This policy explains what Memoato stores, the privacy modes available in the app, the service providers involved, and the controls available to you.
Privacy modes
- Cloud sync — data is stored normally to power history, views, and multi-device access.
- Encrypted cloud — category titles and per-entry notes are encrypted on your device before saving to the database. You unlock them with a passphrase on each device.
- Local-only — data stays on the device in IndexedDB. Switching to local-only wipes server data for that account.
If you lose the encrypted-cloud passphrase, Memoato cannot recover the encrypted content. Local-only data may be lost if browser storage is cleared or the device is lost.
Data we store
- Account details such as email and username.
- Your categories, including names, emoji, colors, goals, and display preferences.
- Your raw logs and derived entries, including values, timestamps, notes, and linked context.
- Scoped API key metadata; API key secrets are stored hashed rather than as readable values.
Data you control
- You can edit and delete entries.
- You can export your data from Profile.
- You can revoke API keys.
- You can delete your account and associated logged data.
Analytics
Memoato may use privacy-friendly analytics on the public memoato.com website. Authenticated application pages do not load third-party analytics scripts.
Service providers
- Hetzner for production application and database hosting.
- Cloudflare for DNS, caching, and networking.
- Zoho SMTP for transactional verification and password-reset email.
- Databuddy for public website analytics only.
- AI processing providers when cloud-assisted extraction is enabled for a raw entry.
Emails
Memoato sends transactional account emails. We do not currently send marketing email.
Contact
Privacy questions and data requests can be sent to [email protected].