Security & privacy
Privacy Policy
Last updated: 17 July 2026
Protecting your data is a top priority for us. This policy explains what personal data Memora processes when you use it privately, why we need it, and which rights you have under the General Data Protection Regulation (GDPR).
1. Controller
The controller under the GDPR and other applicable data protection law is:
- Florian Zager
- Ravensbergstraße 7b
- 14558 Nuthetal
- Germany
- Email: privacy@getmemora.ai
You can contact us at the address above with any privacy question or to exercise your rights. We are not legally required to appoint a data protection officer; the controller handles privacy requests directly.
2. Scope
This policy applies when you use Memora as a private individual through our website or applications. Personal data means any information relating to an identified or identifiable person.
If you use Memora through a school, our separate privacy policy for schools also applies. In that setting, the school or school authority may be the controller.
3. Account and sign-in
You can create and access a personal account with your email address or through Google or Apple. A school access code is not used for personal accounts.
Email sign-in
When you sign in by email, we process your email address and the data required for secure authentication. We also use your address for necessary account messages, such as security or recovery notices.
Sign in with Google or Apple
If you choose Google or Apple, the provider sends us a unique provider identifier and your email address after you approve the sign-in. Depending on your choices and provider settings, a profile name may also be sent. With Apple, you can use Hide My Email, in which case we receive an Apple relay address. We never receive your Google or Apple password.
Optional nickname
You may add a nickname so your tutor can address you personally. This is optional and does not need to be your real name. You can change or remove it in your settings.
4. Legal bases
| Processing | Purpose | Legal basis |
|---|---|---|
| Account, sign-in and learning features | Provide the service you choose | Article 6(1)(b) GDPR (contract and pre-contractual steps) |
| Learning progress and adaptive task selection | Personal learning support and progress display | Article 6(1)(b) GDPR |
| Technical logs and security controls | Stability, debugging, abuse prevention and IT security | Article 6(1)(f) GDPR (legitimate interests) |
| Support and necessary account messages | Handle requests and administer our relationship with you | Article 6(1)(b), (c), or (f) GDPR, depending on the context |
| Optional analytics technologies | Audience measurement and product improvement | Article 6(1)(a) GDPR (consent), where required |
Where we rely on legitimate interests, these are chiefly the secure, stable, and user-friendly operation of Memora. You can withdraw consent at any time with effect for the future.
5. Data we process
Account and profile data
- email address, internal user ID, and chosen sign-in method
- for Google or Apple sign-in: provider ID and profile data released by the provider
- an optional nickname; a real name is not required
- optional learning preferences and personalisation settings
Learning and content data
- completed tasks, answers, learning results, and progress
- learning materials you create or upload, such as flashcards and documents
- prompts and interactions with the AI tutor and the learning context needed to respond
- tutor, language, and interface settings
Technical and communication data
- IP address, access time, browser, operating system, device type, and error and security logs
- pseudonymised or aggregated usage events
- content and contact details in support requests you choose to send
6. Purposes and necessity
- authenticate and manage your account
- provide, operate, and improve the service
- understand your learning level and select suitable tasks or explanations
- save your settings and learning progress
- maintain security, stability, and reliability
- respond to support requests and meet legal obligations
A personal account requires an email address, either provided directly or through Google or Apple. Without account, learning, and answer data, we cannot provide core features such as saved progress and personalised tasks. Your nickname and other profile details are optional; leaving them blank does not affect basic use.
7. AI, profiling, and automated decisions
We use your learning, usage, and input data only to support your learning. We do not use it to train, fine-tune, or develop AI or machine-learning models. External AI providers are also contractually required not to use submitted content to train their models.
Memora evaluates answers and progress to suggest suitable tasks and explanations. It does not make solely automated decisions under Article 22 GDPR that produce legal or similarly significant effects. We do not sell your data or share it for advertising.
8. Recipients and service providers
We use carefully selected providers where needed to deliver Memora. Processors act on our instructions under contracts meeting Article 28 GDPR.
| Provider | Service | Data categories | Location/safeguards |
|---|---|---|---|
| netcup GmbH | Backend hosting | technical, log, and operational data | Germany |
| Supabase, Inc. | Authentication, database, and backend services | account, profile, learning, and usage data | EU data centre region; Standard Contractual Clauses for relevant third-country transfers |
| Cloudflare, Inc. | Frontend delivery and protection | IP address, technical access, and security data | global network; Standard Contractual Clauses and, where applicable, EU-U.S. Data Privacy Framework |
| Google Ireland Limited or Google LLC | Google Gemini for the AI tutor | prompts, tasks, and context needed to respond | EU/USA; Standard Contractual Clauses and, where applicable, EU-U.S. Data Privacy Framework; no model training |
| PostHog, Inc. | Privacy-conscious product analytics | pseudonymised or aggregated usage events | EU Cloud in Frankfurt; Standard Contractual Clauses for relevant third-country transfers |
| Cloudflare and Google Workspace | Email routing and support email | contact, communication, and technical email data | EU/USA; Standard Contractual Clauses and, where applicable, EU-U.S. Data Privacy Framework |
Google and Apple sign-in
If you choose Google or Apple sign-in, that provider also processes data as an independent controller under its own privacy policy. These methods are optional; you can use email sign-in instead.
9. EU hosting and international transfers
Our backend and database providers generally store account and learning data in the European Union. Some providers are based in the United States or may process data in other third countries.
For these transfers, we maintain an appropriate level of protection through adequacy decisions, European Commission Standard Contractual Clauses, and supplementary measures such as encryption, access restrictions, and data minimisation. You can request a copy or summary of the relevant safeguards from us.
11. Retention and deletion
- We store account, profile, and learning data while you use Memora.
- After account deletion, we delete or anonymise account and learning data within 30 days unless a legal retention duty applies.
- Backups are overwritten regularly; personal data is generally removed from them within 30 days.
- We generally delete server and security logs after 30 days unless needed longer to investigate an incident or defend legal claims.
- We delete support and contact email no later than three years after a request is closed, unless legal duties or evidence requirements justify longer storage.
- We generally retain pseudonymised analytics events for 12 months, then delete or further anonymise them.
You can delete your account through the account settings or our account deletion page. You can also contact us at any time using the address below.
12. Data security
We use appropriate technical and organisational measures under Article 32 GDPR. These include encrypted data transfer, secure authentication, role-based access restrictions, data minimisation, and regular review of our security controls. No method can guarantee absolute security.
13. Children and young people
Minors may also use Memora, and protecting them is a particular priority. Where processing relies on consent and applicable law requires a parent or guardian to consent, that consent must be obtained before use. Parents and guardians can exercise a minor's rights using the contact details below.
Minors do not need to provide a real name either. An optional nickname is enough for the tutor to address them personally. Learning and usage data is not used for advertising or to train AI models.
14. Your rights
- access to your data (Article 15 GDPR)
- correction of inaccurate data (Article 16 GDPR)
- erasure of your data (Article 17 GDPR)
- restriction of processing (Article 18 GDPR)
- data portability (Article 20 GDPR)
- objection to processing (Article 21 GDPR)
- withdrawal of consent for the future (Article 7(3) GDPR)
To exercise your rights, email our contact address. We may request additional information where necessary to verify your identity.
15. Right to complain
Under Article 77 GDPR, you can complain to a data protection authority, particularly the authority for your place of residence or stay. Our competent authority is the Brandenburg Commissioner for Data Protection and Access to Information, Stahnsdorfer Damm 77, 14532 Kleinmachnow, Germany, poststelle@lda.brandenburg.de.
16. Changes and contact
We update this policy when legal requirements or our service change. The current version published here applies; the date at the top shows when it was last updated.
For privacy questions or to exercise your rights, contact us at privacy@getmemora.ai.