Legal & policies

M3XI policies.

Everything in one place: how the M3XI website handles your data, plus a policy for each product — Cornelia (NoteTaker), AutoUV and CallMe. Plain English wherever the law allows.

Effective: 28 April 2026 · Last updated: 12 July 2026 · Contact: support@m3xi.com

Policy 01 · m3xi.com

Website & waitlists

Who we are

M3XI ("we", "us") operates this website from England and Wales. Full honesty: M3XI is not yet a registered company — it is an early-stage studio in the process of being set up. Until registration completes, the individuals behind M3XI act as the data controller. Privacy requests: support@m3xi.com.

What the website collects

  • Waitlist signups. If you join a product waitlist (Cornelia, AutoUV or CallMe) we store the email address you give us, an optional name, which product you signed up for, and the page you signed up from. This is stored securely in our database (Supabase, EU region).
  • Email you send us. If you contact support@m3xi.com we receive whatever you include in your message.
  • Operational data. Our hosting provider (Vercel) processes standard server logs (IP address, user agent) to deliver the site over HTTPS. We do not run advertising trackers.

How we use waitlist data

  • To email you about the product you signed up for — launch news, early-access invites, and important updates. Nothing else.
  • We do not sell or share waitlist emails with third parties for their marketing.
  • You can leave a waitlist at any time by emailing us or using the unsubscribe link in any email we send; we then delete your entry.

Cookies

This site uses only strictly necessary operational cookies, if any. If we ever add analytics, we will update this policy and add consent tooling first.

↑ Back to all policies

Policy 02 · Cornelia — listed on stores as NoteTaker

Cornelia (NoteTaker)

Cornelia is our study note-taking app: lecture recording, transcription, and notes organised with the Cornell method — cues, main notes and summaries — plus photo-to-notes and account sync.

Data we collect

  • Account & identity. Email address, name and avatar basics from your sign-in provider (e.g. Google Sign-In), plus an internal user ID.
  • Your content. Audio recordings you make; generated transcripts; images you capture or import; note text, titles and tags; timestamps and ordering metadata.
  • Device & telemetry. Device type, OS, app version and coarse diagnostic/stability data where enabled — used to operate and secure the app. We do not sell personal data.
  • Usage metering. A count of AI minutes used, uploads and timestamps, so we can apply your plan's allowance. This is a measure of how much you used — never the content itself.
  • Payments. Handled entirely by Google Play or the Apple App Store. We never see or store card numbers — only the subscription status and store transaction ID needed to give you what you paid for.
  • Advertising. On the free plan Cornelia shows ads via Google AdMob, which uses your device's advertising ID. See "Advertising & consent" below. Pro subscribers see no ads.

AI runs on your device

Transcription and note generation run entirely on your phone. Your lecture audio, transcripts and generated notes are not uploaded to us and we cannot read them. The AI models are downloaded to the device and run locally, which is why Cornelia works offline. Content leaves your device only if you export or share it yourself, or switch on optional cloud sync.

Advertising & consent

Ads are served by Google AdMob. If you are in the UK or EEA you will see a consent form the first time the app opens, provided by Google's User Messaging Platform, and you can change your answer at any time from Account → Ad privacy options. On iOS you will also be asked for permission to track (Apple's ATT prompt); you can decline and still use every feature. Declining means ads are non-personalised, not absent.

App permissions

Microphone — record lectures and voice notes.

Camera / photos — attach images you choose.

Storage / media — pick or export files locally.

Internet — sync, sign-in, transcription, backups.

Subprocessors

Supabase (auth, database, storage — EU region) · Google (sign-in) · Google Play & Apple (purchase verification) · Google AdMob (advertising) · Vercel or similar (hosting/CDN). No third-party AI processor — generation is on-device.

Retention & children

Active accounts keep their content until you delete items or close the account — we then erase or anonymise within a reasonable window (typically 30 days), except records we must keep for legal, tax or fraud-prevention reasons. Anything held only on your device disappears when you uninstall. You can delete your account from Account → Delete my account in the app. Cornelia is not aimed at children under 13 and we don't knowingly collect their data.

↑ Back to all policies

Policy 03 · AutoUV — Blender add-on

AutoUV

AutoUV is a desktop add-on for Blender that unwraps, seams, scores and exports UVs. It is built to keep your work on your machine.

Your 3D work stays local

  • Meshes, textures, UVs and project files are processed entirely on your computer. AutoUV does not upload your models or scenes to us or anyone else.
  • Quality scoring and Adaptive UV Intelligence run locally inside Blender.

What AutoUV may collect

  • Update checks. The add-on may contact our servers to compare your version against the latest release (a standard version check). This involves your IP address as part of any web request.
  • License / early access. If we issue keys or accounts for early access, we store the email and key needed to validate them (Supabase, EU region).
  • Crash reports & diagnostics. Only if you choose to send them — they include technical details (Blender version, OS, error trace), never your mesh data.
  • Waitlist. Covered by the Website & waitlists policy above.

Payments

If and when AutoUV is sold, payments will run through a payment processor (e.g. Stripe or a marketplace like Blender Market); we will receive order and license status, never full card numbers. We will update this policy before launch if the details change.

↑ Back to all policies

Policy 04 · CallMe — call-first dating

CallMe

CallMe connects two compatible adults in a live voice call instead of endless swiping. Dating data is sensitive and every user's identity is verified before they can call anyone, so this policy is deliberately specific about what that involves.

Age and identity verification

CallMe is strictly 18+, and verification is mandatory — there is no way to skip it and reach the calling features. The check is carried out by Didit, our verification provider, and involves three steps:

  • photographing an identity document — passport, driving licence or national ID;
  • taking a live selfie, checked for liveness: that a real person is present rather than a photograph, mask or video;
  • a face match between that selfie and the photograph on your document.

The face match is biometric processing. Under UK and EU GDPR, biometric data used to identify someone is special-category data, and we rely on your explicit consent together with the substantial public interest in keeping under-18s out of an adult service.

Your document images and selfie are never sent to us and are never stored on our servers. They go directly to Didit. We receive only the outcome — pass or fail, your date of birth, and your derived age.

Data we collect

  • Account. Email sign-in (Google), display name, and an internal user ID.
  • Verification outcome. Pass or fail, date of birth and derived age — not the documents themselves.
  • Profile. Age, city, bio, gender, interests, and optionally occupation, education, relationship aim, sexual orientation and ethnicity. The last two are optional special-category fields; leave them blank if you would rather not say.
  • MeCards. The trading-card profiles you design — stats, motto, colourway, the stickers and GIFs you place on them, and the photographs you add.
  • Preferences. Age range, distance, which genders you want to be matched with, and optionally which broad ethnicity groups — used only to pair you with compatible people. See "Ethnicity in matching" below.
  • Location. Your city, and coordinates if you choose to use GPS, for distance-based matching. You can type a city instead; we show distance to others, never a precise position.
  • Photos. Images you upload to a MeCard, shown during call intros. If you and your match both opt in to connect, the photo captured at that moment is saved to each of your connection walls.
  • Call metadata. Who was matched with whom, call start/end times, whether video was mutually enabled, and connection quality — needed to run the service, prevent abuse and improve matching.
  • Connections and social handles. When you and another person both choose to connect, each of you can see the social handle the other chose to share.
  • Safety reports. If you report, block or mute someone, we store the report and enough context to act on it, plus any moderation flags raised against your content.
  • Purchases. Premium subscription status. Card details are handled entirely by Apple or Google and never reach us.
  • Sticker searches. What you type into the sticker and GIF picker is sent to GIPHY to return results.
  • Advertising. CallMe shows ads via Google AdMob, which uses your device's advertising ID. See "Advertising & consent" below.

Your calls

  • Calls are live voice conversations. We do not record call audio or video.
  • Video is off by default and turns on only when both people opt in during the call.
  • If any moderation or safety feature ever requires audio processing, it will be clearly disclosed in-app before it applies, and this policy will be updated first.
  • Your phone number and email are never shown to other users; calls connect through the app.

Photos, stickers and moderation

Images and text you publish may be scanned automatically by a content moderation provider before they appear. Content that fails is blocked and the account is flagged; repeated flags lead to a warning, then suspension, then a permanent ban. Stickers and GIFs come from GIPHY and are requested at GIPHY's family-safe "G" rating.

Ethnicity in matching

Ethnicity is optional everywhere in CallMe. You can state it on your profile, and you can separately choose broad ethnicity groups you would like to be matched with. These are two different things and we ask for each separately, because storing a characteristic and filtering people by it are different purposes under data protection law.

Ethnicity is special-category data under UK and EU GDPR. We rely on your explicit consent to use it in matching, given when you set that preference. You can clear it at any time from Settings → Who should we call?, and matching immediately stops using it.

How the preference behaves, so you know what you are agreeing to:

  • If you set no preference, it has no effect at all — you are matched with everyone.
  • Someone who has not stated their ethnicity is never excluded by anyone's preference. Choosing not to share yours does not cost you matches.
  • The preference is the first one we relax. After roughly eight seconds in the queue it stops applying, before we widen your age range or distance. It shapes who you are offered first; it is not a wall.

Gender and orientation preferences work differently — those are never relaxed.

What other people can see

  • During a call: your display name, age, city, interests and the MeCard you were dealt.
  • For 24 hours after a call, the person you spoke to may see one of your MeCards on their home screen. It disappears on its own.
  • Your social handle is revealed only when both of you have chosen to connect. A one-sided like never reveals it.
  • People you block or mute cannot be matched with you again and do not appear anywhere in your app.

How long we keep things

  • Account, profile and MeCards — until you delete your account.
  • Recent calls list in the app — visible for 48 hours.
  • MeCard wall in the app — visible for 24 hours.
  • Call metadata — up to 12 months, so we can investigate reports.
  • Verification outcome — while your account exists; it is what keeps you verified.
  • Blocks, reports and moderation flags — retained after an account closes, so that a banned user cannot simply come back.

Ground rules

  • 18+ only. CallMe is strictly for adults. Accounts found to belong to minors are removed.
  • We never sell your dating preferences or match history, and we never share them with advertisers. Ads in CallMe are not targeted using your profile, preferences or who you matched with.
  • Blocking someone prevents them from being matched with you again.
  • Delete your account from Settings → Delete account & data, or at m3xi.com/delete-account if you no longer have the app installed. We erase your profile, MeCards, photos, preferences and match history within 30 days, except safety records we are required to keep to protect other users.
  • You must not create an account for anyone else, use another person's identity document, or attempt to defeat the verification check.

Advertising & consent

Ads are served by Google AdMob. In the UK and EEA you will see a consent form when the app first opens, provided by Google's User Messaging Platform, and can change your answer any time from Settings → Ad privacy options. On iOS you will also see Apple's tracking prompt; declining still leaves every feature available. You can also choose to watch a rewarded advert to earn an extra call. As above, your dating data is never used to target ads.

Subprocessors

Supabase (auth, database, storage — EU region) · Didit (identity document, liveness and face-match verification — EU) · Agora (live voice and video transport only — calls are not recorded or stored) · Google AdMob (advertising) · GIPHY (sticker and GIF search — USA) · content moderation provider (automated image and text scanning) · ElevenLabs (the synthesised host voice used in call intros) · Google Play & Apple (purchase verification) · Vercel or similar (hosting).

Where a provider processes data outside the UK or EEA, we rely on Standard Contractual Clauses or the UK International Data Transfer Addendum.

↑ Back to all policies

Applies to everything above

Your rights & the shared small print

Legal bases (UK / EU GDPR)

Contract — delivering the apps and features you ask for. Legitimate interests — security, debugging, preventing abuse, improving products (balanced against your rights). Consent — where required, such as optional diagnostics or non-essential cookies.

Where data lives

Our primary database region is the EU (Supabase, eu-west-1). Some providers (AI processors, Stripe, hosting) may process data in the UK, EEA or United States; where transfers leave your country we rely on appropriate safeguards including Standard Contractual Clauses. All traffic is encrypted in transit (HTTPS/TLS) and access follows least-privilege controls.

Your rights

Depending on your jurisdiction you can request access, correction, deletion, portability, restriction or objection, and you can complain to a regulator. UK users can contact the ICO at ico.org.uk. Send requests to support@m3xi.com from your registered email where possible — we respond to all of them.

Changes

When we update these policies we change the date at the top of this page; for material changes we notify you in-app or by email. See also our Terms of Use.

↑ Back to all policies