Skip to content
Mellplus AIBack to the service

Poluco LLC · Mellplus AI

Privacy notice

Effective September 19, 2026

Poluco LLC operates Mellplus AI and is responsible for the handling of information described in this notice. This notice covers the invite-only service at mellplus.com, account access, research and analysis, planned seller-authorized Amazon business management, and support. Our Terms of Service explain permitted use. Do not upload buyer personal information, passwords or API keys into conversations.

What the service handles

We handle your account email, profile preferences and authentication records; questions, conversation history, uploaded files and extracted content; generated answers, checklists and reports; feedback; and support correspondence. Technical records may include request and run identifiers, timestamps, errors, model and tool activity, and usage and cost records. Hosting and authentication providers also process network and device information needed to deliver and secure their services.

An optional Keepa connection stores the API key you provide separately from conversations. Keepa receives the key and product or category queries when you use that connection. We do not collect payment-card details during the free pilot.

The planned Amazon Selling Partner API connection supports seller-business management: listings and pricing; orders, returns and fulfillment; FBA inventory and replenishment; Amazon Warehousing and Distribution (AWD); financial transactions and profitability; sales and traffic; and Brand Analytics. Processing would include authorization credentials, seller/account and marketplace identifiers, and the business records needed for the features you authorize. Planned actions include seller-approved listing and price changes and supported operational workflows. A separately authorized Amazon Ads connection is planned for advertising analysis and seller-approved campaign, budget and bid management.

Amazon connections are not active in this release. The currently implemented connectors are limited to marketplace, listing and FBA inventory reads, plus separate advertising-profile and campaign-configuration reads. Broader features require implementation, applicable Amazon approval, seller authorization and eligibility. Restricted buyer information is not currently requested through SP-API; any future need requires a specific permitted purpose and the required approvals and safeguards. Uploaded or pasted seller files may still contain personal or commercially sensitive information; remove unnecessary personal information before submitting them.

Why data is processed

We process information to authenticate you, maintain your case history, analyze your inputs, retrieve relevant reference material and public research, generate reports, support you, prevent misuse, and diagnose service failures. Account and analysis processing provides the service you request; security and operational records help protect and maintain that service. Where applicable law requires consent for an optional connection or other processing, you can decline that feature or withdraw the authorization.

Planned Amazon processing is limited to the accounts, marketplaces and business functions you authorize. Future write actions will require your explicit approval or a clearly defined standing authorization, permission checks, validation and an audit record. You will be able to withdraw that authorization; it does not permit access to other sellers’ private accounts. We do not sell your account information, conversations or seller data, or use them for advertising profiles.

AI processing and service providers

Analysis uses external services. Relevant conversation history, extracted file content, images and tool results may be sent to the selected AI endpoint. Do not submit information you are not authorized to share for this processing.

Google Identity
Google authenticates your sign-in and supplies authorized identity information, such as your email address and profile, to our authentication service. Mellplus AI does not receive your Google password. Google privacy policy.
Supabase
Authentication and account emails, the product database, private uploaded-file storage, case history and backend secret storage. Our project is hosted in the US East (Northern Virginia) region. Supabase privacy policy.
Vercel
Website delivery, server-side requests, upload processing and operational logs. Server functions are deployed in the US East region; website delivery uses a distributed network. Vercel privacy policy.
Hetzner
Our analysis workers and execution queue process requests, temporary analysis files and conversation state in the Helsinki, Finland (EU) region. Hetzner supplies the hosting infrastructure; the application controls access to these systems. Hetzner privacy policy.
OpenRouter and the selected model endpoint
OpenRouter routes analysis content to the configured AI endpoint. Google is the model provider identified in our current routing evidence, separately from Google sign-in; the endpoint operator can change with the selected model and eligible routes. Our inference requests require endpoints that disallow data collection and have a zero-data-retention policy (data_collection=deny and zdr=true); unavailable eligible routes must fail rather than fall back to unrestricted processing. This routing requirement covers model inference, not our separate embeddings, search, weather or other tools. Endpoint policies can permit transient in-memory caching, and this does not establish a single processing region or erase historical copies. OpenRouter account logging and other provider-held operational records are separate from this routing rule. See OpenRouter’s ZDR policy and scope. Contact us before submitting data with specific residency or processing restrictions.
OpenAI
The Professional Knowledge search query is sent to OpenAI’s embeddings API to create a numerical search vector. This is separate from the AI provider generating your answer; a query can contain information from your request. OpenAI API data practices.
Neo4j Aura
The search vector and an access-control identifier are sent to our hosted reference database to retrieve Professional Knowledge. The website search is read-only; it does not add your conversation or uploads to that reference library. Neo4j privacy policy.
Keepa — optional
Your saved key authorizes public product and category research requested through the service. Keepa receives those queries, not your entire case history. Your separate Keepa account and subscription remain governed by Keepa. Keepa legal information.
DuckDuckGo and Microsoft Bing — public research
Web searches send the search query to DuckDuckGo, with Bing as a fallback. Search providers apply their own policies: DuckDuckGo and Microsoft.
Open-Meteo — weather queries
When weather research is requested, Open-Meteo receives a place-name query, an optional country code and the resolved coordinates used to retrieve weather. These locations may come from your request; this tool does not receive your entire conversation. Open-Meteo terms and privacy information.
Resend — security alerts
Resend processes the designated security monitors’ email addresses, sanitized security-event metadata and delivery records to send operational alerts. These alerts are not intended to contain conversation content, uploaded files or credentials. Resend privacy policy.
Amazon — connections not yet enabled
After applicable approval and activation, Amazon will receive authorization and API requests for the seller or advertising account you authorize. The planned scope includes the business reads and approved actions described above. Amazon Ads requires separate authorization; access is limited by approved roles, account eligibility and available features.

Providers may use their own subprocessors and operate in countries outside your location. This is not a single-country-residency service. Links above describe each provider’s practices; they do not mean that we have enabled every privacy option that provider offers. We may also disclose information where required by law or necessary to protect accounts and investigate abuse.

Storage and safeguards

The website uses HTTPS. Case and file access is tied to your authenticated account, and uploaded files use private storage rather than public links. Saved provider keys and Amazon authorization credentials use backend Vault secret storage and are not returned to the browser. Files are scanned before analysis, spreadsheet parsing runs with restricted permissions, and application access requires Google sign-in and authenticator multi-factor authentication.

These controls reduce risk but cannot guarantee that every security incident will be prevented. Report suspected unauthorized access to support@poluco.co. Do not include passwords, keys or buyer personal information in your report.

Retention, disconnection and deletion

Account and case history: profile information remains while your account exists. Conversations, extracted content and generated reports remain in saved cases until you delete the case or request deletion. There is no automatic age-based expiry for saved case history in the current pilot. Deleting a case removes it from active history and initiates deletion of its stored attachments.

Original uploads: these are not a permanent backup. Spreadsheet and queryable CSV/TSV source objects are scheduled for cleanup after the worker accepts them for analysis. A worker’s local spreadsheet access lease expires after 15 minutes; that is not a promise that every copy, extracted value or conversation is erased within 15 minutes. Other retained file content follows the case lifecycle. Uploads that are never finalized cannot be submitted after their two-hour upload window.

Credentials: removing your Keepa connection deletes its stored secret. A running analysis may finish using the key it already received. The implemented Amazon disconnect control removes the locally stored grant; you should also revoke permission in Amazon. Removing a credential is not itself deletion of saved Amazon-derived data. The planned Amazon lifecycle must also stop further access and trigger the deletion process described below.

Operational records: scan-job records are eligible for hourly cleanup after one day and Amazon integration-event records after 30 days. Worker execution payloads and checkpoints are cleared from the execution queue after delivery is acknowledged. Run identifiers, delivery digests, usage and audit metadata can remain for operational integrity and are not all subject to an automatic age-based deletion schedule. Worker logs rotate by size, not a fixed number of days.

Amazon-derived information: our policy for the planned connection requires permanent deletion within 30 days of the earliest applicable trigger: Amazon requires deletion, you revoke authorization or terminate access, we are no longer authorized to process the information, or our participation in Amazon’s service ends. This covers Amazon information in saved cases, extracted content, derived reports, temporary files, logs, backups and provider-held copies; the general pilot case-history policy does not override it. Any legally required retention must be limited to the applicable legal purpose. Contact support to request deletion of Amazon information you have supplied in uploads or conversations.

Deletion scope: file deletion can require follow-up if storage is temporarily unavailable. Deleting active records does not itself delete provider-held logs or backup copies. We coordinate provider-held deletion through the applicable service and processing arrangement.

For account closure or access, correction, export or deletion requests, contact support@poluco.co from your account email. State whether the request covers one case, all cases, credentials or the entire account. We verify the requester’s authority before disclosing or deleting records and assess any applicable legal retention duties. Requests involving provider-held records require coordination with the relevant provider. You may exercise rights available under the law that applies to you, including raising a concern with the relevant supervisory authority.

Cookies and changes to this notice

Authentication cookies keep you signed in and support account security. Blocking them can prevent the signed-in service from working. This notice does not describe third-party websites you visit through research links; their own privacy notices apply.

We identify changes to this notice with an updated effective date. Amazon connections remain unavailable in this release. Their activation and any material change to processing must be reflected in the service’s disclosures.

Contact and privacy requests

Poluco LLC · Operator of Mellplus AI

Support & privacy email
support@poluco.co
Registered business address
151 Calle San Francisco, Suite #200, Unit 5300
San Juan, PR 00901, US

Contact us for access, support or privacy questions. Do not email passwords, API keys or buyer personal information.