Last updated: August 6, 2026
The short version
Melvin is an assistant that does things on your Mac. To do that it has to see things: the app you are in, the page you are on, the task you typed. This page explains exactly what stays on your machine, what leaves it, and who receives it.
- Most of what Melvin learns about you stays on your Mac and is never uploaded.
- When you give Melvin a task, the text of that task and the context needed to carry it out are sent to an AI model provider. That is how the product works.
- We record product analytics that include the text of your prompts, so we can see where Melvin fails. This is described in full below, and we would rather tell you plainly than bury it.
- We do not sell your personal information, and we do not run advertising.
- You can delete your account and your local data at any time.
This summary is not the policy. The sections below are.
1. Who we are and what this covers
[LEGAL ENTITY NAME] of [REGISTERED ADDRESS] (“Melvin”, “we”) is the controller of the personal data described here. This policy covers the Melvin macOS application, trymelvin.com, the Melvin account and billing services, and the optional Melvin Chrome extension.
It does not cover third-party services you connect to Melvin, or websites Melvin visits on your instruction. Those are governed by their own policies.
2. What we collect
Account and billing
- Your email address, and a display name (which defaults to the part of your email before the @, and which you can change).
- Authentication identifiers and session tokens.
- Your plan, subscription status, trial start date, and how many runs you have used.
- Payment details are collected and stored by Stripe, not by us. We never see or store your card number. Stripe holds your billing address, and a tax ID if you provide one; we store only Stripe’s customer and subscription identifiers.
Task content
- The text of tasks and questions you give Melvin.
- The context needed to carry a task out: the contents of the app window or web page you point Melvin at, the accessibility structure of that interface, and, when you ask Melvin about your screen, a screenshot of it.
- Content from services you explicitly connect, such as mail, calendar, reminders, or contacts, limited to what a task requires.
Usage and diagnostics
- Product analytics tied to a per-installation identifier and, once you sign in, to your account. These records include the text of your prompts (up to the first 4,000 characters), which model was used, how many steps a run took, what it cost, whether it succeeded, and error categories. We use this to find where Melvin is failing people.
- Run counts and cost totals, used to enforce plan limits.
- Anonymous, aggregated learning contributions: when Melvin works out how to do something, it may contribute a generalised pattern to a shared library. A contribution can include up to 200 characters of your task text. You can turn this off in Settings.
Approximate location
For weather and “near me” style questions, Melvin may look up your approximate location from your IP address using ipapi.co. You can set a manual location in Settings instead, which stops these lookups.
3. What stays on your Mac
A large part of what Melvin knows about you never leaves your machine. It is stored under Melvin’s Application Support directory and in ~/.melvin:
- Activity history. While observation is enabled, Melvin records which application you are in, the window title, and the full address of the page you are viewing, along with file paths in editors. It records the length and a coarse category of text you select, but not the text itself.
- Learned patterns. Models built from that history. These retain application names and the domains you visit as part of their structure.
- Run logs. A detailed record of each run, including the plan, the steps, tool inputs and outputs, and anything you were asked and answered. Email addresses, phone numbers and credentials are masked in these logs, but they are otherwise complete.
- Workflows, schedules, templates and learned UI handles for the apps and sites you use.
- A dedicated browser profile, if you use Melvin’s own browser rather than your Chrome. It holds cookies, logins and history for the sites Melvin visits for you.
- Credentials. Account, mail and integration tokens are held in the macOS Keychain. Note that if you enter your own API keys for optional third-party search providers, those are stored in a settings file on disk rather than the Keychain.
Voice input is transcribed locally on your Mac. Audio is held in memory and is not written to disk or uploaded. Your chat history with the Ask surface is kept in memory only.
4. What leaves your Mac, and who receives it
These recipients are active by default, because the product does not function without them.
| Recipient | What they receive | When |
|---|---|---|
| Supabase Our database, sign-in and server functions | Your email, display name, synced settings, plan and usage counters, product analytics including prompt text, and synced skills. | On sign-in, and while you use Melvin. |
| DeepSeek AI model provider | Your task text and the context needed to answer it, which can include page and document content and screenshots. Sent through our server, so DeepSeek does not receive your identity or IP address. | Each time you ask or run something. |
| Tavily, and DuckDuckGo as a fallback Web search | Your search query. Tavily is called by our server; DuckDuckGo is fetched directly by your Mac. | When a task needs a web search. |
| Our memory service Hosted on Render | Context and memory records used to give Melvin continuity between sessions. | While memory is enabled. It can be turned off in Settings. |
| ipapi.co IP geolocation | Your IP address, in exchange for an approximate city. | Only for location-dependent questions, and not if you set a manual location. |
| Stripe Payments | Your email, name, billing address, payment method and subscription. Card details go to Stripe directly and never reach us. | When you subscribe or manage billing. |
| GitHub App updates | Your IP address and app version, as part of checking for and downloading updates. | Automatically, to keep the app current. |
| Vercel and Google Fonts Website hosting and fonts | Standard web request data, including your IP address, when you visit trymelvin.com. | When you visit the site. |
| Websites Melvin visits | Whatever the task involves. Requests come from your own machine and IP. When Melvin drives your own Chrome, they carry that browser’s existing cookies and sessions, exactly as if you had visited yourself. | When you give Melvin a task involving the web. |
Only if you choose it
These are off unless you connect an account, supply your own API key, or enable a feature: Google (sign-in, Gmail, Docs and Drive), Apple and Microsoft sign-in, Slack, mail servers you connect over IMAP, Anthropic, OpenRouter, Alibaba DashScope, Brave Search, Exa, a CAPTCHA-solving provider, any Model Context Protocol servers you install, and any diagnostics endpoint you configure yourself. Where you supply your own key, your Mac contacts that provider directly.
Crash reporting
Melvin includes crash reporting and the setting is on by default, but no reporting endpoint is configured in the released build, so no crash reports are currently transmitted. If that changes, this page will be updated before it does. You can turn the setting off regardless.
5. The Chrome extension
The optional Melvin extension lets Melvin work in the Chrome you are already signed into, rather than a separate signed-out browser. It is the browser half of the Mac app and does nothing on its own.
To carry out a task, it reads the content of the page you direct it to and the addresses and titles of your open tabs, so it can find the right one. Because you can point it at any page, that content can include personal information or the contents of your mail.
The extension itself sends nothing off your machine. Its only network destination is the Melvin app running on the same Mac, over a local loopback connection that both sides authenticate. It contains no remote server address, no analytics and no telemetry. Page content it passes to the app is then handled as described in section 4. Chrome displays its own “being debugged” banner whenever the extension is active, and we have deliberately not suppressed it.
It stores two things in your browser’s session storage: the local connection token, and the last run’s step titles so a reopened panel is not blank. Both are cleared when Chrome closes. Removing the extension ends all of this.
6. Why we process your data, and our legal basis
For users in the UK and European Economic Area, we rely on the following bases under the UK and EU GDPR:
| Purpose | Legal basis |
|---|---|
| Providing the assistant, running your tasks, and syncing your settings | Performance of a contract |
| Accounts, sign-in, billing and enforcing plan limits | Performance of a contract |
| Product analytics, including prompt text, to find and fix failures | Legitimate interests: improving a product people rely on. You may object at any time. |
| Security, abuse prevention and service reliability | Legitimate interests |
| Connecting optional third-party accounts, and contributing to the shared learning library | Consent, which you can withdraw |
| Meeting tax, accounting and other legal duties | Legal obligation |
We do not use your data to train general-purpose AI models, and we do not sell it or use it for behavioural advertising. Data received through Google APIs is handled under the Google API Services User Data Policy, including the Limited Use requirements.
We do not make decisions about you by automated means that produce legal or similarly significant effects.
7. How long we keep it
- Account and billing records: while your account is open, and afterwards only as long as tax and accounting law requires.
- Product analytics: retained while your account is open. Deleting your account deletes them.
- Data on your Mac: kept until you clear it. Observation history follows the retention period you set in Settings, and everything can be erased at once with “Wipe all data”.
- Shared learning contributions: generalised patterns are retained without a link to your account.
- Backups: may persist for a short period after deletion before being overwritten.
8. Your rights
Wherever you live, you can ask us to give you a copy of your data, correct it, or delete it. In the app you can additionally pause observation, exclude individual applications, change how long local history is kept, disconnect any integration, and erase local data yourself.
UK and European Economic Area
You have the right to access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interests (including our product analytics). Where processing rests on consent, you can withdraw it at any time without affecting what came before. You also have the right to complain to your local supervisory authority.
California
Under the CCPA as amended by the CPRA, you have the right to know what personal information we collect and why, to delete it, to correct it, and to not be discriminated against for exercising those rights. In the last twelve months we have collected the categories described in section 2: identifiers, commercial information, internet activity, geolocation inferred from IP address, audio while you are dictating, and the contents of your tasks.
We do not sell or share personal information as those terms are defined by the CCPA, and we have not done so in the preceding twelve months. We do not knowingly collect or sell the personal information of minors.
To exercise any of these rights, write to privacy@trymelvin.com, or follow the account deletion instructions. We will verify your request against your account and respond within the period the law allows, normally 30 days. You may use an authorised agent.
9. International transfers and security
Our service providers are located in several countries, including the United States. Where personal data leaves the UK or EEA, we rely on the European Commission’s Standard Contractual Clauses and the UK Addendum, together with the safeguards those providers operate.
We use transport encryption, account-scoped authorisation, operating-system credential storage, least-privilege integrations and redaction in diagnostic logs. The connection between the Chrome extension and the app is authenticated in both directions and never leaves your machine. No system removes all risk, and you should avoid putting secrets you would not want processed into a task prompt.
10. macOS permissions
macOS asks your permission before Melvin can use any of the following, and you can withdraw each one in System Settings at any time:
- Screen Recording — to see the screen you are asking about.
- Accessibility — to read interface structure and act in apps for you.
- Automation (Apple Events) — to control apps such as Mail, Calendar, Notes and Safari.
- Microphone — for voice input, transcribed on your Mac.
- Calendars, Reminders and Contacts — to read and create items when a task needs it.
- Location — for location-relevant answers, if you grant it.
11. Children
Melvin is not intended for, or directed to, anyone under 18, and we do not knowingly collect their personal data. If you believe a child has provided us with data, write to us and we will delete it.
12. Changes to this policy
We will update this page when what we do with your data changes, and revise the date at the top. If a change materially affects you, we will tell you in the app or by email before it takes effect.
13. Contact
Privacy questions and rights requests: privacy@trymelvin.com.
Security reports: security@trymelvin.com.
Postal: [LEGAL ENTITY NAME], [REGISTERED ADDRESS].