Privacy Policy
Last updated: 7 August 2026
This policy explains how Melio Labs Ltd, a company registered in England and Wales (company number 16136624), whose registered office is at 1 High Gates, Sale, England, M33 2LN ("Melio Labs", "we", "us"), collects and uses personal data when you use Melio Studio (https://studio.meliolabs.io and https://app.meliolabs.io, the "Service").
For the purposes of the UK GDPR and the Data Protection Act 2018, Melio Labs is the data controller of the personal data described in this policy.
We do not sell your personal data. Ever.
1. What data we collect
Account data. Your email address and a password (stored as a secure hash), managed through our authentication provider, Supabase. Optionally, a name and workspace/brand details you choose to add.
Customer content. Text, images and video that you upload to the Service or that the Service generates for you.
Connected account data. If you connect an Instagram or Facebook account, we receive and store, with your explicit OAuth consent: the access tokens Meta issues, and basic profile/page/account identifiers needed to publish on your behalf (for example page names and IDs).
YouTube and other connected platforms. If you connect a YouTube channel, we receive and store, with your explicit Google OAuth consent: the OAuth access and refresh tokens Google issues (and their expiry), and your channel's ID and title. That is all. We do not receive or store your Google password, your Google email address, your subscriber list, your viewers' data, your analytics, or the contents of your channel. Section 2 sets out the YouTube connection in full. The same pattern applies to any other platform you connect (for example LinkedIn or Threads): tokens, plus the minimum account identifiers needed to publish on your behalf.
Billing data. Your subscription plan and billing status. Payments are processed by Stripe; we do not receive or store your full card details. Stripe shares with us limited information such as payment status and the last digits of your card.
Usage and technical data. Log data generated when you use the Service (such as IP address, browser type, timestamps and actions taken), used for security, debugging and service operation.
2. Google and YouTube API Services
Melio Studio uses YouTube API Services to publish videos to a YouTube channel you connect and control. By connecting a channel you also agree to the YouTube Terms of Service. Google's own privacy policy, which governs Google's handling of your data, is at http://www.google.com/policies/privacy.
What we ask Google for. Exactly two OAuth scopes, and nothing else:
- youtube.upload: to upload the video you have approved to your channel. This is the feature you connected the channel for.
- youtube.readonly: used for one thing only, reading your channel's ID and title, so we can show you "Connected as [your channel]" in Settings and address the upload to the right channel. We do not read your analytics, your subscribers, your viewers, your comments or your video library.
What we store. The OAuth access and refresh tokens Google issues (and their expiry), your channel ID and your channel title. Nothing else from your Google account is received or stored, and the video you publish is the video you approved in the Service.
Limited Use. Melio Studio's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell this data, we do not transfer it to advertising platforms or data brokers, we do not use it for advertising or retargeting, and we do not use it to train AI models.
Disconnecting and revoking. You can disconnect at any time in Melio Studio under Settings → Connections, which deletes the stored tokens and channel details. You can also revoke Melio Studio's access from your Google account's security settings at https://security.google.com/settings/security/permissions, which stops us being able to publish and marks the connection in Melio Studio as needing reconnection.
3. How we use your data, and our lawful bases
| Purpose | Data used | Lawful basis (UK GDPR Art. 6) |
|---|---|---|
| Providing the Service: accounts, login, storing and publishing your content, scheduling | Account data, customer content, connected account data | Contract: necessary to perform our contract with you |
| Billing and subscription management | Billing data, account data | Contract |
| Generating content with AI at your request | Customer content you submit for generation | Contract |
| Publishing to the platforms you connect (for example Instagram, Facebook, YouTube) on your behalf | Connected account data, customer content | Contract (and your explicit OAuth consent to connect the account) |
| Securing the Service, preventing abuse, debugging | Usage and technical data | Legitimate interests: keeping the Service secure and working |
| Service emails (e.g. receipts, important changes, security notices) | Account data | Contract / legitimate interests |
| Complying with legal obligations (e.g. tax and accounting records) | Billing data | Legal obligation |
We do not use your personal data for automated decision-making that produces legal or similarly significant effects.
4. AI processing
When you use content-generation features, the content you submit is processed via Anthropic's Claude API. Anthropic acts as our processor for this data and, under Anthropic's commercial terms, does not use your content to train its models.
5. Who we share data with
We share personal data only with the service providers (processors) we need to run the Service:
| Provider | What they do | Where |
|---|---|---|
| Supabase | Authentication and database hosting | EU region |
| Cloudflare R2 | Storage of uploaded and generated media | EU-adjacent storage |
| Stripe | Payment processing | Stripe's own infrastructure; Stripe is an independent controller for payment data |
| Anthropic | AI content generation (as processor; no model training) | See Anthropic's commercial terms |
| Meta (Instagram/Facebook) | Receiving the content you choose to publish, via APIs you have authorised | Meta acts under its own terms once content is published to its platforms |
| Google (YouTube) | Receiving the video you choose to publish, via the YouTube Data API you have authorised | Google acts under its own terms once content is published to YouTube |
We may also disclose data if required by law, or as part of a business sale or reorganisation (in which case this policy will continue to apply to your data).
6. International transfers
We keep primary data storage in the EU (Supabase EU region) and EU-adjacent storage (Cloudflare R2). Where a provider processes data outside the UK or EEA (for example Stripe or Anthropic), we rely on appropriate safeguards recognised under UK GDPR, such as adequacy regulations and the UK International Data Transfer Agreement/Addendum to the EU Standard Contractual Clauses, as reflected in each provider's data processing terms.
7. How long we keep your data
We keep your personal data and content for the lifetime of your account plus 30 days after deletion, after which it is deleted from our active systems. The 30-day window exists so we can restore your account if you delete it by mistake.
Exceptions: we may keep limited billing records for longer where tax and accounting law requires it, and short-lived encrypted backups may persist briefly beyond deletion before they are cycled out.
Access tokens for connected accounts, including Meta accounts and a connected YouTube channel (tokens, channel ID and channel title), are deleted when you disconnect the account in Settings, or when your account is deleted, whichever comes first.
8. Data deletion
You can delete your data at any time. This section also serves as our data deletion instructions for Meta platform users.
Option 1 (in the app): Go to Settings in the Melio Studio app (https://app.meliolabs.io) and choose to delete your account. This deletes your account, your content, and any stored access tokens for connected accounts (Meta, Google/YouTube and any other platform), subject to the 30-day window described in Section 7.
Option 2 (by email): Email contact@meliolabs.io from the email address on your account and ask us to delete your data. We will confirm and complete the deletion within 30 days.
To disconnect a platform without deleting your whole account, go to Settings and disconnect it; we delete the associated access tokens immediately, along with the channel or page details stored with them. For a YouTube channel you can additionally revoke Melio Studio's access in your Google account's security settings (see Section 2).
9. Your rights
Under UK GDPR you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate data;
- Erase your data (see Section 8);
- Restrict or object to processing, including processing based on legitimate interests;
- Data portability: receive a copy of data you provided in a machine-readable format;
- Withdraw consent at any time where processing relies on consent (for example by disconnecting a Meta account or a YouTube channel).
To exercise any right, email contact@meliolabs.io. We will respond within one month.
Complaints. You have the right to complain to the UK supervisory authority, the Information Commissioner's Office (ICO), at https://ico.org.uk or 0303 123 1113. If you are in the EU/EEA, you may also complain to your local data protection authority. We'd appreciate the chance to resolve any concern first, but you don't have to contact us before going to the ICO.
10. Cookies
We use essential session cookies only: cookies strictly necessary to keep you logged in and keep the Service secure. We do not use advertising, analytics or other non-essential cookies, so we do not show a cookie consent banner. If this changes, we will update this policy and ask for consent where required.
11. Security
We take reasonable technical and organisational measures to protect your data, including encryption in transit, hashed passwords, access controls, and hosting with reputable providers. No system is perfectly secure; if a breach occurs that risks your rights, we will notify you and the ICO as required by law.
12. Children
The Service is not intended for anyone under 18, and we do not knowingly collect data from children. If you believe a child has created an account, contact contact@meliolabs.io and we will delete it.
13. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you by email or in the app before they take effect. The "Last updated" date at the top shows the current version.
14. Contact us
Melio Labs Ltd (company number 16136624)
1 High Gates, Sale, England, M33 2LN
Email: contact@meliolabs.io