Privacy Policy

Last Updated: October 24, 2025

This Privacy Policy explains how Memodock ("we," "us," or "our") collects, uses, shares, and protects your personal information when you use our website and services (collectively, the "Service").

Memodock is operated by Dorian Bouchard Santiago, a micro-enterprise registered in France.

Contact: support@memodock.app
Website: https://memodock.app
Address: 15 Rue du Pin d'Alep, 83260 La Crau, France

By using Memodock, you consent to the data practices described in this Privacy Policy.

1. Information We Collect

1.1 Information You Provide Directly

When you create an account and use Memodock, we collect:

  • Email address (required for account creation and verification)
  • Username (chosen by you for account identification)
  • Password (encrypted and stored securely)
  • Payment information (processed by Stripe; we do not store full card details)

1.2 Content You Upload

  • Source documents (text files in .txt or .md format)
  • Flashcards (generated from your sources or edited by you)
  • Deck names
  • Study session data (card review history, performance metrics)

This content remains private unless you explicitly choose to share it publicly through our future "Shared Library" feature.

1.3 Automatically Collected Information

When you use Memodock, we automatically collect:

  • Usage data: Pages visited, features used, time spent, interactions
  • Device information: Browser type, operating system, IP address, device identifiers
  • Log data: Access times, error logs, performance data
  • Analytics data: Aggregated usage patterns and statistics

1.4 Cookies and Similar Technologies

We use cookies and similar tracking technologies for:

  • Authentication (keeping you logged in)
  • Session management (maintaining your active session)
  • Preferences (remembering your settings)
  • Analytics (understanding how you use the Service)

See Section 5 for more details on cookies.

2. How We Use Your Information

We use your information for the following purposes:

2.1 To Provide the Service

  • Create and manage your account
  • Generate flashcards from your uploaded content using AI
  • Enable study sessions with spaced repetition
  • Store and organize your decks and cards
  • Process your study progress and performance data

2.2 To Communicate With You

  • Send account verification emails
  • Send password reset emails
  • Send study reminders (if you enable this feature)
  • Respond to your support requests
  • Notify you of important service changes or updates

2.3 To Process Payments

  • Process subscription payments and manage billing
  • Prevent fraud and unauthorized transactions
  • Provide receipts and invoices

2.4 To Improve the Service

  • Analyze usage patterns to understand how features are used
  • Identify and fix bugs or technical issues
  • Develop new features based on user needs
  • Conduct internal research and analytics

2.5 To Ensure Security and Compliance

  • Detect and prevent fraud, abuse, or security threats
  • Enforce our Terms of Service
  • Comply with legal obligations
  • Protect our rights and those of our users

2.6 Legal Basis for Processing (GDPR)

Under GDPR, we process your personal data based on:

  • Contract: Processing necessary to provide the Service you signed up for
  • Legitimate interests: Improving our Service, security, and analytics
  • Consent: When you opt-in to optional features (e.g., marketing emails)
  • Legal obligation: When required by law to retain or disclose information

3. How We Share Your Information

We do not sell your personal information to third parties.

3.1 Service Providers

We share data with third-party service providers who help us operate the Service:

  • AI Providers (OpenAI, Google Gemini): To generate flashcards from your content
  • Email Service (Mailgun): To send transactional emails
  • Payment Processors (Stripe, RevenueCat): To process payments
  • Hosting Provider (Hostinger): To store your data on servers in Europe
  • Analytics (PostHog): To understand service usage

These providers are contractually obligated to protect your data and use it only for the purposes we specify.

3.2 AI Processing

When you generate flashcards:

  • Your source content is sent to OpenAI or Google Gemini for processing
  • This processing is necessary to provide the card generation service
  • We do not authorize these providers to use your content for their model training
  • Content is processed temporarily and not stored by AI providers beyond what's necessary

3.3 Public Sharing

If you choose to make a deck public through our future "Shared Library" feature:

  • The deck's content becomes visible to other Memodock users
  • Your username may be associated with the public deck
  • You can remove public decks at any time

3.4 Legal Requirements

We may disclose your information if required by law or in response to:

  • Valid legal processes (subpoenas, court orders)
  • Government requests
  • Protection of our rights, safety, or property
  • Enforcement of our Terms of Service

3.5 Business Transfers

If Memodock is acquired or merged with another company, your information may be transferred to the new entity. You will be notified of any such change.

4. Third-Party Services and Data Processing

We use the following third-party services:

SERVICE: OpenAI (GPT models)

PURPOSE: AI flashcard generation

DATA SHARED: Your uploaded source content (temporarily, for processing)

LOCATION: United States

PRIVACY POLICY: https://openai.com/privacy

SERVICE: Google Gemini

PURPOSE: AI flashcard generation (alternative provider)

DATA SHARED: Your uploaded source content (temporarily, for processing)

LOCATION: United States / Global

PRIVACY POLICY: https://policies.google.com/privacy

SERVICE: Mailgun

PURPOSE: Transactional email delivery

DATA SHARED: Email address, email content

LOCATION: Europe (servers)

PRIVACY POLICY: https://www.mailgun.com/privacy-policy

SERVICE: Stripe

PURPOSE: Payment processing

DATA SHARED: Payment information, billing details

LOCATION: Global (GDPR compliant)

PRIVACY POLICY: https://stripe.com/privacy

SERVICE: RevenueCat

PURPOSE: Subscription management

DATA SHARED: Purchase data, subscription status

LOCATION: United States (GDPR compliant)

PRIVACY POLICY: https://www.revenuecat.com/privacy

SERVICE: Hostinger

PURPOSE: Web hosting and data storage

DATA SHARED: All account and usage data

LOCATION: Europe

PRIVACY POLICY: https://www.hostinger.com/privacy-policy

SERVICE: PostHog

PURPOSE: Usage analytics

DATA SHARED: Anonymized usage data, IP address

LOCATION: European Union (Frankfurt)

PRIVACY POLICY: https://posthog.com/privacy

We ensure all third-party providers comply with GDPR or have appropriate safeguards in place for data transfers outside the EU.

5. Cookies and Tracking Technologies

5.1 What Are Cookies?

Cookies are small text files stored on your device that help us provide and improve the Service.

5.2 Types of Cookies We Use

ESSENTIAL COOKIES (Required)

  • Authentication: Keep you logged in
  • Session management: Maintain your active session
  • Security: Prevent fraud and protect your account

These cookies are necessary for the Service to function and cannot be disabled.

FUNCTIONAL COOKIES (Optional)

  • Preferences: Remember your settings and choices
  • User interface: Enhance your experience with personalized features

ANALYTICS COOKIES (Optional)

  • Usage tracking: Understand how you use the Service
  • Performance monitoring: Identify technical issues
  • Feature optimization: Improve features based on usage data

5.3 Managing Cookies

You can control cookies through:

  • Your browser settings (block or delete cookies)
  • Our cookie consent banner (opt-in/opt-out of optional cookies)
  • Opting out of analytics tracking in your account settings

Note: Disabling essential cookies will prevent you from using the Service.

5.4 Third-Party Cookies

Some third-party services (analytics, payment processors) may set their own cookies. We do not control these cookies. Refer to their privacy policies for more information.

6. Data Storage and Security

6.1 Where We Store Your Data

Your data is stored on servers provided by Hostinger, located in Europe. This ensures your data remains within the European Economic Area (EEA) and is subject to GDPR protections.

6.2 How We Protect Your Data

We implement industry-standard security measures:

  • Encryption: Data is encrypted in transit (HTTPS/TLS) and at rest
  • Access controls: Limited access to personal data on a need-to-know basis
  • Authentication: Strong password requirements and secure authentication
  • Regular backups: To prevent data loss
  • Security monitoring: To detect and respond to threats

6.3 Your Responsibility

You are responsible for:

  • Keeping your password secure and confidential
  • Using a strong, unique password
  • Notifying us immediately of any unauthorized access

6.4 No Absolute Security

While we take reasonable precautions, no system is 100% secure. We cannot guarantee absolute security of your data.

7. Data Retention

7.1 Active Accounts

We retain your data for as long as your account is active and as needed to provide the Service.

7.2 Deleted Accounts

When you delete your account:

  • We will delete or anonymize your personal information within 30 days
  • Some data may be retained longer if required by law or for legitimate business purposes (e.g., preventing fraud, resolving disputes)

7.3 Backups

Deleted data may persist in backups for up to 90 days before being permanently removed.

7.4 Public Content

If you made decks public before deleting your account, we may retain anonymized versions for other users who copied or used that content.

8. Your Rights (GDPR)

As a user in the European Union, you have the following rights under GDPR:

8.1 Right to Access

You can request a copy of all personal data we hold about you.

8.2 Right to Rectification

You can correct or update inaccurate personal information.

8.3 Right to Erasure ("Right to be Forgotten")

You can request deletion of your personal data, subject to legal obligations.

8.4 Right to Restrict Processing

You can request we limit how we use your data in certain circumstances.

8.5 Right to Data Portability

You can receive your data in a structured, machine-readable format or request transfer to another service.

8.6 Right to Object

You can object to processing of your data for certain purposes (e.g., direct marketing, analytics).

8.7 Right to Withdraw Consent

For data processing based on consent, you can withdraw consent at any time.

8.8 Right to Lodge a Complaint

You can file a complaint with your national data protection authority (in France: CNIL - https://www.cnil.fr).

8.9 How to Exercise Your Rights

To exercise any of these rights, contact us at support@memodock.app with:

  • Your account email
  • Specific request (access, deletion, correction, etc.)
  • Any additional information to verify your identity

We will respond within 30 days of receiving your request.

9. Children's Privacy

Memodock is intended for users aged 13 and older. We do not knowingly collect personal information from children under 13.

If you believe we have inadvertently collected information from a child under 13, please contact us immediately at support@memodock.app, and we will delete that information.

If you are between 13 and 18, please obtain parental consent before using the Service.

10. International Data Transfers

10.1 Primary Storage

Your data is primarily stored on servers in Europe (via Hostinger) and is subject to GDPR protections.

10.2 Third-Party Services Outside EU

Some third-party services (OpenAI, Google Gemini, RevenueCat) may process your data outside the EU. When this occurs:

  • We ensure these providers have adequate safeguards (Standard Contractual Clauses, Privacy Shield frameworks, or equivalent protections)
  • Data transfers are necessary to provide the Service you requested
  • We limit data sharing to what is necessary for the specific purpose

10.3 Your Consent

By using the Service, you consent to these international data transfers under the conditions described above.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect:

  • Changes to our data practices
  • New features or services
  • Legal or regulatory requirements

When we make changes:

  • We will update the "Last Updated" date at the top
  • We will notify you via email or in-app notification for material changes
  • Your continued use of the Service after changes constitutes acceptance

We encourage you to review this Privacy Policy periodically.

12. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:

Email: support@memodock.app
Website: https://memodock.app
Address: 15 Rue du Pin d'Alep, 83260 La Crau, France

For GDPR-related inquiries or to exercise your rights, please use the same contact information above.