Privacy · V2026.08.2

Mellow Privacy Policy

This policy applies to the Mellow apps for iOS, iPadOS, and macOS, their Share extension, the Mellow website, account system, and cloud service.

Version V2026.08.2 · Effective August 5, 2026

Summary: Mellow does not retain microphone recordings or create cloud text history from Rewrite, Quick Note, or Arrange input and results. Signed-in users may choose to sync their knowledge base across devices. Optional records stay on device. Mellow does not sell personal information or use it for advertising profiles.

1. Operator and contact

Mellow is provided by the operator identified in the applicable regulatory filings and app distribution platforms. Contact support@mellow.halosearch.cn for privacy questions, data rights requests, security reports, account deletion assistance, and complaints.

To avoid unnecessary exposure of a sole operator's private information, this public page does not display an identity number, home address, or personal telephone number. Information required by regulators or app marketplaces is provided through those official channels.

2. Data we process

DataPurpose and processingStorage and retention
Microphone audioUsed only after you start recording, for system speech recognition and level detectionTemporarily processed in device memory and released when recording ends or fails; Mellow does not upload or save audio files
Transcript, text you enter, selected mode, and necessary contextSent over an encrypted connection to Mellow Cloud and a generative AI provider when you request Rewrite, Quick Note organization, or Arrange extraction. Appending to a Quick Note includes the current note body; Arrange includes the device time and time zone to interpret relative dates such as “tomorrow”Input and generated text are not written to Mellow's cloud business database or used to create cloud text history; optional local records are controlled by you
Generation compliance recordSupports generated-content disclosure and security duties and contains only a salted hash of an account or guest device, time, mode, provider, model, and disclosure methodContains no input, output, or audio content; access is restricted and the record is kept for at least six months, then deleted
Knowledge-base canonical terms and aliasesImprove speech recognition and provide consistent correction across Rewrite, Quick Note, and Arrange for professional terms, names, and similar entries; when signed in, sync across Mac, iPhone, and iPad according to your settingStored locally by default; encrypted in transit and retained while the account exists when account sync is enabled. Deleting an entry scrubs its term and aliases and leaves only a content-free synchronization tombstone
Notion authorization tokens and status, plus the title and body of a note you explicitly saveCreate one private Notion page only after you sign in, connect Notion, and tap Save; Mellow does not use this access to read existing pagesOAuth access and refresh tokens are encrypted on the Mellow server until you disconnect or delete your account. The selected note is relayed for that save request and is not added to Mellow cloud text history; Notion retains the created page under its own policy
Email address, password hash, and sign-in tokensOptional registration, sign-in, email verification, password reset, and account entitlementsKept while the account exists; passwords are stored only as irreversible hashes; deleted on account deletion subject to short security backup rotation
Usage, entitlement, and transaction referencesShow remaining quota, prevent duplicate redemption, and resolve entitlement issuesKept for the account lifetime or the shortest period required for a transaction, dispute, or legal duty
Anonymous device identifier and salted network-address groupingProvide a guest trial, enforce limits, prevent abuse, and protect the service; raw IP addresses are not storedInactive guest credentials are removed after 45 days; aggregated security records are normally kept for no more than 180 days
Random installation identifier, version, build, device family, distribution channel, and content-free product milestonesDistinguish App Store, TestFlight, and development installations and measure agreement, onboarding completion, first successful processing, and registration. Audio, transcripts, source text, and results are excluded. After registration or sign-in, an installation may be linked to the account so it is not incorrectly counted as unregisteredThe server stores only a salted hash of the installation identifier. Unlinked inactive records are kept for no more than 24 months; account-linked records are kept while the account exists, then unlinked and cleaned on the same schedule. De-identified aggregate statistics may be retained
Aggregate App Store reports supplied by AppleUnderstand aggregate impressions, sources, and first-time downloads while keeping Apple's acquisition data separate from Mellow activation milestonesOnly Apple's aggregate counts and report dimensions such as date are retained; Mellow does not receive Apple Account information identifying an individual downloader
Error state and test interaction eventsDiagnose failures, validate important flows, and improve reliability; rewrite text and recordings are excludedTest events are normally kept for no more than 90 days; necessary security records use the shortest applicable period
Feedback you choose to submitInvestigate a problem, respond to a suggestion, or reproduce a failureKept while the issue is handled and for a reasonable support period; you may request deletion

3. Data stored on your device

iPhone and iPad

Custom scenes, the knowledge base and its local sync cache, and necessary preferences are stored in an Apple App Group container. Account and guest credentials are stored in Keychain. Rewrite, Quick Note, and Arrange records are stored only in the main app's private container and are not shared with the Share extension. The Share extension processes only content you explicitly send to Mellow from the system share sheet.

Arrange first creates a draft card and never writes automatically. Only after you tap a main action such as Add to Calendar, Add to Reminders, or Create Alarm does Mellow request the corresponding permission and write the content you confirmed. Calendar access is write-only and does not read existing events. Reminder access is used only to create the reminder you confirmed. Sending a Quick Note to Apple Notes, Feishu, or another app uses the system share sheet, where you confirm the destination. Signed-in users may also connect Notion. Authorization alone sends no note; Mellow relays a specific title and body only after you explicitly save that note to Notion.

Mac

Scenes, the knowledge base and its local sync cache, preferences, and history are stored under ~/Library/Application Support/Mellow/. Accessibility and input permissions are used only to invoke Mellow, recognize shortcuts, and insert a result into the source app. They are not used to inspect unrelated content in other apps.

Deleting the app may not remove every local support file. Clear history in the app first or contact support for complete removal instructions.

4. Voice, AI, and generated text

Speech recognition uses Apple system capabilities. Apple's handling of system speech services is governed by Apple's terms and privacy policy. Mellow Cloud receives the resulting text, not the recording.

Rewrite, Quick Note organization, and Arrange extraction use the Zhipu GLM-5.2 generative AI service (service filing number: Beijing-ChatGLM-20230821). Text is provided only as necessary to complete the request. We require service providers to apply appropriate safeguards and do not permit Mellow requests to be used for advertising profiles. Do not submit passwords, payment-card numbers, identity numbers, medical records, trade secrets, or another person's sensitive information unless you are authorized and it is necessary.

Mellow labels Rewrite, Quick Note, and Arrange results as “AI-generated” in the result interface. Copying or exporting clean text is an explicit request for a result without an embedded visible label. If you later publish it or use it where it may affect another person's judgment, preserve or add any disclosure required by applicable rules.

5. System permissions

  • Microphone: captures audio only while you actively record.
  • Speech Recognition: turns speech into text on the device; text input remains available if you decline.
  • Calendar, Reminders, or Alarms: requested only after you confirm an Arrange card and choose the corresponding destination, and used to create that item.
  • Accessibility on macOS: supports shortcuts and inserting a result at the active input position.

You may revoke a permission in system settings. Features that depend on it will stop working, while unrelated text input and local data remain available.

6. Service providers and disclosure

We do not sell personal information. Necessary processing may involve Apple system and distribution services, cloud infrastructure such as Tencent Cloud, transactional email, generative AI, payment providers, and app marketplaces. Mellow does not receive full payment-card details. Providers are restricted to the service purpose through technical and contractual measures where applicable.

If you connect and save to Notion, Notion receives the selected note title and body and processes it under its own terms and privacy policy. Mellow does not automatically synchronize, bulk-read, or scrape your existing Notion content. You may disconnect in Me → Connectors or revoke access in Notion; manage or delete already-created pages in Notion. When you use the system share sheet for Feishu or another app, the system and destination app process the content you confirm.

If the service is transferred through a merger or business change, we will provide notice as required and require the recipient to continue protecting the information under this policy.

7. International processing

We prioritize infrastructure and AI services that meet mainland China service requirements. If a future feature requires sending personal information to a recipient in another jurisdiction, we will provide the information required by applicable law and obtain separate consent or complete another required procedure before that transfer.

8. Your choices and rights

  • Access or correct account information that can be changed;
  • Add, edit, or delete knowledge-base entries and turn off cross-device knowledge sync;
  • Delete individual local-history items or clear all local history;
  • Turn off local history, revoke system permissions, or stop using cloud rewriting;
  • Sign out, reset a password, or permanently delete an account in the app;
  • Request access, a copy, correction, restriction, or deletion through support;
  • Ask for an explanation or raise a complaint or objection.

We may verify identity before fulfilling a request. We normally provide a progress response within 15 working days unless applicable law provides otherwise.

9. Account deletion

Signed-in iPhone and iPad users can permanently delete an account from Account in the app. Mac users may use the account interface or contact support. Account credentials, the cloud knowledge base, cloud usage, and linked entitlements are deleted or de-identified. Local scenes, history, and knowledge cache must be removed separately on each device.

Transaction, security, or dispute records that must be kept by law remain access-restricted until the required period ends, then are deleted or anonymized.

10. Children

Mellow is not directed to children under 14. A user under 14 should use it only with a guardian's guidance and consent and should not submit sensitive information. Contact us if you believe a child's information was processed without valid guardian consent.

11. Security

We use HTTPS, password hashing, token rotation, least privilege, access control, rate limiting, and data minimization. If a security incident may affect individual rights, we will contain and remediate it and provide notice as required.

12. Policy updates

This policy is versioned. Minor clarifications may update the page date. Material changes to processing purposes, data types, recipients, or user rights will receive prominent notice and renewed consent where required. Previous versions are available from support.

13. Contact

Privacy, account deletion, data rights, or security: support@mellow.halosearch.cn.