Privacy Policy for momemo
Last updated: 17 June 2026
This privacy policy applies to the momemo app and the associated websites and services under the domains momemo.app (marketing and pricing page), my.momemo.app (account portal), api.momemo.app and id.momemo.app. The German version is legally authoritative; this English text is a convenience translation.
Privacy at a glance
Your voice recordings are never stored, never uploaded, never synced. They exist only transiently in your device's working memory (RAM) while speech recognition is running, and are discarded immediately afterwards. There is no cloud-based speech recognition. No audio record is ever created on a server.
The essentials:
- Offline-first. momemo works without a permanent internet connection. The offline AI runs directly on your device (on-device).
- Text only, never audio. If you enable optional online features, only the recognized text leaves your device — never audio.
- EU hosting. Your online data is processed on servers within the EU (Germany and France). There are no US providers in the processing chain of your user data — with clearly named exceptions (payment via Paddle; Google/Apple only if you choose social login).
- You stay in control. Online AI features are off by default and can be revoked at any time. You can delete your account and all associated online data yourself and export it as JSON.
- Your content is yours. Recordings, notes, ToDos and your dictionary go neither to the payment service Paddle nor to Google/Apple — they are processed, if at all, only on our own backend in the EU (Germany and France).
Table of contents
- Controller
- Scope and definitions
- Audio: the core non-storage
- What data we process and why
- Recipients and processors
- Payment processing via Paddle (Merchant of Record)
- Transfers to third countries
- Online AI: your separate consent
- AI transparency (EU AI Act)
- Retention and deletion
- Your rights
- Data security
- Cookies and tracking
- Contractual information, withdrawal and cancellation
- Changes to this privacy policy
1. Controller
The controller within the meaning of Art. 4(7) GDPR is:
memo labs UG (haftungsbeschränkt) Kolonnenstraße 8 10827 Berlin Germany
Represented by the Managing Director: Sascha Kaderka
Phone: +49 30 4243 4444 Email: impressum@momemo.app
Commercial register: Amtsgericht Charlottenburg (Local Court of Charlottenburg), HRB 280741 B VAT identification number: DE458375356
For data protection enquiries, you can reach us at support@momemo.app.
Data protection officer: We are not legally required to appoint a data protection officer, and have not appointed one. For data protection questions, please contact support@momemo.app.
2. Scope and definitions
This policy applies to the use of the momemo app (available for Android) as well as the associated websites and services:
momemo.app— marketing and pricing pagemy.momemo.app— account portal (account and data management)api.momemo.app— interface for synchronisation and online featuresid.momemo.app— sign-in and single sign-on
Account requirement: Using momemo requires a user account. Use is not possible without an account; the data required for this (see section 4 a) must therefore be provided.
3. Audio: the core non-storage
In short: Audio is processed exclusively and transiently in your device's working memory (RAM) and discarded immediately afterwards. It is never persistently stored, transmitted to our servers, or synced.
Speech recognition (speech-to-text) runs via a local STT engine directly on your device. There is no cloud-based speech recognition (no cloud STT).
Separately from this, the optional on-device AI model (Gemma) processes only already-transcribed text (e.g. for grammar/spelling correction, rewriting, translation and ToDo detection, where these run offline). The on-device AI model is not the speech recognition and does not process any audio.
Consequence: Since no audio is stored or transmitted, no personal audio record is created on the server side. Only the transcribed text result and associated metadata (duration, word count, language, engine used, device) are processed further.
Sensitive content: You decide what you dictate. Any special categories of personal data within the meaning of Art. 9 GDPR (e.g. health information) can only be contained in the text you dictate — not in an audio recording, since none is created. You are responsible for the content of the text you generate.
4. What data we process and why
The following is structured by purpose. For each purpose we state what is processed, why, on which legal basis, for how long (bundled in section 10) and to which recipients (see section 5).
a) Account and sign-in
In short: So that you can have an account and sign in securely.
- What: email address, authentication data, one-time codes (OTP), passkey/WebAuthn credentials.
- Why: provision and protection of your account; momemo cannot be used without an account.
- Legal basis: Art. 6(1)(b) GDPR (performance of the usage contract; provision is required to perform the contract — without this data, use is not possible).
- Processed via: our self-operated login / single sign-on system on Hetzner infrastructure (Germany), accessible via
id.momemo.app.
b) Optional social login (Google, and Apple where available on your platform)
In short: Only if you actively choose "Sign in with Google" or — where offered on your platform — "Sign in with Apple".
- What: the sign-in data provided by the respective provider (Google or Apple) via the OpenID Connect procedure (e.g. email address, account identifier).
- Why: convenient sign-in using an existing account of your choice.
- Legal basis: Art. 6(1)(a) GDPR (consent through your active choice) or Art. 6(1)(b) GDPR (performance of the contract).
- Availability: Which login providers are offered depends on your platform. On Android, the Google login is additionally available; the Apple login is offered where it is available on your platform.
- Only login data, no content: Only identity and login data is exchanged (e.g. email address, account identifier) so that we can sign you in. Your content created in momemo — recordings, notes, ToDos and your dictionary — is never transmitted to Google or Apple.
- Note: With this choice, the login data mentioned above is transmitted to the respective provider (Google or Apple); these providers are separate controllers in this respect and may also process data in the USA (see section 7). If you do not use this login, no transfer to Google or Apple takes place.
c) Synced content (only with paid plans or activated synchronisation)
In short: So that your notes and settings are available across devices.
- What: notes and texts, ToDos (internally
sync_objects), your online dictionary, and device/installation identifiers. No audio. - Why: cross-device synchronisation of the content you create.
- Legal basis: Art. 6(1)(b) GDPR (performance of the usage contract in the respective plan).
- Note on scope: Content (notes, ToDos, dictionary) is only synchronised if you use a paid plan or have activated synchronisation. The usage counter is handled separately from this (see section 4 c-bis).
c-bis) Usage counter (quota enforcement, account-wide)
In short: So that we can enforce the usage limits of your plan — regardless of whether you sync content.
- What: usage counter (
usage_counters) for usage/quota measurement. - Why: enforcement of the usage limits applicable under your plan. The usage counter is processed account-wide for quota enforcement, independently of content sync — so only the counter is ever synced, never the underlying content.
- Legal basis: Art. 6(1)(b) GDPR (performance of the usage contract in the respective plan).
d) Optional online AI features
In short: Only if you switch them on — and only text leaves your device, never audio.
- What: the text to be processed (no audio) for features such as grammar/spelling correction (GEC), translation, rewriting, and ToDo detection.
- Why: AI-assisted improvement and processing of your texts.
- Legal basis: Art. 6(1)(a) GDPR (your separate, granular and revocable consent; off by default — see section 8).
- Processed via: Scaleway (France, EU). Only text is transmitted.
e) Offline AI on-device
In short: Runs entirely on your device — no data is transmitted.
- What/why: local AI processing of already-transcribed text via the on-device model (Gemma) for features that work offline. The model does not process any audio (see section 3).
- Data transfer: none. This processing does not leave your device; it is mentioned here only for clarity.
f) Transactional emails
In short: Service messages relating to your account.
- What: your email address and the content of the respective message (e.g. sign-in confirmations, security and account notices).
- Why: sending necessary service messages.
- Legal basis: Art. 6(1)(b) GDPR (performance of the contract) or Art. 6(1)(f) GDPR (legitimate interest in reliable service communication and account security).
- Sent via: Scaleway Transactional Email (TEM), sender address
noreply@momemo.app.
g) Payment and subscription
Purchase, subscription and payment processing take place via our reseller Paddle as Merchant of Record. Details in section 6.
h) Consent, subscription and entitlement records
In short: So we can demonstrate which plans and consents apply.
- What: consent records (evidence of consents granted/revoked) and subscription/entitlement records (plan and entitlement status).
- Why: management of your entitlements and fulfilment of our accountability obligation.
- Legal basis: Art. 6(1)(b) GDPR (performance of the contract) and Art. 6(1)(c) GDPR in conjunction with Art. 7(1) GDPR (evidence of consents granted).
i) Sharing notes as a link, and replies from recipients
In short: You can share an individual note as a link. Anyone who opens the link needs no account and is not tracked. If they reply to you, we pass the reply on to you and delete it afterwards.
This feature concerns two groups of people: you as the sender (momemo user, paid plan) and the recipient, who opens the link without the app and without an account. We describe both perspectives here.
When you create a link (sender):
- What: the note you deliberately select for sharing; a random token (192 bit) generated by our server as the address of the link; optionally a recipient label assigned by you (e.g. "Mum") as well as the sharing channel you choose (e.g. WhatsApp, Messenger); an indicator of whether you asked the recipient for a reply. In addition, your name and a version of the note prepared for the recipient: the key message, detected tasks, questions, appointments, phone numbers and addresses (up to 50 entries), the speaking duration and the language. Your app generates this version when you share — not only when someone opens the link.
- Visible to the recipient: The recipient label and your name are displayed to the recipient on the page — choose the label accordingly.
- Why: so that you can pass a note on to a specific person of your choice.
- Legal basis: Art. 6(1)(b) GDPR (performance of the usage contract in the respective plan).
- For how long: The link can be opened for 90 days and can be revoked by you at any time — after that, or from the revocation onwards, it can no longer be opened. The record of the link itself (recipient label, channel, time, revocation) is retained as your sharing overview until you delete your account — including for expired or revoked links, so that you can trace what you shared and when.
- Limit: Encrypted notes cannot be shared. The attempt is rejected.
When you only open a link (recipient, without the app and without an account):
- No account, no sign-in, no cookies, no tracking. The page at
my.momemo.app/s/<token>is a read view that our server delivers ready-made. The page language is derived server-side from the language setting sent by your device (Accept-Language). - For mere reading, the page loads nothing further. Only if you reply or tick off a request does your browser send this information directly to our server. Pending ticks are still submitted even if you close the tab. During these send operations, our server sees — as with every request on the internet — your IP address; what we do with it is set out below under "Protection against misuse".
- Not discoverable: The page is blocked for search engines (
noindex/nofollow) and does not disclose any origin when you click through (no-referrer). - No content in the link preview: The preview card that messengers display when a link is sent is deliberately static and free of content in our case — it never retrieves the note at any point and is identical for all links in the same language. All that the link reveals is therefore the language in which the note is written — no content. This means no note content ends up in the caches of chat services.
What the page stores locally in your browser (recipient):
So that your draft, your ticks and your settings are not lost, the page stores some information only locally in your browser (no cookie, no tracking, no transmission to us for this purpose alone): the draft text for a link, your send history for this link (what you have already submitted), the tick states for requests, the font size you have chosen and the name you provide when replying. The name is remembered for your browser as a whole — that is, it is also used if someone else sends you a momemo link later, so that you are not asked for it again. This information resides on your device and can be deleted at any time via your browser's website data.
When you reply as a recipient:
- What we store: your reply text (or your replies per question); the type of reply (text or a completion notice for a request); optionally a name — either the label that the sender assigned themselves (a name sent along by the device is ignored; we use exclusively the sender's label), or a name that you provide yourself with the nameless group link (max. 80 characters, voluntary); the page language (de/en/es/fr or empty); the time; technical references (link identifier, note identifier, token, the sender's account identifier as well as an identifier to prevent duplicate submission) and an indicator of whether the sender has already read the reply.
- What we do not store: no account of yours (only the identifier of the sender account to which your reply goes), no email address, no IP address in this record, no audio.
- Why: so that your reply reaches the sender who expressly requested it.
- Legal basis: Art. 6(1)(f) GDPR (legitimate interests). Our legitimate interest — and that of the sender — lies in delivering a reply that the sender previously asked you for themselves. Without this processing, the feature you are currently using could not fulfil its purpose. We deliberately require no sign-in and no consent checkbox, in order to collect as little data from you as possible.
- Recipients of your reply: the sender who sent you the link (the momemo user). Beyond that, we do not pass your reply on to anyone. It is hosted with our processor Hetzner in the EU; our servers are located in Germany (see section 5).
- For how long: As soon as the sender's app has retrieved the reply and confirmed receipt, the record is permanently deleted on our server. If the sender's app does not retrieve the reply, or the sender does not view it, we delete it automatically after 30 days at the latest. We do not store your reply permanently.
When you report content as a recipient:
- What: the reason you select (threat, private, fraud or other), a voluntary free text (max. 1,000 characters), the reference to the reported link (link identifier, note identifier, token), the time as well as an internal indicator of whether we have already processed the report.
- What we deliberately do not collect: no name and no email address. The report is deliberately designed to be as data-minimising as possible.
- Why: so that we can investigate misuse of the sharing feature.
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the security of our service and in preventing misuse).
Protection against misuse (IP address):
The reply and reporting feature is publicly accessible — without sign-in. In order to prevent spam and automated attacks, we limit the number of requests per sender IP. For this purpose we process your IP address only transiently in a counter (in-memory database Redis, time window 60 seconds); for this purpose it is passed through from the web server up to this counting, so that not all visitors fall into a shared counter. Your IP address is not stored permanently and in particular does not end up in the reply or report records. The access log of our web server is deliberately switched off, and we do not log the tokens of the sharing links at any point. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the security and availability of our service).
Your right to object (Art. 21 GDPR):
Because we base the reply, reporting and misuse-prevention features on a legitimate interest (Art. 6(1)(f) GDPR), you have the right to object to this processing at any time on grounds relating to your particular situation — even if you do not have a momemo account. A message to support@momemo.app is sufficient. Since we delete replies in any case after delivery or after 30 days at the latest, an objection is in practice usually already settled by that; we will of course still examine it and delete immediately on request. To assign your request, the link via which you replied helps us.
You as the sender are responsible for the content: You decide what you pass on in a shared note. This also applies to any special categories of personal data within the meaning of Art. 9 GDPR (see section 3).
No automated decision-making in individual cases: No automated decision-making, including profiling, with legal effect or similarly significant impact within the meaning of Art. 22 GDPR takes place.
5. Recipients and processors
We use carefully selected service providers. The following recipients process data on our behalf under Art. 28 GDPR (processors), unless stated otherwise:
| Recipient | Location | Purpose | Classification / safeguard |
|---|---|---|---|
| Hetzner Online GmbH | Germany | Hosting / servers | Processor (Art. 28), EU |
| Scaleway SAS | France | LLM inference (online AI) and transactional email (TEM) | Processor (Art. 28), EU |
| Self-operated login / SSO system | Germany | Sign-in / SSO | Own processing in own infrastructure (on Hetzner); no additional external processor |
| INWX GmbH & Co. KG | Germany | DNS / domain management | Processor (Art. 28), EU |
| Google / Apple | incl. USA | Optional social login (OIDC) | Only with your active choice and where available on your platform; separate controllers; third country (see section 7) |
| Paddle (Merchant of Record) | United Kingdom | Payment processing as Merchant of Record | Independent controller (not a processor) — see section 6 |
Clarification: Our company email address (memolabs.de, via Google Workspace) is used solely for business correspondence and is not part of the processing path for your app user data. It is therefore not listed here as a recipient of your app data.
6. Payment processing via Paddle (Merchant of Record)
In short: When you buy or subscribe to momemo, you complete the purchase with Paddle. Paddle is an independent data controller for the payment data — not our processor.
Paddle.com Market Ltd is our authorised reseller and your contractual seller for the purchase, acting as Merchant of Record. Paddle handles payment, invoicing, VAT, dunning, refunds and fraud prevention.
For these purposes, Paddle is an independent controller within the meaning of the GDPR and specifically not a processor of memo labs. Paddle is therefore listed here expressly separately from our processors (section 5).
- No in-app purchases: Purchase and subscription run exclusively via our website or the account portal (
momemo.app/my.momemo.app), where Paddle acts as the contracting party for the purchase. - Data direction: For purchase processing, we provide Paddle with the data necessary for this (e.g. account/email reference, selected plan). In turn, Paddle transmits back to us the data necessary for the contract and entitlement (e.g. purchase/subscription status). We do not receive full payment-method/card data; these are held by Paddle.
- No content to Paddle: Your content created in momemo — voice recordings, notes, ToDos and your dictionary — never reaches Paddle. Only the payment and purchase data necessary for purchase, subscription and tax goes to Paddle; your content is technically not part of the payment process.
- Paddle's own privacy policy: For the data processed by Paddle on its own responsibility, Paddle's privacy policy applies additionally:
https://www.paddle.com/legal/privacy.
Third country: The Paddle contracting entity is based in the United Kingdom. The United Kingdom is recognised by an adequacy decision of the EU Commission under Art. 45 GDPR as a third country with an adequate level of data protection. Transfers from the EU to the United Kingdom therefore do not require Standard Contractual Clauses (SCC).
For Paddle's own-responsibility processing — including any transfers within the Paddle group of companies and the safeguards used — Paddle's own privacy policy applies (linked above). This further processing is Paddle's responsibility as an independent controller and is not part of our own transfer (which goes to the United Kingdom, see above).
7. Transfers to third countries
Principle: The processing chain of your user data remains within the EU (Hetzner in Germany, Scaleway in France). Transfers outside the EU/EEA only take place in the following clearly named exceptions:
- Paddle (payment): Our own transfer goes to Paddle.com Market Ltd in the United Kingdom, for which the EU Commission has issued an adequacy decision under Art. 45 GDPR confirming an adequate level of data protection — no separate safeguard (SCC) is required for this. For Paddle's own-responsibility further processing (including any intra-group transfers and the safeguards used), Paddle's own privacy policy applies. See section 6.
- Google/Apple (only with social login, where available on your platform): With this login you have chosen, data may be processed in the USA. For this, an adequacy decision of the EU Commission based on the EU-US Data Privacy Framework (Art. 45 GDPR) exists, insofar as the respective provider is certified; standard contractual clauses additionally apply.
8. Online AI: your separate consent
In short: Online AI is off by default. You switch it on yourself and can switch it off again at any time. Only text leaves your device, never audio.
The optional online AI features (grammar/spelling correction, translation, rewriting, ToDo detection) are based on your separate consent under Art. 6(1)(a) GDPR. This consent is:
- separate from the contractual and general usage consent (no bundling, Art. 7 GDPR),
- granular with respect to the features concerned,
- off by default (opt-in),
- revocable at any time with effect for the future, via the corresponding setting in the app (Art. 7(3) GDPR).
When consent is active, only text (no audio) is transmitted to Scaleway (France, EU) for processing. Revocation does not affect the lawfulness of processing carried out up to the point of revocation.
9. AI transparency (EU AI Act)
The grammar/spelling correction, rewriting, translation and ToDo detection features are provided by an AI system (large language model, LLM). You are interacting with results generated or edited by AI.
The transparency obligations under Art. 50 of the EU AI Act apply from 2 August 2026. We mark AI-assisted features accordingly so that you can recognise when a result comes from an AI system.
This does not involve any automated decision with legal effect within the meaning of Art. 22 GDPR.
10. Retention and deletion
- Audio: no storage (see section 3).
- Online content (e.g. notes, ToDos, dictionary): After your subscription or trial period ends, a 30-day read-only grace period applies to your online content. After that, the online copy is deleted. Your local device data always remains and is not affected by this.
- Shared links and replies from recipients (see section 4 i): A sharing link can be opened for 90 days and can be revoked by you at any time — this is an opening window, not a retention period. The record of the link itself (recipient label, channel, time, revocation) is retained afterwards as your sharing overview and is not deleted automatically; it disappears when you delete your account. A reply from a recipient is permanently deleted on our server as soon as the sender's app has retrieved it and the sender has viewed it; if the app does not retrieve it or the sender does not view it, we delete it automatically after 30 days at the latest. The IP address of visitors to the reply page is not stored permanently (only transient counters for misuse prevention). Reports submitted via the reporting feature contain neither a name nor an email address; they are deleted together with the sender's account.
- Data in the recipient's browser (see section 4 i): Draft text, send history, tick states, font size and the name provided when replying reside exclusively locally in the recipient's browser — not on our server. They remain there until the recipient deletes their browser's website data.
- Account deletion: Via
my.momemo.app/account/deleteyou can delete your account. All associated online data is removed by cascade. A data export as JSON is available to you. - General principle: We process personal data only for as long as is necessary for the purposes stated. We retain account, contract and consent data until the expiry of the applicable statutory retention periods; commercial and tax retention periods are generally 6 to 10 years.
- Statutory retention: Invoice and subscription records are maintained as part of payment processing by Paddle as Merchant of Record; in this respect, commercial and tax retention periods may apply that exceptionally prevent immediate deletion.
11. Your rights
Under the GDPR you have the following rights:
- Access to the data processed about you (Art. 15 GDPR),
- Rectification of inaccurate data (Art. 16 GDPR),
- Erasure (Art. 17 GDPR) — including via account deletion (see section 10),
- Restriction of processing (Art. 18 GDPR),
- Data portability (Art. 20 GDPR) — you can export your data as JSON,
- Objection to certain processing (Art. 21 GDPR),
- Withdrawal of consent granted, with effect for the future (Art. 7(3) GDPR) — in particular for the online AI (see section 8).
To exercise your rights, a message to support@momemo.app is sufficient.
Right to lodge a complaint: You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). Due to our registered office in Berlin, the competent authority for us is:
Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit) Alt-Moabit 59–61 10555 Berlin Germany
12. Data security
Transmission between your device and our services is encrypted via TLS (HTTPS). Our online processing takes place on servers within the EU (Germany, France).
13. Cookies and tracking
We currently use no analytics cookies and no tracking on our websites. There is currently no storage of information on, or access to, your device that is not strictly necessary.
Technically necessary storage operations (e.g. login/session cookie on my.momemo.app) are exempt from consent under Section 25(2) TDDDG, as they are strictly necessary to provide the service you have expressly requested.
Insofar as information is stored on your device or accessed in the future in a way that is not strictly necessary, we will obtain your consent for this under Section 25(1) TDDDG.
14. Contractual information, withdrawal and cancellation
This privacy policy deals exclusively with the processing of personal data. Contractual information, your right-of-withdrawal notice for digital services, and the option to cancel your subscription are not part of this privacy policy; you will find them in our Terms and Conditions (T&Cs) or in the order/checkout process. See our Terms and Conditions and the withdrawal notice.
15. Changes to this privacy policy
We will adapt this privacy policy when the processing or the legal framework changes. The version published on this page with the date stated above applies in each case.
See also: Legal notice · Terms and Conditions · Withdrawal notice · Privacy Policy
Last updated: 17 June 2026
Back to the start page