Privacy Policy
This privacy notice for Mellivo OÜ (“Company”, “we”, “us”, or “our”) describes how and why we collect, store, use, and share (“process”) your information, and explains your privacy rights under the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.
Scope. This notice applies to the website https://www.mellivoai.com, and to all mobile applications, web applications, and games published or operated by Mellivo OÜ — including the application or game from which you were directed to this notice — together with all related features, content, and support services (collectively, the “Services”). Where an individual application or game processes data differently from what is described here, a supplementary notice will be made available within that application or on its store listing.
If you do not agree with this notice, please do not use our Services. Questions or concerns? Contact us at studio@mellivoai.com.
SUMMARY OF KEY POINTS
This summary gives you the key points of this notice. Each point links to the full section, where you will find the detail.
What information do we collect?
Depending on which of our Services you use and which features you choose, we may process information you give us (such as an email address or content you upload), and information collected automatically (such as device and usage data). More →
Do we process sensitive information?
We do not intentionally process special categories of personal data. We do not create or use biometric identifiers to establish anyone’s identity. More →
Do we receive information about you from third parties?
No. We do not purchase personal data and we do not receive personal data about you from data brokers. More →
Do we use your content to train AI models?
No. We do not use the content you submit, or the output generated for you, to train, retrain, or improve artificial intelligence models — ours or anyone else’s — without your explicit consent. More →
How do we process your information?
To provide, maintain, and secure the Services, to communicate with you, to prevent fraud and abuse, and to meet our legal obligations. We process your information only where we have a valid legal basis. More →
Who do we share your information with?
Only with vetted service providers bound by data processing agreements — cloud hosting, AI model providers, payment processors, and analytics. We do not sell your personal information and we do not share it for cross-context behavioural advertising. More →
How long do we keep it?
Only as long as necessary. Account data is removed within 30 days of a deletion request; technical logs within 90 days; financial records are kept for 7 years as Estonian law requires. More →
How do we keep your information safe?
Through encryption, access controls, and monitoring. No system is completely secure, so we cannot guarantee that unauthorised access will never occur. More →
What device permissions do we ask for?
Only those a feature actually needs — such as the camera, photo library, or microphone when you choose to create something from a photo or a recording. You can grant or revoke each one at any time in your device settings. More →
Do children use our Services?
Account registration and content submission are restricted to adults. Some of our games carry a general-audience age rating; those products require no account and collect no contact details or uploaded content. More →
What are your rights?
Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent — plus the right to complain to a supervisory authority. US residents have additional rights. More →
How do you exercise them?
Email studio@mellivoai.com, or use the account deletion request form linked in Section 17. More →
1. WHO ARE WE AND HOW CAN YOU CONTACT US?
Mellivo OÜ is the data controller responsible for the personal data described in this notice.
- Company Name: Mellivo OÜ
- Registry Code: 17522398 (Estonian Business Register)
- Address: Harju maakond, Tallinn, Lasnamäe linnaosa, Sepapaja tn 6, 15551, Estonia
- Contact Email: studio@mellivoai.com
We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 GDPR. All privacy enquiries are handled at the contact address above.
2. WHAT INFORMATION DO WE COLLECT?
We collect the minimum amount of personal data necessary to provide, support, and secure our Services. Not all of the categories below apply to every part of the Services; we collect a given category only where the relevant feature is offered and used.
Information you provide to us
- Account Information. Where account registration is offered, we may collect information such as your name, email address, username, and authentication credentials.
- Content You Submit (Inputs) and Generated Results (Outputs). Where AI features are offered, we process the prompts, queries, files, images, audio, text, or instructions you upload or submit (“Input”), as well as the output generated for you (“Output”).
- Communications. Where a contact form, support channel, or email address is offered, we process the contact details and message content you choose to send us.
Information collected automatically
- Technical & Usage Data. IP address, browser type, operating system, device model and identifiers, language settings, session metadata, in-app event and diagnostic logs, crash reports, and cookie records collected automatically when you access the Services.
- Approximate Location. We may derive an approximate location (country or region) from your IP address for security, fraud prevention, and regional configuration. We do not collect precise or GPS-based location data.
Payment information
Where paid products or subscriptions are offered, payments are processed by PCI-DSS compliant third-party payment processors (e.g., Stripe) or by the applicable app store billing systems. We do not store or process your full payment card details on our servers. Where a purchase is made through an app store, payment data is held by that store under its own privacy notice: Apple and Google.
What we do not do
- We do not use your Inputs or Outputs to train AI models. We do not use the content you submit, or the output generated for you, to train, retrain, or improve artificial intelligence models — whether ours or those of any third party — without your explicit consent.
- We do not receive personal data about you from third parties. We do not purchase personal data and we do not obtain personal data about you from data brokers or advertising networks.
- We do not intentionally process special categories of personal data within the meaning of Article 9 GDPR. Content you upload may incidentally contain such data; we do not analyse it for that purpose.
- We do not create biometric identifiers. We do not generate, store, or use faceprints, voiceprints, or comparable biometric templates to identify or authenticate any individual.
- We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
3. WHY AND ON WHAT LEGAL BASIS DO WE PROCESS YOUR INFORMATION?
We process your personal data under the following legal bases:
- Performance of a Contract (Art. 6(1)(b) GDPR). To operate, maintain, and deliver the applications, games, AI features, and customer support services you request.
- Legitimate Interests (Art. 6(1)(f) GDPR). To prevent security breaches, fraud, and abuse, to maintain network integrity, to diagnose faults, and to improve the performance and quality of our software. For the avoidance of doubt, this basis does not cover the use of your Inputs or Outputs to train, retrain, or improve artificial intelligence models; such use occurs only with your explicit consent, as described in Section 2.
- Legal Obligations (Art. 6(1)(c) GDPR). To comply with statutory tax, accounting, and financial reporting requirements under Estonian and EU legislation, and to respond to lawful requests from authorities.
- Vital Interests (Art. 6(1)(d) GDPR). In rare cases, to protect the vital interests of you or another person, such as where there is a credible threat to someone’s safety.
- Consent (Art. 6(1)(a) GDPR). For optional AI model training, direct marketing communications, and any non-essential tracking. You may withdraw your consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.
4. WHOM DO WE SHARE YOUR INFORMATION WITH?
We share personal data only with trusted third-party providers who perform services for us, who are bound by written data processing agreements, and who may not use your data for their own purposes:
- AI Infrastructure & API Providers. Leading LLM and machine learning infrastructure providers (e.g., OpenAI, Anthropic, Google Cloud AI), strictly for processing real-time Input/Output requests.
- Cloud Hosting & Databases. Cloud infrastructure providers (e.g., AWS, Vercel, Supabase) operating in secure data centre environments.
- Payment Processors. Industry-standard secure payment platforms (e.g., Stripe) and app store billing providers.
- Analytics and Diagnostics Providers. Privacy-compliant usage analytics and crash reporting tools.
We may also disclose personal data where required to comply with a legal obligation, court order, or lawful request from a public authority, or to establish, exercise, or defend legal claims. Disclosures in connection with a corporate transaction are described in Section 16.
5. DO WE TRANSFER YOUR DATA OUTSIDE THE EEA?
Your data is primarily processed and stored within the European Economic Area (EEA). If personal data is transferred outside the EEA, we ensure that appropriate safeguards — such as standard contractual clauses approved by the European Commission, or an equivalent legal framework — are in place to ensure a high level of data protection.
6. HOW LONG DO WE KEEP YOUR INFORMATION?
We retain personal information only for as long as necessary for the purposes set out in this notice:
- Account and Content Data. Retained for the duration of your active account. Following account deletion, data is removed from active systems within 30 days and from routine backups within 90 days, except where longer retention is required by law.
- Inputs and Outputs. Retained only for as long as needed to deliver the requested feature and any history function you have enabled. Where you delete a conversation, project, or generated file, the corresponding Input and Output are removed from our active systems within 30 days.
- Retention by AI Providers. Our third-party AI API providers may retain Inputs and Outputs for a limited period (typically up to 30 days) solely for abuse monitoring, security, and legal compliance, after which they are deleted. These providers are contractually prohibited from using your Inputs or Outputs to train their models.
- Technical Logs. Stored for a limited period (typically 30 to 90 days) for network security and diagnostic purposes.
- Financial Records. Retained for up to 7 years in compliance with Estonian statutory legal and tax obligations.
Where we no longer have a legitimate need to process your personal data, we delete or anonymise it, or — where deletion is not immediately possible because the data resides in backup archives — we isolate it from further processing until deletion is possible.
7. WHAT ARE YOUR RIGHTS UNDER THE GDPR?
You hold the following data protection rights:
- Right to Access. Request a copy of the personal data we hold about you.
- Right to Rectification. Request correction of inaccurate or incomplete personal data.
- Right to Erasure (“Right to be Forgotten”). Request deletion of your personal data where processing is no longer necessary. See Section 17 for how to submit a deletion request.
- Right to Restrict Processing. Request temporary restriction of processing in certain circumstances.
- Right to Data Portability. Receive a copy of your personal data in a structured, commonly used, machine-readable format, and have it transmitted to another provider.
- Right to Object. Object to processing carried out on the basis of our legitimate interests.
- Right to Withdraw Consent (Art. 7(3) GDPR). Where processing is based on your consent, withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing performed before the withdrawal, nor processing carried out on another legal basis.
- Right to Lodge a Complaint. Complain to a supervisory authority. In Estonia, the competent authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon – AKI), www.aki.ee. You may also complain to the supervisory authority of the EU Member State in which you live or work.
To exercise any of these rights, contact us at studio@mellivoai.com. We will respond within one month, which may be extended by a further two months where the request is complex, in which case we will tell you within the first month.
8. DO WE USE AUTOMATED DECISION-MAKING?
No. We do not use your personal data for automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR. Our AI features generate content in response to your Inputs; they are not used to make decisions about you.
9. DO WE COLLECT INFORMATION FROM MINORS?
We do not knowingly solicit data from or market to children under 18. Account registration and the submission of content are restricted to users aged 18 or over. By using the Services you represent that you are at least 18, or that you are the parent or legal guardian of a minor and consent to that minor’s use of the Services.
Certain games we publish carry an age rating suitable for a general audience. A general-audience age rating does not mean a product is directed to children: none of our current titles, including Deltango and Story Teller, are directed to children or aimed at a mixed audience, and none are listed in a family or kids programme. In those games we do not require registration and we do not collect names, email addresses, photographs, voice recordings, precise location, or contact details.
If we ever publish a product that is directed to children or to a mixed audience, that product will carry only contextual, non-personalised advertising, will not transmit persistent advertising identifiers, and will comply with the Google Play Families Policy, the Apple App Store Kids Category requirements, and the Children’s Online Privacy Protection Act (COPPA).
Where you submit content that contains another individual’s personal data — including a photograph or voice recording of a child — you confirm that you are that individual’s parent or legal guardian, or that you have their authorisation. Such content is processed solely to produce the result you requested. It is never used to train artificial intelligence models, is not used for advertising or profiling, is not subject to routine human review other than where strictly necessary to investigate a reported abuse or to meet a legal obligation, and is deleted from active systems within 30 days of a deletion request.
If you become aware of any data we may have collected from a child without appropriate authorisation, contact studio@mellivoai.com and we will delete it without undue delay.
10. DO WE USE COOKIES?
We use only strictly necessary cookies — those required for platform functionality, navigation, security, and user authentication. We do not use advertising cookies or non-essential tracking cookies on our website, and no consent banner is therefore required for the cookies we set.
Should we introduce optional analytics or marketing cookies in the future, they will be used only with your prior explicit consent, obtained through a consent mechanism, and this notice will be updated accordingly.
11. WHAT DEVICE PERMISSIONS DO WE REQUEST?
Our applications request device permissions only where a feature you have chosen to use requires them. Each permission is requested at the moment the feature is first used, together with an on-screen explanation of why it is needed, and each can be granted or revoked at any time in your device settings. Declining a permission does not prevent you from using the rest of the application.
- Camera — to let you take a photograph directly within an application for use in a feature you have selected. We do not access the camera in the background or at any other time.
- Photo Library — to let you select an existing image for use in a feature you have selected. We access only the items you choose; we do not scan or index your photo library.
- Microphone — to let you record audio within an application for use in a feature you have selected. We do not record audio in the background or when the feature is not in use.
- Push Notifications — to send you notifications about your account, your requests, or application features, where you have enabled them. You may turn them off at any time in your device settings.
- Storage / Files — to save results you have generated to your device, and to load files you choose to submit.
Photographs, audio, and files accessed through these permissions are processed solely to produce the result you requested, are handled as described in Sections 2, 6, and 9, and are never used to train artificial intelligence models or for advertising or profiling.
We do not request access to your contacts, calendar, call logs, SMS messages, health data, or precise location.
12. DO WE SHOW ADVERTISING?
Story Teller is supported by advertising. It shows ads until you buy its one-time ad-free unlock, which permanently removes them. Those ads are delivered by Google AdMob, which acts as an independent controller of the data it collects (see how Google uses data from sites and apps that use its services). AdMob may collect, process and share personal data — such as device and advertising identifiers, and app interaction data — for advertising purposes, including personalised advertising and measurement. Full detail is in the Story Teller privacy policy.
We do not display third-party advertising in our other Services. In those products no advertising SDK is integrated, and no advertising identifier (such as the Google Advertising ID or Apple’s IDFA) is collected or transmitted by us or on our behalf.
Where advertising is shown, and if we introduce it in a further product, the following principles apply:
- Advertising is delivered by third-party advertising networks, each of which acts as an independent controller of the data it collects. We will name any further networks here before they are enabled, and we will update this notice before advertising is switched on in another product.
- In any product directed to children or to a mixed audience, we will serve only contextual, non-personalised advertising, through providers certified for family-oriented applications, and we will not transmit persistent advertising identifiers from those products.
- Where personalised advertising is offered in a product intended for adults, it will be enabled only with your prior consent, collected through a compliant consent mechanism (such as a GDPR consent prompt and, on iOS, the App Tracking Transparency prompt).
- You will always be able to limit ad personalisation through your device settings — on Android via Settings → Google → Ads, and on iOS via Settings → Privacy & Security → Tracking.
13. HOW DO WE KEEP YOUR INFORMATION SAFE?
We implement appropriate technical and organisational measures in accordance with Article 32 GDPR to protect personal data against unauthorised access, alteration, disclosure, loss, or destruction. These measures include encryption of data in transit (TLS) and at rest, role-based access controls and the principle of least privilege, secure authentication for administrative access, network and infrastructure hardening, logging and monitoring, and periodic review of our security practices.
No method of transmission or storage is completely secure, and we cannot guarantee that unauthorised third parties will never defeat our safeguards. In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the Estonian Data Protection Inspectorate (AKI) without undue delay and, where feasible, within 72 hours of becoming aware of it, in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk to you, we will notify you directly without undue delay, in accordance with Article 34 GDPR.
14. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
This section applies if you are a resident of a US state that has enacted comprehensive consumer privacy legislation — including, among others, California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Tennessee, Indiana, Kentucky, and Rhode Island. The rights available to you depend on the law of your state.
Categories of personal information we collect
We have collected the following categories of personal information, as those categories are defined under the California Consumer Privacy Act:
| Category | Collected |
|---|---|
| A. Identifiers — real name, alias, unique personal identifier, online identifier, IP address, email address, account name | YES |
| B. Personal information under the California Customer Records statute — name, contact information | YES |
| C. Protected classification characteristics — gender, date of birth, race, religion | NO |
| D. Commercial information — transaction and purchase history | YES, where a purchase is made |
| E. Biometric information — fingerprints, faceprints, voiceprints used to establish identity | NO. We do not create or use biometric identifiers. Images and audio you upload are covered under category H. |
| F. Internet or other network activity — usage of our Services, in-app events, diagnostic and crash data | YES |
| G. Geolocation data — approximate location derived from IP address. We do not collect precise geolocation. | YES, approximate only |
| H. Audio, electronic, or visual information — images, audio, and other content you choose to upload | YES, where you upload it |
| I. Professional or employment-related information | NO |
| J. Education information | NO |
| K. Inferences drawn to create a profile | NO |
| L. Sensitive personal information | NO |
Sale, sharing, and targeted advertising
We have not sold or shared any personal information in the preceding twelve (12) months, as “sale” and “share” are defined under the CCPA as amended by the CPRA, and we have not processed personal information for targeted advertising or for profiling in furtherance of decisions producing legal or similarly significant effects. This includes the personal information of consumers under 16 years of age. We do not use or disclose sensitive personal information for purposes that would give rise to a right to limit.
We disclose personal information to service providers for business purposes only, under written contracts, as described in Section 4.
Your rights
Depending on your state of residence, you may have the right to:
- confirm whether we are processing your personal data, and access it;
- obtain a portable copy of the personal data you previously provided to us;
- request correction of inaccurate personal data;
- request deletion of your personal data;
- opt out of the sale or sharing of personal data, targeted advertising, and certain profiling (we do not engage in any of these);
- limit the use and disclosure of sensitive personal information (we do not process it); and
- not be discriminated against or retaliated against for exercising any of these rights.
California “Shine the Light”. California residents may request, once per year and free of charge, information about categories of personal information (if any) disclosed to third parties for their direct marketing purposes. We do not disclose personal information for such purposes.
How to submit a request
Email studio@mellivoai.com, or use the deletion request route described in Section 17. We will respond without undue delay and in any case within 45 days, which may be extended once by a further 45 days where reasonably necessary; we will tell you within the initial period if an extension applies.
Verification. We will verify your identity by matching the information in your request against information already held by us — typically the email address associated with your account. We use information provided for verification only for that purpose and delete it once verification is complete.
Authorised agents. You may designate an authorised agent to submit a request on your behalf. We may deny a request from an agent who does not provide proof of valid authorisation.
Right to appeal. If we decline to act on your request, we will tell you and explain why. You may appeal that decision by emailing studio@mellivoai.com with the subject line “Privacy Request Appeal”. We will inform you in writing of the outcome of the appeal, and of the reasons for it, within 45 days in Colorado and within 60 days in Connecticut, Virginia, and other states applying that period. If your appeal is denied, you may contact your state Attorney General to submit a complaint.
15. DO WE RESPOND TO DO-NOT-TRACK SIGNALS?
Most web browsers and some mobile operating systems include a Do-Not-Track (“DNT”) feature you can activate to signal that you do not want your online activity monitored. No uniform technology standard for recognising and implementing DNT signals has been finalised. We therefore do not currently respond to DNT browser signals. This has no practical effect on our website, as we do not track users across third-party websites or services. If a standard for online tracking is adopted that we are required to follow, we will update this notice accordingly.
16. WHAT HAPPENS IF OUR BUSINESS IS SOLD OR TRANSFERRED?
If we are involved in a merger, acquisition, financing, reorganisation, insolvency, or a sale of all or part of our business or assets, your personal data may be transferred to the acquiring or successor entity as part of that transaction. We will require any such recipient to protect your personal data in a manner consistent with this notice, and we will notify you before your personal data becomes subject to a materially different privacy notice.
17. HOW CAN YOU REVIEW, UPDATE, OR DELETE YOUR DATA?
You may review, correct, or delete your personal data at any time:
- In the application. Where an application offers account registration, it also offers account deletion from within the application itself, in the account settings.
- On the web, without installing anything. Submit a request through our Account Deletion page. This page is publicly accessible and does not require you to have the application installed.
- By email. Write to studio@mellivoai.com.
What is deleted. A deletion request removes your account, your profile and authentication data, any content you submitted (including images and audio), the outputs generated for you, and your usage history, from our active systems within 30 days, and from routine backups within 90 days.
What is retained, and why. We may retain a limited set of records where the law requires it or where we have an overriding legal need: transaction and invoicing records, for up to 7 years, under Estonian tax and accounting law; and a minimal record of the deletion request itself, together with any information needed to prevent fraud, resolve a dispute, or enforce our agreements, for as long as that need exists. Retained records are isolated from further processing.
18. DO WE MAKE UPDATES TO THIS NOTICE?
We may update this notice from time to time to reflect operational, legal, or regulatory developments. The updated version will be indicated by a revised “Last Updated” date and takes effect as soon as it is accessible. Where changes are material, we will notify you by prominently posting a notice or by email or in-app notification. We encourage you to review this notice periodically.
19. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
If you have questions, feedback, or data privacy requests regarding this notice, contact:
Mellivo OÜ (Registry Code 17522398)
Harju maakond, Tallinn, Lasnamäe linnaosa, Sepapaja tn 6, 15551, Estonia
Email: studio@mellivoai.com

