Privacy Policy
Last updated: 2026-06-02
1. Introduction
This Privacy Policy describes how Memorio (“we”, “us”) collects, uses, and shares information when you use our Service.
2. Information we collect
Account data: email address, name (if provided), authentication identifiers when you use email/password or OAuth providers (e.g. Google, Apple), and subscription status.
Learning data: decks, words, study progress, statistics, streaks, and similar data you create in the app.
Technical data: IP address, browser or device type, approximate timestamps, and cookies or similar technologies needed for sessions and security.
AI chat: messages you send to the AI assistant and related context may be processed by us and by AI providers to generate responses.
Worksheet scan (Premium): photos you upload to extract vocabulary are sent to our servers and processed by AI vision providers (e.g. Groq) to return word pairs; images are not used for advertising.
3. How we use information
We use the information to provide, maintain, and improve the Service; authenticate users; process subscriptions; prevent abuse and enforce our Terms; analyze usage in aggregate form; and communicate with you about the Service.
Legal bases under GDPR may include contract performance, legitimate interests (security, anti-abuse, product improvement), consent (where required), and legal obligations.
4. Sharing and processors
We may share data with service providers who help us host the application, process payments, send email, or run AI inference (e.g. Groq or other model hosts), subject to contractual safeguards.
We may disclose information if required by law, to protect rights and safety, or in connection with a merger or asset sale (with notice where appropriate).
5. Retention
We retain your information as long as your account is active and as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. You may request deletion of your account where supported; some data may be retained in backups for a limited period.
6. Security
We implement reasonable technical and organizational measures to protect personal data. No method of transmission or storage is 100% secure.
Security measures may include encryption in transit, access controls, logging, and restricted administrative access on a need-to-know basis.
7. International transfers
Your data may be processed in countries where we or our providers operate. Where required, we rely on appropriate safeguards (such as standard contractual clauses) or your consent.
8. Your rights
Depending on your location, you may have rights to access, rectify, delete, restrict, or port your personal data, and to object to certain processing. You may also lodge a complaint with a supervisory authority. Contact us through the app to exercise these rights.
For GDPR requests (DSAR), we may need to verify your identity before processing the request and may deny or limit requests where allowed by law.
9. Data categories and retention periods
Account and subscription records are retained for account administration and legal compliance obligations (including financial and anti-fraud records).
Learning content and progress are retained while your account is active, and for a limited period after account deletion where required for backup integrity, legal obligations, or dispute resolution.
Operational logs and security logs are retained for limited periods based on operational necessity and incident response requirements.
10. Cross-device synchronization
If you sign in on multiple devices (web/iOS/Android), your learning data may be synchronized between devices to provide continuity of the Service.
Synchronization metadata (timestamps, identifiers, conflict-resolution markers) may be processed to keep your data consistent across devices.
11. Data protection contact and complaints
If you have privacy concerns, submit a request through in-app support or the official support contact channel listed in the Service.
If you are in the EEA, you may lodge a complaint with your local supervisory authority.
12. Children
The Service is not directed at children under the age where parental consent is required in your jurisdiction. If you believe we have collected such data, contact us and we will take appropriate steps.
13. Changes
We may update this Privacy Policy from time to time. We will adjust the “Last updated” date and, where appropriate, provide additional notice.
14. Contact
For privacy questions, contact us through support channels provided in the application or on the official website.
15. Named sub-processors
We use the following sub-processors bound by data protection agreements: • Vercel Inc. — Hosting, edge delivery, serverless functions (USA / EU) • Supabase Inc. — PostgreSQL database, authentication infrastructure (USA / EU) • Stripe, Inc. — Payment processing and subscription billing (USA / EU) • Groq, Inc. — AI inference (chat, grammar, worksheet vision) (USA) • Google LLC — OAuth sign-in (where enabled) (Global) • Apple Inc. — Sign in with Apple (where enabled) (Global) • Meta Platforms, Inc. — Ads measurement (Meta Pixel, with consent) (USA / EU) • TikTok Technology Limited — Ads measurement (TikTok Pixel, with consent) (EU / Global)
16. Grammar and learning analytics
Grammar course progress, topic completion, practice scores, weak-pattern signals, and reading-passage interactions may be stored locally and synchronized to our database (Supabase) when you are signed in, to resume learning across devices.
17. Camera, photos, and device permissions
Worksheet scan requests camera or photo library access on mobile devices. Images are uploaded to our servers for AI processing and are not used for advertising profiles. Android may declare microphone permission for system components; we do not record audio for learning features unless a future feature explicitly requests it and updates this Policy.
18. OAuth sign-in
When you use Google or Apple sign-in, we receive identifiers and (where provided) name and email from the provider according to your consent on their screen. We do not receive your Google/Apple password.
19. Payment data
Stripe processes card and billing details. We receive subscription status, customer IDs, and limited billing metadata — not full card numbers.
20. AI data handling
Prompts, chat history, grammar generation context, and scan images may be sent to Groq or similar providers for inference. We do not use your content to train public foundation models. Logs may be retained briefly for abuse prevention, debugging, and quota enforcement.
21. UK, Switzerland, and California notices
UK GDPR and Swiss FADP: you have similar rights to EEA users; contact getmemorio.dev@gmail.com. California residents (CCPA/CPRA): we do not sell personal information as defined by CPRA; you may request access/deletion. We do not use sensitive personal information for inferencing beyond providing the Service.
22. Automated decisions
We do not make solely automated decisions with legal or similarly significant effects. AI suggestions are advisory only.