Melos

Privacy

Privacy Policy

Last updated: August 3, 2026

Melos is an AI-assisted poetry studio. This page describes what we collect, where it goes, and what control you keep. The short version: we collect what the studio needs to work, we send content to AI providers only to produce what you asked for, we run no analytics or advertising, and deleting your account deletes your writing and photos.

What we collect

  • Account — your email address and either a securely hashed password (argon2id, never stored in plain text) or a link to your Apple or Google sign-in. Optionally a display name, handle, bio, and language preference.
  • Your writing — poems, drafts, readings, and craft notes you create; duets you take part in; grades and badges you give or receive; reports and blocks you make.
  • Photos — only if you use the photo → poem mode. The photo is resized on your device and its embedded metadata (including any GPS location) is removed before upload, so we never receive it.
  • Purchases — subscription and credit state. Payments are processed by Stripe on the web and by the Apple/Google app stores (via RevenueCat) on mobile; we never see your card number.
  • Notifications — on mobile, a push token (encrypted at rest) and your notification preferences. There are only five notification categories, all of them optional.
  • Operational records — server logs and error reports needed to keep the service running. There are no analytics or tracking scripts in the app.

Generative AI

Poems are composed with AI assistance. When you ask Melos to write, read, polish, or critique, your input is sent through our routing layer to AI model providers — currently OpenAI and Anthropic — solely to produce the result you asked for. Other features use AI the same way: narration voices are synthesized by Google or OpenAI text-to-speech; poem card art is generated by OpenAI (with SiliconFlow as a fallback); and in photo → poem, a vision model (Anthropic) writes a short factual description of your photo, which is what the poem is then written from. We do not use your content to train AI models, and we do not sell or monetise your personal data.

AI moderation and safety

Text you submit passes automated safety screening: a screening service we host ourselves, plus OpenAI's moderation service with an Anthropic fallback when it is unavailable. Photos are screened the same way before any other AI processing — a photo that cannot be screened is rejected rather than let through. Poems published to the gallery pass a separate moderation gate. When a safety rule triggers, we record the event with a cryptographic hash of the content — never the content itself — and keep that record for incident review.

Photos (photo → poem)

  • Your photo is visible only to you. It is never published, never shown to other members, and no public page carries it — even if you publish the poem it inspired.
  • Before upload, the photo is resized on your device and stripped of embedded metadata (EXIF), including any location data.
  • It is stored privately and accessed only through short-lived signed links.
  • A short machine-written description of the photo is stored with your poem as provenance.
  • Photos are kept while your account exists and are permanently removed when you delete your account.

Community content

Publishing a poem to the gallery, entering the leaderboard, or joining a duet makes that poem's text public under your handle. You can unpublish at any time. Everything else — drafts, your library, craft notes, source photos — stays private to you.

Storage and security

All connections use TLS. Passwords are hashed with argon2id and a server-side secret, and checked against known breach lists at signup. Web sessions use HTTP-only cookies with CSRF protection. Media — card art, narration audio, photos — lives in private object storage reachable only through short-lived signed links. Push tokens are encrypted at rest.

Cookies

Essential cookies only: an HTTP-only session cookie, an HTTP-only refresh cookie, and a CSRF cookie. No tracking cookies, no third-party analytics, no advertising.

Retention and deletion

Your content is kept while your account is active. Deleting your account (Settings → delete account) permanently deletes your poems — including published ones — photos, narration audio, card art, profile, sign-in links, and push tokens, and removes your email address. Two things are retained: the purchase/credit ledger (an immutable financial record) and safety-event records, which contain content hashes only, never your text or images. App-store subscriptions are managed by Apple/Google — cancel there.

Your rights

You can read and correct your information in the app, and delete your account yourself in Settings. For access, correction, or deletion requests beyond what the app offers, contact us at the address below.

Age

Melos is intended for users aged 13 and older, and signup requires confirming this.

Changes

If this policy changes in a way that matters, we will update this page and its date. We will not quietly expand what we collect.

Contact

For privacy questions or requests: privacy@simplerlife.cc.