At a glance
Collected
- Email and user ID from sign-in (Apple or email)
- Your cards, decks and study history, synced via Supabase (US)
- AI inputs you submit: text, images, PDFs (sent to Google Gemini)
- Anonymous usage analytics
Never collected
- No location, contacts or browsing history
- Sign-in sync, not iCloud — works without an account otherwise
- No third-party analytics SDKs
- No personalized ads
The full policy below is the authoritative version.
Privacy Policy
Effective: 2026-04-26 · Last updated: 2026-09-14
1. Overview
This Privacy Policy explains how Memento (“the App”) collects, uses, and protects your personal information.
2. Information we collect
- Email address — Received when you sign in with Apple or email (including Apple private relay emails). Used for authentication and account identification.
- User ID — A unique identifier issued at sign-in. Used for syncing and account management.
- User content — Flashcards, decks, and study history you create. Used for syncing across devices.
- AI usage data — The text, images, PDFs, and card content you submit when using AI features. Used for generating AI responses and managing limits. Requests go to the OpenAI or Google Gemini API (see section 5); your email address, account identifier, and purchase information are never sent with them.
- Usage analytics — Anonymous usage events (for example, which features you use and how often), used only to analyze and improve the App. Tied to a randomly generated install identifier, and to your account identifier when you are signed in. Never used for advertising or tracking.
3. Information we do not collect
- Location data
- Contacts
- Search or browsing history
- Health or fitness data
- Advertising identifiers (the App itself does not collect them)
4. Third-party services
- Apple — Sign in with Apple: Handles user authentication. Apple's privacy policy applies.
- Supabase — Authentication & sync: Handles user authentication and card syncing. Data is stored on Supabase cloud servers in the United States.
- OpenAI — AI responses: When you use AI features, the text, images, and PDFs you submit are sent to the OpenAI API. OpenAI's data handling policy applies.
- Google Gemini — AI responses: The same content may instead be sent to the Google Gemini API. Google's data handling policy applies. Section 5 explains which provider handles a given request.
- Google AdMob — Advertising: The App displays banner ads served through Google AdMob. The App is configured to request Non-Personalized Ads only. To serve ads, Google may process limited device information such as IP address and device identifiers. policies.google.com/technologies/ads
The App uses no third-party analytics SDKs (such as Firebase); usage analytics is processed only on servers we operate, and we do not sell or share your data for marketing purposes.
5. AI subprocessors and international transfers
Generating and refining cards with AI is entrusted to the two providers below. Any single request is handled by one of them, and which one is decided by our server configuration. The requests are made by our server, not by the app; the API keys live only on the server.
- OpenAI, L.L.C. — Generating AI responses
- Google LLC — Generating AI responses
Both involve a transfer of data outside South Korea, on the following terms.
- Destination country — United States
- When and how — At the moment you use an AI feature, over an encrypted connection (HTTPS).
- What is transferred — The text you enter, any image or PDF you attach, and the card content being worked on. Your email address, account identifier, and purchase information are not included.
- Purpose — Generating AI responses
- Retention — Discarded once the request has been processed. Each provider may retain it for a limited period for abuse monitoring; for OpenAI that period is up to 30 days.
- If you would rather not — Simply do not use the AI features. They run only when you explicitly request them, and everything else, including writing and reviewing cards, remains available.
Both providers state that content sent through their APIs is not used to train their AI models.
6. Data retention
Your data is retained until you delete your account. Upon account deletion, all cards, study history, and authentication information are permanently removed.
7. Your rights
- Access — View all your cards and study history within the app.
- Export — Download all your data in JSON format via Settings → Export.
- Deletion — Delete your account immediately via Settings → Account → Delete Account.
8. Security
All communication is encrypted via HTTPS. AI requests are verified using user authentication tokens. The App does not store passwords: Apple sign-in uses device authentication, and email sign-in uses a code sent to your email.
9. Children's privacy
The App is not directed at children under the age of 13, and we do not knowingly collect personal information from children.
10. Changes to this policy
This policy may be updated from time to time. Changes will be reflected by updating the “Last updated” date above.
- 2026-09-14 — Added email sign-in alongside Apple, and updated the collected-data and security wording from Apple-only to both.
- 2026-08-30 — Added OpenAI as a provider handling AI responses, and set out the AI subprocessors and international transfers in section 5.
- 2026-06-26 — Updated the collected-data and third-party sections to match how the app actually handles data.
- 2026-04-26 — Initial version.