YOUR DATA, CLEARLY EXPLAINED

Privacy Policy

Information we process

Depending on the features you choose, we process account identifiers and profile information; WhatsApp and Telegram identifiers and messages sent to MelloFlo; reminders, commitments, summaries and preferences; Google account details and OAuth tokens; Gmail sender, subject, labels, dates and short previews; Google Drive file names, links and files selected or created through MelloFlo; authentication, consent, support, security and privacy-request records. Short-lived email sign-in codes are not stored in readable form.

How we use information

We use information to create and secure your account, provide the assistant and reminder features you request, connect services you choose, interpret content, create reminders and summaries, deliver notifications, troubleshoot the service, prevent abuse, comply with law and answer privacy requests. We do not sell personal information or use Google user data for advertising.

Google user data

Google sign-in provides basic account information. Gmail access is read-only: MelloFlo does not delete, move, send or modify Gmail messages. Google Drive access is limited to files MelloFlo creates or files you select for MelloFlo. Access is used only to provide visible user-facing features, such as extracting a follow-up from an email or selected file. You can disconnect Google from MelloFlo Settings and can also revoke access from your Google Account.

MelloFlo’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Service providers

We use service providers to operate MelloFlo, including Cloudflare for application infrastructure, Meta for WhatsApp Business messaging, Google for optional sign-in, Gmail and Drive integrations, and Resend for transactional sign-in email. Providers may process information only for the services they supply and under their applicable contracts and safeguards.

Retention

Expired login and one-time-code records are removed promptly. Raw inbound webhook records are retained for up to 30 days; cached Gmail metadata for up to 90 days; and security audit records for up to 365 days. User-created reminders, commitments, messages and files are retained while the account is active or until the user deletes them, subject to legal obligations and legitimate security needs.

Security

Specified sensitive application fields and OAuth refresh tokens use AES-256-GCM encryption. We also use secure transport, access controls, secure cookies, narrow integration permissions, rate limits, webhook verification and audit records. No internet service can guarantee absolute security.

Your choices and rights

You can review and delete reminders, disconnect integrations, export available account information, or request account deletion from MelloFlo Settings. Depending on applicable law, you may also request access, correction, portability, restriction or deletion; object to certain processing; withdraw consent; or complain to the relevant authority. We may need to verify your identity before acting on a request.

Cookies

MelloFlo uses a strictly necessary secure session cookie to keep signed-in users authenticated. We do not currently use advertising cookies on the MelloFlo service.

Automated assistance

MelloFlo uses automated tools to interpret user-provided content and suggest reminders, summaries or priorities. These productivity features may make mistakes. Where appropriate, MelloFlo asks for confirmation and lets users correct or remove saved information.

Children

MelloFlo is not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child has provided information, contact us so we can review and delete it where required.

Changes and contact

We may update this policy as MelloFlo develops. Material changes will be posted here with a revised effective date. For privacy questions or requests, email sales@hummingapps.in.