Back to home

Trust & Data Protection

You are handing us the most personal data you have.

Blood biomarkers. Insulin and glucose values. Photographs of your food. Conversations with an AI coach about your body. This page explains what happens to all of it — in plain English, with the paperwork attached.

Registered with the UK Information Commissioner’s Office

Meterbolic Health LtdZC039400

Registration reference
ZC039400
Date registered
11 November 2025
Registration expires
10 November 2026

Registered address: Number 2, 2 Barons Pastures, Kirby Muxloe, Leicester, LE9 2BG. We are the data controller for everything collected through meterbolic.com and the Meo app — which means we are the ones legally accountable for it, and the ones you hold responsible.

The second link goes to the ICO’s own website, not ours. A trust claim you can only check with us is not worth much.

The legal footing

Health data is special-category data. We treat it as such.

Under UK GDPR, data about your physical health sits in a protected category of its own (Article 9). It cannot be processed on the ordinary grounds that cover a name and address. It needs your explicit consent — freely given, specific, and separately asked for.

That is why the Meo app asks you to consent to health-data processing as its own deliberate step, rather than folding it into a tick-box next to the terms of service. Consent is the basis we rely on for your metabolic data, and consent you have given you can take back. Withdraw it and we stop processing on that basis.

Two narrower grounds sit alongside it: we process your order and account details because we need them to perform our contract with you — we cannot ship a device without an address — and we keep invoice records because the law requires us to. Those are not health data and are not covered by your health consent.

The full notice, with the formal detail, is the Privacy Policy. This page is the version written to be read.

What we collect

So the coach can be about you, not about averages.

Population averages are why metabolic advice usually fails. “Eat less fat” is a statement about a cohort; it is not a statement about your triglycerides on a Tuesday. Everything Meo collects exists to replace an average with a measurement of you.

Your readings

Lipid panel results from the Digital Lipid Meter, and insulin and glucose values where you record them. This is the trend line — the reason the product exists. Without your own history, Meo has nothing to compare today against.

Food photographs

Optional. A photo is read to identify what you ate, so a meal becomes a data point instead of a memory. It is held privately and is never attached to your name in anything we publish or analyse in aggregate.

Your conversations with Meo

What you ask, and what Meo answered. Kept so the coach has continuity — so you are not re-explaining your history every session, and so you can go back and read what you were told.

Account and order details

Name, email, delivery address, and what you bought. Payment card details we never see or store — those go directly to Stripe.

We do not buy data about you from anyone else, and we do not enrich your profile from third-party sources. What we hold is what you gave us or measured yourself.

Where your data lives

Specifics, not adjectives.

“Bank-grade security” means nothing. Here is what is actually true, and we have tried to be equally clear about where it stops.

  • Your record lives in London. The primary database holding your readings, profile and conversation history is a managed PostgreSQL instance in Amazon Web Services’ London region (eu-west-2).
  • Encrypted in transit, everywhere. Traffic to the site and app is served over HTTPS, and our own services talk to the database over TLS. Nothing about your health moves across a network in the clear.
  • Logging in is handled by AWS Cognito. We do not store your password. Every request carries a signed token that our services verify cryptographically against Cognito before returning a single row.
  • Your records are scoped to you. Requests are answered against the identity in your token, never an account number supplied in the request. Ask our API for a record that is not yours and it reports that no such record exists — it will not even confirm the row is there.
  • Food photos are not on a public URL. They sit in a private store. When one needs to be displayed, we mint a link to that single image which expires within minutes. There is no permanent address for your photograph.

Being straight about the edges: the master record is in London, but not every piece of processing happens inside the UK. Some of the services we rely on — parts of the AI processing, and image storage — run in other regions operated by the same providers. If you want the specifics for your own assessment, ask us and we will tell you exactly which service runs where.

Our main processors are Amazon Web Services (hosting, database, identity, and the AI models), and Stripe (payments). We maintain a full list of sub-processors and will send it on request.

The AI questions

What Meo does with your data — and what it doesn't.

These are the questions people actually want answered about an AI health coach, and they are usually the ones left out.

Does my data train somebody else’s AI model?

No. We do not use your health data to train publicly available AI models, and we do not hand it over for anyone else to train on. Meo runs on Anthropic’s Claude models through Amazon Bedrock, inside our own cloud account — not by pasting your results into a consumer chatbot.

Is the coach making things up about me?

Meo answers from your own records — your readings, your history, what you have told it. That is the entire point: it is grounded in your data rather than in a general impression of what a person like you probably looks like. It is still a language model, so it can be wrong, and it is not a clinician. Where a reading warrants medical attention, the right answer is a doctor, and Meo will say so.

Can a human read my conversations?

A human clinician is involved only when you choose to engage one — by booking a programme or a consultation through the marketplace. It does not happen silently in the background. Separately, a small number of our own engineers can reach production data when they are fixing something that is broken; that access is limited to the people who need it to do the job.

Do you use my health data to advertise to me?

No. Nothing about your biomarkers, your weight, your food or your conversations is used for ad targeting, and none of it is shared with advertising networks. There is no version of this business where we sell your bloods.

How long we keep it

For as long as the trend is useful to you.

A single cholesterol reading is close to meaningless. Fourteen readings over eleven weeks is a trend you can act on. So we keep your metabolic history for as long as you have an account — deleting last year’s readings would quietly destroy the thing you bought.

When you close your account, we delete your record: your readings, profile, food log, conversations and session history all go. Invoice and tax records we are legally obliged to keep for a fixed period, so those survive — that is a legal requirement, not a preference.

What we are not going to do is invent a number. We have not yet published a fixed retention period for every individual category of data. When those periods are set, they will appear here and in the Privacy Policy. In the meantime, if you want your data gone, you do not have to wait for a policy — ask us, or delete your account, and it goes.

Your rights

Six things you can make us do.

These are rights under UK GDPR, not concessions we are granting. One email starts any of them.

  • Access. Get a copy of everything we hold about you.
  • Rectification. Make us correct anything that is wrong.
  • Erasure. Have it deleted, except where the law makes us keep it.
  • Portability. Receive your data in a machine-readable form and take it elsewhere.
  • Objection. Object to how we are processing it, or withdraw a consent you gave.
  • Complaint. Escalate past us entirely and go to the regulator.

How to actually exercise them

Email us and say what you want. You do not need to cite an article number or use a particular form of words — “send me my data” or “delete my account” is enough. We will respond within one month, which is the statutory deadline.

privacy@meterbolic.com

If we get it wrong, or you are unhappy with how we handled your request, you can complain to the Information Commissioner’s Office directly at ico.org.uk/concerns. You do not need our permission, and you do not have to come to us first.

For affiliates, partners and clinicians

You are putting your name to this. Here is what that commits you to.

Meterbolic is sold co-branded. A partner supplies the human layer — coaching, clinical or therapeutic — wrapped around the device and the Meo subscription, and their clients arrive on a page carrying their logo. That makes data protection a shared reputational question, not just ours.

We are the controller for platform data. Readings, app accounts, Meo conversations — Meterbolic Health Ltd is the data controller and carries the accountability, including with the ICO. You are not inheriting our compliance obligations for the platform by co-branding with us.

You remain the controller for your own clients. Your client list, your notes, your correspondence and your own clinical records are yours. We do not acquire rights over them by supplying the device and the AI layer, and we do not ingest your CRM.

Co-branding does not hand you a data feed. Sending traffic to a co-branded page does not give you access to those visitors’ health records. A partner sees a client’s metabolic data when that client has engaged them for a programme and the data is shared as part of delivering it — not as a by-product of the referral.

A client of one partner is not a lead for another. We do not resell or cross-sell one partner’s clients into another partner’s offer, and we do not hand your client list to a competing practitioner. Each co-branded offer is presented as that partnership — both brands, one relationship.

If you are conducting due diligence before you put your name to us: start with the ICO certificate above, then email partner@meterbolic.com and ask for the data-protection pack. We would rather answer a hard question at the diligence stage than have it surface in front of your client.

Commitments

What we will never do.

Short list, because a long one is a sign nobody intends to keep it. These are commitments about our own conduct, and we can keep every one.

  • Sell your health data. Not to insurers, not to employers, not to data brokers, not to anyone, at any price.
  • Use your health data to target advertising at you, or share it with an advertising network.
  • Hand your data to a third party to train their AI models on.
  • Disclose your results to your employer, your insurer or your GP without you asking us to.
  • Make a diagnosis. Meo is a wellness and monitoring tool; where something needs a doctor, we will tell you to see one.
  • Quietly widen what we do with your data. If the purpose changes materially, we will ask you again rather than update a policy page and hope you miss it.

Honesty section

What we don't claim.

Trust pages tend to imply more than they say. Here is what we are not telling you, stated plainly, so you can price it into your decision.

  • We are not ISO 27001 or SOC 2 certified. We hold neither certification. Anyone implying otherwise — including us, in some future draft of this page — would be wrong. What we do instead is described above, in specifics.
  • HIPAA does not apply to us. HIPAA is US legislation covering US healthcare providers and their business associates. We are a UK company regulated under UK GDPR and the Data Protection Act 2018. A HIPAA badge on a UK consumer wellness product is decoration.
  • Meo is not a diagnostic device. The Digital Lipid Meter is CE-marked for wellness monitoring. It does not diagnose, treat, cure or prevent disease, and neither does the AI coach.
  • We are a young company, not a fortress. We are building a metabolic health platform, and our security programme is growing alongside it. We would rather tell you what is true today than describe the company we intend to be.

Still have a question?

Ask it. If the answer belongs on this page, we will put it here.

Also worth reading: Terms of Service · Cookies Policy · How Meo works