Free forever ยท No credit card
Loading...
The UK has some of the strongest data protection laws in the world. Most AI companions don't comply properly. MEOK was built in England, for UK law โ from the ground up.
Nicholas Templeman
Founder, MEOK AI LABS ยท Built in England
Nicholas founded MEOK AI LABS in England. He built MEOK because he believed UK citizens deserved an AI companion designed around their legal rights โ not around a Silicon Valley data model. He is not a solicitor; this article is for informational purposes only.
The United Kingdom retains some of the most stringent data protection legislation on the planet. The Data Protection Act 2018 enshrines the UK GDPR into domestic law, the Information Commissioner's Office actively enforces it, and the Age Appropriate Design Code โ the Children's Code โ sets a global standard for how digital services must treat minors. These are not aspirational guidelines; they carry real financial penalties and, in some cases, criminal liability.
Most AI companions โ ChatGPT, Gemini, Replika, and others โ were designed primarily for American markets under American legal assumptions. When they arrived in the UK, they brought their data architectures with them: default training on user conversations, unclear lawful bases, and erasure processes that are neither cryptographic nor prompt. UK users deserve better. MEOK was built here, from the start, to meet every obligation that UK law imposes.
The UK General Data Protection Regulation โ retained post-Brexit as a matter of domestic law and amended by the Data Protection Act 2018 โ governs how personal data is collected, processed, stored, and transferred. For AI companions, several principles are directly relevant.
Lawful basis for processing. Every time an AI service processes personal data, it must point to one of the six lawful bases set out in UK GDPR Article 6: consent, contract, legal obligation, vital interests, public task, or legitimate interests. For a conversational AI companion that stores deeply personal disclosures โ mental health, relationships, daily life โ โlegitimate interestsโ is a contested basis. Consent, freely given and specific, is the cleanest option, but it must be real consent, not a buried checkbox in a 40-page privacy policy.
Data minimisation. Article 5(1)(c) requires that personal data be โadequate, relevant and limited to what is necessaryโ for the purpose. An AI companion that retains years of conversation transcripts in identifiable form, used to improve corporate models, struggles to satisfy this principle.
Purpose limitation. Data collected for one purpose โ delivering a personal companion experience โ cannot then be repurposed for model training without a new lawful basis and, in most cases, fresh consent.
Right to erasure. UK GDPR Article 17 gives individuals the right to have their personal data deleted. For AI services, this means not just removing the display of a conversation, but actually deleting the underlying data โ including any derived memories, embeddings, or model fine-tuning inputs derived from it.
Yes โ but the conditions are demanding. Under UK GDPR Chapter V, personal data can only be transferred to countries outside the UK if adequate protections are in place. The UK has issued adequacy decisions for a limited number of countries, and for others, companies must rely on mechanisms such as International Data Transfer Agreements (IDTAs) or binding corporate rules. The United States is not an adequacy country; US companies must use IDTAs or the UK Extension to the EUโUS Data Privacy Framework.
The transfer mechanism is only the first hurdle. The company must still satisfy all substantive UK GDPR obligations: lawful basis, data minimisation, purpose limitation, security, and rights fulfilment. Several major AI providers have relied on vague โlegitimate interestsโ assessments for processing highly sensitive companion conversations โ an approach the ICO has signalled it will scrutinise closely as AI companion use grows. Honest assessment: many US AI companies operate in a grey zone of technical legal compliance while falling short of the spirit of UK data law.
The right to erasure โ sometimes called the โright to be forgottenโ โ requires a data controller to delete your personal data without undue delay when you request it, unless one of a limited number of exceptions applies. For AI companions, this means:
MEOK handles erasure through cryptographic key deletion. All stored memories and conversations are encrypted with a per-user AES-GCM-256 key. When you request deletion, the encryption key is destroyed first, making the underlying data mathematically irrecoverable before the physical deletion sweep completes. This is the gold standard for provable erasure โ and it is what UK GDPR demands.
The Information Commissioner's Office is the UK's independent regulator for data protection and privacy. It is empowered to investigate complaints, audit organisations, issue enforcement notices, and levy fines of up to ยฃ17.5 million or 4% of global annual turnover โ whichever is higher โ for serious infringements.
Any organisation that processes personal data in the UK and is not exempt must register with the ICO and pay the annual data protection fee. For commercial AI services that store conversation history, this is not optional. The ICO has already investigated several AI companies โ most notably issuing a warning to Replika's operator Luka, Inc. in 2023 regarding the processing of children's data โ and has publicly stated that AI is a regulatory priority.
MEOK AI LABS is ICO registered. Registration is publicly verifiable on the ICO register. This is not a marketing claim; it is a legal obligation we take seriously.
MEOK was designed from the ground up to operate within the UK legal framework. Compliance is not a bolt-on; it is an architectural constraint.
ICO registration. MEOK AI LABS is a registered data controller with the Information Commissioner's Office.
Lawful basis. MEOK processes companion data under a clear contractual basis โ it is necessary to deliver the service you have requested. We do not rely on opaque legitimate interests assessments for the core processing of your conversations.
Privacy by design. UK GDPR Article 25 requires that data protection be considered from the earliest stages of product design. MEOK's encrypted vault architecture, per-user key management, and row-level database security were all specified at the design stage, not added to an existing system after the fact.
No default training. MEOK never trains on your conversations. This is not a setting buried in account preferences โ it is the architectural default and the contractual commitment in our terms of service.
UK data residency. MEOK is actively building UK-region hosting options. The forthcoming Desktop OS (Summer 2026) will process all data entirely on your own hardware โ making international transfer law irrelevant because no transfer occurs.
The Age Appropriate Design Code โ known as the Children's Code โ came into force in September 2021. It is a statutory code of practice issued under the Data Protection Act 2018, and it applies to any online service โlikely to be accessed by childrenโ in the UK. A service need not be explicitly targeted at children to be in scope; if it is likely that under-18s will use it, the Code applies.
For AI companion services, the implications are significant:
Several AI companion services โ including Replika, which actively markets itself as an emotional companion โ have faced regulatory pressure under the Children's Code. MEOK applies Children's Code standards to all users under 18 by default, with enhanced protections in Guardian mode for children whose accounts are linked to a parent or carer.
Under the UK GDPR and Data Protection Act 2018, you hold a comprehensive set of rights over personal data that any organisation โ including an AI service โ holds about you:
These are not theoretical rights. Failure to respond to a Subject Access Request within the statutory timescale is an enforceable breach โ and the ICO takes them seriously.
MEOK provides self-service tooling for all UK GDPR rights, accessible directly from your account dashboard:
Data export (portability). A single-click export endpoint generates a complete structured JSON archive of your entire MEOK vault โ every conversation, every memory, every preference. The file is yours to take to any platform. No request to customer support required; no waiting.
Full deletion (right to erasure). Selecting account deletion initiates the cryptographic erasure flow described above. The per-user encryption key is destroyed immediately; the physical data sweep completes within 24 hours; and you receive a deletion confirmation. The entire process is completed within the one-month statutory window โ typically within 24 hours.
Subject Access Requests. Formal SARs can be submitted via privacy@meok.ai. MEOK will acknowledge within 72 hours and fulfil within one calendar month. For straightforward requests, the self-service export tool satisfies the obligation immediately.
Corrections and restrictions. Both can be actioned via the account settings panel or by contacting our data protection contact. We aim to confirm completion within five working days.
Based on publicly available privacy policies, ICO register records, and regulatory findings as at March 2026. Partial indicates incomplete, unclear, or opt-out-only compliance.
| Compliance Dimension | ChatGPT | Gemini | Replika | MEOK |
|---|---|---|---|---|
| ICO Registered OpenAI and Google operate under separate EU/UK transfer mechanisms; Replika is US-only registered. | โ | โ | โ | โ |
| UK GDPR Lawful Basis (Companion Data) Legitimate interest is commonly claimed but contested for deeply personal companion conversations. | โ | โ | โ | โ |
| Children's Code Compliance ChatGPT and Replika have faced criticism from the ICO for inadequate child protections. | โ | โ | โ | โ |
| Right to Erasure (Cryptographic) MEOK uses cryptographic key deletion to make data provably irrecoverable on erasure. | โ | โ | โ | โ |
| Data Portability (Full Export) MEOK provides a full structured JSON export endpoint including all memories and conversations. | โ | โ | โ | โ |
| No Training on User Data (Default) MEOK never trains on user conversations. ChatGPT and Gemini train by default unless opted out. | โ | โ | โ | โ |
| UK Data Residency Option MEOK is building UK-region hosting. Desktop OS (Summer 2026) will be fully local. | โ | โ | โ | โ |
| Designated Data Protection Officer Replika has no publicly listed DPO contact for UK users. | โ | โ | โ | โ |
UK data protection law was not written with Silicon Valley business models in mind. It was written to protect people โ specifically, to ensure that intimately personal data cannot be harvested, profiled, and monetised without meaningful consent. An AI companion, by definition, processes some of the most personal data that exists: your thoughts, your anxieties, your relationships, your daily rhythms. The UK law is clear that this data demands the highest standard of care.
MEOK AI LABS was founded in England precisely because Nicholas Templeman believed that a UK company should build a UK-law-native AI companion โ not adapt an American product to UK law as an afterthought. Sovereign AI and UK data rights are the same argument from different directions: your data belongs to you, the law agrees, and the technology should enforce it.
Built in England ยท ICO Registered ยท Free Forever
MEOK is the only AI OS built from the ground up for UK data rights. ICO registered. UK GDPR compliant. Cryptographic erasure. No training on your conversations. Your data is genuinely yours โ protected by law and by architecture.
Hatch your sovereign AI free โ