memoquid

Privacy Policy

Effective 7 September 2026 · Version 2.0

This Privacy Policy explains how Memoquid ("Memoquid", "we", "us", "our") collects, uses, shares and protects information when you use the Memoquid mobile application (the "App"), the website at memoquid.com (the "Site"), our waitlist, and any related services (together, the "Service"). It also explains the choices and rights you have.

By using the Service you acknowledge this Policy. If you do not agree with it, do not use the Service. Capitalised terms not defined here have the meaning given in our Terms of Service.

1. The short version

  • Nothing leaves your phone until you say the wake word. The wake word is detected on your device by a model that runs there. Until you say it, the App is not listening to the room and sends nothing anywhere.
  • What leaves after that is the audio of what you said, so it can be understood; the text of your request; and the smallest slice of connected-app data the request needs. A message's contents are read only when you ask about that message.
  • No voiceprints, ever. We do not create, store or use biometric identifiers, we never use your voice to identify you, and we never clone it.
  • Your history stays on your phone. What you asked and what the App answered is kept on your device, deleted automatically after 30 days, and erasable by you at any time.
  • Our providers work under zero-retention, no-training terms. None of them gets your data for their own purposes. We do not sell personal information and we do not show advertising.

The rest of this Policy is the long version of those five sentences.

2. Who we are

Memoquid operates the Service. For the purposes of the EU and UK General Data Protection Regulation, Memoquid is the controller of the personal information described in this Policy. You can reach us at contact@memoquid.com.

3. Information we collect

3.1 Information you give us

What When Examples
Account information When you sign in Your name and email address as provided by Sign in with Apple or Google, and an account identifier
Waitlist information When you join the waitlist on the Site Your email address, which form you used, and — only if you tell us — which app you would connect first and whether you are on a phone the beta does not yet support
Messages to us When you contact us Your name, email address and the content of your message
Preferences When you set them in the App Which apps you have connected, settings you choose

3.2 Voice and requests

The App has two listening states, and the difference between them is the most important fact in this Policy.

Before the wake word. A small model on your device listens only for the wake phrase. Audio in this state is processed in memory on the device and discarded. It is never recorded, stored or transmitted, and no one, including us, can hear it.

After the wake word. For as long as a request lasts, the App sends the following to carry it out:

  • the audio of what you said, to a speech-recognition provider, so it can be turned into text;
  • the resulting text of your request, to a language-understanding provider, so the App knows which action you meant and with what details;
  • names of people you have recently emailed or have meetings with, sent to the speech-recognition provider as recognition hints so that a name is heard correctly. Names only, never message contents, and not retained by the provider;
  • the spoken reply, which is generated by a text-to-speech provider from the text of the answer.

Audio is processed to produce a transcript and is not retained by us. Our providers process it under zero-retention terms (see Section 6).

3.3 Connected-app data

The App works by acting in apps you choose to connect, such as your calendar, your email, your team chat, your task list or your music. When you connect an app you authorise us, through that app's own sign-in (for example Google OAuth), to access it with the narrowest permissions that do the job. What we access depends on what you ask:

  • Calendar: the events in the period you ask about, including titles, times and attendee names, in order to read them back, move or create an event, or answer a question about your day.
  • Email: the senders, subjects, dates and labels of recent messages, in order to tell you what is unread, what is important, or what arrived from someone. A message's body is read only when you ask about that specific message, and only the part needed to answer.
  • Other connected apps: the minimum data the request requires, described in the App before you connect each one.

Connected-app data is used only to carry out the request you made. It is not stored on our servers beyond what is needed to complete that request, is never used to build a profile of you, and is never used for advertising. You can disconnect any app at any time in the App's Settings, which revokes our access.

3.4 Device and usage information

To run and improve the Service we collect limited technical information: a random device identifier the App generates, the App version, your device model and operating system version, crash reports and performance measurements (for example how long a request took), and error logs. Logs are structured so that the content of your requests, transcripts and connected-app data is excluded from them.

3.5 Website information

When you visit the Site our hosting provider records standard server logs (IP address, browser type, pages requested, timestamps) for security and to keep the Site running.

We measure how the Site is used with Vercel Web Analytics, which is cookieless. It stores nothing on your device, sets no cookies of any kind, and uses no third-party tracking. A visit is counted using a hash derived from the incoming request, that hash is discarded after 24 hours, and no IP address is stored against a measurement. We record four things and nothing else: that a page was viewed, that someone put the cursor in the waitlist field, that someone joined the waitlist, and that someone clicked the confirmation link. Your email address is never sent to it, and the address bar is stripped of any token before a measurement is sent.

Because the Site sets no cookies and does not track you across other sites, there is no cookie banner and nothing for you to consent to.

3.6 Purchases

Subscriptions are sold through the Apple App Store. Apple processes your payment; we never receive your card number. We receive a receipt identifier and the status of your subscription so that we can unlock what you paid for.

3.7 Information we do not collect

We do not collect precise location, contacts lists, photos, health data, or advertising identifiers. We do not create voiceprints or any biometric template. We do not record calls or ambient audio.

4. How we use information

Purpose What we use Legal basis (EEA/UK)
To provide the Service: understand your request and carry it out in the app you connected Voice, requests, connected-app data, account information Performance of a contract
To operate the waitlist and let you know when you can install the App Waitlist information Consent, which you can withdraw at any time
To respond when you contact us Messages to us Legitimate interests (answering you)
To keep the Service secure, prevent abuse and enforce fair use Device and usage information, account information Legitimate interests (security)
To fix problems and improve reliability Crash reports, performance measurements, error logs Legitimate interests (a working product)
To see whether the Site explains the product well enough that people join Anonymous, aggregated page and event counts described in Section 3.5 Legitimate interests (running a website), with no cookie and nothing that identifies you
To bill subscriptions Purchase information Performance of a contract
To comply with law Any of the above, as required Legal obligation

We do not use your personal information for advertising, we do not sell it, and we do not use it to train machine-learning models. We do not make decisions about you by automated means that have legal or similarly significant effects.

5. Voice, biometrics and recordings

This section restates, as a commitment, what Sections 3.2 and 3.7 describe technically.

  • We never create, collect, store or use a voiceprint, speaker embedding, or any other biometric identifier or biometric information, as those terms are used in laws such as the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act, the Washington biometric privacy law, and the GDPR's special categories.
  • We never attempt to identify who is speaking. The App recognises what was said, not who said it.
  • We never clone, synthesise or imitate your voice.
  • We do not keep recordings of your voice. Audio captured after the wake word exists only as long as it takes to transcribe it.

6. Who we share information with

We share personal information only with the service providers below, only to the extent needed for the purpose stated, and under contracts that require them to protect it and forbid them from using it for their own purposes.

Provider What they do for us What they receive
Deepgram Speech recognition and text-to-speech Audio of your request after the wake word; name hints; the text of replies. Zero data retention, no training on your data.
OpenAI Language understanding (which action you meant) and, for some questions, composing an answer from connected-app data The text of your request; the minimum connected-app data the question needs. Zero data retention, no training on your data.
Google Sign-in and the Google apps you choose to connect (Calendar, Gmail and others) Our requests to your Google account, made with your authorisation and within the scopes you granted
Apple Sign in with Apple, App Store purchases, TestFlight distribution Your Apple account interactions with the App; purchase status
Railway Hosting of our servers and database Server-side data described in this Policy, at rest in the United States
Vercel Hosting of the Site, and cookieless usage measurement (Vercel Web Analytics) Site traffic and server logs; anonymous, aggregated counts of the four events described in Section 3.5, with no cookie and no identifier that persists beyond 24 hours
Resend Sending email we send you (for example waitlist confirmation) Your email address and the content of the message we send

We may also disclose information: to comply with law or a valid legal process; to protect rights and safety, including to enforce our Terms and prevent fraud or abuse; and in a business transfer, such as a merger or acquisition, in which case this Policy will continue to apply to your information until it is amended and you are notified.

We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the preceding twelve months.

7. Google API Services: Limited Use

The App's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular:

  • We use Google user data only to provide and improve the user-facing features you asked for, and never to serve advertising.
  • We do not transfer Google user data to third parties except as necessary to provide those features (for example to the speech and language providers listed in Section 6, under zero-retention terms), to comply with law, or as part of a business transfer with notice to you.
  • Humans do not read your Google user data unless you have given us explicit permission for a specific message, it is necessary for security or to comply with law, or the data has been aggregated and anonymised.
  • We do not use Google user data to train generalised artificial-intelligence or machine-learning models.

8. How long we keep information

Information Kept for
Wake-word audio (before the wake word) Not kept. Processed in memory on the device and discarded.
Request audio (after the wake word) Not kept by us. Processed by the speech provider to produce a transcript under zero-retention terms.
Request text and connected-app data used to answer For the duration of the request. Not stored on our servers afterwards.
Session history (what you asked, what was answered) On your device only. Deleted automatically after 30 days; deletable by you at any time.
Account information Until you delete your account, then deleted within 30 days except where law requires longer.
Waitlist information Until you unsubscribe or ask us to delete it, or 24 months after the App becomes generally available, whichever is sooner.
Messages to us Up to 24 months, so we can follow up.
Server logs and diagnostics Up to 90 days.
Purchase records As long as required for accounting and tax law.

9. Security

We protect information with encryption in transit (TLS), encryption at rest for data we store, access controls that limit who at Memoquid can reach production systems, per-request authorisation so that one user can never reach another's data, rate limiting, and logging that excludes the content of your requests. Provider keys never ship in the App. No method of transmission or storage is completely secure, and we cannot guarantee absolute security; if we learn of a breach affecting your personal information we will notify you and any regulator as the law requires.

10. Your rights and choices

Depending on where you live you may have some or all of the following rights. We honour them for everyone, regardless of location, where we reasonably can.

  • Access the personal information we hold about you and receive a copy.
  • Correct information that is inaccurate.
  • Delete your information. Deleting your account in the App deletes what we hold; session history is on your device and deleted with the App or from Settings → History.
  • Port your information in a machine-readable format.
  • Restrict or object to certain processing, including any processing based on legitimate interests.
  • Withdraw consent at any time where processing is based on consent, without affecting processing before withdrawal. You can leave the waitlist from any email we send.
  • Not be discriminated against for exercising any of these rights.
  • Appeal a decision we make about a request, by replying to our response.
  • Complain to a supervisory authority. In the EEA that is the authority in your country; in the UK, the Information Commissioner's Office; in the US, your state attorney general.

To exercise a right, use the controls in the App's Settings or email contact@memoquid.com. We will verify that a request comes from you, which may mean asking you to confirm from the email address on your account. An authorised agent may make a request on your behalf if they provide proof of your authorisation. We respond within the time the applicable law requires, and in any case within 45 days.

Do Not Track and Global Privacy Control. The Site does not track you across other websites, so there is nothing for these signals to switch off; we treat a Global Privacy Control signal as a request to opt out of any sale or sharing, which we do not do in any case.

California residents. The categories of personal information we collect, the purposes, and the recipients are described in Sections 3, 4 and 6. We do not sell or share personal information, and we do not use or disclose sensitive personal information for purposes other than providing the Service. You have the rights to know, delete, correct and to non-discrimination described above.

11. International transfers

We are based in the United States and our providers process information there and in other countries. Where we transfer personal information from the EEA, the UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) with the receiving provider, or on that provider's participation in the EU-US Data Privacy Framework, and on supplementary measures such as encryption.

12. Children

The Service is not directed to children under 13, or under 16 in the EEA and UK, and we do not knowingly collect personal information from them. If you believe a child has provided us information, email contact@memoquid.com and we will delete it.

13. Third-party services

Connected apps and the platforms you reach through the Service (for example Google, Apple, Slack, Spotify) have their own privacy policies, which govern their handling of your information. We encourage you to read them. We are not responsible for the privacy practices of third parties.

14. Changes to this Policy

We will update this Policy as the Service changes. When we do we will change the effective date above, and if a change materially affects how we handle your information we will tell you in the App or by email before it takes effect. Your continued use of the Service after the effective date means you accept the updated Policy.

15. Contact

Questions, requests and complaints about this Policy or your information: contact@memoquid.com. We answer every message.