Mellow.Family

Privacy policy

Last updated September 8, 2026 · applies to the Mellow Family service

Account data and previous beta applications

Account and service data includes your email, authentication records, messages and attachments, calendars, expenses and receipts, journal entries, vault files, professional grants, call-consent records and recordings, export snapshots, timestamps, delivery states, and security audit events.

The August beta application is closed. Previously submitted applications contain name, email, parent or professional role, state or country, feedback availability, consent versions, timestamps, and application status.

Retired public demo

The public demo and its AI endpoint are closed. They no longer accept draft text. Illustrations on the website use fictional details and do not represent a real family account.

Before retirement, the demo sent requested draft rewrites to Google Gemini and recorded limited security telemetry, including a keyed network-address hash, request identifier, action, model, status, safety outcome, latency, and token counts. The demo did not store draft text or responses in family records. This telemetry remains scheduled for cleanup after 48 hours, including after retirement. Cleanup runs hourly, so deletion is not immediate at the 48-hour mark.

Google Calendar data

Google Calendar connection remains unavailable while provider review is pending.

If you connect Google Calendar, Mellow Family requests read-only access to your primary calendar. For the visible overlay, it accesses the Google event ID, title, description, start value, and end value. Mellow does not write to Google Calendar.

Overlay events are fetched from Google on demand and are not cached by the application. Mellow stores an encrypted refresh token, the granted scopes, connection state, and any account identifier returned by Google so it can maintain the connection. It does not keep a persistent copy of an event unless you deliberately select Copy into Mellow. A copied event becomes a Mellow record and follows Mellow's retention rules.

Disconnecting Google Calendar attempts to revoke the token with Google, removes the locally stored token, and immediately prevents further Google access. You can also revoke access from your Google Account permissions.

Google API Limited Use

Mellow Family's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Google data is not sold, used for advertising, used for credit or lending decisions, or used to train generalized artificial-intelligence models. It is shared only as needed to provide the user-facing calendar feature, protect security, comply with law, or for another narrowly permitted purpose under Google's policy.

How we use and share information

We use information to provide, secure, support, and improve the features you request; process applications and payments; maintain records; communicate service notices; prevent abuse; and comply with law. Marketing email requires separate optional consent and is not required to apply or use the service.

Shared sections are visible to family-space members. Your private journal and private vault files remain under your control. A professional receives read-only access only to the sections explicitly authorized for them. We do not sell personal information or show advertising.

Supabase provides database, authentication, and storage infrastructure; Stripe processes payments; and Resend delivers transactional email. They receive only the information necessary to perform those services under their applicable terms and safeguards. Stripe, not Mellow Family, stores payment-card details.

Vercel hosts the application and processes requests and operational logs. Cloudflare provides domain and email-routing services; messages sent to our privacy, legal, and support addresses are forwarded to our support inbox.

Daily provides the audio-call service. When you join a call, it processes audio, connection information, your account identifier and the email used as your participant name. Recording requires both parents' recorded consent in Mellow. Recordings are processed by Daily and copied into our storage; the ingestion worker verifies the stored copy before requesting deletion of Daily's copy. Failed transfers or deletion requests require retries, so provider deletion is not immediate.

For independently timestamped exports, DigiCert receives a cryptographic fingerprint and timestamp-request information. The timestamp request does not contain the underlying family messages, receipts, or export document.

AI features

Mellow Coach and receipt scanning use the OpenAI API. Asking Coach to review a draft sends that draft and a hashed account identifier; requesting a receipt scan sends the selected receipt image. These requests do not include the rest of your message history, journal, or vault. Suggestions are optional and can contain errors; review them before use.

Mellow does not train its own models on family content. OpenAI's API policy excludes API inputs and outputs from model training by default. Our requests disable stored response objects; that setting does not eliminate provider security or abuse-monitoring retention. Provider processing is governed by the applicable service terms. Contact privacy@mellow.family for questions about AI processing.

Retention, deletion, and shared records

We remove unneeded beta screening fields when their scheduled retention period ends. If no deletion date was set, that period is one year from the application date. We may retain limited suppression, consent, entitlement, security, and financial records when necessary to honor choices, provide benefits, prevent abuse, or meet legal obligations.

Sent messages and journal entries are append-only by design; calendar and expense corrections create revisions. Closing an account does not erase shared records from another family-space member. Copied Google events follow these same Mellow retention rules.

You may request access, correction, disconnection, or deletion by emailing privacy@mellow.family. We verify requests and respond subject to shared-record integrity and applicable legal retention duties.

Owners can delete standalone private vault files through the app. Files attached to retained records follow those records' retention rules. Removing professional access prevents new authorized requests; a download link already issued can work until it expires, and we cannot recall files someone has already downloaded.

File uploads use private temporary copies while we verify the transfer. Temporary copies, including unsaved receipt scans and copies of a deleted vault file, are scheduled for cleanup after 48 hours. Failed cleanup attempts are retried and monitored. A receipt scan does not create a shared expense record until you save it.

Security

Data is encrypted in transit and at rest. Access is restricted by row-level database controls, service roles, authorization checks, and logged administrative operations. No security program can guarantee absolute protection.

Contact

Privacy questions and requests: privacy@mellow.family.