mymemo

Legal

Privacy policy

mymemo holds personal notes, photos, recordings and places. This page sets out exactly what is collected, who it reaches, and what you can require of us.

1. Who is responsible

The controller of your personal data is mymemo ("we", "us").

For anything in this policy, including any request under section 7, write to support@mymemo.cloud.

2. What we collect, and why

DataWhyLegal basis
E-mail address, password (stored hashed), and — if you use Google sign-in — the identifier and e-mail address Google returns To create and secure your account, and to send you service e-mail such as address verification and password resets Performance of the contract, Art. 6(1)(b) GDPR
Your content: entries, notes, tasks, reminders, categories, subtags and saved locations This is the service — storing what you record and showing it back to you across your devices Performance of the contract, Art. 6(1)(b) GDPR
Photos, videos and files you attach To store them against your entries Performance of the contract, Art. 6(1)(b) GDPR
Voice recordings and the transcripts made from them To turn what you say into an entry. Recording only happens when you hold the microphone button Your consent, given through the microphone permission, Art. 6(1)(a) GDPR
Precise location Only when you ask for it — "use my current location" in the place picker, and to attach a place to an entry Your consent, given through the location permission, Art. 6(1)(a) GDPR
Device notification token To deliver reminders you set Performance of the contract, Art. 6(1)(b) GDPR
Technical and usage records: sign-in attempts, error diagnostics, credit consumption To keep the service running, to investigate faults, and to prevent abuse of the account and of paid capacity Our legitimate interests in a secure, working service, Art. 6(1)(f) GDPR

We do not use your content for advertising, we do not sell it, and we do not use it to train artificial-intelligence models.

3. Automated processing

When you record a voice note, the audio is transcribed and the text is analysed to propose a structure for the entry — whether it looks like a note, a task or a cost, and which category, date, amount or place it mentions. This is a suggestion shown to you for confirmation. It produces no legal or similarly significant effect, and nothing is decided about you without your involvement.

4. Who processes your data on our behalf

We do not sell or rent your data. It is handled by the following providers, acting on our instructions:

ProviderWhat it handlesWhere
Microsoft Azure Application hosting, database, and file storage — your account, entries and attachments West Europe (Netherlands)
Azure OpenAI Service (Microsoft) Speech-to-text and the analysis described in section 3 Sweden Central (Sweden)
Azure Communication Services (Microsoft) Sending service e-mail to your address European Union
OpenFreeMap Vector map tiles for the in-app map. Receives the map coordinates being displayed and your device's IP address Not publicly disclosed by the provider
CARTO Raster map tiles used as a fallback when the vector map cannot be loaded. Receives the map coordinates being displayed and your device's IP address Not publicly disclosed by the provider
Photon, operated by Komoot GmbH Converting place searches into coordinates and coordinates back into addresses. Receives what you type into the place search and, for "use my current location", your coordinates Germany
Google (Firebase Cloud Messaging) Delivering reminder notifications to your device European Union and United States
Google (Sign-In) Only if you choose to sign in with Google European Union and United States

5. Transfers outside the European Economic Area

Your account, content and attachments are stored inside the EEA. Notification delivery and Google sign-in may involve transfers to the United States; those are covered by the European Commission's standard contractual clauses and, where applicable, the EU–US Data Privacy Framework.

6. How long we keep it

We keep your account and content for as long as your account exists — until you delete it. You can delete individual entries, attachments and recordings yourself at any time, and you can have the whole account removed: see deleting your account. We action confirmed deletion requests within 30 days.

Limited technical records, such as security and error logs, are kept for a short period for the purposes in section 2 and then discarded.

7. Your rights

Under the GDPR you may:

To exercise any of these, write to support@mymemo.cloud.

You also have the right to complain to the Polish supervisory authority: Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa.

8. Security

Data is encrypted in transit between the app and our service, and is encrypted at rest by our hosting provider. Passwords are stored only as hashes and cannot be read back by us. Access to production systems is limited to those who need it.

No service can promise perfect security. If a breach affects your data and poses a high risk to you, we will tell you.

9. Children

mymemo is not intended for children under 16. We do not knowingly collect data from them. If you believe a child has given us their data, write to us and we will remove it.

10. Changes

If this policy changes in a way that matters, we will update the date below and, where the change is significant, tell you in the app or by e-mail.

Last updated: 13 September 2026