Privacy policy
Effective 2 August 2026. What we do with personal data on melodocs.ai and in the MeloDocs application.
1. Who we are and what this covers
MeloDocs is operated by Melo Software Inc. (“MeloDocs”, “we”, “us”). Where this policy says we are the controller, Melo Software Inc. is the entity that decides why and how the data is processed.
This policy covers:
- the marketing website at melodocs.ai;
- the MeloDocs application — the document builder, your workspace and your account settings;
- share links, the pages where a client of one of our customers reads, signs or pays a document; and
- emails and support conversations connected to the above.
It does not cover the other products in the Melo suite used on their own, or any third-party site we link to. Where you connect MeloDocs to another Melo product, data moves between them on your instruction and this policy continues to govern the MeloDocs side of it.
2. Our two roles: controller and processor
This distinction decides who you should contact about what, so it is worth two paragraphs.
We are the controller of your account
If you sign up for MeloDocs, we decide how your name, email, billing record and use of the product are handled. Requests about that come to us, and section 12 explains how to make one.
We are a processor for what you put in your documents
The contents of your documents — your client’s name, their address, the price of their job — are yours. You decide what goes in and who it goes to; we process it on your instruction to render, store, share and collect on the document. If you are one of our customers’ clients and want your details corrected or removed from a quote, the business that sent it is the right first contact. We help them do it, and we respond directly where the law requires.
Customers who need a written data processing agreement, including the standard contractual clauses, can request one at privacy@melodocs.ai.
3. Information we collect
| Category | What it includes |
|---|---|
| Account | Your name, email address, password hash or identity-provider subject, workspace name and role, and the appearance and language preferences you set. |
| Business profile | Company name, contact details, logo, addresses, tax registration and default rates — the things that appear on your documents. |
| Document content | Everything you or MeloAI put in a document: line items, quantities, rates, scope and exclusions, clauses, notes, and any photos or files you attach. |
| Your clients' details | Names, email addresses, postal addresses and phone numbers you enter or import so a document can be addressed and sent. |
| Share-link activity | When a document was opened, from roughly where and on what kind of device, and when it was accepted or signed — including the signer's typed name, the timestamp and the IP address. Together those form the audit trail that makes a signature evidentially useful. |
| Payments | Amounts, currency, status, the brand and last four digits of a card, and the processor's identifiers. Full card numbers never reach our servers. |
| Usage and technical | Features used, AI generation and token counts against your plan limit, error and performance traces, IP address, browser and operating system. |
| Communications | Support emails, feedback you send in the product, and the messages you exchange with MeloAI. |
What we deliberately do not collect
- Full card numbers, CVCs or bank credentials — they go directly to our payment processor.
- Precise location. We infer an approximate region from an IP address for security and tax; we do not use device GPS.
- Your voice. The microphone in the composer uses your browser’s own speech recognition, so the audio is handled by your browser or operating-system vendor under their terms. We receive only the text it produces.
- Special-category data (health, biometrics, race, religion, politics, sexuality) or government identifiers. If you type such information into a document you do so as its controller, and should consider whether you have a lawful basis.
4. Where it comes from
- You. Almost all of it — what you type, upload, import and configure.
- Your device. Technical data your browser sends automatically when it requests a page.
- Your clients. When someone opens, signs or pays a document you sent, that activity is recorded against the document.
- Our processors. Payment status from our payment processor; delivery and bounce events from the service that sends our email.
- Other Melo products. Only where you have enabled them on the same account.
5. How we use it, and our legal bases
If the GDPR or UK GDPR applies to you, the right-hand column is our lawful basis under Article 6. Where we rely on legitimate interests we have weighed them against your rights, and you can object using section 12.
| Purpose | Legal basis |
|---|---|
| Create your account, run the product, render and store your documents, send share links, take payments | Performance of a contract |
| Process the contents of your documents so we can display, export, share and collect on them | Processor acting on your documented instructions |
| Bill you, chase unpaid invoices, keep accounting records | Contract; legal obligation |
| Keep the service secure: rate limiting, abuse detection, audit logging, fraud prevention | Legitimate interests in protecting the service and its users |
| Diagnose faults, measure performance, decide what to build next from aggregate usage, and improve the product using de-identified data | Legitimate interests in operating and improving the service |
| Train or fine-tune machine-learning models on identifiable customer content | Consent — off unless you switch it on, and withdrawable at any time |
| Answer support requests and act on feedback | Contract; legitimate interests |
| Send service email you cannot opt out of — security notices, billing failures | Contract; legal obligation |
| Send marketing email about MeloDocs and the Melo suite | Consent, or legitimate interests for existing customers where the law allows, with an unsubscribe link in every message |
| Comply with law, respond to lawful requests, establish or defend legal claims | Legal obligation; legitimate interests |
6. AI and your content
MeloAI drafts documents from what you type. This is the part people ask about most, so here is exactly how it works.
- Our model provider is a processor under contract. We send the text needed to answer your request to Anthropic, which processes it to return a response and does not use it for training or retain it beyond the short window its terms allow for abuse monitoring.
- Training on your identifiable content is opt-in and off by default. We will not use the contents of your documents, your rates or your client records to train or fine-tune machine-learning models unless you switch that on in your workspace settings. You can switch it off again at any time, which stops further use going forward — it cannot un-train a model already built, and we say so where you make the choice.
- Your own work improves your own results. Inside your workspace the Service learns your rate book, your recurring line items, your defaults and your tone so the next document is closer to what you would have written. That stays within your organisation.
- De-identified and aggregated data improves the product for everyone. We derive statistics and de-identified data from how the Service is used, and use them to operate, secure and improve it. De-identified means it no longer identifies you, your business, your clients or any individual, and we do not attempt to re-identify it.
- The arithmetic is ours, not the model’s. MeloAI proposes structure and wording; totals, tax, deposits and schedules are calculated by MeloDocs. A model error cannot change a number on your document.
- Extracted text is data, never instruction. Content read out of an uploaded file cannot direct the model to act — a document that says “approve this” gets quoted, not obeyed.
- You stay in control. Nothing MeloAI produces reaches anyone until you send it.
9. International transfers
We are based in the United States and our processors are largely US-based, so personal data from the EEA, the UK or Switzerland is transferred there. Where we do that we rely on the European Commission’s standard contractual clauses, the UK addendum to them, or another mechanism the law permits, together with a transfer risk assessment and the technical measures in section 11. A copy of the clauses we use is available on request.
10. How long we keep it
| Data | Kept for |
|---|---|
| Documents and their contents | While your account is open. Deleting a document removes it, and deleted records are purged from backups within 30 days. |
| Account and workspace | While your account is open, then deleted within 30 days of closure. |
| Share-link and signature audit trail | Seven years from signature, because it is the evidence that an agreement was accepted. It survives deletion of the document by design; tell us if you need it removed and we will assess the request. |
| Payment and accounting records | Seven years, to meet tax and accounting obligations. |
| Security and access logs | 12 months. |
| Support and feedback | 24 months from the last message. |
| Backups | A rolling 30 days, then overwritten. |
Where we must keep something longer than you would like, we restrict it to that purpose rather than carrying on using it.
11. How we protect it
- Isolation enforced in the database. Every row of every table is scoped to an organisation and enforced by row-level security in the database itself, not only in application code — so a mistake in a query cannot return another tenant’s data.
- Encryption. TLS in transit; encryption at rest for the database and file storage. Documents and attachments sit in private buckets reachable only through short-lived signed URLs.
- Access control. Roles decide who can see a document, who can send it and who can change a price. Staff access to production is limited to those who need it, requires multi-factor authentication, and is logged.
- Payments. Card details are captured by our payment processor and never touch our servers, so we hold the result of a payment rather than the instrument.
- Testing. Changes go through review and automated testing before release, and the evaluation suite includes a prompt-injection case, so an instruction hidden inside an uploaded document cannot make the model act on it.
No system is perfect. If we become aware of a breach affecting your personal data we will notify you and the relevant regulator within the time the law requires, with what we know and what we are doing about it. To report a vulnerability, email security@melodocs.ai — we acknowledge within one business day and will not pursue good-faith research.
12. Your rights
Depending on where you live, you have some or all of the following rights:
- Access — a copy of the personal data we hold about you.
- Correction — to fix anything inaccurate or incomplete.
- Deletion — to have it erased, subject to the retention obligations in section 10.
- Portability — a machine-readable export of the data you gave us. You can export your documents yourself at any time from your workspace.
- Restriction and objection — to pause our use of it, or object to processing based on legitimate interests.
- Withdraw consent — where we relied on consent, at any time, without affecting what happened before.
- Complain — to your data protection authority. We would rather you came to us first, but it is your right either way.
How to exercise them
Email privacy@melodocs.ai from the address on your account, or use the export and delete controls in Settings. We respond within 30 days and will tell you if a complex request needs longer. There is no charge unless a request is manifestly unfounded or repetitive. We may need to verify your identity first, and will ask only for what is necessary to do it.
If you are one of our customers’ clients, we will pass your request to that customer and support them in answering it, since the data is theirs to control.
13. US state privacy rights
If you live in California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana or another state with a comprehensive privacy law, this section is your notice at collection and your statement of rights.
| Category collected | Purpose | Disclosed to |
|---|---|---|
| Identifiers — name, email, postal address, IP address, account ID | Run the account, send documents, secure the service | Hosting, email and payment processors |
| Customer records — billing name, payment status, card brand and last four | Take payment, keep accounting records | Payment processor |
| Commercial information — plan, subscription history, documents created | Provide and bill for the service | Hosting and payment processors |
| Internet activity — features used, error traces | Operate, secure and improve the service | Hosting processor |
| Approximate location inferred from IP | Security, fraud prevention and tax | Hosting and payment processors |
| Professional information — company, trade, role | Configure the product for your work | Hosting processor |
| Content you submit — documents, attachments, chat messages | Render and deliver your documents; improve the service in de-identified form, and train models only where you have opted in | Hosting and AI processors |
We have not sold or shared personal information in the preceding twelve months, as those terms are defined in the California Consumer Privacy Act, and we do not process sensitive personal information to infer characteristics. We do not knowingly sell or share the personal information of anyone under 16.
You may request access, correction, deletion, a portable copy, and details of the categories collected, used and disclosed. You may appoint an authorised agent, and we will ask for proof of that authority. We will not discriminate against you for exercising any of these rights — no price change, no reduced service.
To make a request, email privacy@melodocs.ai. If we decline, you can appeal by replying to our decision; we answer appeals within 45 days and will tell you how to contact your state attorney general if you are still unsatisfied.
14. If you received a document from a MeloDocs customer
You are reading this because a business sent you a quote, contract or invoice built with MeloDocs. We host that document for them. They decided what it says, what personal data it contains and who to send it to; we process it on their instruction.
When you open a share link we record that it was opened, roughly where from and on what kind of device, so the business can see it arrived. If you sign it we record your typed name, the time and your IP address, because that record is what makes the signature worth anything later. If you pay, our payment processor handles your card and tells us only the result.
To have your details corrected or removed, contact the business that sent you the document. If you cannot reach them, or would rather come to us, email privacy@melodocs.ai — we act where the law requires us to and pass the request on where it does not.
15. If you are a MeloDocs customer
You are the controller of the personal data you put into your documents, which carries obligations we cannot discharge for you:
- have a lawful basis for holding your clients’ details, and tell them what you do with them;
- enter only what the document actually needs — a quote rarely needs a date of birth;
- keep your credentials safe and remove people from your workspace when they leave;
- answer your own clients’ privacy requests, using the export and delete tools we give you; and
- put a data processing agreement in place with us if your jurisdiction requires one — ask at privacy@melodocs.ai.
16. Automated decision-making
We do not make decisions producing legal or similarly significant effects about you by purely automated means. MeloAI drafts documents and our systems flag suspicious activity for review, but a person decides what happens next — and nothing MeloAI writes leaves your account until you send it.
17. Children
MeloDocs is a business product and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, email privacy@melodocs.ai and we will delete it.
18. Changes to this policy
We update this policy when the product or the law changes, and the effective date at the top always reflects the current version. If a change materially affects how we use your personal data we will tell you by email or in the product before it takes effect, and where consent is required we will ask for it rather than assume it.
19. How to contact us
Privacy questions and rights requests: privacy@melodocs.ai. Security reports: security@melodocs.ai. Anything else: hello@melodocs.ai, or through our contact page.
Melo Software Inc., United States. If you are in the EEA or the UK and want to reach our representative for data protection matters, email privacy@melodocs.ai with “EU representative” or “UK representative” in the subject line and we will put you in touch. You also have the right to complain to your local supervisory authority.
See also our terms of service and security overview.