Privacy

Local project understanding, deliberate sharing.

This page describes the current Meloft product boundary. It is not a substitute for independent legal review.

Project analysis

Project Doctor and compatibility analysis run locally. Private FLP content is not uploaded merely to diagnose a project. Analysis is read-only and does not overwrite the source.

Capability publication

A Capability Snapshot is published only through an explicit product action. It contains the minimum device, DAW, and plugin facts needed for recipient-aware comparison and excludes local installation paths, license keys, serials, and provider tokens.

Identity and credentials

Google is used for sign-in with basic identity scopes. Meloft identifies an external account by the provider issuer and subject, not by merging on email. Provider tokens do not go to the Desktop. Meloft refresh credentials are stored in Windows Credential Manager; access credentials stay in native process memory.

Handoff transfer

Selected project packages are encrypted on the sender device before cloud transfer. Private R2 storage receives opaque ciphertext; server metadata coordinates authorization, integrity, retention, and recipient access.

Diagnostics

Diagnostics are created only when the user chooses Export. Safe diagnostics may include app/runtime versions, environment, update channel, counts, and status flags. They exclude project names and paths, registered root paths, account email, tokens, People identifiers, and raw Handoff codes.

Deletion

A production account deletion request suspends authorization immediately and has a recovery window before scheduled purge. Transfer ciphertext cleanup is verified before related account metadata is finally removed. Detailed retention behavior is enforced by the production service contract.