Maelon ("we", "us") is a productivity workspace with tasks, notes, calendar, a visual canvas, and an AI assistant (Quinn), at app.maelon.co. Maelon is operated by Tinsly Co. from Canada. This policy explains what we collect, why we collect it, and the choices you have. If anything here is unclear, email us at hello@maelon.co.
What we collect
Account information
When you sign up we receive your email address and (if you sign in with Google) your name and profile photo. We use these to authenticate you and personalize the app.
Content you create
Tasks, notes, workspace names, calendar events, files and images you upload, canvas creations, and any text or prompts you submit through Capture or Quinn. This content is yours; we store it on your behalf so the app works. When you use an AI feature, the content you submit to it is sent to our AI providers (listed below) to generate a response.
Onboarding answers
When you first sign up we ask optional questions about your role, team size, intended use cases, and where you heard about us. Most fields are skippable. We use the answers to tailor the product and improve our marketing.
Google data (only if you sign in with Google)
With your consent, we request access to your Google Calendar so Maelon can read and write your events on your behalf. We store an access token and refresh token server-side, encrypted at rest, so we can refresh access without prompting you again. We never sell Google data, never use it to train AI models, and never share it with third parties beyond what's required to run our app.
You can revoke this access at any time from your Google Account permissions page. Revoking immediately stops Maelon from accessing your calendar.
Usage and server logs
Standard server logs (IP address, request path, timestamps, and user agent) so we can debug, monitor performance, and prevent abuse.
Product analytics and diagnostics
To understand how the app is used and to fix problems, we use a small set of privacy-conscious tools. PostHog measures product usage (which features are used, how flows perform) and may capture session replays of your interactions with the app interface. Sentry captures error and crash reports, including the diagnostic context around a failure, when something goes wrong. We use these strictly to improve reliability and the product. We never use them to build advertising profiles, and we do not run advertising trackers.
Desktop app downloads
When you download the Maelon desktop app from our site, we record the download along with an approximate location derived from your IP address (country, region, and city), the page that referred you, and your browser user agent. We use this to understand demand and where our users are. We store the derived location, not the raw IP address, with the download record.
How we use your data
- To provide and improve the Maelon product
- To authenticate you and keep your account secure
- To send transactional email (sign-in links, account notices)
- To send occasional product updates by email — you can opt out anytime
- To respond when you contact us
- To prevent fraud, abuse, and security incidents
How we share your data
We do not sell your data. We share data only with service providers we use to run Maelon, and only to the extent they need it:
- Supabase — managed Postgres + authentication
- Vercel — application hosting
- Anthropic — AI for Quinn, Capture, and the daily briefing (your input is sent server-side; not used for training per Anthropic's API terms)
- OpenAI — image generation (your image prompts are sent server-side; not used for training per OpenAI's API terms)
- fal.ai — image, audio, and other media generation (your prompts and inputs are sent server-side to generate the media)
- Polar — payments processor and merchant of record; receives your name, email, and subscription billing details. Card data is handled by Polar and its payment processors and is never stored on Maelon's servers
- Google — Calendar integration when you opt in
- Resend — transactional email delivery
- Beehiiv — newsletter and product-update emails (your email and name, only if you opt in)
- PostHog — product analytics and session replay of the app interface
- Sentry — error and crash monitoring (web app and, if you install it, the desktop app)
- GitHub — hosts the desktop app download file
- UptimeRobot — external uptime monitoring (no user data)
- Mapbox — address autocomplete in the calendar (only the partial address you type)
Each of these providers has its own privacy policy and security practices. We'll only ever add new processors for things that improve the product, and we'll update this list when we do.
We may also disclose information if required by law, to protect our rights, or to protect the safety of users.
Where we store data (international transfers)
Maelon is operated from Canada, but your data is stored and processed by our providers primarily in the United States. Application data is stored on Supabase (US region) and Vercel (global edge cache for non-sensitive content), and the AI, email, analytics, and payment providers listed above process data in the US and elsewhere. This means your data may be subject to the laws of those countries, including lawful access requests by their authorities. By using Maelon you consent to this transfer and processing. Provider tokens for third-party services (e.g. Google) are encrypted at rest in Supabase.
How long we keep your data
We keep your account and Content for as long as your account is active. When you delete your account, we delete your Content within 30 days, except where we need to keep limited records to meet legal, tax, accounting, or fraud-prevention obligations (for example, billing records held by our payment processor). Backups are purged on a rolling schedule.
Your rights
You can access, edit, or delete most of your data directly inside the app. To request a full export or to delete your account entirely, email hello@maelon.co and we'll action it within 30 days. If you are in Canada, you have rights under PIPEDA and applicable provincial privacy laws to access and correct your personal information and to withdraw consent. Depending on where you live (e.g. the EU, UK, or California) you may have additional rights such as data portability and the right to object. Those rights apply, and you can exercise any of them by contacting us.
Cookies and similar technologies
We use first-party cookies for authentication (keeping you signed in) and a small number of preferences (e.g. right-rail width, mute toggle for the welcome animation). Our analytics provider (PostHog) also sets cookies or local storage to measure product usage. We don't use cross-site advertising cookies.
Children
Maelon is not directed at children under 13 (or under 16 in the EU). If we learn we've collected data from a child, we'll delete it.
Security
We use TLS in transit, encrypted storage at rest, row-level security (RLS) policies in Postgres so users can only see their own data, and short-lived auth tokens. No system is perfect — if you spot a security issue, please email us at hello@maelon.co.
Changes
When we make material changes to this policy we'll update the effective date above and notify signed-in users by email or in-app notice. Continued use after a change means you accept the updated policy.
Contact
Questions, requests, or anything else: hello@maelon.co.
Maelon is operated by Tinsly Co.