for its owner. We store it and show it to the people the owner allows, and we do not use it for anything else.
For your meibo account, and for the logs our service keeps, we decide how the information is used, and this policy describes all of it.
2. What we hold
Your account
When you sign in we keep your email address and the identifier Firebase Authentication gives your sign-in. You can sign in with Google, with Apple, or with a link sent to your email address.
Directory entries
An entry holds what you, or the directory's owner, put in it.
A family entry can include parents' names, email addresses, phone numbers, home addresses and photos, and children's names, teachers and photos.
A staff entry can include a name, title, email address, phone number, a short description, links and a photo.
We also record who created each entry, who may edit it, and any report someone makes about it.
Directory settings
A directory's name, web address and logo, the email addresses or domains its owner lets in, and how many invitations the owner has sent and when. If an owner invites you, we use your email address to send the invitation, and our server logs record that it was sent to you. A directory's name and logo are not private: the logo is stored as a public image.
Billing
If a directory's owner pays for a plan, Stripe handles the payment. We receive the plan, whether it is paid up, and Stripe's references to them. We never receive or store a card number.
Technical logs
Our network edge, firewall and servers see your IP address, your browser's details and the requests you make, as any website's do. Our firewall uses your IP address to limit abusive traffic, and our server logs record request details. Our application's own event log records identifiers, such as which directory or entry a request touched, rather than what an entry says.
3. Who can see a directory
Signing in is required. No directory, entry or photo is shown to anyone who is not signed in.
The owner decides the rest: who may view the directory, and whether new entries wait for approval. A new directory can be viewed only by people its owner approves, and holds new entries for its owner to approve.
Photos are private. They are kept in private storage and shown only through links that expire within two hours, issued to people allowed to view the directory.
Our staff. Only our administrators can reach directory contents in our admin tools. They look at them only to run, secure or support the service, or when the law requires it.
4. Who else handles information
We use these service providers, and share with each only what it needs to do its part:
Amazon Web Services runs our servers, our database (Amazon RDS) and our file and photo storage (Amazon S3), and sends our email (Amazon SES), all in the us-west-2 (Oregon) region. Its network edge and firewall (Amazon CloudFront and AWS WAF) serve the website.
Google Firebase Authentication handles sign-in.
Google reCAPTCHA protects email-link sign-in from abuse.
Stripe takes payments from owners on a paid plan.
The Google Gemini API is used only for directories with AI approval, a paid-plan feature. New entries, and edits that send a published entry back for review, are sent to Gemini to be checked before they reach the owner: their names, photos, staff titles, descriptions and links, children's teachers, and the domain of each email address. Phone numbers, home addresses, whole email addresses and other families' entries are never sent. We use a paid Gemini API project, whose terms do not let Google use that content to improve its products.
We do not sell personal information, and we do not use directory contents for advertising.
5. Cookies and browser storage
meibo sets no cookies of its own, runs no analytics or advertising tags, and does not track page views or where visitors came from. That is why there is no cookie banner.
Firebase Authentication keeps you signed in using your browser's storage.
While you sign in with an email link, we keep your address and the page to return to in your browser's storage.
Google reCAPTCHA, used on email-link sign-in, may set Google's own cookie.
6. How long we keep things
Entries are kept until their author or the directory's owner deletes them. Deleting an entry removes it at once. Its photos can no longer be viewed, but stay in private storage until the directory itself is deleted.
Directories are kept until their owner asks us to delete them. Deleting a directory removes its entries, settings and photos.
Accounts are kept until you ask us to delete yours. We keep billing records for as long as tax law requires, which can be up to seven years.
Server logs are deleted after about two weeks. Our application's event log, which holds identifiers rather than entry contents, is kept.
Backups of our database are kept for [backup retention period — to confirm], so something you delete can remain in a backup until then.
7. Your choices and rights
You can edit or delete an entry you created from the directory itself. For anything else in a directory, ask its owner, who decides what it holds. You can also ask us for a copy of the information we hold about you, to correct it, or to delete your account, by writing to the address below.
8. Children
meibo accounts are for adults. Entries about children, meaning their names, teachers and photos, are added by a parent or guardian or by the school or club, and are seen only by people the directory's owner allows. We do not knowingly let anyone under 18 create an account.
9. Changes
We will post changes to this policy on this page and update the date at the top. If a change affects how directory contents are used, we will email directory owners before it takes effect.
10. Contact
Fennec Studio LLC, support@fennec.studio