Privacy Policy
Effective date: 05/07/2026
This Privacy Policy explains who we are, what personal data we collect, why and how we use it, who we share it with, how long we keep it, and the rights you have. It is written to meet the requirements of the EU General Data Protection Regulation (GDPR) and applicable Swedish data-protection law, and forms part of, and should be read together with, our Terms of Service.
1. Who We Are (Data Controller)
Meplio is operated by STRUKT AB, a company registered in Sweden (org. no. 559389-8686), with its registered address at Ärvingevägen 14, Stockholm, Sweden. For the personal data we process to operate the Platform for our own users, we act as the data controller.
For any privacy question or to exercise your rights, contact us at gabriel@meplio.com or at the postal address above.
2. Our Role, and the Role of Creators
The Platform involves two kinds of processing, and the distinction matters because it determines who is responsible for what:
- Platform data — we are the controller. For the personal data we process to run the Platform — accounts, billing and payouts, security, communications, and analytics — we determine the purposes and means of processing and are the controller. This Policy describes that processing.
- Community data — the Creator is responsible. When a Creator uses the Platform to operate their own Community, the Creator decides how they engage with their Members and what they do with information about them — for example, communicating with Members, moderating, and running their community. In respect of that activity, the Creator acts as a controller (or joint controller) for their own purposes, and is responsible for their own compliance with data-protection law, including informing their Members and honouring their rights. This Policy does not describe how individual Creators use data within their Communities; for that, refer to the relevant Creator. Where the law requires a data-processing agreement between us and a Creator in respect of processing we carry out on their behalf, we will put one in place.
3. Personal Data We Collect
3.1 Information you provide
- Account information: name or username, email address, password (stored only in hashed form), and profile details such as an avatar, bio, or links you choose to add;
- Creator and payment-related information: information needed to set up payments and payouts. Much of this (including identity and bank or card details) is collected and processed directly by our Payment Processor; we receive limited related information such as account and verification status and the identifiers needed to operate the service;
- Content you submit: posts, comments, chat messages, uploads, course activity, event participation, and other Content you create on the Platform;
- Communications: messages you send us (for example, support requests) and your preferences;
3.2 Information we collect automatically
- Usage data: how you interact with the Platform, such as pages viewed, features used, and actions taken;
- Device and technical data: IP address, browser and device type, operating system, and similar technical identifiers;
- Cookies and similar technologies, as described in Section 9;
3.3 Information from third parties
- From our Payment Processor: payment, payout, verification-status, and dispute-related information necessary to operate the Platform;
- From infrastructure and security providers: information used to keep the Platform secure and available;
3.4 Special-category and children’s data
We do not seek to collect special categories of personal data (such as data revealing health, religion, or political opinions). Please do not submit such data unless necessary, and be aware that Content you choose to post may reveal it. The Platform is not directed to children under the minimum age stated in our Terms, and we do not knowingly collect personal data from anyone below that age.
4. How and Why We Use Your Data (Lawful Bases)
Under the GDPR we must have a lawful basis for each use of your personal data. We rely on the following:
4.1 To provide the Platform — performance of a contract
We process account, profile, Content, and transaction data to create and manage your account, operate Communities, process payments and payouts, and provide the features you use. The lawful basis is performance of our contract with you (our Terms), or taking steps at your request before entering into it.
4.2 To process payments — contract and legal obligation
We process payment-related data to take payments, settle funds to Creators, calculate fees, handle refunds and chargebacks, and keep required financial records. The lawful basis is performance of our contract and compliance with our legal obligations (including accounting and anti-money-laundering law).
4.3 To secure and improve the Platform — legitimate interests
We process usage, device, and technical data to keep the Platform secure, prevent and investigate fraud and abuse, debug and improve our services, and understand how the Platform is used. The lawful basis is our legitimate interests in operating a secure, reliable, and improving service, balanced against your rights.
4.4 To communicate with you — contract, legitimate interests, or consent
We use your contact details to send service and transactional messages (such as receipts, security alerts, and important notices), relying on contract or legitimate interests. Where we send optional marketing messages, we do so only where permitted, and where consent is required we obtain it; you can withdraw consent or unsubscribe at any time.
4.5 To comply with law — legal obligation
We process data as needed to comply with legal obligations, respond to lawful requests, and establish, exercise, or defend legal claims.
4.6 Withdrawing consent
Where we rely on consent, you may withdraw it at any time. Withdrawing consent does not affect processing carried out before withdrawal, or processing under a different lawful basis.
5. Who We Share Your Data With
We do not sell your personal data. We share it only as described here:
5.1 Service providers (processors)
We use trusted third parties to provide the Platform, who process personal data on our behalf under appropriate agreements, including:
- Payment Processor — Stripe (including Stripe Payments Europe, Ltd.), for payments, payouts, identity verification, and fraud prevention;
- Hosting and infrastructure — our cloud hosting and content-delivery provider (such as Cloudflare), for serving and securing the Platform;
- Database and storage — our database and file-storage provider (such as Supabase), for storing account and Content data;
- Other providers — for example, email delivery, analytics, and customer-support tools, where used.
5.2 Other Users
Information you choose to make visible (such as your profile and the Content you post in a Community) is shared with other Users according to the settings and nature of that Community. Where a Creator showcases Content on a public page or custom domain, it may be visible to anyone, including Visitors who are not logged in.
5.3 Creators
If you are a Member, the Creator whose Community you join receives information necessary for them to operate their Community and their relationship with you (such as your membership status and the Content you contribute). The Creator’s own use of that information is their responsibility, as described in Section 2.
5.4 Legal, safety, and corporate transactions
We may disclose personal data where necessary to comply with law or a lawful request, to enforce our Terms, to protect the rights, safety, or property of the Company, Users, or others, or in connection with a merger, acquisition, financing, or sale of assets (subject to appropriate confidentiality).
6. International Data Transfers
Some of our service providers may process personal data outside the European Economic Area (EEA). Where we transfer personal data outside the EEA, we rely on an appropriate safeguard recognised under the GDPR, such as an adequacy decision of the European Commission or the European Commission’s Standard Contractual Clauses, together with any additional measures required. You can ask us for more information about the safeguards we use by contacting us at gabriel@meplio.com.
7. How Long We Keep Your Data, and What Happens When You Leave or Delete
We keep personal data only for as long as necessary for the purposes described in this Policy, and then delete or irreversibly anonymise it. Because the Platform handles payments, some records must be kept for longer periods required by law even after you stop using the service.
7.1 Leaving a Community is different from deleting your account
These are two different things, with two different outcomes for your data:
- If your membership or subscription ends (you cancel, a Creator removes you, or a Community closes) but you do not delete your account, you lose access to that Community, but the Content you contributed there (such as posts, comments, and messages) generally remains in the Community, attributed to you, so that conversations stay intact. Your subscription ending does not by itself anonymise or remove your Content.
- If you delete your account, or exercise your right of erasure, we anonymise your identifying information: for example, we replace your email address with a non-identifying placeholder, replace your display name with a generic label (such as “Deleted User”), reset your avatar to a default, and remove free-text profile fields such as your bio. Content you posted may remain in the relevant Community in this de-identified form, to preserve the integrity of conversations, unless we are required to remove it.
7.2 What we retain, and for how long
- Account and profile data: for as long as your account is active, and for a reasonable period afterwards to handle wind-down, disputes, and legal obligations, after which it is deleted or anonymised as described above;
- Transaction and financial records: retained for the periods required by applicable accounting, tax, and anti-money-laundering law (which for financial records in Sweden is generally several years, and for certain records longer). These records are kept even after account deletion, in de-identified form where possible, because we are legally required to keep them — which the GDPR permits as an exception to erasure;
- Moderation and safety records: retained where necessary to keep the Platform safe, to enforce our Terms, and to establish, exercise, or defend legal claims, in de-identified form where possible;
- Security and log data: retained for a limited period appropriate to security and fraud-prevention purposes.
When we no longer need personal data and are not required to keep it, we delete it or irreversibly anonymise it, subject to backups that are overwritten in the ordinary course.
8. Your Rights
Subject to the conditions and exceptions in applicable law, you have the following rights over your personal data:
- Access — to obtain confirmation of, and a copy of, the personal data we hold about you;
- Rectification — to have inaccurate data corrected and incomplete data completed;
- Erasure — to have your personal data deleted in certain circumstances (“right to be forgotten”), subject to records we are legally required to keep (see Section 7);
- Restriction — to restrict our processing in certain circumstances;
- Portability — to receive certain data in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible;
- Objection — to object to processing based on legitimate interests, and to object at any time to processing for direct marketing;
- Withdraw consent — where processing is based on consent, to withdraw it at any time;
- Not be subject to solely automated decisions — with legal or similarly significant effects, except as permitted by law.
To exercise any of these rights, contact us at gabriel@meplio.com. We may need to verify your identity. We will respond within the time required by law (generally one month, extendable where permitted). Many rights can also be exercised directly through your account settings, including updating your profile and requesting deletion of your account. Where you are a Member and your request concerns how a Creator uses your data within their Community, you may also need to contact that Creator (see Section 2).
8.1 Right to complain
If you are unhappy with how we handle your personal data, you may lodge a complaint with your local supervisory authority. In Sweden, this is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), www.imy.se. You may also contact the supervisory authority in your country of residence or work.
9. Cookies and Similar Technologies
We use cookies and similar technologies to operate the Platform (for example, to keep you logged in and to keep the service secure), and, where you consent, for analytics or other non-essential purposes. Strictly necessary cookies do not require consent; other cookies are used only with your consent where required. You can manage non-essential cookies through our cookie controls (where provided) and through your browser settings. Disabling some cookies may affect how the Platform works.
For more detail on the specific cookies we use, see our Cookie Notice at [link to cookie notice, if separate], or contact us.
10. How We Protect Your Data
We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, or alteration. These include access controls, encryption in transit, generating short-lived access links for private files rather than long-lived ones, limiting who can access data, and relying on reputable infrastructure and payment providers. No system is completely secure, and we cannot guarantee absolute security. If a personal-data breach is likely to result in a risk to your rights, we will notify the relevant supervisory authority, and affected individuals, as required by law.
11. Third-Party Links and Services
The Platform and Communities may contain links to third-party websites and services, and rely on third-party providers with their own privacy practices. We are not responsible for the privacy practices of third parties, and we encourage you to review their policies.
12. Changes to This Policy
We may update this Privacy Policy from time to time. If we make a material change, we will provide reasonable notice, for example by posting the updated Policy with a new effective date or by other appropriate means. Your continued use of the Platform after the change takes effect indicates your awareness of the updated Policy, to the extent permitted by law.
13. How to Contact Us
Controller: STRUKT AB
Organisation number: 559389-8686
Registered address: Ärvingevägen 14, Stockholm, Sweden
Privacy contact: gabriel@meplio.com
General support: gabriel@meplio.com
Website: www.Meplio.com