Melya Privacy Policy

Published: August 3, 2026

Effective: August 3, 2026

Melya (“we”, “us”, or “our”) respects your privacy and the security of your personal data. We use reasonable safeguards required by applicable law and provide controls that allow you to manage your data.

This Privacy Policy explains how we collect, use, store, protect, share, and delete personal data when you use the Melya application and related services.

Please read this Policy carefully before using Melya. By using Melya, you confirm that you understand the processing described in this Policy. Where applicable law requires consent for a specific activity, we will request that consent separately.


Part I Definitions

Melya: the Melya application and related services operated by us.

User: any person who accesses or uses Melya.

Guest Identity: the automatically created identity used to authenticate a user and separate that user's data without requiring a phone number or email registration.

Personal Data: information that identifies, relates to, describes, or can reasonably be linked to an individual, directly or indirectly.

Sensitive Personal Data: personal data that may create a significant risk to a person if disclosed or misused, such as passwords, payment information, precise location, identity documents, health records, or private communications.

Processing: any operation performed on personal data, including collection, use, storage, sharing, protection, or deletion.

Deletion: removing personal data from systems used for ordinary business operations so that it can no longer be accessed or retrieved, unless retention is required by law.


Part II Privacy Policy

Article 1 How We Collect and Use Personal Data

We collect only the data reasonably necessary for the functions you use. If required data is not provided, the relevant function may not work. Refusing optional data will not affect unrelated basic functions.

1. Guest Identity and Authentication

When Melya starts, the app generates a random UUID on your device and sends it to our server to create a Guest Identity. The server returns a user ID, access token, and token expiration time.

We use this data to create and maintain your Guest Identity, authenticate requests, refresh credentials, separate user data, and process deletion requests. The access token is stored in the operating system's secure storage.

2. AI Chat and Companion Functions

When you chat with an AI Character, we process the text you submit, AI replies, message IDs, character IDs, session IDs, timestamps, and the conversation context needed to generate a response.

We use this data to generate and deliver AI responses, display and restore conversations, create local summaries and companion records, maintain continuity, operate safety measures, and troubleshoot failed requests.

Chat content is primarily stored on your device, but the text and necessary context must be transmitted to Melya servers to generate and review a response.

3. Character and Safety Controls

When you browse or select a character, create a session, block a character, or submit a report, we may process the relevant character ID, session relationship, blocked status, report reason, report description, report status, and timestamps.

We use this data to provide character and session functions, synchronize block status, investigate possible violations, prevent abuse, and communicate report outcomes.

4. App, Device, Network, and Security Data

We may process the app version, build number, operating system, system language, request time, IP address, endpoint status, and error type. The app also reads the operating system version, device model, manufacturer, and whether the device is physical for local compatibility and troubleshooting.

We use this data to provide the correct language and protocol, maintain compatibility, secure the service, diagnose faults, prevent attacks and fraud, and meet legal obligations.

The current client does not read an advertising identifier or hardware unique identifier and does not integrate advertising, payment, analytics, or crash-reporting SDKs.

5. Local Preferences and Cache

Melya stores language preferences, selected character information, local chat data, chat summaries, active chat dates, character blocklists, page cache, and image cache on your device.

We use this data to remember your settings, display your history, speed up loading, and maintain page state. You may manage or delete this data through the controls described in Article 7.

6. Customer Support, Complaints, and Data Requests

If you contact us, we may process your correspondence, the information you provide, the relevant Guest Identity, and the status and result of your request. We use this data to verify the request where necessary, investigate the issue, respond to you, and keep a record required for security or legal compliance.

Do not send your access token, complete chat history, identity documents, or other unnecessary Sensitive Personal Data through ordinary email.

7. AI Model Training

The current version does not use the text of your chats to train general-purpose AI models by default. If this practice changes, we will explain the purpose, data scope, retention, and withdrawal method and obtain separate consent where required. Refusing or withdrawing model-training consent will not affect basic chat functionality.

8. Data You Should Not Submit

Please do not submit identity documents, passwords, payment details, exact addresses, complete medical records, or another person's private information unless it is strictly necessary and we have specifically requested it through an appropriate secure channel.


Article 2 Cookies and Similar Technologies

The current mobile application does not rely on advertising cookies. It uses local databases, secure storage, preferences, and cache technologies to maintain your Guest Identity, settings, chat history, and application performance.

If a Melya website later uses cookies or similar technologies, we will provide an appropriate notice and consent controls where required.


Article 3 Sharing, Transfer, and Disclosure

1. Sharing and Disclosure

We do not sell personal data. We share or disclose personal data only:

2. Business Transfers

If a merger, acquisition, restructuring, or asset transfer involves personal data, we will require the recipient to continue protecting the data under this Policy or obtain new consent where required.


Article 4 How We Store Personal Data

1. Storage Location

Personal data collected through Melya is stored in the Republic of Singapore. If data is transferred outside your country or region, we will use safeguards required by applicable law and provide any required notice or consent mechanism.

2. Retention

We retain personal data only for the shortest period necessary to provide Melya, protect service security, handle reports and disputes, and comply with legal obligations. Local chats, summaries, companion records, and preferences remain on your device until you delete them, clear application data, or uninstall Melya. When data is no longer required, we delete or anonymize it unless continued retention is required by law.


Article 5 How We Protect Personal Data

We use reasonable technical and organizational safeguards, including encryption in transit, operating-system secure storage for credentials, separation of user data, access controls, limited authorization, and redaction of sensitive logs.

No method of transmission or storage can guarantee absolute security. If a personal data incident may materially affect your rights, we will investigate, take remedial measures, and provide notice where required by law.


Article 6 Adults and Minors

Melya is intended for adults. You must be at least 18 years old, or meet any higher minimum age required by local law, to use the service.

We do not knowingly collect personal data from an ineligible minor. If we learn that such data has been collected, we may restrict the Guest Identity and delete or otherwise process the data as required by law. A parent or guardian who believes that a minor has used Melya should contact us through Article 9.


Article 7 How You Can Manage Personal Data

1. Access, Correction, and Other Requests

Subject to applicable law, you may ask about our processing rules and request access, a copy, correction, completion, deletion, or restriction of personal data. You may also withdraw consent where processing is based on consent or complain about our processing.

Some local data can be managed through Settings > Data & Privacy. For requests that cannot be completed in the app, contact zhangyisdy1@gmail.com. We may request the minimum information necessary to verify the Guest Identity and prevent fraud.

2. Delete Your Guest Identity and Data

In the app: Open Melya and go to Settings > Data & Privacy > Delete All Data. Review the consequences and confirm the request. After the server confirms deletion, Melya clears local chats, sessions, summaries, companion records, character blocklists, page cache, image cache, and credentials associated with the current Guest Identity.

If you cannot access the app: Email zhangyisdy1@gmail.com with the subject “Delete Melya Data” and include only the information necessary to help locate the Guest Identity. Do not include an access token, complete chat history, or identity documents in ordinary email.

A deletion request covers the Guest Identity and associated server data, undelivered replies, and caches. Data that must be retained by law or is necessary to resolve disputes or protect security will be isolated for the required period and then deleted or anonymized.

Deletion is generally irreversible. After deletion, Melya may create a new Guest Identity that is not connected to the deleted data.

3. Withdrawal of Consent

Withdrawal does not affect processing lawfully performed before withdrawal. If data is necessary for a core function, deleting it or withdrawing permission may prevent that function or the Guest Identity from continuing to work.


Article 8 Changes to This Policy

We may update this Policy when our functions, processing practices, or legal obligations change. We will provide a prominent notice for material changes. Where renewed consent is required, we will request it before the change takes effect.

The publication and effective dates at the top show the current version of this Policy.


Article 9 Contact Us

If you have questions, complaints, or personal data requests, contact us at:

Email: zhangyisdy1@gmail.com

We will respond within 7 working days.


© 2026 Melya. All rights reserved.