Skip to content
MEVARA
Privacy Policy

Private-first shopping with clear choices.

Mevara is built so the core shopping experience can work without OpenAI. Your shopping memory stays on your iPhone unless you choose an optional feature that shares limited information.

Last updated: August 13, 2026

Stored on your iPhone

Your Mevara conversations, shopping missions, purchase history, and Restock information are stored locally on your device.

AI is optional

ChatGPT Discovery only works after you add your own OpenAI API key, turn the feature on, and accept the in-app disclosure.

Retailer sign-ins stay with retailers

Mevara does not receive or store retailer passwords, and its AI requests do not include retailer cookies or session tokens.

You're in control

You can turn ChatGPT Discovery off, remove your API key, or clear your local Mevara shopping data from Settings.

1. Overview

Mevara is an independent multi-retailer shopping browser and shopping assistant. It helps you search supported retailers, compare product information, open live retailer listings, save purchases you choose to record, continue shopping missions, and manage Restock timing. Mevara does not require a Mevara account and does not process retailer checkout.

2. What Mevara keeps locally on your device

Mevara keeps shopping information locally on your iPhone so you can continue your shopping tasks and use repeat-purchase memory. This may include:

  • recent Mevara conversations and active shopping context;
  • shopping lists, missions, and saved results;
  • purchase history you choose to record, including product, retailer, date, and price;
  • Restock items, timing, and related preferences; and
  • recent searches, settings, and optional-AI consent choices.

Retailer webpages opened inside the app may also keep their own cookies or session data so retailer pages and sign-ins continue to work. That retailer data is separate from Mevara’s local shopping memory and remains subject to the retailer’s own privacy practices.

3. On-device assistance

Core shopping, purchase history, and Restock features can work without an OpenAI API key. Some assistance may also be processed directly on your iPhone. Information processed entirely on your device is not sent to OpenAI.

4. Optional ChatGPT Discovery and OpenAI

Optional ChatGPT Discovery is used only after all three of the following are true:

  1. you supply your own OpenAI API key;
  2. you turn Use ChatGPT for discovery on; and
  3. you accept the current optional-AI disclosure in the app.

You can withdraw that permission at any time by turning Use ChatGPT for discovery off. Turning it off stops Mevara’s normal OpenAI requests even if your API key remains saved on the device. Removing the key is a separate control.

Information an optional OpenAI request may include

Depending on your request, Mevara may send OpenAI:

  • your current discovery prompt or question;
  • relevant recent conversation context needed to continue the topic;
  • relevant product facts, such as product title, retailer, price, unit information, rating, or delivery information; and
  • a limited summary of relevant purchase or Restock information when helpful to answer your request.

Information not included in normal OpenAI requests

Mevara does not send retailer passwords, retailer cookies or session tokens, or your complete shopping history to OpenAI as part of normal ChatGPT Discovery requests.

Your API key and OpenAI processing

Your OpenAI API key is stored in the iOS Keychain on your device and is used by the app to authenticate requests under your OpenAI API account. It is not entered on the Mevara website. OpenAI usage, billing, processing, and account controls are governed by your relationship with OpenAI.

Mevara may request store:false for applicable API requests, but that is not a promise of zero provider retention. OpenAI states that standard abuse-monitoring logs may include prompts and responses and may be retained for up to 30 days by default, unless legal requirements or account-specific controls require otherwise. OpenAI also states that API data is not used to train its models by default unless the API customer opts in, subject to its current policies. Review OpenAI’s API data controls and service terms for the current rules.

Random safety identifier

When Optional ChatGPT Discovery is used, Mevara may send a random pseudonymous safety identifier with OpenAI requests for safety and abuse handling. It is not your name, email address, retailer account, or advertising identifier.

Current deletion scope: the current Clear Mevara chat, shopping mission, purchase history & Restock control does not remove this safety identifier. It remains in the app’s local storage until that storage is removed or the identifier is changed or rotated by the app. It is not used for advertising or cross-app tracking.

5. Sharing you choose to initiate

If you choose to share or export shopping information from Mevara, the information you select may include product details, prices, retailer information, delivery details, and retailer links. Information you intentionally share is subject to the privacy practices of the destination you choose.

6. Retailer websites, sign-in, and checkout

Retailer sign-in is optional and happens on the retailer’s live webpage. Mevara does not receive or store retailer passwords. Prices, availability, delivery estimates, product content, account access, payment, orders, returns, warranties, and customer service are provided by the retailer and are governed by that retailer’s own terms and privacy policy.

7. Optional Shop connection and delivery area

You may optionally connect your Shop account so Shopify can issue Mevara a short-lived buyer-linked catalog token. The sign-in happens through Shop’s authorization service. Mevara does not receive your Shop password, payment details, or full saved shipping address.

The Mevara website acts as a secure login broker for this connection. It temporarily processes authorization data, holds the buyer-linked token only until the app redeems a short-lived one-time code, and then deletes that temporary server record. The buyer-linked token is stored in the iPhone Keychain until it expires or you disconnect Shop.

Your delivery country, state or region, and ZIP or postal code are entered separately and stored locally on your device. Mevara may send that delivery area and the optional buyer-linked token to Shopify to localize catalog results and check shipping eligibility. Shop login does not provide Mevara with a documented full shipping-address claim, and Mevara does not promise an exact delivery date unless Shopify supplies reliable delivery information.

8. Local retention, consent withdrawal, and deletion

Local conversation, mission, purchase, and Restock information remains on the device so you can continue shopping tasks and use repeat-purchase memory. You have the following controls in Mevara Settings:

1
Stop OpenAI requests

Turn Use ChatGPT for discovery off. Local Mevara functions continue to work, but Mevara stops its normal OpenAI requests.

2
Remove the OpenAI key

Tap Remove in Optional ChatGPT Discovery. This deletes the saved key from the iPhone Keychain and resets optional-AI permission.

3
Clear local Mevara shopping data

Tap Clear Mevara chat, shopping mission, purchase history & Restock. This clears local Mevara conversation, list, mission, purchase, Restock, and related shopping data.

The Clear Mevara Data control does not clear retailer WebView cookies or retailer account sessions, does not remove the separately stored OpenAI API key or Shop buyer token, and does not remove the random safety identifier described above. Use Disconnect Shop to remove the Shop connection from the app.

9. Website forms, product updates, and support

When you use a Mevara website form or contact support, Mevara may receive your name, email address, message, screenshots, screen recordings, device information, and any other information you choose to provide. WordPress, the website host, form services, and email providers may process this information to operate the website and deliver the message. Standard website or security logs may include IP address, browser type, requested pages, timestamps, and similar technical information.

Product-update contact information is retained until you unsubscribe, ask for deletion, or the update list is discontinued. Ordinary support communications are normally retained for up to 24 months after the last response so Mevara can follow up, identify repeat issues, and document resolutions. Information may be retained longer when reasonably necessary for security, fraud prevention, legal obligations, or dispute resolution.

Access is limited to the Mevara operator and service providers that need the information to host the site, deliver email, maintain security, or respond to you. To unsubscribe or request deletion of website or support information, email shaya@mevara.ai. Include the email address or message details needed to locate the record.

10. Analytics, advertising, cookies, and data sales

The current Mevara app does not include Mevara-operated advertising, cross-app tracking, or a third-party analytics SDK. The website does not intentionally use advertising or cross-site behavioral tracking. WordPress, form protection, hosting, and security services may use essential cookies or similar storage needed to operate the site and prevent abuse.

Mevara does not sell personal information submitted through the app or website and does not use local shopping history for third-party advertising.

11. Security

Mevara uses reasonable technical and organizational safeguards appropriate to the current service, including iOS Keychain storage for the optional API key and Shop buyer token, minimized automatic AI payloads, one-time authorization codes, short-lived authorization state, and server-side storage of Shopify credentials. No storage or transmission method can be guaranteed completely secure. Protect your OpenAI API key, use a restricted project key with a low spend limit, and revoke it through OpenAI if a device is lost or compromised.

12. Changes to this policy

This policy may be updated when the app, website, providers, or legal requirements change. The “Last updated” date identifies the current public version. Material changes to optional-AI sharing should also be reflected in the app’s consent disclosure before they take effect.

13. Contact

For privacy questions, access requests, deletion requests, or concerns about this policy, contact shaya@mevara.ai.