Privacy Policy for momemo

Last updated: 17 June 2026

This privacy policy applies to the momemo app and the associated websites and services under the domains momemo.app (marketing and pricing page), my.momemo.app (account portal), api.momemo.app and id.momemo.app. The German version is legally authoritative; this English text is a convenience translation.


Privacy at a glance

Your voice recordings are never stored, never uploaded, never synced. They exist only transiently in your device's working memory (RAM) while speech recognition is running, and are discarded immediately afterwards. There is no cloud-based speech recognition. No audio record is ever created on a server.

The essentials:


Table of contents

  1. Controller
  2. Scope and definitions
  3. Audio: the core non-storage
  4. What data we process and why
  5. Recipients and processors
  6. Payment processing via Paddle (Merchant of Record)
  7. Transfers to third countries
  8. Online AI: your separate consent
  9. AI transparency (EU AI Act)
  10. Retention and deletion
  11. Your rights
  12. Data security
  13. Cookies and tracking
  14. Contractual information, withdrawal and cancellation
  15. Changes to this privacy policy

1. Controller

The controller within the meaning of Art. 4(7) GDPR is:

memo labs UG (haftungsbeschränkt) Kolonnenstraße 8 10827 Berlin Germany

Represented by the Managing Director: Sascha Kaderka

Phone: +49 30 4243 4444 Email: impressum@momemo.app

Commercial register: Amtsgericht Charlottenburg (Local Court of Charlottenburg), HRB 280741 B VAT identification number: DE458375356

For data protection enquiries, you can reach us at support@momemo.app.

Data protection officer: We are not legally required to appoint a data protection officer, and have not appointed one. For data protection questions, please contact support@momemo.app.


2. Scope and definitions

This policy applies to the use of the momemo app (available for Android) as well as the associated websites and services:

Account requirement: Using momemo requires a user account. Use is not possible without an account; the data required for this (see section 4 a) must therefore be provided.


3. Audio: the core non-storage

In short: Audio is processed exclusively and transiently in your device's working memory (RAM) and discarded immediately afterwards. It is never persistently stored, transmitted to our servers, or synced.

Speech recognition (speech-to-text) runs via a local STT engine directly on your device. There is no cloud-based speech recognition (no cloud STT).

Separately from this, the optional on-device AI model (Gemma) processes only already-transcribed text (e.g. for grammar/spelling correction, rewriting, translation and ToDo detection, where these run offline). The on-device AI model is not the speech recognition and does not process any audio.

Consequence: Since no audio is stored or transmitted, no personal audio record is created on the server side. Only the transcribed text result and associated metadata (duration, word count, language, engine used, device) are processed further.

Sensitive content: You decide what you dictate. Any special categories of personal data within the meaning of Art. 9 GDPR (e.g. health information) can only be contained in the text you dictate — not in an audio recording, since none is created. You are responsible for the content of the text you generate.


4. What data we process and why

The following is structured by purpose. For each purpose we state what is processed, why, on which legal basis, for how long (bundled in section 10) and to which recipients (see section 5).

a) Account and sign-in

In short: So that you can have an account and sign in securely.

b) Optional social login (Google, and Apple where available on your platform)

In short: Only if you actively choose "Sign in with Google" or — where offered on your platform — "Sign in with Apple".

c) Synced content (only with paid plans or activated synchronisation)

In short: So that your notes and settings are available across devices.

c-bis) Usage counter (quota enforcement, account-wide)

In short: So that we can enforce the usage limits of your plan — regardless of whether you sync content.

d) Optional online AI features

In short: Only if you switch them on — and only text leaves your device, never audio.

e) Offline AI on-device

In short: Runs entirely on your device — no data is transmitted.

f) Transactional emails

In short: Service messages relating to your account.

g) Payment and subscription

Purchase, subscription and payment processing take place via our reseller Paddle as Merchant of Record. Details in section 6.

h) Consent, subscription and entitlement records

In short: So we can demonstrate which plans and consents apply.

i) Sharing notes as a link, and replies from recipients

In short: You can share an individual note as a link. Anyone who opens the link needs no account and is not tracked. If they reply to you, we pass the reply on to you and delete it afterwards.

This feature concerns two groups of people: you as the sender (momemo user, paid plan) and the recipient, who opens the link without the app and without an account. We describe both perspectives here.

When you create a link (sender):

When you only open a link (recipient, without the app and without an account):

What the page stores locally in your browser (recipient):

So that your draft, your ticks and your settings are not lost, the page stores some information only locally in your browser (no cookie, no tracking, no transmission to us for this purpose alone): the draft text for a link, your send history for this link (what you have already submitted), the tick states for requests, the font size you have chosen and the name you provide when replying. The name is remembered for your browser as a whole — that is, it is also used if someone else sends you a momemo link later, so that you are not asked for it again. This information resides on your device and can be deleted at any time via your browser's website data.

When you reply as a recipient:

When you report content as a recipient:

Protection against misuse (IP address):

The reply and reporting feature is publicly accessible — without sign-in. In order to prevent spam and automated attacks, we limit the number of requests per sender IP. For this purpose we process your IP address only transiently in a counter (in-memory database Redis, time window 60 seconds); for this purpose it is passed through from the web server up to this counting, so that not all visitors fall into a shared counter. Your IP address is not stored permanently and in particular does not end up in the reply or report records. The access log of our web server is deliberately switched off, and we do not log the tokens of the sharing links at any point. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in the security and availability of our service).

Your right to object (Art. 21 GDPR):

Because we base the reply, reporting and misuse-prevention features on a legitimate interest (Art. 6(1)(f) GDPR), you have the right to object to this processing at any time on grounds relating to your particular situation — even if you do not have a momemo account. A message to support@momemo.app is sufficient. Since we delete replies in any case after delivery or after 30 days at the latest, an objection is in practice usually already settled by that; we will of course still examine it and delete immediately on request. To assign your request, the link via which you replied helps us.

You as the sender are responsible for the content: You decide what you pass on in a shared note. This also applies to any special categories of personal data within the meaning of Art. 9 GDPR (see section 3).

No automated decision-making in individual cases: No automated decision-making, including profiling, with legal effect or similarly significant impact within the meaning of Art. 22 GDPR takes place.


5. Recipients and processors

We use carefully selected service providers. The following recipients process data on our behalf under Art. 28 GDPR (processors), unless stated otherwise:

RecipientLocationPurposeClassification / safeguard
Hetzner Online GmbHGermanyHosting / serversProcessor (Art. 28), EU
Scaleway SASFranceLLM inference (online AI) and transactional email (TEM)Processor (Art. 28), EU
Self-operated login / SSO systemGermanySign-in / SSOOwn processing in own infrastructure (on Hetzner); no additional external processor
INWX GmbH & Co. KGGermanyDNS / domain managementProcessor (Art. 28), EU
Google / Appleincl. USAOptional social login (OIDC)Only with your active choice and where available on your platform; separate controllers; third country (see section 7)
Paddle (Merchant of Record)United KingdomPayment processing as Merchant of RecordIndependent controller (not a processor) — see section 6

Clarification: Our company email address (memolabs.de, via Google Workspace) is used solely for business correspondence and is not part of the processing path for your app user data. It is therefore not listed here as a recipient of your app data.


6. Payment processing via Paddle (Merchant of Record)

In short: When you buy or subscribe to momemo, you complete the purchase with Paddle. Paddle is an independent data controller for the payment data — not our processor.

Paddle.com Market Ltd is our authorised reseller and your contractual seller for the purchase, acting as Merchant of Record. Paddle handles payment, invoicing, VAT, dunning, refunds and fraud prevention.

For these purposes, Paddle is an independent controller within the meaning of the GDPR and specifically not a processor of memo labs. Paddle is therefore listed here expressly separately from our processors (section 5).

Third country: The Paddle contracting entity is based in the United Kingdom. The United Kingdom is recognised by an adequacy decision of the EU Commission under Art. 45 GDPR as a third country with an adequate level of data protection. Transfers from the EU to the United Kingdom therefore do not require Standard Contractual Clauses (SCC).

For Paddle's own-responsibility processing — including any transfers within the Paddle group of companies and the safeguards used — Paddle's own privacy policy applies (linked above). This further processing is Paddle's responsibility as an independent controller and is not part of our own transfer (which goes to the United Kingdom, see above).


7. Transfers to third countries

Principle: The processing chain of your user data remains within the EU (Hetzner in Germany, Scaleway in France). Transfers outside the EU/EEA only take place in the following clearly named exceptions:


8. Online AI: your separate consent

In short: Online AI is off by default. You switch it on yourself and can switch it off again at any time. Only text leaves your device, never audio.

The optional online AI features (grammar/spelling correction, translation, rewriting, ToDo detection) are based on your separate consent under Art. 6(1)(a) GDPR. This consent is:

When consent is active, only text (no audio) is transmitted to Scaleway (France, EU) for processing. Revocation does not affect the lawfulness of processing carried out up to the point of revocation.


9. AI transparency (EU AI Act)

The grammar/spelling correction, rewriting, translation and ToDo detection features are provided by an AI system (large language model, LLM). You are interacting with results generated or edited by AI.

The transparency obligations under Art. 50 of the EU AI Act apply from 2 August 2026. We mark AI-assisted features accordingly so that you can recognise when a result comes from an AI system.

This does not involve any automated decision with legal effect within the meaning of Art. 22 GDPR.


10. Retention and deletion


11. Your rights

Under the GDPR you have the following rights:

To exercise your rights, a message to support@momemo.app is sufficient.

Right to lodge a complaint: You have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). Due to our registered office in Berlin, the competent authority for us is:

Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit) Alt-Moabit 59–61 10555 Berlin Germany


12. Data security

Transmission between your device and our services is encrypted via TLS (HTTPS). Our online processing takes place on servers within the EU (Germany, France).


13. Cookies and tracking

We currently use no analytics cookies and no tracking on our websites. There is currently no storage of information on, or access to, your device that is not strictly necessary.

Technically necessary storage operations (e.g. login/session cookie on my.momemo.app) are exempt from consent under Section 25(2) TDDDG, as they are strictly necessary to provide the service you have expressly requested.

Insofar as information is stored on your device or accessed in the future in a way that is not strictly necessary, we will obtain your consent for this under Section 25(1) TDDDG.


14. Contractual information, withdrawal and cancellation

This privacy policy deals exclusively with the processing of personal data. Contractual information, your right-of-withdrawal notice for digital services, and the option to cancel your subscription are not part of this privacy policy; you will find them in our Terms and Conditions (T&Cs) or in the order/checkout process. See our Terms and Conditions and the withdrawal notice.


15. Changes to this privacy policy

We will adapt this privacy policy when the processing or the legal framework changes. The version published on this page with the date stated above applies in each case.

See also: Legal notice · Terms and Conditions · Withdrawal notice · Privacy Policy

Last updated: 17 June 2026

Back to the start page
Privacy policy · momemo