Legal
Privacy policy
mymemo holds personal notes, photos, recordings and places. This page sets out exactly what is collected, who it reaches, and what you can require of us.
1. Who is responsible
The controller of your personal data is mymemo ("we", "us").
For anything in this policy, including any request under section 7, write to support@mymemo.cloud.
2. What we collect, and why
| Data | Why | Legal basis |
|---|---|---|
| E-mail address, password (stored hashed), and — if you use Google sign-in — the identifier and e-mail address Google returns | To create and secure your account, and to send you service e-mail such as address verification and password resets | Performance of the contract, Art. 6(1)(b) GDPR |
| Your content: entries, notes, tasks, reminders, categories, subtags and saved locations | This is the service — storing what you record and showing it back to you across your devices | Performance of the contract, Art. 6(1)(b) GDPR |
| Photos, videos and files you attach | To store them against your entries | Performance of the contract, Art. 6(1)(b) GDPR |
| Voice recordings and the transcripts made from them | To turn what you say into an entry. Recording only happens when you hold the microphone button | Your consent, given through the microphone permission, Art. 6(1)(a) GDPR |
| Precise location | Only when you ask for it — "use my current location" in the place picker, and to attach a place to an entry | Your consent, given through the location permission, Art. 6(1)(a) GDPR |
| Device notification token | To deliver reminders you set | Performance of the contract, Art. 6(1)(b) GDPR |
| Technical and usage records: sign-in attempts, error diagnostics, credit consumption | To keep the service running, to investigate faults, and to prevent abuse of the account and of paid capacity | Our legitimate interests in a secure, working service, Art. 6(1)(f) GDPR |
We do not use your content for advertising, we do not sell it, and we do not use it to train artificial-intelligence models.
3. Automated processing
When you record a voice note, the audio is transcribed and the text is analysed to propose a structure for the entry — whether it looks like a note, a task or a cost, and which category, date, amount or place it mentions. This is a suggestion shown to you for confirmation. It produces no legal or similarly significant effect, and nothing is decided about you without your involvement.
4. Who processes your data on our behalf
We do not sell or rent your data. It is handled by the following providers, acting on our instructions:
| Provider | What it handles | Where |
|---|---|---|
| Microsoft Azure | Application hosting, database, and file storage — your account, entries and attachments | West Europe (Netherlands) |
| Azure OpenAI Service (Microsoft) | Speech-to-text and the analysis described in section 3 | Sweden Central (Sweden) |
| Azure Communication Services (Microsoft) | Sending service e-mail to your address | European Union |
| OpenFreeMap | Vector map tiles for the in-app map. Receives the map coordinates being displayed and your device's IP address | Not publicly disclosed by the provider |
| CARTO | Raster map tiles used as a fallback when the vector map cannot be loaded. Receives the map coordinates being displayed and your device's IP address | Not publicly disclosed by the provider |
| Photon, operated by Komoot GmbH | Converting place searches into coordinates and coordinates back into addresses. Receives what you type into the place search and, for "use my current location", your coordinates | Germany |
| Google (Firebase Cloud Messaging) | Delivering reminder notifications to your device | European Union and United States |
| Google (Sign-In) | Only if you choose to sign in with Google | European Union and United States |
5. Transfers outside the European Economic Area
Your account, content and attachments are stored inside the EEA. Notification delivery and Google sign-in may involve transfers to the United States; those are covered by the European Commission's standard contractual clauses and, where applicable, the EU–US Data Privacy Framework.
6. How long we keep it
We keep your account and content for as long as your account exists — until you delete it. You can delete individual entries, attachments and recordings yourself at any time, and you can have the whole account removed: see deleting your account. We action confirmed deletion requests within 30 days.
Limited technical records, such as security and error logs, are kept for a short period for the purposes in section 2 and then discarded.
7. Your rights
Under the GDPR you may:
- ask what we hold about you, and get a copy;
- have inaccurate data corrected;
- have your data erased;
- have our processing restricted while a dispute is resolved;
- receive your data in a portable format;
- object to processing we carry out on the basis of legitimate interests;
- withdraw consent — for the microphone or for location — at any time, in your device settings. Withdrawing it does not affect what was done beforehand.
To exercise any of these, write to support@mymemo.cloud.
You also have the right to complain to the Polish supervisory authority: Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa.
8. Security
Data is encrypted in transit between the app and our service, and is encrypted at rest by our hosting provider. Passwords are stored only as hashes and cannot be read back by us. Access to production systems is limited to those who need it.
No service can promise perfect security. If a breach affects your data and poses a high risk to you, we will tell you.
9. Children
mymemo is not intended for children under 16. We do not knowingly collect data from them. If you believe a child has given us their data, write to us and we will remove it.
10. Changes
If this policy changes in a way that matters, we will update the date below and, where the change is significant, tell you in the app or by e-mail.
Last updated: 13 September 2026