Memo AI
Back home

Privacy policy

This policy explains which personal data we process, why we process it, who we pass it to, how long we keep it and what rights you have. It covers the memoai.eu website and the Memo AI app.

1. Data controller

The controller of your personal data is the provider of the Memo AI service, available at memoai.eu.

Contact for privacy questions and for exercising your rights: info@memoai.eu

2. Which data we process

Account data

  • email address
  • user identifier and authentication data
  • the data Google or Apple pass on if you sign in through them: email address, name and account identifier
  • your name, if you enter one

Data from the initial setup

  • your answers in the onboarding survey, such as field of study, how you use the app and why

Content you send

  • audio recorded in the app, and audio files you upload
  • pasted text, handwritten notes and prompts
  • PDFs, documents and images you upload or scan
  • public web links you ask Memo AI to read
  • messages in the chat with your notes

Data produced by using the service

  • transcripts, summaries, notes, flashcards, quizzes, tests and chat answers generated from your material
  • your library structure, folders, progress markers and processing history
  • the state of background jobs, and error logs

Payment data

  • subscription status, chosen plan, period and payment history
  • your Stripe customer and subscription identifiers

We neither receive nor store your card details. You enter those directly with Stripe.

Technical data

  • IP address, device type, browser and operating system
  • access times, requests and server responses
  • error and crash data
  • aggregated page-visit statistics

3. Purposes and legal bases

Performance of a contract (Article 6(1)(b) GDPR)

  • creating and running your account, and signing in
  • storing and organising your note library
  • transcribing, analysing and processing the material you send
  • producing summaries, notes, flashcards, quizzes, tests and chat answers
  • billing the subscription, and processing payments and refunds
  • user support

Legal obligation (Article 6(1)(c) GDPR)

  • issuing and keeping invoices, and other tax and accounting obligations
  • responding to requests from competent authorities

Legitimate interest (Article 6(1)(f) GDPR)

  • security of the service, preventing abuse, rate limiting and detecting fraud
  • fixing faults and improving the reliability of the product
  • aggregated usage statistics from which no individual can be identified
  • establishing or defending legal claims

Where we process on the basis of legitimate interest, we have weighed our interest against your rights. You can object to such processing at any time.

Consent (Article 6(1)(a) GDPR)

  • optional product messages, where you sign up for them
  • optional cookies or similar technologies, where these are in use

You can withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before it.

4. Special categories of personal data

Memo AI is not intended for processing special categories of personal data, such as health data, biometric data, or data about religion, political opinions or sexual orientation.

If you upload such material anyway, you do so at your own responsibility and must have a valid legal basis for it. We advise against uploading such material about other people.

5. Permissions for recordings and material

By using Memo AI you confirm that you have every permission and right needed to record, upload, paste or link the content you send to the app. That includes permission from a school, teacher, lecturer, institution, employer, the people being recorded, or other rights holders, where such permission is required.

Do not upload recordings of lectures, slides, teaching material, documents or other content to Memo AI if you do not have permission or a legal basis for doing so.

Where other people appear in your material, you are the one who decides how their personal data is processed, and we process the material on your instructions.

6. Who we pass data to

We do not sell data. We pass it only to the providers we need in order to run the service, and only to the extent a given function requires. We have data processing agreements in place with them.

  • Supabase — authentication, database and file storage
  • Stripe — processing payments, subscriptions and refunds
  • Google (Gemini) — transcription, extracting text from documents, embeddings, generating notes and chat answers
  • Soniox — audio transcription, where that service is switched on
  • Vercel — hosting the app, and aggregated visit statistics
  • Inngest — running background jobs, where switched on
  • Sentry — error and crash monitoring
  • Google and Apple — sign-in, where you choose to sign in through them

We may also disclose data to competent authorities where we are legally required to, and to our legal or accounting advisers where necessary.

If there is a change of corporate status or a sale of the business, data may be transferred to the acquirer, with this policy continuing to apply until we notify you of a change.

7. Transfers outside the EU and EEA

Some providers also process data outside the European Economic Area, in particular in the United States of America.

In those cases the transfer is made on the basis of:

  • an adequacy decision of the European Commission, where one exists, or
  • the European Commission's standard contractual clauses together with additional safeguards

You can request a copy of the safeguards used at info@memoai.eu.

8. How long we keep data

  • account data — for as long as your account exists, then for up to 30 days after deletion
  • content and generated notes — until you delete them or delete your account; removed from backups within 30 days at the latest
  • payment data and invoices — 10 years, as tax law requires
  • error and security logs — up to 12 months
  • support correspondence — up to 24 months after the matter is closed
  • data needed for legal claims — until the claim is time-barred

Content stays linked to your account until you delete it in the app, or until we remove it through support or routine clean-up.

9. Security

We use technical and organisational measures appropriate to the risk, among them:

  • encryption of data in transit
  • separation of data access at database level, so that only you can reach your own notes
  • limited and logged staff access, restricted to cases where it is necessary
  • monitoring of errors and unusual traffic

No system is completely secure. If a personal data breach occurs that could pose a high risk to you, we will notify you and also notify the Information Commissioner, as the law requires.

10. Your rights

Under the GDPR you have the right to:

  • access — confirmation of whether we process your data, and a copy of it
  • rectification — correction of inaccurate data, or completion of incomplete data
  • erasure — deletion of data where there is no longer a basis for processing it
  • restriction of processing — in the cases the law provides for
  • portability — receiving your data in a machine-readable form, or having it transferred to another provider
  • objection — to processing based on legitimate interest
  • withdrawal of consent — where processing is based on consent

We do not carry out automated decision-making with legal effects for you, nor profiling within the meaning of Article 22 GDPR.

11. How to exercise your rights

Send your request to info@memoai.eu from the email address linked to your account. We reply within one month at the latest; in complex cases the deadline may be extended by two months, and we will tell you if it is.

To verify your identity we may ask for further details, but only to the extent needed for that.

If you believe we are processing your data unlawfully, you can lodge a complaint with the Information Commissioner of the Republic of Slovenia, Dunajska cesta 22, 1000 Ljubljana, gp.ip@ip-rs.si.

12. Cookies and similar technologies

We use:

  • essential cookies and local storage — for signing in, keeping your session, security and basic settings. These are required for the service to work and cannot be switched off
  • visit statistics — aggregated, non-personal measurements of page visits through Vercel Analytics

We do not use advertising cookies or cross-site tracking. If we introduce optional cookies in future, we will ask for your consent to them.

13. Children

Memo AI is not intended for children under 16. If we find that we have processed the data of a child under 16 without an appropriate basis, we delete it. If you are a parent or guardian and believe this has happened, write to us at info@memoai.eu.

14. Your choices

If you do not want the processing described in this policy to take place, do not upload, paste, record or link that content in Memo AI. If you need stricter terms on retention, deletion or contractual provisions, contact us before using the service.

15. Changes to this policy

We may update this policy as the product, the providers or the law change. We will notify you of material changes by email or in the app.

16. Contact

info@memoai.eu

© 2026 Memo AI

Terms of useRefund policy

This text is a translation. Where the versions differ, the Slovenian one prevails.