Memoniq
Privacy Policy
How Memoniq collects, uses, protects, exports and deletes account, study, AI and payment data.
Last updated: October 3, 2026
In short
- We process your data to provide Memoniq: your account, your study materials and the AI-generated content.
- AI processing of the materials you upload is part of the service you request (contract). It is not advertising or profiling.
- We do not sell data, we do not use advertising cookies and we make no automated decisions with legal effects on you.
- Do not upload identifiable patient data or other people’s personal data: Memoniq is for notes and study materials.
- You can export or delete everything yourself in Settings > Account, or write to us.
1. Controller and contact
The data controller is Roberto Coscia, Italy, who runs the Memoniq service (website memoniq.app and Android app).
For any privacy, security, access, export or deletion request: infomemoniq@gmail.com.
No data protection officer (DPO) has been appointed: given the size and type of processing, one is not required under Art. 37 GDPR. Requests are handled directly by the controller.
2. Data we process
| Category | Examples |
|---|---|
| Account | Email, account ID, language, optional name and avatar, plan, trial or subscription status; with Google sign-in, the name and email provided by Google. |
| Consent and age | Accepted Terms and Privacy version, date, sign-up method and confirmation that you are at least 16. |
| Study materials | Notebooks, categories, uploaded files, extracted text, OCR, transcripts, extracted images, YouTube, website or Google Drive sources you choose. |
| Generated content | Summaries, flashcards, quizzes, mind maps, podcasts, lessons, exported videos, chat and oral examiner answers, images and diagrams. |
| Progress | Quiz and flashcard answers, spaced repetition, per-topic oral practice scores, preferences and settings. |
| Voice | Recording of your answer in oral exam practice (only to transcribe it, not stored) and the transcript sent to the AI for evaluation. |
| Optional provider keys | Personal API keys you add for AI, image, voice or search providers. Encrypted in the database; may be cached in the browser. |
| Payments | Plan purchased, Stripe customer and subscription IDs, payment and refund status, refund reason. Full card data is handled only by Stripe. |
| Communications | Founding list, waitlist and newsletter sign-ups, emails sent, feedback, survey answers, interviews and testimonials, creator applications sent through the /creator form (email, platform and profile, message). |
| Technical and security | Session cookies, IP address and request metadata processed by hosting, application and AI pipeline logs, usage counters, error events, rate limits. |
Public tools without an account (calculators) process answers in the browser and do not store them. The interactive demo uses a fixed dataset and does not accept personal files.
3. Purposes and legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating and managing your account, saving notebooks and materials, exports, sharing, support | Performance of a contract, Art. 6(1)(b) |
| AI processing of the materials you upload (summaries, quizzes, flashcards, chat, oral exam practice, podcasts, lessons, images, transcription) | Performance of a contract, Art. 6(1)(b): it is the service you request. No separate consent is needed; you always choose which files to upload and which features to use |
| Payments, invoicing, refunds, tax and accounting duties | Legal obligation, Art. 6(1)(c) (and contract for the purchase) |
| Security, abuse prevention, rate limits, technical logs, error diagnosis and AI pipeline reliability | Legitimate interest, Art. 6(1)(f) (protecting the service and its users) |
| Aggregated visit and usage statistics (cookieless Vercel Web Analytics, internal counters) | Legitimate interest, Art. 6(1)(f). You can object in Settings > Privacy |
| Trial emails (up to 3 service messages) | Legitimate interest, Art. 6(1)(f), with an opt-out link in every email |
| Newsletter, Founding list, paid plans waitlist | Consent, Art. 6(1)(a), withdrawable at any time |
| Optional feedback, surveys, interviews, published testimonials, creator applications | Consent, Art. 6(1)(a), withdrawable at any time |
| Handling privacy requests, complaints, authority requests, data breaches | Legal obligation, Art. 6(1)(c) |
Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
4. Oral exam practice and speech recognition
In oral exam practice the default mode is “accurate”: your answer is recorded (up to 3 minutes), sent to our server and transcribed by the transcription provider. The same mode is always used on iPhone and iPad, when the browser does not support speech recognition or when the browser microphone fails. Alternatively you can choose the browser’s “live” recognition, which does not go through our server but through the browser’s own speech service (for example Google for Chrome, Apple for Safari).
The transcription route does not store the audio file. The transcript is sent to the AI provider to evaluate your answer; in your account we only store per-topic scores and, for wrong answers, a short note on what was missing, not the full transcript. We do not analyse tone, emotions or biometric features of your voice and we do not create voiceprints.
5. AI and model training
- What we send: AI providers receive only the content needed for the feature you asked for (source text, prompts, images, oral answer audio), without your email.
- Training: we use the providers’ paid or professional API tiers. Where a provider lets us opt out of using content to train its models, we opt out; Memoniq does not use your materials to train its own models.
- Free endpoints: some features use models offered for free through OpenRouter. In particular the default narration voice for podcasts and lessons (Fish Audio S2.1 Pro, free version) receives the text to be read aloud. Under their providers’ terms, free endpoints may retain or log inputs. For this reason the text sent to these endpoints is the generated study text, not your original files.
- Local models: with LM Studio, Ollama or local voices (Kokoro, Piper) that you configure, processing stays on your device.
- Model changes: we may change provider or model for quality, cost, security or availability. The current list is on the AI transparency page.
Health data and third-party data
Memoniq is designed for notes, lecture transcripts and study materials. Do not upload identifiable patient data (names, initials with dates, record numbers, images showing patient details) or other people’s personal data without a legal basis: these are special categories of data (Art. 9 GDPR) that the service is not designed to process. Anonymise clinical cases and examples before uploading. If we notice that publicly shared content contains such data, we may disable its link.
6. Providers (processors) and transfers
We use the following providers as processors (Art. 28 GDPR), each only for its own function. Content is sent only when needed for the requested feature.
| Provider | Role and data | Location and safeguards |
|---|---|---|
| Infrastructure | ||
| Supabase | Database, authentication, backups: account, materials, progress, encrypted keys. | EU (project region); any support access from the US under SCCs |
| Vercel | Website and server function hosting, request logs, cookieless Web Analytics: IP, requests, technical metadata. | US and global network; DPF and SCCs |
| Cloudflare (R2) | File storage: uploaded files, images, exports and shared videos. | Cloudflare global network; DPF and SCCs |
| Payments and email | ||
| Stripe | Payments, subscriptions, invoices, refunds: email, payment data, amounts. For fraud prevention and legal duties Stripe also acts as an independent controller. | EU (Stripe Payments Europe, Ireland) and US; DPF and SCCs |
| Klarna | Only if you choose Klarna at checkout: assessment and instalment payment, as an independent controller. | EU (Sweden) |
| Resend | Email delivery: confirmations, trial emails, Founding list, newsletter. Email address, message content, delivery status. | US; DPF where certified, otherwise SCCs |
| AI managed by Memoniq | ||
| OpenRouter | Gateway to AI models: text (DeepSeek, OpenAI), claim verification, image reading (Qwen), embeddings (OpenAI), images (Black Forest Labs, Google), synthetic voice (Fish Audio, Kokoro), transcription (Whisper). Source text, prompts, images, oral answer audio. OpenRouter routes the request to an inference provider hosting the model. | US and inference provider locations; SCCs (and DPF where certified) |
| Google (Gemini API) | Transcription of large audio files uses Gemini through OpenRouter (Google Vertex provider, paid, no retention for training). | EU/US; DPF and SCCs |
| Groq | Fallback transcription (Whisper) and fallback models: audio and text. | US; SCCs (and DPF where certified) |
| OpenAI | Fallback text provider, used only if the main gateway is not configured or unavailable. | US (OpenAI: DPF and SCCs) |
| Kroki | Diagram rendering: receives the diagram code (labels derived from the summary), not your files. | Public kroki.io service with no contract with us: its operator processes the data as an independent controller. No personal data should go into diagram labels. |
| Langfuse (if enabled) | Quality monitoring of AI calls: truncated prompt and response excerpts (max 2,000 characters), model, pseudonymous account ID (hash). | EU (cloud.langfuse.com) |
| Image and source search | ||
| Serper, Searlo, Scrapingdog | Image search: they receive only short search queries generated from the content. | US/outside the EEA; SCCs |
| Public services (Wikimedia Commons, Wikipedia, Openverse, NIH Open-i, PubMed, NASA Images) | Receive search queries for images and bibliographic references; no account data. | US; non-identifying queries only |
| Services used by your browser or only if you choose them | ||
| Microsoft (Edge voice) | Fallback voice: the browser sends the text to be read to the Microsoft speech service. | Public Microsoft service with no contract with us: Microsoft processes the text as an independent controller (US/EU). Used only when the other voices are unavailable. |
| jsDelivr | Delivers the Tesseract OCR engine and libraries to the browser: text recognition runs on your device; jsDelivr only sees the file request (IP). | Global CDN |
| Google (sign-in, Drive Picker, YouTube) | Google sign-in, picking files from Google Drive and YouTube videos embedded in privacy-enhanced mode (youtube-nocookie), only when you use them. For YouTube imports we use the video URL, transcript and metadata. | EU/US; DPF and SCCs |
Transfers outside the European Economic Area. Some providers process data in the US or other countries. Transfers rely on the EU-US Data Privacy Framework adequacy decision for certified providers or on the Standard Contractual Clauses approved by the European Commission (Art. 46 GDPR). You can ask for details on the safeguards at the contact above.
7. Lists, newsletter and emails
Paid plans waitlist
Only if you explicitly join, we record your account ID, verified email, language, date and consent version to notify you when paid plans open. Legal basis: consent. Joining does not enable newsletters or general advertising. We keep the data until the launch notice and in any case no longer than 24 months. You can withdraw at any time on the waitlist page or by writing to us, without affecting Free access.
Founding list (no account) and invite links
If you join the Founding list, even without an account, we process: email, consent with date and version, language, source page, campaign or creator parameters (utm and creator code) and, only if you provide them, year of study, university and next exam type. We generate an invite code and record who invited you. Legal basis: consent (Art. 6(1)(a) GDPR). Purposes: notifying you at launch, reserving the Founding price for the first 300 sign-ups who create an account with the same email, and granting the free month to people who invite at least 3 classmates.
Emails are sent through Resend; we record which messages we sent you so we never send them twice. Every email contains an unsubscribe link. Sign-ups that never become an account are deleted after 24 months, unless you withdraw earlier.
Trial emails and study profile
After signing up you may receive up to 3 service emails about the trial (days 1, 7 and 12): how to start, how to use oral exam practice and what happens when the trial ends. Legal basis: legitimate interest in helping you use the service you activated; every email contains a link to stop receiving them.
If you answer the first dashboard question, we store degree, subject and next exam type to preset new notebooks. You can change them at any time; they are deleted with your account.
Feedback, surveys and testimonials. They are optional and based on consent. A testimonial is published only after your explicit approval and you can ask for its removal at any time.
Creator applications. If you apply through the /creator form we process your email, platform, public profile and message only to reply and to manage the collaboration, on the basis of the consent you give in the form (Art. 6(1)(a)), withdrawable at any time. If a collaboration starts, we link a code to your profile to attribute the clicks and sign-ups that come from your link: clicks are counted in aggregate form, without IP addresses or data about the people who click.
8. How long we keep data
| Data | Retention |
|---|---|
| Account, notebooks, sources, materials, progress | While your account is active or until you delete them. When you delete your account they are erased immediately; copies in database backups expire within 30 days. |
| Shared links and videos | Until you revoke them or delete the material or the account. |
| Answer history for the Progress view (topic, score, exercise type, date; not the text of your answers) | 12 months, then automatic deletion; earlier if you delete the notebook or the account. |
| Technical and usage logs (AI pipeline runs, usage events, diagnostics, AI decision log, link clicks) | 12 months, then automatic deletion. |
| Daily aggregate statistics (counts per day, feature, plan or channel, with no user identifiers) | Kept without an end date: they contain no personal data. |
| Daily anti-abuse counters (keyed hash of the IP for the public widget, account id for cost limits) | 7 days, then automatic deletion; immediately when the account is deleted. |
| Hosting logs | For the technical period set by the hosting provider. |
| Feedback, surveys, interviews, creator applications, testimonials | 24 months, or earlier if you delete your account (feedback is anonymised where possible) or withdraw consent. Approved and published testimonials stay for as long as you keep your consent: you can ask for removal at any time. |
| Invoicing, payment and refund records | 10 years (Art. 2220 Italian Civil Code), also after account deletion. |
| Unconverted Founding list, waitlist | 24 months at most, unless you withdraw earlier. |
| Newsletter | Until you unsubscribe; unconfirmed sign-ups deleted after 7 days. |
| Data stored in your browser | On your device until you clear site data or log out. |
10. Security measures
- Row Level Security on every table: each user only sees their own data; server-side ownership checks on files and materials.
- Personal API keys encrypted with AES-256-GCM; server secrets never exposed to the browser.
- Encrypted TLS/HTTPS connections with HSTS; files on Cloudflare R2 and the database encrypted at rest by the providers.
- CSP and security headers, rate limits, plan limits, input validation, SSRF protection for external URLs.
- Administrative access limited to the controller; internal reports without emails or study content.
11. Data breaches
If a personal data breach occurs, we assess it without delay and, if it poses a risk to your rights, we notify the Italian Data Protection Authority (Garante) within 72 hours of becoming aware of it (Art. 33 GDPR). If the risk is high we inform you directly, by email or with an in-app notice (Art. 34). Every breach is recorded in an internal register.
12. Your rights
Under Articles 15-22 GDPR you can request access, rectification, erasure, restriction, data portability, object to processing based on legitimate interest and withdraw consent at any time.
- Self-service: in Settings > Account you can export your data and delete your account.
- By email: write to infomemoniq@gmail.com from your account address. We reply within one month (extendable by two more months for complex requests, with notice).
- Complaint: you can lodge a complaint with the Garante per la protezione dei dati personali (www.garanteprivacy.it) or with the authority of the EU country where you live or work.
Users outside the EU
Where local law applies, we recognise equivalent rights as required. For California users: we do not sell or share personal data for behavioural advertising; you can request access and deletion.
How to delete your account and data
This applies to the website and the Android app. After signing in: Account > Delete account > Delete my account. Deletion is immediate and erases your account, notebooks, uploaded sources, generated materials, chat history and categories. If you cannot sign in, write from your account email to infomemoniq@gmail.com: we complete the deletion within one month (Art. 12 GDPR). Only data we are legally required to keep (accounting records, also at Stripe) and backup copies, which expire within 30 days, remain.
13. Automated decisions
Memoniq does not make decisions based solely on automated processing that produce legal or similarly significant effects on you (Art. 22 GDPR). Quiz scores, oral practice evaluations and mastery indicators are practice estimates: they are not official grades and are not shared with universities or third parties.
14. Minimum age
You must be at least 16 to use Memoniq, in every country; we ask you to confirm this at sign-up. This is the age set by GDPR Art. 8 and the highest threshold chosen by EU member states (Italy uses 14, Art. 2-quinquies of the Italian Privacy Code, Legislative Decree 196/2003): we apply one rule that is valid everywhere. If you are between 16 and 18, purchases require the involvement of a parent or guardian. If we find that an account belongs to someone under 16 we delete it; parents and guardians can write to us to request this.
15. Updates
We update this notice when features, providers or laws change. The date at the top shows the latest revision. For material changes we notify registered users and, when needed, ask you to confirm the new version at your next sign-in.
Payments and refunds
Satisfaction guarantee: within 14 days of your first payment you can request a full refund of the subscription or Session Pass directly from Settings, without contacting anyone. The refund covers the first payment (not later renewals) and returns the account to the Free plan. Statutory withdrawal rights and legal guarantees remain unaffected.