Privacy policy
Last updated: July 2026
The short version
We collect what we need to run your AI team and nothing more. We do not sell your data, we do not use your content to train foundation models, and we do not set tracking cookies. What you build belongs to you.
1. Scope
This policy covers the Melcor.ai platform, operated by Melcorsoft LLC, a Florida limited liability company. It does not cover the apps founders build and publish with Melcor: each founder is responsible for their own app and its visitors (see Section 6).
2. What we collect
- Account information: your name, email address, and sign-in method (email or Google).
- Workspace content: your standup conversations, decisions, plans (including your Build Contract), project state, build logs, and the application code generated for your projects.
- Usage and telemetry: product events (pages viewed, features used), build timings and outcomes, and AI model usage and cost metadata we need to operate and bill the Service.
- Support communications: emails you send us.
3. How we use it
- To provide the Service: your workspace content is sent to AI model providers to generate your team's responses and your app's code.
- To operate, secure, and improve the platform, and to prevent abuse.
- To send transactional email (sign-in, account, and service notices). We do not send marketing email without your consent.
4. AI model providers
Your AI team is powered by third-party models, including those from OpenAI, Anthropic, and Google, and models accessed through OpenRouter. The content needed to answer you or build your app is processed by these providers under agreements that restrict their use of it. We do not use your content to train foundation models, and we do not permit our providers to do so through the APIs we use.
5. Analytics, session replay, and cookies
- We use PostHog (hosted in the United States) for product analytics: pageviews, clicks, and feature events. It runs without tracking cookies (it uses browser localStorage), anonymous visitors do not get a stored profile, and we do no cross-site advertising or tracking.
- If session replay is enabled to help us fix product issues, everything you type into any input field is masked before it leaves your browser: we cannot see emails, passwords, or form text in a replay.
- The only cookies we set are essential ones that keep you signed in. Because we use no advertising or non-essential cookies, we do not show a cookie banner.
6. Your app's visitors
When visitors submit a form on an app you built with Melcor (for example a waitlist, order, or contact form), that submission is delivered to your dashboard. That data belongs to you: we store and process it on your behalf so you can act on it, and we do not use it for our own purposes. You are responsible for how your app collects and uses its visitors' data, including any privacy notice your app needs.
7. Who we share data with
We do not sell personal data. We share data only with the providers that run the Service, under their processing terms:
- Supabase (database and authentication)
- Google Cloud (hosting, builds, and deployment of your apps)
- GitHub (managed code repositories for your projects)
- Resend (transactional email)
- PostHog (product analytics)
- AI model providers (Section 4)
We may also disclose information if required by law, or as part of a merger, acquisition, or asset sale, in which case this policy continues to apply to your data.
8. Where your data lives
Melcor is operated from the United States and your data is processed and stored on US infrastructure. By using the Service you understand your data is transferred to and processed in the US.
9. Retention and deletion
We keep your account and workspace data while your account is active so your team remembers your project. You can export your code and data at any time, and you can ask us to delete your account and its data by emailing hello@melcor.ai. We delete or de-identify it within 30 days, except where the law requires us to keep it longer.
10. Security
Your workspace is isolated from other customers, data is encrypted in transit, and access to production systems is restricted and audited. No system is perfectly secure; if a breach affects your data we will notify you as required by law.
11. Children
The Service is for business use and is not directed to children under 16. We do not knowingly collect their data.
12. Changes
We may update this policy as the Service evolves. For material changes we will give notice (for example by email or in the app) before the change takes effect.
13. Contact
Privacy questions or requests: hello@melcor.ai.