Meluno
Privacy policy
This policy generally describes how Meluno processes personal data needed to provide and protect the service.
The owner still needs to configure their real identity, address and privacy contact. No invented details are shown and payments remain blocked.
Data controller
The controller is the owner shown in the server-configured details. While their identity or privacy email is missing, this page says so visibly and never substitutes fictional details.
Data processed
Meluno processes name, email, credentials handled by Supabase Auth, language and profile; subjects, topics, dates, availability, calendars, sessions, progress, feedback and notifications; and, for uploaded materials, name, type, size, file, extracted text and chunks. Technical security records and Test Mode identifiers may also be processed. Meluno does not receive plain-text passwords or full card details.
Purposes
Data is used to create and protect the account, generate and display the calendar, adapt sessions, save progress, analyse requested materials, handle support and rights requests, prevent abuse and maintain security. It is not used for advertising or to sell profiles.
Legal bases
The beta processes data needed to provide the requested free service and to take steps before its use. Security and abuse prevention rely on legitimate interests, subject to assessment. Legal obligations apply where required. Optional storage requires consent and can be withdrawn. Any payment basis must be validated before payments are enabled.
Providers and recipients
Supabase provides authentication, database and Storage; Vercel hosts and delivers the application; Groq may interpret on the server the availability and bounded academic text the user chooses to analyze, without account identifiers, and Meluno uses a local fallback when the service is unavailable; Stripe is limited to Test Mode and processes no real charges; Google Search Console only verifies domain ownership. No analytics or transactional email provider is active in the current code.
International transfers
Supabase and Vercel may use infrastructure or subprocessors outside the European Economic Area depending on the configured region and support. Before commercial launch, the owner must verify the effective region, data-processing agreements, subprocessors and applicable transfer mechanism. Stripe Test Mode does not authorise real payments.
Retention
Academic data and files are kept while the account or related content remains active and are deleted with the account. Technical queues remain until deletion completes. Provider logs, support and backup periods still need to be configured and will appear in the controller details; no unapplied period is claimed.
Your rights
You may request access, correction, deletion, restriction, objection and portability where applicable, withdraw consent without affecting earlier processing, and complain to the competent data protection authority.
How to exercise them
Send the request to the configured privacy email, stating the right and account email. Meluno may request data already provided to verify identity, never more than necessary. Requests are free and normally answered within one month; for a complex request this may be extended by up to two months with reasons provided. The account can also be deleted directly from the user menu.
Account deletion
Delete account requires the password again. It first removes physical objects through the Supabase Storage API and then deletes the Auth user, cascading to the profile, subjects, topics, calendars, sessions, progress, feedback, analyses and notifications. The local session is closed; a token issued on another device may exist until it expires, but account data is no longer available.
Uploaded files
Files are kept in a private Supabase bucket under user-bound paths. Only validated types and sizes are accepted. Content may be extracted and split to produce the requested plan. Deleting a subject or account creates a durable deletion and removes the physical object through the Storage API; the internal Storage table is not deleted directly.
Security
Meluno applies RLS to public tables, ownership checks, input validation, private buckets, restrictive web headers and server keys kept out of the browser. No measure removes all risk; incidents will be assessed and notified where the law requires.