1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is Lukas Waschul, Memotoria.
Contact for privacy requests: support@memotoria.com
2. Scope
This policy applies to the public websites at memotoria.com and docs.memotoria.com, the app domains app.memotoria.com and beta.memotoria.com, the authentication helper domains auth.memotoria.com and auth.beta.memotoria.com, and the use of the Memotoria application.
3. Personal data we process
Depending on how you use Memotoria, we process in particular the following categories of personal data:
- technical access data such as IP address, date and time, requested URL, referrer, browser and device information, HTTP status, and transferred data volume;
- account and authentication data such as email address, user ID, display name, linked login providers, verification status, session information, and security information;
- content you create or upload, such as decks, cards, tags, images, learning progress, favorites, shared decks, import data, and export data;
- communication data such as email address, sending time, technical delivery information, and the content of transactional authentication emails;
- security data such as App Check tokens, abuse and rate-limit signals, and logs for error analysis and system integrity;
- locally stored preferences, for example the selected landing page language or app settings.
4. Purposes and legal bases
We process personal data only to the extent necessary to provide, secure, and improve Memotoria.
- Providing the website and app, account creation, login, authentication, and use of the learning features: Art. 6(1)(b) GDPR.
- Sending transactional emails such as password reset, email verification, and email change emails: Art. 6(1)(b) GDPR.
- Protection against abuse, error analysis, operational security, rate limiting, App Check, and logging: Art. 6(1)(f) GDPR. Our legitimate interest is the secure and reliable operation of Memotoria.
- Compliance with legal obligations, where applicable: Art. 6(1)(c) GDPR.
- Processing based on explicit consent, if future optional features require consent: Art. 6(1)(a) GDPR.
5. Hosting, infrastructure, and service providers
Memotoria uses technical service providers that process personal data only on instruction and to provide the respective service.
- Firebase and Google Cloud: hosting, authentication, database, file storage, Cloud Functions, App Check, reCAPTCHA Enterprise, and technical logs.
- Mailjet / Sinch: sending transactional authentication emails, for example verification and password reset emails.
6. International transfers
Some service providers may also process personal data outside the European Union or the European Economic Area. Where this happens, the transfer is based on an adequacy decision by the European Commission, standard contractual clauses, or other appropriate safeguards under Art. 44 et seq. GDPR.
7. Cookies and local storage
The public landing page and documentation site currently do not use marketing tracking cookies. Your browser may store a local entry for the landing page language preference. The app may also use local settings and caches so that features work reliably and efficiently.
8. Retention period
Personal data is stored only for as long as necessary for the purposes described above. Account data and content generally remain stored as long as your account exists or until you delete the respective content. Technical logs and security data are retained for a limited period unless they are needed for longer to investigate abuse, errors, or legal claims. Statutory retention obligations remain unaffected.
9. Recipients of personal data
Only people and service providers that need the data for operation, support, security, or legally required processes receive access to personal data. We do not disclose personal data for advertising purposes and we do not sell personal data.
10. Your rights
Subject to the GDPR requirements, you have in particular the following rights:
- access to the data processed about you;
- rectification of inaccurate data;
- erasure or restriction of processing;
- data portability;
- objection to processing based on legitimate interests;
- withdrawal of consent with effect for the future;
- complaint with a data protection supervisory authority.
To exercise your rights, you can contact support@memotoria.com.
11. Requirement to provide data
Providing certain data is necessary to create an account, log in, store learning content, or use security features. Without this data, individual functions cannot be provided or can only be provided with limitations.
12. Automated decision-making
Memotoria currently does not make automated decisions within the meaning of Art. 22 GDPR that produce legal effects concerning you or similarly significantly affect you.
13. Security
Memotoria uses technical and organizational measures to protect personal data against loss, misuse, unauthorized access, and unauthorized modification. These measures include transport encryption, Firebase security rules, server-side permission checks, App Check, and limited access rights.
14. Changes to this Privacy Policy
We may update this Privacy Policy if features, service providers, legal requirements, or technical processes change. The current version is permanently available at https://memotoria.com/privacy.