MEMARO Privacy Policy

Effective Date: 7 September 2026 · Last Updated: 7 September 2026

1. Introduction

This Privacy Policy explains how MEMARO collects, uses, stores, protects and otherwise processes personal data when you use the MEMARO mobile application, website and related services (collectively, the “Services”). MEMARO is designed as a personal application for storing memories, experiences and related content. We aim to process personal data lawfully, fairly and transparently and in accordance with Regulation (EU) 2016/679 (“GDPR”), applicable Polish data-protection law and applicable Google Play requirements.

2. Who Is the Data Controller?

The data controller responsible for the processing described in this Privacy Policy is the operator of MEMARO:

MSCOJ / MEMARO
Os. Armii Krajowej 70/6
61-139 Poznan, Poland
Email: support@memaroatlas.app

For purposes of this Privacy Policy, “MEMARO”, “we”, “us” and “our” refer to the operator of the MEMARO Services. Before publication, the legal name above should be replaced, if necessary, with the exact registered legal name shown in the relevant Polish business register. The same legal name should be used consistently in the MEMARO website, Terms of Service and Google Play developer information.

3. What Personal Data We Process

Depending on how you use MEMARO, we may process the following categories of personal data:

CategoryExamplesWhy processedTypical basis
Account dataEmail address, authentication/account identifiers, account settingsCreate and maintain your account; authenticate you; provide the ServicesPerformance of contract
Profile dataInformation you choose to add to your MEMARO profilePersonalize your experience and provide requested featuresPerformance of contract; consent where applicable
User ContentMemories, life events, notes, descriptions, dates, places, relationships and other information you choose to store in MEMAROStore, organize, display and otherwise provide the Services you requestPerformance of contract
Technical dataIP address, device/browser information, app version, operating system, diagnostic and security information where availableSecurity, troubleshooting, service operation and abuse preventionLegitimate interests; legal obligation where applicable
Support dataInformation you provide when contacting supportRespond to requests, troubleshoot problems and maintain service recordsPerformance of contract; legitimate interests; legal obligation where applicable

We do not intentionally request special-category personal data for ordinary use of MEMARO. However, because MEMARO is a personal memory application, you may voluntarily enter information that could reveal sensitive or special-category information about yourself or other people. Please consider carefully what you choose to store.

4. User Content and Personal Memories

MEMARO is designed to store personal memories and life information. User Content may therefore contain personal data about you and, potentially, information about family members, friends or other individuals.

You remain responsible for the information you choose to upload or enter. Where User Content contains personal data relating to another person, you should only provide that information where you have a lawful basis to do so.

We process User Content only to provide, operate, maintain, secure and improve the MEMARO Services, to provide features you request, and where necessary to comply with legal obligations. We do not sell your User Content.

We do not use your personal memories or User Content to train general-purpose AI models unless we first provide an appropriate disclosure and obtain any consent required by applicable law.

5. Why We Use Personal Data

  • To create and manage your MEMARO account.
  • To authenticate you and maintain account security.
  • To store, organize, display and synchronize the User Content you choose to save in MEMARO.
  • To provide personalization and account settings requested by you.
  • To provide customer support and respond to your communications.
  • To maintain, secure, troubleshoot and improve the Services.
  • To detect, prevent and investigate fraud, abuse, security incidents and unauthorized access.
  • To comply with legal obligations and respond to lawful requests from competent authorities.
  • To establish, exercise or defend legal claims where necessary.

6. Legal Bases Under the GDPR

Depending on the particular processing activity, we rely on one or more of the following legal bases under Article 6 GDPR:

  • Performance of a contract (Article 6(1)(b)) — for processing necessary to provide the Services and manage your account.
  • Legal obligation (Article 6(1)(c)) — where processing is necessary to comply with applicable law.
  • Legitimate interests (Article 6(1)(f)) — for security, fraud prevention, service reliability, troubleshooting, defending legal claims and other legitimate operational purposes, where our interests are not overridden by your rights and freedoms.
  • Consent (Article 6(1)(a)) — where we specifically ask for consent and consent is the appropriate legal basis. You may withdraw consent at any time; withdrawal does not affect processing carried out before withdrawal.

We do not rely on consent where another lawful basis is appropriate.

7. Authentication and Account Security

MEMARO currently supports account authentication using the mechanisms made available in the application. Your authentication information is used to establish and secure your account.

Where authentication is provided through a third-party provider, the provider may process information according to its own privacy policy. We will update this Privacy Policy before introducing additional authentication methods where the change materially affects the processing of personal data.

You are responsible for keeping your account credentials confidential and should notify us promptly if you believe your account has been accessed without authorization.

8. Third-Party Service Providers

MEMARO uses selected technology and infrastructure providers to operate the Services. These providers may process personal data on our behalf where necessary to provide their services.

The current MEMARO FREE production architecture includes third-party cloud/backend infrastructure and authentication services. Where a provider acts as our processor, we require appropriate contractual and technical safeguards consistent with applicable data-protection law.

We do not include a provider in this Privacy Policy merely because MEMARO was developed or hosted using that provider’s development platform. A provider will be listed as a recipient where its services actually involve processing personal data from MEMARO users.

A current provider list and any material changes will be reflected in this Privacy Policy before or when the relevant functionality is introduced.

MEMARO does not use third-party advertising networks in the MEMARO FREE application unless this Privacy Policy and the applicable in-app disclosures are updated to describe such processing.

9. Payments and Future Paid Features

The MEMARO FREE application is intended to provide its free functionality without requiring users to provide payment-card details directly to MEMARO.

If MEMARO introduces paid subscriptions or in-app purchases in the future, payment processing may be provided by Google Play or another authorized platform. The relevant processing, subscription information and applicable privacy disclosures will be updated before paid functionality is introduced.

10. Sharing of Personal Data

We do not sell your personal data.

We may disclose personal data only where necessary and lawful, including:

  • To service providers and processors that help us operate MEMARO.
  • To authentication, hosting, infrastructure, security, support or other technology providers where necessary to provide the Services.
  • To competent public authorities where required by law.
  • To legal advisers, auditors or other professional advisers where reasonably necessary to protect our rights or comply with legal obligations.
  • In connection with a merger, acquisition, restructuring or transfer of the relevant business, subject to applicable law and appropriate safeguards.

We do not disclose your personal memories to advertisers for advertising purposes.

11. International Transfers

Some service providers may process personal data outside the European Economic Area (EEA). Where personal data is transferred outside the EEA, we will use a lawful transfer mechanism under Chapter V GDPR, such as an applicable European Commission adequacy decision or, where appropriate, Standard Contractual Clauses and supplementary measures.

The European Commission has established modern Standard Contractual Clauses as one of the mechanisms that can provide safeguards for transfers of personal data to third countries.

You may contact us at support@memaroatlas.app to request further information about applicable transfer safeguards, subject to legal restrictions.

12. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law.

  • Account data is generally retained while your MEMARO account remains active.
  • User Content is generally retained while it remains stored in your account or until you delete it, subject to the deletion and backup rules described below.
  • Support and technical records may be retained for as long as reasonably necessary to resolve issues, maintain security, defend legal claims or comply with legal obligations.
  • Certain information may be retained after account deletion where necessary for legal, security, fraud-prevention, accounting or other legally permitted purposes.

Where data is no longer required, we will delete it, anonymize it or otherwise securely dispose of it in accordance with our retention practices.

13. Account Deletion and Data Deletion

You may request deletion of your MEMARO account and associated personal data through the account-deletion function provided in the application.

We intend to provide an external account-deletion request mechanism on the MEMARO website so that users can initiate account deletion without using the application. This external mechanism will be made available at a publicly accessible MEMARO web address before Google Play publication.

When we receive a valid deletion request, we will delete the account and associated personal data unless we are legally required or permitted to retain particular information. Data that must be retained for legal, security, fraud-prevention or dispute-resolution purposes will be retained only for the necessary period and will be protected from further use where appropriate.

Deleted data may remain temporarily in encrypted backups until the applicable backup-retention cycle expires.

14. Your Rights Under the GDPR

Subject to applicable legal conditions and limitations, you may have the following rights:

  • Right of access — to obtain confirmation as to whether we process your personal data and, where applicable, a copy of that data.
  • Right to rectification — to correct inaccurate or incomplete personal data.
  • Right to erasure — to request deletion of personal data in circumstances provided by law.
  • Right to restriction — to request restriction of processing in circumstances provided by law.
  • Right to data portability — where applicable, to receive personal data in a structured, commonly used and machine-readable format.
  • Right to object — to object to processing based on legitimate interests or other grounds where the GDPR provides this right.
  • Right to withdraw consent — where processing is based on consent.
  • Rights concerning automated decision-making — where applicable under the GDPR.

To exercise your rights, contact support@memaroatlas.app. We may need to verify your identity before completing a request.

15. Response Times

We will normally respond to a valid GDPR rights request within one month. Where permitted by GDPR, this period may be extended by up to two additional months because of the complexity or number of requests. If an extension is required, we will inform you within the applicable initial period.

We generally do not charge a fee for exercising your rights. We may charge a reasonable fee or refuse a request where permitted by law, for example where requests are manifestly unfounded or excessive.

16. Right to Complain to a Supervisory Authority

You have the right to lodge a complaint with a competent data-protection supervisory authority if you believe that our processing of your personal data infringes applicable data-protection law. In Poland, the competent supervisory authority is the President of the Personal Data Protection Office (Urząd Ochrony Danych Osobowych — UODO).

17. Children's Privacy

MEMARO is not intended to encourage children below the minimum age permitted under applicable law to create accounts or provide personal data independently. We do not knowingly collect personal data from children where collection is prohibited without appropriate parental or guardian involvement.

If you believe that a child has provided personal data to MEMARO in circumstances where this was not permitted, please contact us at support@memaroatlas.app so that we can assess the situation and take appropriate action.

18. Data Security

We implement appropriate technical and organisational measures designed to protect personal data against unauthorized access, accidental loss, destruction, alteration or disclosure.

These measures may include access controls, authentication safeguards, encryption in transit, restricted access to personal data and monitoring or other security measures appropriate to the risks.

No internet-based service can guarantee absolute security. You should also protect your account credentials and use a secure device and network.

19. Cookies and Website Technologies

The MEMARO website may use strictly necessary technologies required for website operation, security and basic functionality. If we introduce non-essential analytics, advertising cookies or similar tracking technologies that require consent under applicable law, we will provide the appropriate notice and consent mechanism before using them.

20. Changes to This Privacy Policy

We may update this Privacy Policy when our Services, data-processing practices, legal obligations or security measures change.

We will update the “Last Updated” date and, where required by applicable law, provide additional notice of material changes.

21. Contact Us

For privacy questions, data-protection requests or account/data-deletion requests, please contact:

MSCOJ / MEMARO
Os. Armii Krajowej 70/6
61-139 Poznan, Poland
Email: support@memaroatlas.app
Website: https://www.memaroatlas.app
Privacy Policy: https://www.memaroatlas.app/privacy-policy

22. Effective Date and Last Updated

Effective Date: 7 September 2026

Last Updated: 7 September 2026