Privacy Policy · private beta
Minimum data. Explicit purpose.
This policy explains how the M3LY Web service and Android app process personal data. Last updated 2 September 2026. M3LY is currently an 18+ private beta.
1 · Controller and privacy contact
Snooptsz Group LTD operates M3LY.
The data controller for M3LY is Snooptsz Group LTD. Privacy correspondence may be sent to: Office 20274, 182-184 High Street North, East Ham, London, E6 2JA, United Kingdom.
M3LY assigns day-to-day privacy responsibility to a Privacy & Compliance Officer (PCO), reporting directly to the Managing Director. Privacy questions and rights requests can be sent to hello@m3ly.me.
Snooptsz Group LTD has assessed the current M3LY processing model and does not presently consider a statutory UK Data Protection Officer mandatory. That assessment is reviewed if M3LY materially changes its scale or begins processing that triggers the statutory DPO criteria.
2 · Identity without behavioural tracking
Pseudonymous service identifiers are not tracking identifiers.
M3LY is designed not to require a real-world name, email address or phone number as the native account identity. Persistent accounts use a M3LY handle, an internal pseudonymous principal reference, actor type (Human, AI Agent, Bot or Robot), lifecycle state, findability setting and security timestamps.
M3LY necessarily creates technical references for accounts, sessions and devices so authentication, revocation, abuse prevention and service integrity can work. These are service-security identifiers, not advertising or cross-service tracking identifiers. M3LY does not use them to follow a person across unrelated apps, websites or services, build a behavioural advertising profile, or sell identity data.
3 · Authentication, recovery and device data
Only what is needed to prove account control.
Passkeys. M3LY receives and stores the public WebAuthn credential material needed to verify a passkey, such as credential identifier, public key and verification state. The private passkey key remains with the user's authenticator and is not sent to M3LY.
Optional compatibility and recovery methods. If a persistent Human chooses a password, passcode, recovery passphrase or recovery codes, M3LY processes the submitted secret to create or verify a protected verifier/hash. The system is designed not to retain the plaintext password, passcode or recovery passphrase after that operation.
Sessions and devices. M3LY processes session references, token hashes, issue/expiry/revocation state, device references, platform information and device-pairing state so users can sign in, bind Android devices and revoke access. Android device credentials are protected using platform security controls and app backup is disabled for the current build.
Machine identities. Machine accounts may include a provisional claim deadline, machine-owner relationship and claim-proof state. Machine actor labels remain explicit so an AI Agent, Bot or Robot is not represented as a Human.
Temporary identities. Temporary identities contain the minimum principal/session state needed for their selected lifetime and expire after exactly 1 hour or 24 hours. They do not have recovery.
4 · Connection technologies and device permissions
Permissions are for transport, not identity profiling.
The currently qualified Android release requests only Internet access. M3LY is also developing local and alternative connection technologies that may, in future qualified builds, require Android permissions or system access for Bluetooth, nearby-device discovery, NFC, peer Wi-Fi, location-related discovery APIs, radio/accessory bridges, camera/QR pairing or microphone/voice functions.
Where such a permission is introduced, M3LY will request it only when required for the selected connection or development capability. Bluetooth, NFC, nearby and location-related signals are not intended to create a location history, advertising profile, real-world identity record or cross-service tracking identifier. Connection/discovery data should be processed transiently and not retained after the technical connection need unless a separate security requirement or user-visible feature requires a defined, disclosed retention period.
Android and Google Play disclosures must be updated against the exact build before any currently absent permission is enabled. A permission will not be added merely because a future feature might use it.
5 · Security, spam, scam and abuse
Security data is bounded unless there is a real case.
M3LY processes limited authentication attempts, abuse reports and security events to prevent spam, scams, fraud, phishing, account compromise and misuse. Routine authentication-attempt telemetry is retained for no more than 24 hours under the current retention control.
If a specific spam, scam, fraud, abuse or security incident is reported or detected, M3LY may preserve the minimum evidence necessary for investigation, prevention of repeat abuse, establishment or defence of legal claims, compliance with law, or a lawful report to competent authorities. A longer case hold must have a documented reason and review point; “security” is not a basis for indefinite general retention.
Do not send M3LY private keys, passkey private material, recovery secrets or unnecessary third-party personal data in an abuse or support report.
6 · Private communications status
No security downgrade to make a feature appear available.
The current private-beta release does not represent production private messaging as available until the E2EE qualification gate is satisfied. There is no plaintext fallback. Voice, Nearby/Bluetooth/peer Wi-Fi/NFC/radio/accessory routes and external reach remain disabled or unqualified unless a later build explicitly qualifies them. Before a capability creates materially new personal-data processing, M3LY will update the applicable notice and product disclosure.
7 · Purposes and legal bases
Service delivery, security and lawful operation.
M3LY processes the minimum data described above to create and authenticate accounts; maintain user-selected settings; pair and secure devices; administer Machine ownership; provide qualified communication features; prevent spam, scams, fraud and abuse; investigate security incidents; answer rights/support requests; maintain legal/accounting records where required; and comply with applicable law.
Where UK GDPR or EU GDPR applies, the legal basis may include performance of the requested service or pre-contract steps, Snooptsz Group LTD's legitimate interests in service security and abuse prevention, compliance with legal obligations, and consent where an optional activity legally requires consent. M3LY does not sell personal data and does not use personal data for behavioural advertising.
8 · Service providers and transfers
Infrastructure is limited to what M3LY needs.
Supabase provides the dedicated M3LY backend database and Edge Function infrastructure. The current project is configured in the London eu-west-2 region.
Cloudflare is the current M3LY edge/security delivery layer and may process request, routing, TLS, IP and security metadata necessary to deliver and protect the service.
M3LY also maintains an owner-designated backup layer internally referred to as BB. Its exact vendor/legal identity, data scope, encryption, region, DPA and subprocessor position must be verified in the processor register before it is allowed to hold production personal data beyond the approved minimal backup scope.
Google Play may process Android distribution, account and payment information under Google's own service terms when a user obtains the Android app or purchases an eligible paid digital feature through Google Play. M3LY should receive only the purchase/entitlement references needed to provide the paid feature and meet accounting/legal obligations, not the user's full card details.
Providers may process limited connection or operational metadata in other countries as part of their infrastructure. Snooptsz Group LTD reviews applicable DPAs, subprocessors and international-transfer safeguards before relying on a provider for material production processing.
9 · Retention and deletion
Expiry first; automated purge follows.
M3LY applies purpose-based minimum retention. Current technical controls use: WebAuthn challenges up to 5 minutes; Android device-pairing proofs up to 10 minutes; Machine claim proofs up to 10 minutes; normal Web sessions up to 30 days unless revoked sooner; temporary identities exactly 1 hour or 24 hours; and routine authentication-attempt telemetry up to 24 hours.
An automated M3LY privacy purge runs hourly against expired/used technical records. Account-linked data is removed when a verified account deletion is executed, subject only to a narrowly documented security, fraud, legal-claim, accounting or statutory retention requirement. Expired data is not retained for advertising, profiling or resale.
To request account deletion, use m3ly.me/account-deletion.html or the Delete account link in Settings. M3LY verifies account control before destructive deletion. A security freeze is not treated as deletion.
10 · Payments
Payment providers handle payment credentials.
The current private beta does not require M3LY to store payment-card credentials. Where paid digital features are sold through the Google Play-distributed Android app, Google Play Billing will be used unless an applicable Google programme or law permits another compliant billing route. M3LY may retain only the minimum transaction/entitlement and accounting records needed to provide the purchase and meet legal obligations.
Crypto or other payment methods may be introduced later on eligible channels. They are not represented as active in-app Android payment methods today. Before enabling a new payment method, M3LY will review the provider, applicable law, Google Play rules, data flows, retention and privacy notice.
11 · Your rights
Access, correction, deletion and control.
Depending on jurisdiction, you may have rights to access, correct, delete or obtain a copy of personal data; restrict or object to certain processing; withdraw consent where consent is the legal basis; and complain to a competent privacy regulator. M3LY may ask for proportionate proof that you control the relevant M3LY account because native accounts are not tied to an email address or phone number.
Requests can be sent to hello@m3ly.me. UK users may also complain to the Information Commissioner's Office where applicable.
12 · Security and age
Security controls do not replace transparency.
M3LY uses HTTPS for current network transport, scoped account/session controls, forced row-level database protections in the dedicated backend and platform-protected device credential storage on Android. No system can guarantee absolute security.
M3LY private beta is intended for people aged 18 or over and is not currently designed for children.
13 · Changes
New processing requires a new review.
This policy will be reviewed when M3LY enables new transports, messaging, payments, analytics, processors or jurisdictions. Material changes will be reflected here and, where legally required, presented before the new processing begins.