Privacy Policy
Effective: 23 September 2026.
Replaces the version effective 5 July 2026. What changed: we no longer say that outside model providers refuse to keep what they are sent, only that their published terms say they do not train on it, and that promise now covers requests for written answers only, because a request for a picture goes out under the picture provider’s own terms; section 5 now names the 14-day backup window and what a deletion does not remove; and Tigris and Amazon Web Services are added to the list of processors.
This explains what Melelem collects, why, and what control you have. The data controller is Melelem, Inc., a company incubated by Fountech.ai Limited (“we”, “us”). Contact: legal@melelem.ai.
1. What we collect
Your account (app.melelem.ai): when you sign in with Google we receive your name and email address, and we store the email and the sessions tied to it. Nothing else, no tracking pixels, no ad tech.
Your content: conversations, material you add as context, writing you provide to train your personal model, and the model’s outputs for you.
Handoffs: when you send or receive work, the shared package (the items you confirmed) and the messages added to it.
Connectors: if you connect services like Notion or Linear, we store the access tokens encrypted and request the narrowest scopes that make the feature work. We access connected data to do what you asked and not otherwise.
Model calls: every call to a model provider runs on Melelem’s own keys. You do not add provider keys, so there are none of yours for us to hold.
Technical basics: logs needed to run and secure the Service (timestamps, IPs, errors). No advertising analytics on the site.
2. Why we process it
To provide the Service you asked for (contract): running your conversations, training your personal model on your writing, executing handoffs you confirm, operating connectors you enabled. To keep the Service secure and debug it (legitimate interest). To contact you about the Service at your account email (legitimate interest, and consent where required; every non-essential email has an opt-out).
3. What we do not do
We don’t sell your data. We don’t show ads. We don’t use your content to train any model but yours: training is per-account, and what your model learns from you serves only you. The router keeps shared scores of how well each model does, which hold none of your content and name nobody. Handoff content goes only to the people you explicitly confirmed.
4. Who processes data for us
We use a small set of processors to run the Service: Vercel (website and app hosting), Fly.io (application gateway), Tigris (backups of the gateway’s data), Amazon Web Services (the server your personal model runs on, and its storage), OpenRouter (model routing, and the route every outside model call takes), Google (sign-in, and Google connectors you enable), Stripe (payments), and Resend (transactional email). Where these processors handle data outside the EEA, transfers rely on recognised safeguards such as the EU-US Data Privacy Framework or standard contractual clauses. The model makers OpenRouter reaches for us may be in any country, under their own terms. Other connectors you enable are reached at that service, under your own account with it.
When your request consults an outside model, the content needed to answer it goes through OpenRouter, which reaches that model on our behalf. The catalogue it reaches runs to several hundred models across many makers, so the maker is whichever one the routing chose for that part of your request. Every request for a written answer asks OpenRouter to use only providers whose published terms say they do not train on what they are sent, and none is sent any other way. That is a rule about training, not about storage: a provider may keep a request for a time under its own terms, for example to check it for abuse. A request for a picture goes to the picture provider OpenRouter chooses, under that provider’s own terms.
5. How long we keep it
Account data and content: for the life of your account. You can delete your account yourself in the app’s settings, or by writing to legal@melelem.ai. A deletion request is honoured within 30 days.
Backups: the Service’s backups keep 14 days of history. What you delete, including your conversations and any pictures you generated, can stay in them for up to 14 days after it leaves the Service.
What a deletion does not remove, and why:
- your invoices and any chargebacks on them, because accounting records are kept by law;
- a record that you asked to be deleted, holding your address, the dates, how the request reached us, which connected services were disconnected, a count of what was removed and the error from any step that failed, because it is how we show the request was honoured;
- a line holding your address that stops your old sign-ins working again;
- your unsubscribe from our emails, if you gave one, so you are not put back on a mailing list;
- work you handed to someone else, which lives in their account like a delivered email. It is no longer linked to your account, though anything you wrote in it stays as written;
- the shared scores of how well each model does, drawn from everybody’s use, which hold none of your content and name nobody.
Some copies are out of our reach: Stripe keeps its own record of your payments, and emails we have already sent stay in your inbox and in our email provider’s sending record.
Logs: short rotation, weeks not years. Operational logs can carry your address until they rotate out.
6. Your rights
Under the GDPR you can ask for access, correction, deletion, restriction, portability, and you can object to processing based on legitimate interest. Write to legal@melelem.ai. You can also complain to your local data protection authority.
7. Cookies
melelem.ai sets no advertising or analytics cookies. app.melelem.ai uses strictly necessary cookies only: a session cookie that keeps you signed in. That’s the list, which is why there’s no cookie banner.
8. Security
Content in transit is encrypted (TLS). Connector tokens are encrypted at rest. Access to production systems is restricted. No system is perfectly secure; if a breach affects your data we will notify you as the law requires.
9. Children
The Service is not directed at children and requires users to be 16 or older.
10. Changes
We’ll post any changes here with a new effective date, and flag material changes in the app.
Contact: legal@melelem.ai