In short
- Your screenshots and photos are read on your phone. Memora never uploads images.
- Online look-ups send a few lines of text with phone numbers, emails, codes, card numbers and IBANs masked first. You can switch look-ups off.
- Vault cards (passwords, codes, health) never leave your phone.
- No ads, no tracking, no analytics kits, and we never sell your data. An account is optional.
- You can delete your account in the app at any time, and your cards whenever you like.
Who we are
This policy covers the Memora app for iPhone and Android and this website, memorashelf.com (together, “Memora”, “we”, “us”). Memora is made and run by an independent developer, who is the controller of the personal data described here.
Questions or requests about privacy go to privacy@memorashelf.com.
What stays on your phone
Most of what Memora does happens on your device, and this data never reaches us:
- Your screenshots and photos. With your permission, Memora reads your screenshots (and other photos, if you turn on “Include all photos”) using the text recognition and image labeling built into your phone: Apple’s Vision framework on iPhone, and Google ML Kit’s on-device models on Android. The images themselves are never uploaded.
- Your library. Cards, shelves, statuses, notes and the search index are stored in a database on your phone.
- Pictures you share to Memora are saved to your photo library so they can be sorted with your screenshots.
- Vault cards. Anything on the Codes & Passwords or Health shelves, and any screenshot that looks like it contains a card number, an IBAN or a password, is processed on the device only. It is never sent for look-ups, never previewed on your shelves, and kept out of widgets and recommendations.
- Aura (your type, mix and nudges) is worked out on your phone from what you save.
- Widgets and notifications are prepared on your phone.
On Android, Google’s ML Kit may send Google anonymous performance and usage metrics about the text-recognition feature. This doesn’t include your images or their text.
What leaves your phone, and why
Some features need the internet. Here is everything Memora sends, where it goes, and when.
| When | What is sent | Where it goes |
|---|---|---|
| Online look-ups On by default; Settings → Privacy | Up to 24 short lines of text recognised in a screenshot, after masking phone numbers, emails, 6-digit codes, card numbers, IBANs, ID numbers and passwords; a guessed title; labels such as “book” or “food”; the app the screenshot came from; numbers that look like an ISBN, a price or a date; and links or @handles in the text. Never the image. | Our server, which may ask the catalogs and AI services below to identify the item and write a short summary. |
| Sharing a link to Memora | The link, plus any title or text the other app shared with it (such as a caption). | Our server, which fetches the public page (title, description, preview picture), sometimes through the platform’s public embed service, and may ask an AI service to pick a shelf. |
| Moving a card to another shelf | The card’s random ID and the old and new shelf. | Our server, to improve sorting. |
| Recommendations (Pro) | Titles and creators of cards on a shelf. Never images, notes or Vault cards. | Our server, which may ask catalogs and AI services for related titles. |
| Using the app at all | A random device ID created by Memora (not an advertising or hardware ID), the app version, your language and your platform (iOS or Android). | Our server, to answer requests, apply your plan and prevent abuse. |
| Creating an account Optional | Your email and, if you give it, your name; your password as a salted hash; or the account ID Apple or Google confirms for you. Sign-in times and language. | Our server. Apple and Google handle their own sign-in screens. |
| Buying Pro or Lifetime | You pay on Stripe’s secure checkout page. We receive your Stripe customer ID, plan, subscription status and dates, and amounts paid. We never see your full card number. | Stripe and our server. |
| Resetting your password | Your email address and a one-time code that expires after 15 minutes. | Our email provider. |
| Maps, covers and fonts | Ordinary web requests for map tiles, cover pictures and typefaces. To place a saved address on your map, the app asks your phone’s built-in geocoding service for its coordinates. | Esri (map tiles); the catalog a picture came from, such as Open Library, TMDB, TheMealDB, Wikimedia or Apple; Google Fonts; Apple (iPhone) or Google (Android) for geocoding. |
Like any website or app server, the services above can see the IP address a request comes from.
How we use information
We use the information above only to:
- Provide the features you ask for: look-ups, link previews, recommendations, sign-in, your plan across devices. Legal basis: performing our contract with you.
- Keep Memora secure and available: rate limits, stopping abuse, fixing errors. Legitimate interests.
- Improve sorting, using which shelves cards get moved between. Legitimate interests.
- Take payments and keep the records tax law requires. Contract and legal obligation.
- Send password reset codes and, rarely, important messages about your account. Contract.
Access to your photos and notifications is based on the permission you give in your phone’s settings, which you can withdraw at any time.
Services we rely on
These providers process data for the purposes above and only as needed to provide their service:
- Stripe: payments and subscription management.
- Groq and Google (Gemini API): AI models that read masked look-up text and link details to name items, write summaries and suggest shelves. Anthropic (Claude) may be used for the same purpose. Google’s free Gemini tier may use submitted text to improve Google’s products; that’s one reason we mask personal details before anything is sent.
- Public catalogs: Open Library (Internet Archive), Google Books, The Movie Database (TMDB), TheMealDB, Wikipedia and Wikiquote (Wikimedia), Apple’s iTunes Search, OpenStreetMap’s Nominatim and ZenQuotes. We send them titles or search words from a look-up, never your account or device details.
- Link platforms: when you share a link, our server may ask that platform’s public embed service (for example YouTube, TikTok, Vimeo, Spotify, SoundCloud, X, Reddit, or Meta for Instagram and Facebook) for the post’s title and preview.
- Email delivery: the mail service that sends our password reset codes.
- Apple and Google: Sign in with Apple and Google Sign-In, if you use them.
- Esri (map tiles) and Google Fonts (typefaces in the app).
- Cloudflare: our domain’s DNS, and forwarding of email sent to @memorashelf.com.
- Our hosting provider, which runs our servers.
What we never do
- Upload your screenshots or photos.
- Show ads, use advertising IDs, or track you across other apps and websites.
- Include analytics or crash-reporting kits in the app.
- Sell or rent your personal data, or “share” it for cross-context behavioral advertising.
- Build a profile of who you are. Aura describes your interests and is computed on your phone.
- Train our own AI models on your content.
How long we keep it
- On your phone: until you delete it. Settings → More → Delete all Memora data removes your cards, notes and search index; uninstalling does the same. Your photos are never touched.
- Your account: until you delete it. When you do, we immediately erase your email, name, password hash and Apple or Google account ID, sign you out on every device and detach your devices from the account. A de-identified record of the account (its ID, plan history and dates) remains.
- Payment records: kept as long as tax and accounting law requires. Stripe keeps its own records under its privacy policy.
- Device records and look-up logs carry only the random device ID, never the text you sent, and are kept while needed to run and secure the service.
- Look-up results about public items (like a book’s details) are cached under a one-way fingerprint of the request, so repeat look-ups are fast. The cache isn’t linked to your account or device.
- Password reset codes expire after 15 minutes. Sign-in sessions last up to 30 days unless you sign out.
Security
All connections use HTTPS. Passwords are stored only as salted scrypt hashes. Sign-in tokens expire and are revoked when you sign out or delete your account. Personal details are masked on your phone before a look-up is sent, and Vault content never leaves it. No system is perfectly secure; if you find a vulnerability, please email security@memorashelf.com.
Your rights and choices
- Use Memora without an account, and without online look-ups: switch off Settings → Privacy → Look things up online.
- Delete your account in the app: open Settings, tap your profile at the top, then Delete account. Other ways are explained here.
- Access, correct, export or delete the personal data we hold, object to or restrict how we use it, or withdraw consent, by emailing privacy@memorashelf.com from the address on your account. We answer within 30 days.
- If you’re in the EEA, the UK or Switzerland, you can also complain to your local data protection authority.
- California residents have the right to know, delete and correct personal information, and to opt out of its sale or sharing. We don’t sell or share it, and we won’t treat you differently for using your rights.
Children
Memora isn’t directed at children under 13 (or under 16 where local law requires) and we don’t knowingly collect their personal data. If you believe a child has created an account, email us and we’ll delete it.
International transfers
Our servers and the providers above may be located in the United States and other countries. When data moves from the EEA, the UK or Switzerland, we rely on the safeguards those providers offer, such as the European Commission’s Standard Contractual Clauses.
This website
memorashelf.com uses no cookies, no analytics and no third-party scripts, fonts or embeds. Our web server may briefly keep basic request logs (IP address, time, page and browser) to keep it secure.
Changes to this policy
If we change this policy, we’ll update this page and the date at the top. If a change is significant, we’ll also let you know in the app before it takes effect.
Contact
Email privacy@memorashelf.com about anything in this policy. For help with the app, write to support@memorashelf.com.