This Privacy Policy explains how Melaya Labs LLC ("Melaya", "we", "us", or "our") collects, uses, discloses, retains, and protects personal information when you access or use the Melaya platform, including the Agentic Framework, the Melaya Engine, the websites at melaya.org and associated subdomains, APIs, clients, and any related services (collectively, the "Services"). It applies to all users of the Services worldwide and should be read together with our Terms of Service and Security Overview. By using the Services, you acknowledge the processing of personal information as described in this Policy.
Privacy at a Glance
This is a plain-language summary and does not replace the full Privacy Policy below. Melaya Labs LLC is based in the United States; our production infrastructure is hosted in Singapore; and we serve users worldwide.
| What we collect | Why | Shared or sold | Kept for |
|---|---|---|---|
| Account and contact details (email, username, name) | Create and secure your account and provide support | Infrastructure and support subprocessors; never sold | Life of your account plus a short post-closure period |
| Exchange API credentials, balances, and trade activity | Run the trading features you enable and execute the actions you authorize | Stored only as AES-256-GCM ciphertext; never sold or used for advertising | While connected; cryptographically erased when you remove them |
| Documents you upload, prompts, and agent output (retrieval and RAG) | Power the AI agents and retrieval you configure | Sent to the model providers you choose, to generate responses; never sold | Until you delete them or close your account |
| Device and usage data (HMAC-hashed IP, user agent, interactions) | Security, fraud prevention, and improving the Services | Analytics and telemetry subprocessors; never sold | By tier and category (see Section 7) |
| Billing data (Stripe customer ID, plan, credit balance) | Process payments and manage your subscription | Stripe, as our payment processor; never sold | At least seven years, for tax and accounting |
| Device Control data | Pair phones, enforce approved apps, relay commands, mirror screens, show run status, approvals, and kill controls. | Service processors needed to host, secure, and operate the feature; your owning session; approved model/tool providers only when a workflow uses them. | Operational data is minimized and retained according to security, debugging, account, and legal-retention needs. |
We do not sell your personal information, share it for cross-context behavioral advertising, or track you across other companies' apps and websites. Your data is processed in the United States and Singapore under Standard Contractual Clauses. You can access, correct, delete, or export your data from your account settings, or contact us at [email protected]. Residents of the EEA, the United Kingdom, Switzerland, California, and Singapore have additional rights described below.
1. Who We Are and Our Role
Melaya Labs LLC is the controller of personal information collected through the Services, except where we process personal information on behalf of an enterprise customer under a written agreement, in which case we act as a processor and the customer is the controller. Where we act as a processor, the customer's own privacy notice governs the processing purposes and lawful bases; this Policy describes our processing activities as controller.
2. Information We Collect
2.1 Information You Provide
When you create an account we collect your email address, chosen username, a bcrypt salted hash of your password (the plaintext password is never stored), and tier selection. When you subscribe to a paid tier we collect billing name, country, and the Stripe customer identifier associated with your subscription; we do not receive or store full payment card numbers, which are handled directly by Stripe, Inc. When you connect a third-party exchange to the Engine we collect metadata describing the connection, such as venue name, key label, permission scope, and creation date; the API key, secret and passphrase themselves are wrapped with AES-256-GCM envelope encryption inside the Melaya server process before being handed to our vault provider or written to the agents.credentials fallback table, so they are never stored in plaintext at rest. When you upload documents, code, or other materials to build a retrieval index we process those materials to generate embeddings and serve retrieval within your tenant. When you contact support we collect the content of your messages and any attachments you provide.
2.2 Information Collected Automatically
When you use the Services we automatically collect technical information, including IP address, approximate geographic location derived from IP, user agent, device type, browser, operating system, referrer, language preference, session identifiers, timestamps of requests, resource identifiers, and the actions you take within the Services. We collect logs of pipeline runs, tool invocations, model calls, Engine orders, authentication events, rate limit events, and error traces, for the purposes of operating, debugging, billing, and securing the Services. Where an IP address is written to the security audit log it is stored only as a keyed HMAC digest rather than in cleartext.
2.3 Sensitive Data We Do Not Intentionally Request
Melaya does not intentionally request government identity documents, biometric templates, health records, precise GPS location, or payment-card primary account numbers as ordinary account fields. However, prompts, uploaded content, connected services, full-display screen frames, screenshots, accessibility trees, tool results, and user-directed workflows can incidentally contain these or other sensitive data. Do not submit or expose sensitive data unless it is necessary, lawful, authorized, and appropriately safeguarded. Melaya does not sell personal information or share it for cross-context behavioral advertising, and does not train a Melaya foundation or general-purpose model on User Content without a separate lawful notice and choice; customer-selected third-party providers apply their own terms and configurations.
3. How We Use Information
We use personal information to provide, operate, maintain, and secure the Services; to authenticate you and control access; to process subscriptions, billing, renewals, and refunds; to execute the pipelines and Engine instructions you configure; to detect, investigate, prevent, and respond to fraud, abuse, security incidents, and violations of our Terms; to communicate with you about service announcements, security notifications, and policy changes; to respond to support inquiries; to produce internal analytics about aggregate usage, reliability, and performance; to comply with legal obligations and respond to lawful requests from authorities; and to establish, exercise, or defend legal claims.
4. Legal Bases for Processing
For users subject to the European Union General Data Protection Regulation (GDPR), the United Kingdom GDPR, the Swiss Federal Act on Data Protection, and similar regimes, our lawful bases for processing are: performance of a contract, when processing is necessary to provide the Services you have requested; legitimate interests, when processing is necessary for fraud prevention, security, abuse detection, billing, product improvement, and defense of legal claims, and those interests are not overridden by your fundamental rights and freedoms; legal obligation, when processing is required to comply with applicable law, court order, or regulatory request; and consent, where we rely on your consent and you have provided it. You may withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
5. How We Share Information
We disclose personal information only as described below. We do not sell personal information.
We share information with subprocessors who perform functions on our behalf under written contracts that impose confidentiality and data protection obligations consistent with this Policy. Our current subprocessors include Stripe, Inc. (payment processing), self-hosted Infisical (vault provider for envelope-encrypted secrets, co-resident on the same production host and not a third-party subprocessor for the secrets surface), our Postgres hosting provider (primary database), our Redis hosting provider (session + rate limit state), our object storage provider (document and backup storage), transactional email providers (service communications), Cloudflare, Inc. (edge TLS termination, WAF, DDoS mitigation, and Access SSO for operator-facing administrative interfaces), Grafana Labs (off-box log and metric collection via Grafana Cloud Loki and Mimir in the same cloud region as the production host; Grafana Labs holds SOC 2 Type II), and third-party language model providers that you choose to route your pipeline traffic through, including OpenAI, Anthropic, Google, and others. A canonical subprocessor list with service descriptions, jurisdictions, and transfer safeguards is published at melaya.org/legal/subprocessors; the specific legal entity names and executed data processing agreements for operator-specified providers are maintained in our internal security vault and offered to enterprise customers under NDA.
We disclose information to supported exchange venues and prediction market venues solely to the extent necessary to execute orders and retrieve account state at your instruction.
We disclose information to law enforcement, regulators, courts, and other authorities where we believe in good faith that disclosure is required by applicable law, legal process, or governmental request, and where we deem such disclosure necessary to enforce our Terms, protect the rights, safety, or property of Melaya, our users, or the public, or investigate fraud or security issues.
We may disclose information in connection with a corporate transaction, such as a merger, acquisition, reorganization, financing, or sale of assets, in which case we will require the acquiring party to honor the commitments made in this Policy or provide affected users with notice and, where required, a choice.
We may share aggregated or de-identified information that cannot reasonably be used to identify you for analytics, research, and product improvement purposes.
Device Control data
If you pair a phone, Melaya may process device labels, platform type, pairing status, last-seen timestamps, approved app package names and labels, active-run metadata, accessibility screen trees, command results, and screen-share frames when you start mirroring.
We use this data to pair the device, show whether it is online, enforce your app allowlist, relay agent commands, show live progress, provide human approvals and kill controls, debug reliability, and secure the service.
Screen frames are treated as sensitive operational data. They are relayed to the owning user's live session and latest-frame tools for Device Control, not sold, and not used to train public models. You should avoid opening sensitive third-party apps unless you intentionally approved them for the workflow.
You can stop mirroring, kill a run, revoke a phone, remove app permissions, disable Accessibility, sign out, or delete your account subject to our retention, security, billing, fraud-prevention, and legal obligations.
Mobile Agents, screen observation, and execution modes
Depending on the feature you enable, we may process device identifiers and labels, platform and app versions, IP address, pairing and last-seen status, device-token metadata, approved or visible app package names, active-run metadata, commands and parameters, command results and errors, accessibility node text and attributes, full-display screen pixels or frames, screenshots, overlays, interaction coordinates, typed or submitted content, prompts, attachments, tool inputs and outputs, model responses, audit events, crash data, and security telemetry.
Screen and accessibility data can incidentally include another person's messages, images, contact details, account identifiers, financial or health information, location, work information, or other sensitive data displayed by an approved app. Customers and users must provide required notices, obtain authority, minimize capture, and avoid exposing unrelated information. Those obligations do not replace our own obligations when we act as controller or processor.
We process Mobile Agent data to pair and authenticate devices, enforce app and command policy, execute and return requested actions, show status and previews, obtain approvals, provide emergency stop and revocation, synchronize runs, prevent replay and abuse, troubleshoot failures, maintain auditability, secure the Services, comply with law, and enforce our Terms. We do not sell screen, accessibility, credential, prompt, or command data. MediaProjection screen streaming is full-display and is not technically limited to an approved foreground app.
Our role depends on context. We generally act as controller for account, billing, security, fraud-prevention, product administration, and our own legal compliance data. For an organization's configured workflows and end-user content, the organization may be controller and Melaya may act as processor under an applicable data processing agreement. You must not rely on this summary to assign roles contrary to the facts or applicable law.
A selected cloud model, connector, app, merchant, or tool provider receives the prompts, screen-derived context, tool data, credentials or authentication material, and command content necessary for the request you direct to it. Those providers process data under their own terms or an enterprise agreement. Melaya does not use Mobile Agent content to train a public or general-purpose Melaya model unless we first provide a separate lawful notice and choice; third-party model training and retention depend on the provider and configuration you select.
Credentials are encrypted at rest where stored by Melaya, but a selected runtime must receive a usable plaintext key, token, or derived authorization in memory to call the chosen service. A local runtime may therefore see selected keys; a Melaya cloud runtime may receive them ephemerally; and the external provider receives the authentication presented to it. Encryption does not make data invisible to an authorized execution endpoint.
Local execution does not necessarily mean that no data reaches Melaya. Run identifiers, device and command metadata, status, messages, traces, tool events, costs, approvals, errors, and other telemetry explicitly emitted by the runtime may be relayed, displayed, or persisted. Data that remains local and is not sent to a cloud model, connector, device relay, telemetry channel, or Melaya service is not received by Melaya.
We retain Mobile Agent data only for the periods stated elsewhere in this Policy or needed for the selected feature, account administration, security, dispute resolution, fraud prevention, legal compliance, backup cycles, or customer instructions. Live frames may be handled as transient latest-frame data while selected screenshots, commands, results, traces, or audit events may persist when the workflow, customer configuration, security need, or law requires it.
You can stop a run or mirroring session, use available kill controls, remove an app from the allowlist, revoke a device or credential, disable Accessibility or screen capture in operating-system settings, disconnect a provider, sign out, or request deletion. Revocation prevents future authorized processing but cannot recall data already sent to a third party or reverse an action already completed.
Mobile Agent permissions and privacy notices must also appear in context inside the mobile application where platform rules require them. This Policy supplements and does not replace those prominent disclosures, runtime permission prompts, Apple privacy information, Google Play Data Safety declarations, or provider-specific notices. If a store label or in-app disclosure conflicts with actual processing, please contact us immediately.
Mobile Agents are not directed to children and must not be used to monitor children or vulnerable persons without a valid legal basis, appropriate guardian or institutional authority, heightened safeguards, and compliance with applicable child-protection and privacy law. Do not submit special-category, biometric, health, financial, precise-location, authentication, or similarly sensitive data unless necessary, authorized, and supported by appropriate safeguards.
What each execution mode can disclose
Local runner + local model. Prompts, local files, tool data, selected keys, and inference stay on the user-controlled machine unless the runtime emits telemetry or calls a cloud connector. Melaya receives the run, command, collaboration, security, or telemetry data actually transmitted to its services.
Local runner + cloud model. Execution and local tools remain on the user-controlled machine, but the selected model provider receives every prompt, retrieved passage, screen-derived detail, tool schema, tool result, and metadata included in the inference request.
Melaya cloud runtime + cloud model. Melaya infrastructure can process runtime inputs, generated code, selected plaintext credentials in ephemeral memory, prompts, retrieved context, files made available to the run, tool results, and emitted telemetry; the selected model provider receives the inference payload sent to it.
Android Device Control. Melaya's command plane processes user and paired-device authentication, the account-level allowlist, requested action, parameters, status, and returned evidence needed to authorize and route a command. Because the queue is presently user-scoped, the first eligible paired phone that polls can claim the job, after which the job result is bound to that claim. The Android executor can inspect allowed accessibility state and perform foreground-restricted actions under Android permissions; full-display screen streaming can include any app visible while mirroring and is not cropped to the allowlist.
iOS and Mac testing routes. The App Store app processes only data available within its sandbox and approved Apple APIs. If a user separately operates a Mac runner with XCTest or WebDriverAgent, that user-controlled route can receive automation commands and captured UI evidence from an expressly paired and authorized test device.
6. International Data Transfers
Melaya operates globally. Personal information may be processed in, or transferred to, countries other than the one in which you reside, including the jurisdictions where our subprocessors operate. Our production infrastructure, including the primary database and cache, is hosted in the Asia Pacific (Singapore) region. Where personal information originating in the European Economic Area, the United Kingdom, or Switzerland is transferred to a country that has not received an adequacy decision, we rely on appropriate safeguards, including the European Commission Standard Contractual Clauses, the UK International Data Transfer Addendum, and equivalent Swiss transfer mechanisms, supplemented by technical and organizational measures. A fifteen-section Data Processing Addendum template incorporating EU SCCs Module 2/3, the UK IDTA, and the Swiss FADP equivalent is committed in our internal security vault. The template is offered on a bilateral basis to enterprise customers; external counsel review is pending before it is offered as a clickwrap at non-enterprise tiers. Copies of the relevant transfer safeguards and the executed subprocessor DPAs are available on request under NDA.
7. Data Retention
We retain personal information only for as long as is necessary to fulfill the purposes for which it was collected, to comply with our legal obligations, to resolve disputes, and to enforce our agreements. Account registration data is retained for the life of the account and for a reasonable period thereafter to permit reactivation, accounting reconciliation, and defense of legal claims. Billing records are retained for the period required by applicable tax and accounting laws, typically at least seven (7) years. Run logs, audit traces, and operational telemetry are retained on a tier-dependent basis that mirrors the tier catalog in our public pricing: sandbox users get a shorter window and citadel users get the longest window, subject to customer-specific overrides agreed in writing. The retention windows are enforced by a scheduled sweep (verified by retention-sweep.ts) which deletes agents.runs rows past their tier-specific cutoff (sandbox 7 days, forge 30 days, bastion 90 days, citadel no cutoff), emits an audit-log event retention.sweep_ran for every run, and exits zero against a dry run of the production database. Retrieval indices and uploaded documents are retained until you delete them or close your account; upon deletion or account closure they are removed from active systems within commercially reasonable timeframes and from backups on our normal backup rotation. Envelope-encrypted exchange credentials are retained until you remove them or close your account, after which the ciphertext is deleted and, once all backups containing it have rotated out, is rendered permanently undecryptable because no more copies of the key remain anywhere paired with it.
8. Your Rights
Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information; withdraw consent; complain to a competent authority; opt out of certain sale, sharing, targeted advertising, or profiling; limit certain uses of sensitive information; and obtain safeguards concerning solely automated decisions producing legal or similarly significant effects. California residents may have rights under the CCPA/CPRA, including know, delete, correct, opt-out, limit, and non-discrimination rights where applicable. Individuals in Singapore, the United Kingdom, the EEA, Switzerland, Brazil, India, the Philippines, the People's Republic of China, Russia, and other jurisdictions may have additional rights under applicable law. Melaya does not intend its general-purpose Services to make solely automated legal or similarly significant decisions about individuals. Customers must not configure such uses without a valid legal basis, required transparency, human review, contestability, impact assessment, and other safeguards. Available controls depend on the workflow; do not assume every consequential action is technically gated by multi-factor authentication or human approval.
You can exercise your core rights yourself at any time from your account settings: export a machine-readable copy of your personal data under "Privacy & your data" (access and portability), correct your account details directly (rectification, with a step-up multi-factor challenge for email or username changes), and permanently delete your account and personal data (erasure), which also writes a tombstone to our tamper-evident audit log. Restriction and objection requests, any other request, or a request where you cannot access your account are handled manually; contact us using the details in Section 15. We will respond within the timeframes required by applicable law. We may need to verify your identity before acting on a request, and we may decline or limit a request where permitted by law, for example to protect the rights of others, to preserve trade secrets, or to comply with legal obligations.
9. Cookies and Similar Technologies
The Services use a limited set of first-party cookies and local storage entries that are strictly necessary to operate, authenticate you, maintain session state, balance load, and secure the Services against abuse. We do not use third-party advertising cookies. Where we use optional analytics, we do so in a privacy-preserving manner with aggregation and without cross-site tracking. A first-visit cookie consent banner is shipped in the Melaya web client. It distinguishes strictly necessary cookies (session, CSRF, rate-limit key) from optional analytics and records the user's choice in browser local storage under mel_cookie_consent_v1. No third-party analytics fire until the user consents. You can manage cookies through your browser settings; disabling strictly necessary cookies will prevent the Services from functioning.
10. Children
The Services are not directed to children, and we do not knowingly collect personal information from anyone under the age of eighteen (18). If you believe that a child has provided us with personal information, please contact us and we will take steps to delete the information and terminate the associated account.
11. Security
We implement administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. Details are provided in our Security Overview. No system is perfectly secure, and we cannot guarantee the absolute security of personal information.
12. Third-Party Services and Links
The Services may interoperate with or link to third-party services, including exchange venues, language model providers, wallet software, and external data sources. This Policy does not apply to those third-party services, and we are not responsible for their privacy practices. You should review the privacy notices of any third-party service you use.
13. Google API Services and Google User Data
When you connect your Google account to Melaya through the Connectors page, we request a specific set of OAuth scopes from Google so that the pipelines you build can act on your behalf. We treat any data accessed through Google APIs ("Google User Data") in accordance with the Google API Services User Data Policy, including the Limited Use requirements set out below.
13.1 Scopes We Request and Why
We request the minimum scopes required to deliver the features you explicitly enable. The current scope list and its rationale is:
openid, email, profile. Used solely to identify you when you sign in with Google or link a Google account to your Melaya identity. We store the email address in our user record and use the profile name and picture, where provided, only to display your account in the Melaya UI.
https://www.googleapis.com/auth/gmail.compose. Used by pipelines that include a "Send email" or equivalent step to draft and send mail on your behalf through Gmail. We do not read existing inbox messages, do not search your mailbox, and do not store the body of sent messages on our servers beyond the operational logs needed to debug pipeline failures (see Section 7 for retention).
https://www.googleapis.com/auth/calendar.events. Used by pipelines that create, update, or cancel calendar events on your primary calendar. We read only the events created or modified by your Melaya pipelines so we can show their status in the run viewer; we do not list, read, or transmit unrelated events from your calendar.
If we add or change scopes, we will update this section, redeploy the consent screen, and ask you to re-authorize before the new scope takes effect.
13.2 How We Use Google User Data
Google User Data is used solely to provide and improve the user-facing features you have explicitly enabled in your pipelines, and for the limited additional uses permitted by the Google API Services User Data Policy. Specifically:
We do not use Google User Data to train, fine-tune, or evaluate generalized AI or machine learning models. We do not transfer Google User Data to third parties except (a) to the recipients you explicitly choose, such as the email address you ask a pipeline to send a message to, (b) to subprocessors strictly necessary for the operation of the Services (for example, our cloud hosting provider), and (c) as required by law or to protect the rights, property, or safety of Melaya, our users, or the public. We do not sell Google User Data and we do not share it for cross-context behavioral advertising.
13.3 Storage and Retention of Google Tokens
OAuth refresh tokens and short-lived access tokens received from Google are wrapped with AES-256-GCM envelope encryption inside the Melaya server process and stored in the agents.credentials table scoped to your user account. Tokens are never logged in plaintext, never returned to the client browser after first issuance, and are decrypted only at the moment of an outbound API call.
You can revoke Melaya's access at any time by removing the Google connector from the Connectors page in the Melaya UI, or directly from your Google Account at myaccount.google.com/permissions. When you revoke or delete the connector, we delete the associated tokens within seven (7) days. Operational logs that reference Google API calls are retained according to the schedule in Section 7.
13.4 Limited Use Disclosure
Melaya's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
14. Changes to This Policy
We may update this Policy from time to time. When we make material changes, we will notify you through the Services or by email at least fifteen (15) days before the changes take effect, except where a shorter period is necessary to comply with law. The "Last updated" date at the top of this Policy reflects the most recent revision.
15. Contact
To exercise your rights, ask questions about this Policy, or submit a privacy complaint, contact:
For users in the European Economic Area, the United Kingdom, and Switzerland, you may also lodge a complaint with your local data protection supervisory authority.