Privacy Policy.
Effective: September 23, 2026
This Privacy Notice explains how Mellovy handles personal data when you use Mellovy as an individual consumer. It describes the information we collect, why we use it, how long we keep it, and the choices and rights available to you.
1. Who is responsible for your personal data?
Mellovy AB, Swedish company registration number 559598-6257 and VAT number SE559598625701, Lyngavägen 15G, 305 64 Gullbrandstorp, Sweden, is the controller for the processing described in this notice. Contact us at [email protected]. Mellovy has not appointed a Data Protection Officer.
If an employer or another organization provides your Mellovy account, that organization may be the controller for content it asks Mellovy to process, and Mellovy may act as its processor under a separate data processing agreement. The organization's privacy information applies to that processing. This notice still covers Mellovy's own purposes, such as account administration, billing and service security.
2. Personal data we process
The information we process depends on the features and connections you use.
- Account and contact information: your name, email address, account settings and information needed to administer your account.
- Purchase and payment information: your subscription, payment status, billing information and payment events. Card details are handled by the payment provider and are not provided to Mellovy where that provider collects them directly.
- Use and technical information: the features you use, when you use them, plan and usage measurements, and records needed to administer usage limits and billing. These events may be associated with your account, organisation, workflow and time of use. We also process device and browser information, IP address, diagnostics, error reports, and service and security logs.
- Content and agent information: instructions, prompts, files, messages, feedback and other content you provide, together with AI-generated responses and information needed to run agents and workflows you request.
- Connected sources: information from email, calendar or other services that you choose to connect and authorize Mellovy to access. This information may include personal data about other people.
- Support communications: messages you send to us and the information needed to handle your request.
- Business and professional contact information: names, professional roles, company affiliations and publicly available business contact details for representatives of prospective or current business customers. We obtain this information from public company registers and annual reports, company websites, public job advertisements, public news and public procurement notices, business-information providers, HubSpot records and people or organisations who contact us.
- Website and form information: when you submit an email capture form, the email address you enter, the page name and URL, browser language, and the company domain derived from your email address.
- Website statistics: when you open a page on mellovy.com, our server adds one to a count for that page. The count is labelled with the page address, the domain of the site that linked to it, any campaign tags in the link, the country Cloudflare derives from your IP address, and whether the page was the first one of the visit. The server reads this from the request your browser already sends to load the page, uses no cookie, stores no IP address, browser details or identifier, and nothing leaves our own infrastructure. The result is a set of totals that cannot tell one visitor from another.
- Cookies and similar technologies: information collected through cookies and similar technologies, if used, as described in our Cookie Notice.
Please provide information about another person only when it is needed for your use of Mellovy and you are entitled to provide it. Do not submit special category or other sensitive personal data unless a feature expressly supports it and you are entitled to use it.
3. Why we use personal data
| Purpose | Legal basis |
|---|---|
| Create and administer your account, provide the service, and run features or agents you request. | Necessary to perform our contract with you (GDPR Article 6(1)(b)). |
| Measure work in Mellovy credits, apply the plan allowance and limits, and calculate any usage charges expressly accepted for your account. Metered work includes model input and output, cached input, tool invocations, evaluation and judge runs, and stored data. | Necessary to perform our contract with you (Article 6(1)(b)). |
| Process purchases, payments and refunds, and meet bookkeeping duties. | Contract performance (Article 6(1)(b)) and legal obligation (Article 6(1)(c)). |
| Operate, secure and troubleshoot the service, and prevent fraud or abuse. | Our legitimate interests in maintaining secure, reliable operations and preventing misuse (Article 6(1)(f)). |
| Answer support requests and send service communications. | Contract performance or our legitimate interests, depending on the communication (Articles 6(1)(b) and 6(1)(f)). |
| Identify relevant business organisations, manage prospective-customer records, and contact business representatives about Mellovy’s services. | Our legitimate interests in developing and maintaining business relationships and offering relevant services (Article 6(1)(f)). You may object to direct marketing at any time. |
| Receive and respond to an email capture form submission. | Steps taken at your request before a possible contract (Article 6(1)(b)) or our legitimate interests in responding to your request (Article 6(1)(f)), depending on the request. |
| Count page views on mellovy.com on our own server, without cookies and without any identifier, as described under Website statistics in section 2. | Our legitimate interest in knowing which pages people read and how they find the site (Article 6(1)(f)). The counts themselves are anonymous. |
| Measure how the website is used with Google Analytics and Microsoft Clarity, after you accept the analytics cookie category. | Your consent (Article 6(1)(a)). |
| Improve a model or the service using content you have specifically chosen to contribute. | Your separate consent (Article 6(1)(a)). |
If you do not provide information needed to create an account, take payment, or operate a feature you request, we may be unable to provide that account or feature.
4. AI features and usage measurement
When you use an AI feature, we process your instructions and the content needed to generate a response or carry out the action you requested. The chat interface identifies when you are interacting with AI. We also process usage measurements to apply the plan allowance and limits shown before purchase. The app shows a weekly usage percentage as an indicator; it is not a cash amount or a fixed amount of work. The work available within a limit may vary with the model, context, files and tools used. Current usage and billing are available in the account at app.mellovy.com.
Mellovy currently uses Anthropic, PBC to provide inference for AI-agent features. Depending on the task and the tools you enable, a request may include your prompts and instructions, files or connected-source content, retrieved information, tool results, and earlier or generated outputs needed to complete the task. Mellovy does not include a direct Mellovy account ID, user ID or email address in the Anthropic request by default. Content you submit or connect may itself identify you or another person. Anthropic may process this data in the locations described in the Data Processing Addendum and its linked terms. Berget AI and xAI are not currently used for production inference; we will update this notice before enabling them for customer data.
5. Optional model or service improvement
Mellovy does not use your conversations or agent data to train or fine-tune models by default. Accepting the Terms does not opt you into model training.
The model-improvement control in your account settings is separate, voluntary and off by default. Before you choose, it explains which data is included, the specific purposes, recipients, whether people may review the material, and how long it will be kept. You can use the ordinary service without opting in. We record your choice.
You can withdraw your consent at any time through the same account setting or by contacting [email protected]. Withdrawal does not affect processing already carried out lawfully. We will stop using new data on the basis of that consent and delete or restrict identifiable material that has not yet been incorporated into a model, to the extent technically and legally possible. It may not be possible to change a model that has already been trained by removing individual training data; we do not promise that a model can forget information already used in training.
Your choice does not automatically cover personal data about other people in your content or connected sources. We use those people's data for model improvement only if Mellovy has a separate valid legal basis.
6. Personal data about other people
If you connect email, calendar or another source, we may process information about people who do not have a Mellovy account. We use that information only to the extent needed for the feature you requested, secure operation and support. Where required, we provide those people with information under GDPR Article 14. We rely on an exception to that information duty only where its legal conditions are met and appropriate safeguards have been assessed.
7. Recipients and service providers
We disclose personal data to the service providers below only where the relevant website or product feature is used. A provider may process data in the locations stated below and through its own listed affiliates or subprocessors. The exact features enabled for your account appear in your service settings or order.
- Hetzner Online GmbH: hosting and server operations in Germany (EEA).
- HubSpot, Inc.: our CRM provider for business account and contact records and website email-capture submissions. The website email-capture form sends the email address entered, the email's company domain where available, preferred language, lead-status fields, and the page name and URL. It also sends the form's data-processing notice. This submission does not depend on whether you accept optional analytics or advertising cookies and does not include campaign identifiers. HubSpot tracking technologies are enabled only after the relevant cookie choice. The Mellovy HubSpot portal is hosted in HubSpot’s EU1 region (Germany). HubSpot affiliates may access data from the countries listed on its subprocessor page, including the United States and Singapore. HubSpot’s DPA describes its transfer terms, including the EU-U.S. Data Privacy Framework where available and Standard Contractual Clauses where required. HubSpot’s website tracking technologies are enabled only after you accept the relevant analytics or advertising cookie category.
- Google Ireland Limited: website analytics through Google Analytics 4, only if you accept the analytics cookie category. Google receives information about your visit to mellovy.com, such as pages viewed, referrer, device and browser details, approximate location and an online identifier stored in a cookie. Mellovy keeps Google signals and ad personalisation signals off. Google may transfer data to the United States and other countries where Google LLC and its subprocessors operate, under the Google Ads Data Processing Terms, including the EU-U.S. Data Privacy Framework where available and Standard Contractual Clauses where required.
- Microsoft Corporation: website usage analytics through Microsoft Clarity, only if you accept the analytics cookie category. Clarity receives information about how you interact with mellovy.com pages, such as clicks, scrolling, mouse movement, device and browser details and an online identifier stored in a cookie, and can reconstruct a session as a recording. Clarity masks sensitive input by default. Microsoft may transfer data to the United States and other countries under the Microsoft Products and Services DPA, including the EU-U.S. Data Privacy Framework where available and Standard Contractual Clauses where required.
- Stripe Payments Europe Limited and Stripe, Inc.: payment processing and payment fraud prevention if billing features are enabled. Stripe may transfer data to the United States and other countries where its affiliates and subprocessors operate. Its DPA and Data Transfers Addendum describe use of the EU-U.S. Data Privacy Framework where applicable and Standard Contractual Clauses as an alternative where required.
- Cloudflare, Inc.: content delivery, DNS and security where those features are enabled. Its global network may process information at locations outside the EEA. Transfers are governed by the Cloudflare DPA and its applicable transfer safeguards, including Standard Contractual Clauses.
- WorkOS, Inc.: authentication and organisation identity if single sign-on or organisation login is enabled. WorkOS may transfer data to the United States and other locations used by its subprocessors under its DPA, including Standard Contractual Clauses where required.
- Anthropic, PBC: live AI-agent inference. Depending on the task and enabled tools, Anthropic may receive prompts and instructions, files, connected-source content, retrieved information, tool results, and earlier or generated outputs needed to complete the task. Mellovy does not include a direct account ID, user ID or email address in the request by default, but content may itself identify a person. Anthropic may process data in selected locations in the United States, Europe, Asia and Australia and stores data in the United States unless the parties agree otherwise. Its commercial terms and DPA include Standard Contractual Clauses for transfers where required.
- Twilio Segment: product analytics and event routing. It receives usage and diagnostic events, event properties and any account or user identifiers Mellovy includes in those events. Prompts, files and connected-source content are not needed for analytics and are not intended to be sent as event properties. Twilio offers EU regional processing, but its affiliates and subprocessors operate internationally. Its Data Protection Addendum and subprocessor list describe transfer safeguards.
- ClickHouse, Inc.: usage measurement, operational and diagnostic records sent to Mellovy’s data store. Records may include event details and identifiers; prompts and files are not needed for this function and are not intended to be stored there. If ClickHouse Cloud is used, the hosting region is selected for the service, while its published schedule also lists control-plane and support processing in the United States, Germany and Singapore. See ClickHouse’s DPA and subprocessor schedule.
- GitHub, Inc.: code repository and development collaboration. GitHub may receive repository content, source code, issues, pull requests, developer account information and technical logs. It is not used as the routine store for prompts or agent conversations. GitHub states that it processes personal data in multiple locations, including the United States and countries where its affiliates and subprocessors operate. See its privacy statement and subprocessor list.
The providers used for Customer Personal Data when Mellovy acts as a processor are also listed in the Data Processing Addendum. Information about browser storage and website technologies is in the Cookie Policy. We do not sell your personal data. We may disclose data to public authorities where required by law, or where needed to establish, exercise or defend legal claims.
8. International transfers
The provider information above identifies the countries or regions in which each provider may process personal data and links to its transfer terms. We transfer personal data outside the EU/EEA only where a transfer mechanism permitted by GDPR Chapter V applies. The specific mechanism and any required supplementary measures depend on the provider and feature used. You may request information about the mechanism applicable to your data by contacting [email protected].
9. How long we keep personal data
We apply the following retention criteria. We delete or anonymise personal data when the relevant purpose ends, unless a legal obligation, security investigation or legal claim requires limited retention for longer.
- Account and access information: while the account is active and as needed to close it, resolve outstanding payments and protect the service.
- Prompts, files, conversations, outputs and workflow data: while retained in your account or needed to complete the workflow you requested. We remove them when you delete them or close the account, subject to limited records needed for security, billing disputes or legal claims.
- Data retrieved from connected sources: while needed for the enabled feature. We stop retrieving it when you disconnect the source and remove stored copies when they are no longer needed for that feature or your account is closed.
- Usage, diagnostic and security records: while needed to measure and bill for use, operate and secure the service, and investigate a specific incident or dispute. Records retained for an incident or dispute are deleted when that purpose ends, unless law requires longer retention.
- Accounting records: for the statutory retention period applicable to the relevant record.
- Business and professional contact records: while needed to evaluate or maintain a relevant business relationship or sales request. We remove or suppress records when they are no longer relevant, when a person objects to direct marketing, or when the purpose ends. We retain only the minimum contact information needed to honour an objection and prevent further marketing.
- Website and form information: until we have handled your request and no further follow-up is needed, unless you enter a customer relationship, separately request further contact, or law requires retention.
- Website statistics: only anonymous counts are stored, so there is nothing to delete about you. The request itself is not stored.
- Website analytics: Google Analytics keeps event-level data for two months, the retention period set for Mellovy’s Google Analytics property, and then deletes it. Microsoft Clarity keeps data for the periods Microsoft sets for Clarity. Your cookie choice itself is stored in your browser for six months.
- Records of notices, model-improvement choices, withdrawals, deletion requests and marketing opt-outs: only the information needed to show what choice was made and to honour it. We retain that evidence while it may reasonably be needed to demonstrate compliance, address a related claim or respond to a regulatory question, then delete or anonymise it.
Operational, usage and security records are kept only as long as needed for the relevant operational, billing, security or investigation purpose. Accounting records are kept for the applicable statutory period. Where you separately authorise model or service improvement, the information shown when you make that choice states the retention period for that use. Backups and provider copies are removed under the applicable deletion processes; where immediate deletion from a backup is not technically practicable, the data remains protected and is deleted through the ordinary backup cycle.
10. Your rights
Subject to the conditions in the GDPR, you may request access to, correction or deletion of your personal data, restriction of processing, or data portability where the GDPR grants that right. In particular, portability applies to data you provided that is processed by automated means on the basis of consent or contract. You may object to processing based on legitimate interests and withdraw consent at any time. Contact [email protected]. We may need to verify your identity before responding.
You may object at any time to the use of your personal data for direct marketing, including related profiling. After you object, we will stop using your data for that purpose.
You may complain to the Swedish Authority for Privacy Protection (IMY) at imy.se.
11. AI transparency
Mellovy uses AI for agent and content-generation features. The chat interface identifies when you interact with AI. Depending on the feature and the parties' roles, applicable law may require other notices or markings for AI-generated content. This notice does not replace any in-product notice or marking required by law.
12. Security and changes
We use technical and organizational measures appropriate to the risks, as required by GDPR Article 32. If we change our processing in a way that requires new information, we will update this notice and notify you where the law requires it. The current version is published at mellovy.com/legal.
13. Contact
Mellovy AB
Lyngavägen 15G
305 64 Gullbrandstorp, Sweden
[email protected]
[email protected]