Summary
Meivish has no user-account server. The app connects your device directly to Microsoft or Google, stores app state locally, and streams Provider content to your device. It does not upload your Videos to a Meivish service.
Data the app handles
- Provider credentials: access tokens, refresh tokens, and expiry information required to keep a Connected identity authorized.
- Connected identity data: Provider, stable Provider identity ID, display name, and an email address when the Provider supplies one.
- Library data: local Library ID and name plus Source folder ID, name, and path.
- Playback data: Folder and Video identifiers, resume position, watched state, audio and subtitle choices, and device-global volume.
- Provider metadata: Folder and Video names and IDs, media type, thumbnails, playback URLs, and authorization headers fetched as needed.
- Premium state: a locally cached entitlement result. Google Play or Apple processes purchases; Meivish does not receive payment-card details.
How data is used
The app uses this data only to authenticate, display the selected Library, play Videos, remember playback state, and determine locally available Premium features. Meivish does not sell personal data.
Storage and security
Identity, Library, and playback state stays on the device. Android credentials are encrypted with a device-bound AndroidKeyStore key. iPhone and iPad credentials use Keychain with device-only accessibility. Desktop app data is stored in the current user's local application data.
Folder metadata is cached in memory for a limited time. Meivish does not persist OneDrive preauthenticated Video URLs. Android backup and device transfer are disabled for app data.
Services that receive data
Microsoft receives authentication and Microsoft Graph requests when you use OneDrive. Google receives authentication and Google Drive requests when you use Google Drive. Google Play or Apple may receive purchase and restore requests on their respective platforms. Those companies process data under their own policies.
Use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
Ads and diagnostics
The current build does not include advertising, analytics, or crash-reporting SDKs. This policy must be updated before any such service is enabled.
Retention and deletion
Removing a Library deletes that Library's local playback state. Removing a Connected identity clears its credentials, Libraries, and playback state. Changing a Source folder clears playback and cached browse state for that Library. You can also revoke Provider access in your Microsoft or Google security settings. Provider revocation may not invalidate an already issued token or playback URL immediately.
Platform storage can have its own lifecycle. Use the platform's app-data controls to clear local app data. Do not rely on uninstall alone to revoke Provider authorization.
Children
Meivish is not directed to children under 13. Do not use the app if local law does not permit you to authorize the Provider access it requires.
Changes and contact
Material changes will be published on this page with a new effective date. For privacy questions, use the Support page. Never send tokens, private links, identity details, or Video names.