Effective date: 29 July 2026
Meldry (“Meldry”, “we”, “us”, or “our”) provides an AI-assisted image studio. This policy applies to the Meldry website, studio, and related administration tools.
1. Information we process
ChatGPT connection data
Sign-in is handled through OpenAI OAuth. Meldry receives the authorization information required to make the request you initiate. We do not ask for or store your OpenAI password. Browser-side session data is managed by the OpenAI OAuth integration.
Creative inputs and outputs
Briefs, selected styles, uploaded reference images, generated prompt contracts, and refinement instructions are processed to deliver the requested result. These materials are sent to OpenAI through the ChatGPT session you authorize. Generated images are returned to your browser and are not persisted by Meldry by default.
Feedback and service records
If you submit a rating, Meldry may store the rating, comment, workflow, prompt model, prompt contract, output dimensions, and a reduced-size preview of the image. Technical failures may be recorded with the failing stage and error message. Contact messages are retained in the inbox used to answer them.
To measure signups and active use, Meldry converts your ChatGPT account identifier into a keyed, pseudonymous value before it is stored. We keep first- and last-seen times, daily activity, workflow, and totals for prompts, renders, and refinements. We do not place the underlying ChatGPT account identifier, OAuth token, name, or email in the analytics database.
Administrative data
The private administration area uses an essential, signed, HTTP-only cookie to maintain an authorized administrator session. It is not used for advertising or cross-site tracking.
2. How we use information
- To authenticate the ChatGPT connection you request.
- To generate prompts, images, and follow-up edits.
- To preserve mode-specific constraints such as face identity and logo fidelity.
- To diagnose errors, prevent abuse, and keep the service reliable.
- To understand product quality through voluntary ratings and aggregate usage.
- To respond to support, security, and team-deployment enquiries.
3. Legal bases
Where applicable law requires a legal basis, we process data to perform the service you request, for our legitimate interests in securing and improving Meldry, with your consent for optional feedback, or to meet a legal obligation. You may withdraw consent for future optional processing at any time.
4. Service providers and disclosure
Meldry uses OpenAI to authenticate eligible ChatGPT sessions and process model requests. When feedback storage is configured, Meldry uses Supabase for product activity, feedback records, and private object storage. Our hosting, email, and infrastructure providers may process limited technical data to operate the service. Their own terms and privacy policies govern their independent processing.
We may disclose information if required by law, to protect people or the service, or as part of a business transfer subject to appropriate safeguards. We do not sell personal information or use studio inputs for targeted advertising.
5. Retention
Creative inputs and outputs are processed transiently by Meldry unless you deliberately include them in feedback. Browser object URLs and recent render history disappear when the relevant browser tab is closed or refreshed. Feedback records are kept until no longer needed for product quality and support, or until a valid deletion request is completed. Aggregate counts may be retained longer because they do not contain the creative input. Pseudonymous product activity is kept while needed to operate, secure, and understand the service.
6. Security
We use signed administrator sessions, server-only service credentials, private feedback storage, input limits, and transport encryption where supported. No online service can guarantee absolute security. Do not submit secrets, access tokens, payment-card data, or material you are not authorized to process.
7. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a copy of personal information, or to object to certain processing. You can disconnect the ChatGPT session using the OAuth control and can decline optional feedback. To make a privacy request, email hello@meldry.app. We may verify the request before acting on it.
8. Children
Meldry is not directed to children under 13, or a higher minimum age required by local law. We do not knowingly collect a child’s personal information without appropriate authorization.
9. International processing
Service providers may process information in countries other than yours. Where required, we use available contractual or legal safeguards for these transfers.
10. Changes and contact
We may update this policy as the service or law changes. The effective date above identifies the current version. Questions or requests can be sent to hello@meldry.app.