Privacy notice
Your change is personal. Your data stays yours.
Effective 9 September 2026 · Contact privacy@meliorly.com
Who is responsible
Meliorly is responsible for the processing described in this notice. Questions, privacy requests, and complaints can be sent to privacy@meliorly.com.
Meliorly is an AI coach for self-directed, everyday habit change. It is not a medical, therapy, monitoring, or emergency service. The app is intended only for adults aged 18 or over.
Data we handle
Depending on which features you use, this includes:
- Account and access data: your email address, internal account and session identifiers, session IP address and user agent, and the one-time code used to verify your email. The current onboarding flow records that you confirmed you are at least 18; it does not ask for your date of birth.
- Your habit programme: the goal you write, your reason for starting, approved plans and fallback steps, difficult moments, check-ins, progress, lapses, urges, and other reflections you choose to record. Some of this may reveal information about health or wellbeing.
- Coach data: messages between you and the coach, short memory notes the coach proposes, and whether you confirm, correct, reject, or delete each note.
- Context and safety data: your time zone, a country or region you select or that is coarsely inferred from device locale or device settings, and records of safety routing. A retained safety event contains the rule and resources shown, timing, region, and a hash of the relevant context—not your message transcript.
- App operation data: app version, request and audit identifiers, consent versions, deletion or export requests, and first-party notification events such as a reminder being scheduled, inferred as delivered or displayed, opened, or acted on. Meliorly has no third-party advertising or cross-app attribution SDK.
- Purchase data: the product, entitlement, store, transaction or receipt identifiers, price and currency, and an opaque store account token. Google, Apple, or Stripe handles payment details; Meliorly does not receive full card details.
- Support data: what you send us if you contact support, together with the information needed to answer and secure the request.
- Website data: IP address and ordinary request metadata processed by the services that host and protect this public website. Website visitors are not joined to Meliorly app accounts.
How we use it
We use this information to:
- create and secure your account and send sign-in codes;
- build the plans you approve, keep your habits in sync, show progress, prepare reminders, and help you return after a missed day;
- generate a coach reply and manage memory notes you control;
- provide offline, region-appropriate safety resources;
- verify purchases and apply the access you bought;
- detect misuse, investigate service faults, preserve service integrity, and keep a content-free audit trail of important system actions; and
- answer support, export, correction, and deletion requests.
We ask for explicit permission before processing health-adjacent habit information. Optional research follow-up and sponsor-level aggregate reporting each have their own separate choice. Refusing either optional choice does not stop you using Meliorly. Where relevant, account, purchase, security, and legal records are also processed to provide the service, protect it, or meet legal obligations.
What the AI coach receives
For a model-generated Coach reply, the approved provider receives the message being answered and a code-bounded window from the same habit's thread: at most 12 recent turns and 4,000 characters, with the oldest content removed first. It also receives the approved plan, limited momentum figures such as the programme day and recent completed or partial days, and—only when relevant—a small, bounded set of memory notes you confirmed. It does not receive your email address, account identifier, another habit's thread, free-text event or check-in notes, or proposed, rejected, or deleted memory notes.
Meliorly instructs its model routing provider to use only approved inference hosts with zero-data-retention support and to disable provider training or data collection for these requests. Full coach history may still be stored by Meliorly so you can reopen, export, or delete it, but only the bounded same-thread window described above can be reused for a later model turn.
Who processes data for us
We disclose only what each provider needs for its task. Our current providers are:
- Neon for the Meliorly Postgres database in AWS Asia Pacific (Singapore);
- Fly.io for the API service in Singapore;
- Resend for email sign-in codes;
- OpenRouter and a code-limited set of inference hosts for the minimal coach input described above;
- Google Play and Apple for native app purchases and receipt verification, and Stripe when a web purchase is offered; and
- OpenAI Sites and its edge delivery providers for this public website. App account data is not sent to the marketing site.
OpenRouter may route only to the providers allowed by Meliorly's production configuration, currently DeepInfra, DigitalOcean, Venice, Morph, Fireworks, AtlasCloud, CoreWeave, or Google Vertex. Providers may process data in Singapore, the United States, and other countries where they operate. Where required, we rely on provider data-processing terms and recognised transfer safeguards such as standard contractual clauses.
We may also disclose the minimum necessary information if the law requires it, to protect a person's rights or safety, or to investigate abuse of the service. We do not sell personal data or share it for targeted advertising.
How data is protected
Data travels over encrypted HTTPS connections. On the server, coach messages, memory text, self-report free text, and other designated sensitive values are encrypted with per-user keys before they are stored. Access to the database uses a restricted runtime role.
On your device, Meliorly may keep an account-bound, bounded offline cache of memory notes, recent coach messages, and prepared plan data. The local database is protected with SQLCipher and a device-only key kept through the operating system's secure storage. Authentication, consent, payment access, and deletion state are never restored from the offline cache. No security system can promise absolute protection, but we use layered controls and minimise what each provider receives.
How long data is kept
- A sign-in code expires after ten minutes. Expired verification and rate-limit records are short-lived and swept by the service.
- Live account, habit, plan, log, coach, and memory data remains until you delete the relevant memory note or delete your account.
- Deleting your account removes the live account data and encrypted content key immediately. An encrypted copy can remain in database backups until those backups expire, for up to 30 days. We do not restore a deleted account into the live service.
- Purchase records may be de-linked from your account and kept where needed for tax, accounting, refund, chargeback, and receipt replay prevention obligations.
- Consent versions, deletion records, de-identified safety events, and a content-free audit trail may remain without the link to your account so Meliorly can demonstrate what the service did and which wording applied. These accountability records contain no coach or goal wording and currently have no fixed automatic expiry.
- A provider may retain its own transaction, security, or backup record under its documented schedule or legal obligations. Meliorly does not describe a local deletion as proof of a provider action that has not occurred.
Optional website analytics
Google Analytics runs on this public website only if you allow it in Analytics preferences. It measures visits and limited actions such as making a planner result, copying a plan, opening the print dialog or downloading the workbook. Opening a print dialog does not tell us whether you printed, and a download click does not prove a file was saved.
We send only the referring website’s origin, excluding its path and search terms. The service processes ordinary connection and device information and uses analytics cookies. We do not send your planner answers, habit text, email address, app account identity, URL query strings or fragments. Advertising personalization and automatic interaction measurement are disabled. Website analytics is separate from the app.
You can refuse or withdraw permission using Analytics preferences at the bottom of any page. With analytics off, the Google tag is not loaded on future page loads, new events are disabled, and the site removes its accessible Google Analytics cookies. Your choice and analytics cookies are kept for up to 180 days. Blocking browser storage may mean choosing again. Withdrawal stops future collection; it does not erase previously collected reports.
Read Google’s privacy policy for its processing practices. Contact privacy@meliorly.com with questions. Copying, downloading or printing a plan is a separate action you control; keep those copies wherever you are comfortable storing them.
Your choices and rights
Inside Meliorly you can:
- review, correct, reject, or delete individual coach memory notes;
- review and withdraw each privacy choice separately;
- export your account data; and
- delete your account and live programme data.
The public account deletion instructions explain the same route if you no longer have the app. You may also contact privacy@meliorly.com to request access, correction, deletion, restriction, portability, or withdrawal of consent where your local law provides those rights. We will verify the request before acting so that another person cannot obtain or erase your account.
Adults only
Meliorly is not directed to anyone under 18. If the service learns that an account holder is under 18, programme access is locked and only public safety resources and data-rights routes remain available. Contact us if you believe a minor has provided personal data.
Changes to this notice
We will update the effective date when this notice changes. If a change materially affects the permission needed to run your programme, Meliorly will ask you to review the new wording before continuing.