Privacy Policy
Last updated: August 27, 2026
Meli is a budgeting application built by Futur Labs LLC. It works by reading transaction alert emails from your email account and turning them into a spending ledger on your Mac. This policy explains what data Meli handles, where it goes, and what controls you have.
The short version
Meli runs on your Mac and keeps your transactions there. The password or token Meli uses to read your email never leaves your Mac, and we do not operate servers that store your transactions or emails. A few features talk to outside services, and each one is described below: crash reports, optional Smart Categorization, license checks for Meli Pro, and free trial setup.
Data stored on your device
All of the following stays on your Mac. None of it is sent to Futur Labs or any third party unless explicitly described below.
- Email account access — For Gmail and Outlook accounts, read-only sign-in tokens. For IMAP accounts, the server address and sign-in details you provide. These are kept in the macOS Keychain and are used only to check your email for transaction alerts.
- Email content — Matching messages, including their body text, are stored locally so Meli can find transaction details. Meli keeps them so it can retry messages it could not interpret as support for more banks and formats improves, and so newer versions can extract details that earlier versions missed. See Google data retention and deletion.
- Transactions — Merchant names, amounts, dates, categories, tags, and notes.
- Rules and preferences — Categorization rules, budget settings, and other configuration you create.
Google API data
When you connect Gmail, Meli requests gmail.readonly access to read your account address and the metadata and text of possible transaction-alert emails. Meli uses this data only to build your local spending ledger. It does not access Gmail settings or send, modify, or delete messages. Meli also requests basic sign-in (openid), which it uses only to set up your free trial. See Free trial setup below.
Meli searches Gmail only for transaction-alert messages from supported banks and payment services (for example, American Express, Chase, Venmo, and PayPal). It does not list or browse the rest of your mailbox. Only the text of matching messages is read. Attachments are never downloaded.
- Storage — OAuth tokens are kept in the macOS Keychain. Gmail messages and derived transactions are stored only on your Mac. Gmail messages are not sent to Futur Labs or any third party provider.
- Optional Smart Categorization — If you opt in, only the disclosed transaction details derived from Gmail alerts are sent to your selected provider; Gmail messages are never sent. See Smart Categorization below.
- Prohibited uses — Meli does not sell Google user data, use it for advertising, or use it to train or improve generalized AI or machine learning models.
- Your controls — Remove the Gmail account from Meli, revoke access in your Google Account, or choose Meli > Uninstall Meli... and delete all locally stored data.
Meli's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Every commitment in this policy about what Google user data Meli accesses, how it uses or transfers that data, and what Meli does not do applies equally to raw email data, information derived from it, and any aggregated or anonymized form of that data.
Features that use outside services
Crash reports
Crash reporting is enabled by default and can be disabled at any time in Settings under Help Improve Meli. When Meli crashes, it sends a crash report to Sentry, a third-party error tracking service, so we can fix the bug. Reports are only sent for application crashes — regular errors, warnings, and log messages are never transmitted.
Crash reports include:
- The error message
- The stack trace
- The app version
- The operating system
- The system architecture
Before sending, Meli removes passwords, tokens, and keys, and strips the user, device name, and request details. Crash reports do not contain your email content, transaction data, or sign-in details.
Smart Categorization (optional, off by default)
Smart Categorization is a Meli Pro feature that suggests categories for your transactions. It is opt-in and off by default. Turning it on always shows you what will be sent and asks for your agreement first.
When Smart Categorization is on with Meli AI, the following transaction details derived from your email alerts are sent through Meli's gateway to our AI provider (OpenAI):
- Merchant name (for example, Amazon, Starbucks, or Uber)
- Note
- Whether it was a refund
- Whether the payment was between two people
- Payment service (for example, Square, Toast, DoorDash, Snack, Shopify, or CAKE)
- The names and descriptions of your categories and tags, and category emoji
- Your past choices
- App version
Payment service means the payment platform that processed the transaction, when known. A category description may include the names of your budget line items when the category has more than one. Your past choices are your previous accept or reject choices on similar transactions. Merchant names are replaced with [Redacted] for payments between two people. Notes are sent as written.
Transaction amounts, transaction dates, account and card details, email address, and the emails themselves are never sent.
Our gateway does not keep Smart Categorization request data. Its database contains only licensing, trial, subscription, and installation records. Its logs record operational information only: the client IP address, the request method and path, a generated reference number for the request, how many transactions were in the request, how many suggestions came back, how long it took, and whether it succeeded or failed. When something goes wrong, the logs also record the reason. That can include the size limit a request exceeded, rate limit details returned by OpenAI, or the length of a response Meli could not read. The logs never contain merchant names, notes, or any other transaction details.
Smart Categorization requests are authorized by a signed token that proves an active Meli Pro subscription. The gateway checks only the token's signature, its expiry, and that it grants Pro. It does not read, log, or store which license or installation the request came from, and it makes no lookup against your license or subscription records. Smart Categorization requests are not linked to your license, your installation, or any account.
Smart Categorization requests that Meli sends to OpenAI use a dedicated OpenAI API project configured for Zero Data Retention. Under this control, OpenAI excludes the customer content in those requests and responses from its abuse-monitoring logs and treats the API's storage setting as disabled, so prompts and responses are not saved through the API's response-storage feature. OpenAI does not use data submitted through its API to train or improve its models unless a customer explicitly opts in; we do not opt in. We use Zero Data Retention as an additional privacy safeguard; it does not change the limited information sent to OpenAI or the separate operational logs maintained by Meli's gateway, described above.
You can also point Smart Categorization somewhere else in the settings:
- Ollama — Runs on your own Mac, so categorization stays local.
- Another compatible service — Requests go directly from your Mac to the service, and its privacy terms apply. Any API key you enter is stored in the macOS Keychain.
On-device email review (Apple Intelligence)
On Macs with Apple silicon, macOS 26 or later, and Apple Intelligence turned on, Meli can use Apple's on-device model to judge whether an unfamiliar email looks like a transaction. This runs entirely on your Mac. Your emails never leave your computer.
License checks (Meli Pro)
If you buy Meli Pro, the application periodically contacts our licensing service to confirm your license. These checks include your license key and an install identifier, and never include transactions or email content. Purchases themselves are handled by Lemon Squeezy, our merchant of record, under its own privacy policy.
Free trial setup
Connecting an email account starts your free trial automatically. Meli sends our licensing service an install identifier and proof that you signed in with Google or Microsoft. It uses these only to check that you are eligible, so each person gets one trial. Your trial is not linked to a license or subscription. These requests never include transactions or email content.
Google data retention and deletion
Meli does not automatically delete Gmail messages or information derived from them based on age. Deleting a transaction in Meli hides it from your ledger. Its record remains on your Mac, and the stored email is unaffected. Removing the email account, or uninstalling and choosing to remove your data, are the two ways to delete stored email content. Removing an email account always deletes every locally stored message for that account and its saved sign-in details from the macOS Keychain. If you choose to keep imported transactions, only the extracted transaction records remain.
Meli's AI gateway keeps its operational logs for 30 days and does not store Smart Categorization request data. Smart Categorization requests sent to OpenAI are protected by the Zero Data Retention safeguards described in Smart Categorization.
Crash reports are kept for 30 days. They do not contain Gmail messages, transaction data, or sign-in details.
Licensing records are not Gmail data. They are kept indefinitely and contain the license key, the customer's email address, subscription status, and activation counts. This information comes from the Lemon Squeezy purchase, not from the user's email account.
Trial and installation records are not Gmail data. They are kept indefinitely. The identifiers in these records are one-way values that cannot be traced back to a person from the record alone.
See Your controls for deleting data on your Mac and requesting deletion of licensing and trial records.
How we protect your data
- Secrets on your Mac: Sign-in tokens, email passwords, and license keys are stored in the macOS Keychain. They are marked as device-only and excluded from iCloud Keychain sync.
- Local database: The Meli database file and its application folder are readable only by your macOS user account. Temporary database working data stays in memory and is never written to temporary files.
- Network connections: All network connections use TLS.
- Smart Categorization: Merchant names are replaced with
[Redacted]for payments between two people before anything is sent. See Smart Categorization for the full disclosure. - OpenAI Zero Data Retention: Meli AI requests use a dedicated OpenAI API project with Zero Data Retention enabled, which excludes customer content from OpenAI's abuse-monitoring logs and disables API response storage.
- Crash reports: Passwords, tokens, and keys are removed before a report is sent. Reports contain no email content, transaction data, or sign-in details.
- On-device email review: Apple's on-device model processes the message on your Mac. Message content never leaves your Mac for this feature.
Website
The Meli website (trymeli.app) uses Umami Cloud, a privacy-focused analytics service, to measure page views, anonymous visits, referral and campaign information, device and browser characteristics, approximate location, and clicks on download and purchase links. Umami does not use cookies. Anonymous sessions are derived from request information such as IP address and user agent; IP addresses are not stored. We do not send names, email addresses, financial data, or account identifiers to Umami, and we do not use session recording, heatmaps, advertising tracking, or cross-site tracking. Our hosting provider also processes standard technical data to serve the site, and we may use request counts, for example to see how often the application is downloaded.
What we do not do
- We do not operate servers that store your financial data or emails.
- We do not sell or rent your data, and we do not share it for advertising or any cross-context behavioral purpose. If you turn on Smart Categorization with Meli AI, limited data is sent through Meli's AI gateway to OpenAI. See Smart Categorization above for exactly what is sent and what is not.
- We do not use analytics or advertising trackers in the application.
- We do not require an account or login to use Meli.
Your controls
- Manage individual data — Deleting a transaction hides it from your ledger, but its record remains on your Mac. Rules, categories, and tags can be deleted from within the application, which removes their records from the local database. Removing an email account always deletes every locally stored message for that account and its saved sign-in details from the macOS Keychain. You can choose whether to keep or delete imported transactions. Keeping them retains only the extracted transaction records, never the original messages.
- Delete off-device records — Email [email protected] to ask Futur Labs to delete your licensing and trial records.
- Smart Categorization — Off by default. Turn it on or off at any time in settings, or choose a local provider.
- Uninstall — Choose Meli > Uninstall Meli... from the application menu. The built-in uninstaller asks whether to keep or remove your data. Choosing to remove it erases everything Meli stored on your Mac.
Changes to this policy
We may update this policy from time to time. Changes will be posted on this page with an updated date. If we make significant changes to how we handle your data, we will note it prominently.
Contact
If you have questions about this policy, contact us at [email protected].