Privacy Policy
How Melvu collects, uses and protects your personal data - and the rights you have under the GDPR.
Last updated 2026-09-05
1. Who we are (data controller)
Melvu is operated by a sole trader trading as "Ultra", established in Portugal (the "operator", "we", "us"). We are the controller of the personal data described below.
- Contact, privacy and Data Protection Officer (DPO): [email protected]
- Postal address: on request - [email protected]
- Governing law: Portugal / European Union (GDPR - Regulation (EU) 2016/679).
2. Data we collect
- Account data - your email address and username, stored in our Supabase profiles table when you create an account.
- Waitlist data - your email address and, when you arrived through a valid creator link, that creator's normalized username, if you sign up to the product waitlist.
- Network data - our servers and infrastructure proxies necessarily receive your IP while handling a connection and may retain ordinary security/access logs under the operator's retention policy. Melvu monitoring never writes raw IPs to its application database or audit trail; a manual network ban persists only a server-keyed, non-reversible HMAC fingerprint.
- Billing data - when you subscribe or purchase Founder’s Edition, payment details are processed by Stripe. We receive limited metadata (payment identifiers and status, plan, card brand and last four digits, invoices). Founder records also contain your account identifier, email, numbered badge, checkout acknowledgements and purchase/refund history. We never see or store full card numbers.
- Retired cloud-sync data - accounts that previously used the original app may still have end-to-end encrypted legacy blobs pending deletion. The operator does not hold the encryption keys and cannot read this content.
- Melvu entitlement data - we check your account plan, plan expiry and, where applicable, Team membership and the Team owner's current plan to decide whether you can use Melvu.
- Melvu operational metadata - enrolled device identifiers and public keys, live process/session identifiers, app/platform/version/channel details, bounded aggregate run/tool/error/restart/latency counters, security nonces, installer-ticket redemption, configuration-lease and activation/failure receipts, and timestamps. Operational endpoints do not receive your prompts, chats, file paths, source files, URLs, keystrokes, screenshots or other local workspace content.
3. Why we use it & legal bases (Art. 6 GDPR)
- Providing the account and the service - performance of our contract with you (Art. 6(1)(b)).
- Processing payments and managing subscriptions - performance of contract (Art. 6(1)(b)) and our legal obligations, e.g. tax/accounting (Art. 6(1)(c)).
- Sending transactional email (confirmations, password resets, billing notices) - performance of contract (Art. 6(1)(b)).
- Abuse prevention, security, rate-limiting and privacy-safe operational monitoring - our legitimate interests in keeping the service reliable and secure (Art. 6(1)(f)).
- Waitlist confirmations and access updates - your consent (Art. 6(1)(a)). Product news and promotions require a separate optional choice and confirmation by email. You can unsubscribe from either type at any time.
- Remembering and recording the creator referral carried by a valid creator link - our legitimate interest in measuring creator referrals (Art. 6(1)(f)); this is first-party attribution and is not used for cross-site or advertising tracking.
- Retaining legacy encrypted cloud-sync blobs until deletion - your prior consent (Art. 6(1)(a)); we cannot read them.
- Authorizing Melvu and securely delivering installers and device configuration - performance of our contract (Art. 6(1)(b)) and our legitimate interests in preventing unauthorized access and replay attacks (Art. 6(1)(f)).
4. Processors & sub-processors
We share the minimum data necessary with the following processors, each bound by a data-processing agreement:
- Stripe - payment processing and subscription billing.
- Supabase - authentication and database hosting (account/profile data).
- Resend - delivery of account and waitlist emails, and promotional emails for confirmed subscribers. We record your language, subscription choices, consent timestamps and delivery status. Email open and click tracking are disabled.
- Our VPS hosting provider - hosting of the application backend.
5. Retention
- Account and profile data - kept while your account is active, and deleted shortly after you delete your account.
- Waitlist data, including creator attribution - kept while managing your access request. Unsubscribing stops the relevant emails; minimal consent and suppression records remain to respect your choice. You can request removal of your waitlist data. Completed website email jobs are removed after 30 days when the queue next changes. The signed, HttpOnly referral cookie lasts no more than 30 days and is cleared after a successful waitlist submission.
- Keyed IP fingerprints - active network bans expire within 30 days; related security records are kept only while needed for abuse investigation and the audit trail.
- Live Melvu session metadata and aggregate counters - removed on disconnect or after the bounded two-minute presence window; local counters reset when the desktop process restarts.
- Billing records and invoices - kept for the period required by Portuguese/EU tax and accounting law, even after account deletion.
- Legacy cloud-sync blobs - retained only until account deletion or an erasure request, then permanently removed.
- Melvu device and operational records - kept while needed to provide and secure the service, investigate failures and protect the audit trail; device access ends automatically when the qualifying plan or Team entitlement ends.
6. International transfers
Some processors may store or process data outside the European Economic Area. Where that happens, transfers are protected by appropriate safeguards under the GDPR, such as the European Commission's Standard Contractual Clauses or an adequacy decision.
7. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict and port your data, to object to processing, and to withdraw consent at any time. To exercise any of these, email us at [email protected].
- Erasure (right to be forgotten) - you can delete your account yourself, directly in the dashboard, using the in-app account deletion flow (delete_own_account). This removes your account and associated profile data.
- Legacy cloud-sync deletion - delete your account in the dashboard or contact us to erase any retained encrypted blobs; once deleted they cannot be recovered.
- You also have the right to lodge a complaint with your supervisory authority - in Portugal, the Comissão Nacional de Proteção de Dados (CNPD).
8. Cookies & local storage
The site uses the storage needed to keep you signed in (Supabase auth/session tokens), minimal preference/session storage, and a server-validated, signed, HttpOnly first-party creator-referral cookie when you arrive through a valid creator link. That referral cookie lasts for up to 30 days and is cleared by the server after a successful waitlist submission. See the Cookies Policy for details.
9. Changes & contact
We may update this policy from time to time; material changes will be reflected by the date above. Questions or requests: [email protected].
Back to home