Privacy Policy

Last updated: September 15, 2026

This Policy explains how mello collects, uses, discloses, and retains information when you use our app, website, event-sharing pages, support channels, and related services.

Information we collect

Account and device data. Email address, authentication and session data, account identifiers, age eligibility, notification preferences, push tokens, device platform, security events, and support communications.

Profile data. Display name, username, full birthdate, gender and event eligibility settings, neighborhood, biography, prompts, interests, photos, verification status, followers, connections, and other information you choose to add.

Location and travel data. With permission, mello processes precise coordinates to suggest your location and find nearby activities. We store coordinates associated with your home area, search area, events, and trips. We also store destination labels and travel dates. We generally display a neighborhood, city, approximate area, or distance instead of your precise home coordinates.

Events and social activity. Events you create, save, join, attend, cancel, or host; venue details; attendee and waitlist status; check-ins; follows; blocks; connections; reviews; search radius; and event costs or attendance requirements.

Messages and media. Event, direct, and crew messages, replies, reactions, photos, voice clips, delivery state, and related metadata. Some content may be cached on your device for performance and offline display.

Safety and moderation data. Reports, categories, account and content references, moderation actions, blocks, appeals or support correspondence, and a protected snapshot of reported content where needed to review a concern or preserve evidence.

Payments. Stripe customer, payment-method, and payment-intent identifiers, transaction state, no-show charge information, and limited billing details. Payment-card details are submitted directly to Stripe; mello does not store full card numbers.

Website and operational data. Requests, IP-derived security information, browser and device characteristics, error logs, function and delivery logs, and interactions needed to protect and operate the service. We do not currently use your information to build third-party advertising profiles or sell personal information.

Where information comes from

We receive information from you, your device permissions, your activity in mello, hosts and members you interact with, service providers acting for us, and safety or support reports. Event hosts may provide attendance information. Stripe provides payment and identity-verification status. Google location services may return place and geocoding results from searches or coordinates you submit.

How information is shared and displayed

Member profiles. Signed-in members may see profile fields such as display name, username, photos, approximate area, interests, prompts, gender or event-eligibility information where relevant, verification badge, and social connections.

Events. Hosts and attendees can see information needed to coordinate an event. Exact venue details are restricted based on event status and eligibility. Hosts can see attendee and check-in information.

Travel discovery. Travel destinations, date ranges, and approximate presence may be used to connect travelers and locals in a selected area.

Public event links. A shared event page may be visible without signing in and may show the event title, description, approximate area, cover image, host display name, attendee count, and a limited preview of attendee first names and avatars. Certain restricted events suppress attendee previews.

Chats. Members of an event, direct conversation, or crew can see content shared in that conversation. Moderators may access reported content when necessary to investigate safety concerns. Chat media is currently delivered through link-addressed files. Conversation members receive those links, and anyone who obtains a valid link may be able to access the file until it is removed.

Do not post information you do not want the relevant audience to see. Blocking limits future interaction but may not remove content already shared, retained safety evidence, or information another person saved outside mello.

Identity verification and biometric information

Identity verification is optional unless a particular feature or event requires it. If you choose it, Stripe Identity collects and processes a government identity document, a selfie, and biometric information derived from those materials to compare identity and liveness. The purpose is to help confirm that an account belongs to a real person and provide a verification signal.

mello does not receive your raw government-ID image, selfie, or facial geometry. We do store your consent record and policy version, verification attempt and status, a Stripe verification-session identifier, failure information where applicable, and relevant timestamps. Stripe processes the underlying verification materials under its own privacy terms and our service arrangement.

You may withdraw biometric consent in Account settings. We promptly return the account to an unverified state and request redaction from Stripe. Provider redaction is asynchronous and may remain pending while Stripe completes it. We retain the minimum session and consent evidence needed to verify completion, handle retries, comply with law, and prevent an unconfirmed deletion from being described as complete.

Our retention schedule is to destroy biometric information collected on our behalf when the verification and legally required deletion process is complete, or no later than three years after your last interaction with mello, whichever occurs first, unless a shorter period is required by law. We do not sell, lease, trade, or profit from biometric identifiers or biometric information.

How we use information

  • provide accounts, discovery, maps, trips, events, chats, reminders, notifications, support, verification, and payment features;
  • personalize nearby results and enforce event eligibility, capacity, privacy, and safety controls;
  • authenticate users, prevent abuse, debug failures, secure infrastructure, and maintain service reliability;
  • review reports, enforce our Terms, preserve evidence, protect members, and comply with valid legal obligations;
  • process transactions, saved payment methods, attendance outcomes, refunds, disputes, and no-show charges where expressly authorized; and
  • measure and improve mello using operational, aggregated, or de-identified information where practical.

Service providers and disclosures

We disclose information to providers only as needed for their services, security, legal compliance, and our instructions. Current categories include:

  • Supabase for authentication, databases, storage, realtime features, and server functions;
  • Stripe for identity verification, saved payment methods, and payment processing;
  • Expo, Apple, and Google for app delivery, updates, device notifications, and platform services;
  • Google Maps Platform for place search, geocoding, and location labels;
  • Resend for service email; and
  • Google Fonts and hosting providers for website delivery and typography.

We may also disclose information with your direction; to event participants as described above; to professional advisers and transaction counterparties under appropriate duties; to protect rights, safety, and security; or when required by valid legal process. If ownership of mello changes, information may transfer subject to this Policy and applicable law.

Retention, withdrawal, and account deletion

We retain information for the shortest period reasonably necessary for the purposes described here, considering account activity, safety, fraud, payment disputes, backups, provider deletion status, and legal duties. Profile, event, social, and active message data generally remain while your account or the relevant feature is active. Device caches remain until cleared, expired, reinstalled, or removed through account controls.

Deleting your account initiates removal of your profile, owned media, account data, and Stripe Identity records. Some deletion work may complete asynchronously or require a retry if a provider cannot confirm deletion. Stripe payment records, transaction records, reported-content evidence, security logs, and legal records may be retained by us or a provider for chargebacks, fraud prevention, safety, accounting, legal claims, or mandatory retention, then deleted or de-identified when those purposes expire.

Backups and provider systems may take additional time to cycle. We may retain de-identified information that cannot reasonably be linked back to you.

Your choices and privacy rights

You can edit profile information, adjust notification settings, manage location permission, block members, withdraw biometric consent, and request account deletion in the app. Depending on where you live, you may also have rights to know, access, correct, delete, or obtain a copy of personal information; opt out of certain sale, sharing, targeted advertising, or profiling; limit certain sensitive-data uses; withdraw consent; and appeal a denied request.

mello does not currently sell personal information or share it for cross-context behavioral advertising. To exercise a right, email legal@mellomeet.com. We may verify your identity and authority before acting. Authorized agents may submit requests where law allows. We will not discriminate against you for exercising a privacy right.

Security and international processing

We use administrative, technical, and organizational safeguards designed for the sensitivity of the information involved, including access controls and protected service boundaries. No system is completely secure, and we cannot guarantee that unauthorized access or loss will never occur. Providers may process information in the United States and other countries where they operate, subject to applicable transfer requirements.

Children

mello is for adults age 18 and older and is not directed to children. We do not knowingly allow anyone under 18 to create an account. If you believe a child provided information to mello, contact us so we can investigate and take appropriate action. See our Child Safety Standards.

Changes to this Policy

We may update this Policy as mello evolves. We will change the date above and provide additional notice or obtain consent where applicable law requires it. Material changes apply prospectively unless we clearly explain otherwise.

Contact us

Questions or privacy requests may be sent to legal@mellomeet.com. Child-safety concerns may also be sent to support@mellomeet.com.