Privacy
Your money stays yours.
Melo is local-first. This notice explains what stays on your device, what can leave it when you choose a connected feature, and the controls available to you.
Last updated 19 July 2026
Who is responsible
Melo is an independently operated UK personal-finance app. Melo is the controller for data processed through its optional online services. Contact support@melo-money.com for privacy questions or rights requests.
What stays on your device
Balances, accounts, transactions, bills, subscriptions, pots, plans, debts, settings, review state, retained statement sources and Melo memory are kept in encrypted local storage. Statement reading and the shipping Melo companion run on the device. Imported rows remain candidates until you confirm them.
When data can leave your device
- Crash diagnostics: Sentry can receive a scrubbed technical crash event. Melo removes user, request, free-text extra and breadcrumb fields; screenshots, view hierarchy, session replay, performance tracing and default personal-data collection are disabled.
- Optional sign-in and encrypted backup: the identity provider processes the identifier and session data needed to sign in. Backup content is encrypted on the device before it reaches Melo's Cloudflare service.
- Purchases: Google Play or Apple processes payment. Melo receives a product identifier and purchase proof needed to verify and restore access, not card details.
- Optional Open Banking: if activated and you explicitly connect a bank, the regulated provider processes the account information covered by your consent. Provider credentials do not live in the app and imported rows still require review.
Purposes and legal bases
Connected-service data is used to provide the feature you request, secure and restore access, verify purchases, diagnose faults and meet legal obligations. Depending on the feature, the legal basis is performance of the service you requested, legitimate interests in security and reliability, consent where required, or a legal obligation.
Retention and deletion
Local data remains until you export, remove or clear it. Crash events follow the configured diagnostic retention period. Optional cloud data remains until you delete the account or backup, subject to short operational backups and legal obligations. Melo does not sell data or use it for advertising or behavioural profiling.
Your choices and rights
You can use Melo's personal core without an account, export your data, remove retained sources, clear local data, disconnect connected services and request account deletion. UK users can also ask for access, correction, restriction, objection, portability or deletion and may complain to the Information Commissioner's Office.
International processing and security
Some service providers may process technical or account data outside the UK. Melo requires an appropriate transfer mechanism where applicable. Melo uses encryption in transit and encrypted local or client-encrypted cloud storage, but no system can promise absolute security.
Children and changes
Melo is intended for people aged 18 and over. This notice will be updated when a material data flow changes; the date above identifies the current version.