mellow family

Privacy policy

Draft for counsel review · updated August 2026

What we collect

Account information: your email address and authentication credentials.

The content you create: messages and attachments, calendar activity, expenses and receipts, journal entries, vault files, professional grants, call-consent records and recordings, and export snapshots.

Operational data: timestamps, delivery states, and audit events required to maintain the tamper-evident record.

What we never do

We never sell your data. We never show advertising. We never use the content of your messages to train AI models.

Our staff cannot casually browse conversations; production access is restricted, logged, and used only for support you request or where the law requires.

Why messages cannot be deleted

Sent messages and journal entries are append-only by design. Calendar and expense corrections create new revisions instead of silently replacing earlier values. Closing an account does not remove shared records from the other family-space member. We retain them to preserve the shared history described when you created or joined the space.

AI features

When you ask Mellow Coach to review a draft or receipt OCR to read an image, that content is sent to our configured AI provider to produce the requested result. Mellow does not use family content to train its own models. Provider processing is governed by our provider agreement and disclosed subprocessors.

Recorded audio calls

Power Tools audio calls require explicit consent from both participants before each recording. Unlocked audio expires one year after the call by default. We notify both parents before expiry and retain the call metadata, consent events, checksum, and deletion event after the audio is removed. Either parent may permanently lock a recording; locked audio cannot later be unlocked and counts toward family-space storage.

Sharing

Your record is visible only to the members of your family space and anyone you explicitly grant access (for example, read-only attorney access). We disclose data to third parties only with your direction, or when legally compelled by valid process.

Security

Data is encrypted in transit and at rest. Access is controlled with row-level security at the database layer, and every mutation is written to a hash-chained audit log.

Contact

Questions about this policy: privacy@mellow.family.