Privacy Policy
Last updated: September 6, 2026
This policy explains what personal data Memodock collects, why, who sees it, how long we keep it, and what you can do about it. It covers the Memodock website, the iPhone and Android apps, and the emails and notifications we send.
The data controller is Dorian Bouchard Santiago, a sole trader (micro-entrepreneur) established in France, who publishes and operates Memodock alone: on our side, only the operator has access to your data, under the conditions described below. We follow the General Data Protection Regulation (GDPR) and the French Data Protection Act (loi Informatique et Libertés).
This policy forms part of our Terms of Service.
1. What we collect
Account details
- your email address, used to verify the account, sign you in and send you the emails described below;
- the username you choose;
- your password, stored only as a salted hash that we cannot reverse (if you sign up with an email address);
- if you sign in with Google or Apple: the identifier that Google or Apple assigns to you and your verified email address. Google also sends us your name, which we do not store. With Apple, you can hide your real email address behind a relay address;
- your language, time zone, and the settings you choose: daily reminder, marketing emails, detailed analytics, sound effects, haptics, new cards per day;
- your subscription status, its renewal date, and the price and currency of your plan, which our subscription platform reports to us. We never receive your card number.
Your study material and cards
- the documents you import (PDF, text and Markdown files), stored in our file storage;
- the photos and images you import, including pictures taken with your camera when you choose to;
- the text you paste;
- for YouTube videos: the address of the video, its title, channel name, thumbnail and transcript;
- for web pages: the address of the page, its title, description and the text extracted from it;
- your decks, and the questions, answers and images on your cards, whether written by you or drafted by the AI;
- a record of each AI generation: which model was used, how much text went in and out, and what it cost us. This is how we apply the free-plan quota and fair use.
Study progress
- for each card, the scheduling data that spaced repetition needs: when you first studied it, when you last reviewed it, and the algorithm's estimate of how well you know it;
- the days on which you studied, your streak, and your available streak freezes;
- the time of day you usually study, which we use to schedule your reminder.
Technical data
- for each sign-in, a session record with a description of the device or browser and the IP address it came from, so that suspicious sessions can be spotted;
- if you enable push notifications, the token that identifies your device to Apple's or Google's notification service, and the platform (iOS or Android);
- server logs of requests to our API: date and time, address called, response time and status, IP address and browser or app version. When a request fails, the log also includes the error details, with passwords, tokens and similar fields removed;
- crash and error reports from the app, only while detailed analytics is on.
Usage analytics
how you use the app: the screens you open, the features you use, the size of the decks you create, how study sessions go, and the type of device and browser. What exactly is collected depends on the detailed analytics setting, explained in the analytics section below.
Support
when you write to us, we keep the conversation and the details you give us in order to help you.
What we do not collect
We do not collect payment card numbers, precise location, your contacts or advertising identifiers, and we do not run advertising or trackers from advertising networks.
2. Why we use it, and on what legal basis
The GDPR requires a legal basis for each use of your data. Here is what we do and why we are allowed to.
To provide the Service (performance of our contract)
- creating and securing your account, signing you in on each device and keeping your decks in sync;
- sending your material to the AI provider to draft your cards, and fetching transcripts and page text from the sources you import;
- scheduling your reviews and keeping your progress and streak;
- managing your subscription and applying the free-plan quota;
- sending the emails the account requires: verification code, welcome message, password reset and password change confirmations, and notices about the security or the limits of your account.
To keep the Service safe and running (our legitimate interest)
- keeping session records and server logs to detect abuse, fix bugs and investigate incidents;
- monitoring AI usage to apply fair use and prevent runaway costs;
- recording basic product events on our servers (an account was created, a deck was generated, a card was reviewed) under your account identifier, without your content, so that we understand how the product is used;
- counting visits anonymously when detailed analytics is off;
- emailing you occasionally about new features, as the law allows for existing customers, unless you opt out in Settings > Notifications.
With your consent (which you can withdraw at any time)
- detailed analytics: identified usage tracking from your device, controlled in Settings > Privacy;
- push notifications, controlled by the permission you give your phone and the switch in Settings > Notifications;
- access to your camera and photos, which your phone asks you for when you first use those features.
To comply with the law (legal obligation)
Keeping the accounting records of web purchases for as long as French commercial and tax law requires, and answering lawful requests from authorities.
We make no automated decisions about you that have legal or similarly significant effects. The spaced-repetition algorithm automatically decides when a card comes back; that is all it decides.
3. AI processing of your material
When you generate cards, the text extracted from your material (and the images you imported, for photo-based decks) is sent to our AI model gateway, a service in the United States that routes requests to large language model providers, together with an opaque identifier of your account that the gateway uses for abuse prevention. Your name, email address and other account details are never sent.
Your material is used for one thing: drafting your cards. We do not use it to train AI models and do not allow our providers to. The gateway's terms do not permit prompts to be used for training unless the customer opts in, and we do not. We have not enabled its prompt logging; the model provider itself may retain a request briefly for abuse monitoring, in accordance with its own policy.
The gateway also reports the cost, size, model and duration of each generation, under the same opaque identifier, to our analytics tool, PostHog, so that we can monitor spending. The content of your material and cards is not included.
5. Where your data is stored, and international transfers
Your account, content and study data are stored on Amazon Web Services infrastructure in the Paris region, in the European Union, and our analytics data stays in Frankfurt. Emails are sent through the European platform of our email service.
Some providers process data in the United States: our AI model gateway for card generation, our web page extraction service, Firebase for push notifications, RevenueCat for subscriptions, Stripe for web payments, and Apple and Google for sign-in and store purchases. Each transfer is covered by the European Commission's Standard Contractual Clauses, or by the EU-US Data Privacy Framework where the provider is certified under it. You can ask us for a copy of the safeguards in place.
6. How long we keep it
We keep personal data only as long as we need it for the purposes described above. Then we delete it.
- your account, content and study progress: for as long as your account exists. When you delete it, everything is erased at once, and copies in our backups are overwritten within 30 days;
- guest profiles created when you start without an account: 7 days, unless you create an account in the meantime;
- free accounts unused for more than two years: may be deleted, after we have emailed you at least 30 days in advance;
- session records: until you sign out or the session expires;
- push notification tokens: until you turn notifications off, uninstall the app or delete your account;
- server logs: 30 days;
- analytics events: up to twelve months at PostHog;
- records of purchases and subscriptions, with us, RevenueCat and the stores: ten years for accounting, as French commercial and tax law requires;
- support conversations: two years after the last exchange.
7. How we protect it
- every connection to the Service is encrypted (HTTPS);
- passwords are stored as salted hashes (bcrypt), never in clear text;
- sign-in relies on short-lived, cryptographically signed tokens, and you can end any session by signing out;
- the database sits in a private network unreachable from the internet, and file storage is private: your files are served only through short-lived signed links;
- access to production systems is limited to the operator and to what running the Service requires;
- the API is rate-limited to slow down brute-force attempts and abuse;
- the database is backed up automatically every day.
No system is perfectly secure. If a breach affects your data in a way that puts you at risk, we will tell you and the supervisory authority as the GDPR requires.
You have a part to play: choose a strong, unique password, keep your devices secure, and tell us if you notice anything suspicious.
9. Analytics: what the switch does
We use PostHog, hosted in the European Union, to understand how Memodock is used and to catch errors. We never see your content in it. What it collects depends on the "Detailed analytics" switch in Settings > Privacy.
When the switch is on, the app sends usage events tied to your account: the screens you open, the actions you take, your study sessions, errors you run into, and the type of device and browser you use. Your account identifier and email address are attached, so that we can follow the journey of one user when we investigate a problem.
When it is off, the app sends no identified events and stores nothing on your device for analytics. Visits are still counted anonymously: PostHog derives a temporary identifier from your IP address and browser, which changes every day and cannot be traced back to you.
The switch is off while you are a guest and is turned on when you create an account. You can turn it off whenever you like; the change applies immediately.
Independently of the switch, our servers record a few product events under your account identifier: account created, deck generated or deleted, card created or reviewed, generation failed. They contain counts and durations, never your content, and we use them to understand and improve the product.
10. Emails and notifications
We send the emails your account needs: the verification code when you sign up, a welcome message, password reset and password change confirmations, a notice if someone requests a password reset for an account that uses Google or Apple sign-in, and a notice if your AI usage reaches the limit we apply for fair use. You cannot opt out of these while you have an account, because they protect it.
Unless you turn it off in Settings > Notifications, we may occasionally email you about new features; each of these emails tells you how to unsubscribe.
If you allow notifications on your phone and keep the daily reminder on, we send one reminder a day, around the time you usually study, or in the evening if you have not studied yet. We stop after 14 days without any study so as not to nag you. Turn it off in Settings > Notifications or in your phone's settings.
11. Children
Memodock is not intended for children under 13, and we do not knowingly collect their data. If you are under the age of digital consent where you live (15 in France), a parent or guardian must agree to this policy for you. If you believe a child has given us data they should not have, email us and we will delete it.
12. Your rights
The GDPR and French law give you the following rights over your personal data:
- access: obtain a copy of the data we hold about you;
- rectification: correct data that is inaccurate or incomplete. Your email address and username can be changed directly in Settings > Profile;
- erasure: have your data deleted. Deleting your account from Settings > Profile does this immediately;
- restriction: ask us to freeze the use of your data in certain situations, for example while we check its accuracy;
- portability: receive the data you gave us in a structured, machine-readable format;
- objection: object to processing based on our legitimate interest, and at any time to direct marketing;
- withdrawal of consent: switch off detailed analytics or notifications whenever you want; earlier processing remains lawful;
- post-mortem directives: tell us what should happen to your data after your death, as French law allows.
To exercise a right that the app does not let you exercise yourself, email us from the address linked to your account. We may ask you for more information to confirm your identity. We answer within one month; if a request is particularly complex, we may take up to two more months and will tell you.
If you believe we are not handling your data lawfully, you can lodge a complaint with the French supervisory authority, the CNIL, at www.cnil.fr, or with the supervisory authority of the country where you live. We would appreciate the chance to address your concern first.
13. Changes to this policy
We update this policy when our practices, our providers or the law change. Substantive changes are announced by email or in the app before they take effect; minor ones simply appear here with a new date at the top. If a change would give us new rights over your data, we will ask for your consent where the law requires it.
14. Contact
For any question about your data or this policy, write to us:
- support@memodock.app
- Address
- 15 Rue du Pin d'Alep, 83260 La Crau, France
We have not appointed a data protection officer, because the law does not require one for a business of our size; the operator answers every data protection request personally.