Privacy policy
Last updated: 29 September 2026
Mekomi ("we", "us") is a tool for managing the Google Business Profiles of local businesses: reading their reviews, drafting replies and publishing the replies that are approved. This policy explains what data Mekomi handles, why, and how you can have it removed.
Data we collect
- Your Mekomi account: your email address and a password, which is stored only as a secure hash.
- Your Google account, when you connect it: your Google email address, and an access token that lets Mekomi act on the Business Profiles you manage. The token is encrypted before it is stored.
- Business Profile data: for the profiles you choose to import, their name, category and location, and their reviews (reviewer name, rating, review text and dates) and any replies.
- Your settings and activity: reply drafts, example replies you save, auto-reply settings, and a log of actions taken in the app.
How we use it
We use this data only to provide Mekomi's features to you:
- showing your profiles' reviews in one inbox;
- classifying reviews and drafting replies in your business's voice;
- publishing replies you approve, or that match auto-reply rules you switch on.
We do not sell your data, use it for advertising, or use it to train AI models.
Google user data
Mekomi requests access to your Google account's email address and to manage your Business Profiles (the business.manage permission). We use that access only to read your profiles and reviews and to post replies on your behalf.
Mekomi's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Service providers
We share data only with the providers that run Mekomi, and only what each one needs:
- Supabase (database and login), hosted in Frankfurt, Germany.
- Vercel (web hosting).
- OpenAI (AI drafting): review text, rating, reviewer name, business name and your example replies are sent to draft and classify replies. We ask OpenAI not to store these requests.
- Inngest (scheduled jobs): receives only internal IDs and times, never review text.
We may also disclose data if the law requires it.
Security
Data is sent over encrypted connections, Google access tokens are encrypted at rest, and the database is not reachable through any public API.
Keeping and deleting data
We keep your data while your account is active. You can remove Mekomi's access to your Google account at any time at myaccount.google.com/permissions. To have your account and all its data deleted, email aviranaharoni4@gmail.com and we will delete it within 30 days.
Changes
If we change this policy, we will update the date at the top of this page.
Contact
Questions about privacy: aviranaharoni4@gmail.com.