MELORI●

Privacy Policy

Beta policy · Last updated August 15, 2026

This policy explains the data Melori processes during the beta. The operating legal entity and formal privacy contact are still being finalized; requests can be submitted through the in-product contact form without publishing a dummy address.

Data we process

For accounts, we process authentication identifiers, email, profile and settings data. Depending on use, we process conversations and messages; user-approved memories, corrections, and user-model inferences; projects and project context; preferences and feedback; and usage, model-route, token, latency, safety, error, and cost telemetry. Inferences and model outputs may be wrong and are not human observations or diagnoses.

Anonymous guest trial

The guest trial uses a server-issued signed, HTTP-only session cookie, message count, expiry time, and a keyed one-way hash of network address for abuse prevention. We do not use invasive device fingerprinting. Guest message content is sent for inference but is not stored as account conversation history by Melori. The browser displays the current guest exchange temporarily; guest history does not migrate to an account.

Memory, projects, and proactive features

Account users may create memories and projects. Melori may store user-model inferences with provenance and confidence so they can be corrected or deleted. If proactive follow-ups are enabled, we may process candidate topic, reason, source conversation/project reference, timing, frequency, mute/disable state, confidence, expiry, and delivery or shadow-evaluation metadata.

Pictures you share

If you are signed in, screenshots and pictures you attach in chat are stored privately with that conversation so they stay in your history and Melori can refer back to them. They are deleted when you delete the conversation or your account. Each plan keeps a limited number of pictures per month; beyond that, Melori still reads the picture but does not keep it. Pictures attached during the guest trial are read for that reply only and are never stored.

Your voice

If you are signed in, you can tap Speak in chat to talk instead of type. The microphone is only on after you tap it, and it stops when you tap again or after one minute. The recording is sent to Google Vertex AI once to be written out as text, and the words appear in your message box so you can check or change them before sending. The recording itself is never stored. Each plan includes a monthly number of voice messages. When Melori reads a reply aloud, the words of that reply are sent to Google Vertex AI to make the sound, which plays in your browser and is not stored. Reading aloud has its own monthly allowance of listening time. In face-to-face mode the microphone turns on by itself after Melori finishes speaking, only while the screen shows Microphone on, and turns off after a short pause or a few seconds of quiet. Nothing is sent if no one spoke.

Integrations and processors

Google Cloud services—including Cloud Run, Cloud SQL, Identity Platform, Secret Manager, and Vertex AI—host or process service data. If billing is enabled, Stripe processes payment and transaction information; Melori stores necessary customer, subscription, price, invoice, entitlement, and webhook identifiers, not full card numbers. If Spotify is connected, Melori may process account/profile, playlist and track metadata, scopes, and server-side OAuth token references. Connections can be revoked.

Why we process data

We process data to authenticate users; provide chat, personalization, memory, projects, and opted-in follow-ups; meter allowances and costs; prevent abuse; secure and troubleshoot the service; provide connected features; process subscriptions when enabled; honor user controls; and comply with law.

Tenant isolation and security

Authenticated application queries scope chats, memories, projects, usage, preferences, and billing records by user identifier. Guest sessions use separate random identifiers and do not expose cross-guest history. Secrets and integration tokens remain server-side. No online system can promise perfect security.

Retention, deletion, and export

Guest counters expire after 24 hours, subject to limited security logging. Account users can delete conversations and memories and request confirmed account deletion. Some backups, security logs, transaction records, legal holds, or processor records may persist for limited periods. A complete self-service export is not yet available; requests may be submitted through support. We will publish a verified retention schedule before broad commercial launch.

Your choices and rights

You can avoid account creation by using only the limited guest trial; edit or delete memories; delete conversations; disable proactive follow-ups; disconnect integrations; and request account deletion. Depending on location, law may provide access, correction, deletion, portability, restriction, objection, appeal, or consent-withdrawal rights. Submit a request through Support; identity verification may be required.

Children, sale, and changes

Melori is not directed to children and the beta is limited to adults 18 or older. We do not sell personal information or use it for targeted advertising in the current beta. We will update this notice when practices materially change and identify the revision date.