Privacy Policy
This policy explains what data the Melies iPhone app (“Melies”, “we”, “us”) handles, why, where it is kept, for how long, who it is shared with, and how you can delete it. Melies is developed and operated by its creator, known publicly as RJ Descubre. Contact: roberto_luengas@hotmail.es.
In short: your videos are edited and rendered on your iPhone and are never stored on our server. A video you schedule for publishing passes through our server only until it is delivered to the networks you chose, and is deleted right after (48 hours at most). We store text (project titles, captions, transcripts, assistant conversations) and the access tokens of the accounts you connect, encrypted. We do not sell your data, we do not use it for advertising, and we do not show ads.
1. Data we handle
1.1 On your iPhone
- Videos, photos and audio you import, record or generate, and your edits (the timeline). They stay in the app's storage on your phone and in your photo library, except a video you schedule for publishing (see 1.2).
- Transcription of your clips, done on the device with Apple's speech recognition. If the on-device model for your language is not available, iOS may send that audio to Apple for recognition; this is decided by iOS and governed by Apple's privacy policy.
- Camera, microphone, photo library and local network are used only after you grant permission and only for the features that need them (recording clips, recording your voice, importing media, bringing recordings from your own computer on your home network).
1.2 On our server
| Data | Why | How long |
|---|---|---|
| Account identifier and session tokens (if you sign in with Apple, the identifier Apple gives us and, if you choose to share them, your name and email) | To keep you signed in and keep your data separate | Until you delete your account |
| Project metadata: title, status, hook and caption text | To let you resume your work | Until you delete the project |
| Assistant conversations (what you asked and what it answered, and a text description of the timeline) | To answer you and to diagnose errors | 180 days |
| Transcripts of your live streams (words with timestamps and audio-level numbers; never audio) | To find clips in your streams | 30 days |
| Live-stream notes: stream links, marked moments, file names and durations of your recordings, Kick chat messages while the live panel is open | Live-stream features | Chat: 24 hours. Marks and recording data: 30 days. Stream records: until you delete them |
| Small still frames (JPEG) taken from a clip, when you ask Melies to find clips or explain something with an image | Visual analysis by an AI provider (section 3) | Deleted when answered, at most 24 hours |
| The video file you schedule for publishing (and, if any, its YouTube thumbnail or a Facebook photo) | To deliver it to the networks you chose at the time you chose | Deleted as soon as every chosen network has finished, when you cancel, if the upload is abandoned (2 hours), and in any case 48 hours after the scheduled time. Stored on a temporary, size-limited volume |
| Publication history: caption, scheduled time, and for each network the result, post ID and link | To show you what was published and what failed | Until you delete it or your account |
| Connected-account tokens and basic account info (section 2) | To publish or act only on the accounts you connect | Until you disconnect the account |
| Push-notification token of your device | To notify you (for example, “your post was published”) | Until Apple reports it invalid or you delete your account |
| Technical log from the app, with personal data removed on the phone before sending | To diagnose bugs | 30 days |
Access tokens are encrypted at rest with a key that is kept outside the database. Our servers are operated by us; traffic passes through Cloudflare.
2. Accounts you connect
You can connect your accounts in More (Más) › Settings (Configuración) › Social networks (Redes sociales). The app is in Spanish. Each connection uses the network's own authorization screen (OAuth); we never see your password. For each one we keep the tokens it gives us (encrypted), the permissions you granted, the account ID and the account name, and we use them only to do what you ask in the app.
2.1 TikTok
- Permissions:
user.info.basic(your open ID, display name and avatar, to show which account is connected) andvideo.publish(to post a video you approved to your profile). - What we do: before each post we read the creator information TikTok provides for posting (nickname, privacy options, interaction settings, maximum video length) to prepare it; we upload the video file you approved with the caption and settings you chose; we check its processing status and save the result (post ID). We store your open ID and display name; we do not store your avatar.
- We do not read your existing videos, followers, messages or analytics, and we do not add watermarks or promotional content to your videos.
- Use of TikTok is also subject to TikTok's Terms of Service and Privacy Policy. You can remove Melies's access in the TikTok app (Settings and privacy › Security › Manage app permissions) or by disconnecting in Melies.
2.2 YouTube (Google)
- Melies uses the YouTube API Services. By connecting a YouTube channel you agree to be bound by the YouTube Terms of Service. Google's handling of data is described in the Google Privacy Policy.
- Permissions:
youtube.upload(upload the video you approved, and set its thumbnail) andyoutube.readonly(read your own channel's name and ID to show which channel is connected). - What we store: the channel ID and name, the encrypted tokens, and the ID and link of each video Melies uploaded for you. We do not access other YouTube data.
- Revoking access: disconnect the channel in Melies (we revoke the token with Google and delete it immediately), or remove Melies at Google security settings › third-party access. If you revoke access from Google's page, the token stops working: we erase it as soon as we detect it (the next time Melies uses or checks it) and delete the rest of that channel's data within 30 days.
- Limited Use. Melies's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data from Google APIs is used only to provide the publishing features you see in the app; it is not sold, not used for advertising, not transferred to AI providers and not used to train AI models, and no person reads it except when you ask us to (for support), for security, or when required by law.
2.3 Instagram and Facebook (Meta)
- Permissions:
pages_show_list,pages_read_engagement,pages_manage_posts,instagram_basic,instagram_content_publishandbusiness_management, to list the Pages and Instagram professional accounts you manage and to publish the videos, Reels, stories and photos you approved on the ones you choose. - After connecting, you choose which Pages and Instagram accounts Melies may use; the tokens of the ones you do not choose are deleted when you save.
- We store the account IDs and names, the encrypted tokens, and the ID and link of each post. We do not read your messages, comments or insights.
- You can remove access in Melies, or in Facebook (Settings › Business integrations / Apps and websites). See also Data deletion.
2.4 Kick
- Permissions:
user:read,channel:read,channel:write,chat:write,events:subscribe, to read your channel, set your stream title and category, send the chat messages you configured, and be notified when your stream starts or ends. Melies does not publish videos on Kick. - We store the channel ID and name and the encrypted tokens; chat messages read while the live panel is open are deleted after 24 hours.
3. Who we share data with
We do not sell personal data and do not share it for advertising. We share data only as needed to provide the features you use:
- The networks you publish to (TikTok, YouTube, Meta, Kick): the content and text you chose, through their official APIs.
- AI providers, to generate text and understand your requests: DeepSeek (text only: your request, captions, transcripts and a text description of your timeline), Anthropic Claude (the same text and, for visual tasks, the small still frames described above) and Google Gemini (only when you ask Melies to draw an illustrated character: one still image and a text prompt). They never receive your full video. Data obtained from YouTube, TikTok or Meta APIs is not sent to AI providers.
- Apple: push notifications, Sign in with Apple, and speech recognition fallback as described above.
- Cloudflare, which carries network traffic to our server.
- Authorities, when required by law.
4. Your choices and rights
- Disconnect any network in Más › Configuración › Redes sociales › Desconectar: we revoke the token with that network and delete it immediately.
- Delete projects in the app, or delete everything by writing to us (see Data deletion). We complete deletion within 7 days and confirm by email.
- You can ask for access to, correction of, or a copy of your data, or object to its use, by writing to roberto_luengas@hotmail.es. We answer within 20 days.
- You can withdraw camera, microphone, photo or notification permissions at any time in iPhone Settings › Melies.
5. Children
Melies is not directed to children. You must be at least 13 years old (or the minimum age required in your country and by the networks you connect, if higher) to use it. We do not knowingly collect data from children; if you believe a child has given us data, write to us and we will delete it.
6. Security
Connections use HTTPS. Tokens are encrypted at rest; secrets are kept outside the code and the database. Video files for publishing live on a temporary volume with a size limit and are deleted automatically; every deletion is logged. No system is perfectly secure; if we learn of a breach affecting you, we will tell you.
7. International transfers
The providers listed in section 3 may process data in other countries, including the United States and China (DeepSeek). We send them only what each feature needs.
8. Changes
If we change this policy, we will update the date above and, for important changes, tell you in the app before they apply.
9. Contact
roberto_luengas@hotmail.es. This policy is also available in Spanish; if the versions differ, the Spanish version prevails.