The Privacy
Policy.
Memoora is built on a foundation of radical privacy. We believe your memories are your own, and our technology should serve as a vault, not a window.
Last updated: September 15, 2026
Data Controller
The data controller for your personal data is Xavi Martín Salat (Spanish tax ID/NIF 53025878E), owner of Memoora, with registered address at París 7, BJ 5, 08110 Montcada i Reixac, Barcelona, Spain. You can contact him at hello@memoora.app for any privacy-related queries. Data processing is governed by Regulation (EU) 2016/679 (GDPR) and applicable Spanish data protection law (LOPDGDD). Memoora acts as data controller for your account and memory data, and as data processor for personal data of third parties (family members, friends) that you introduce into the platform.
Data We Collect
We collect only what is strictly necessary to provide the service: (1) Account: name, email address, and encrypted password (never stored in plain text). (2) Profile: optional profile photo. (3) Content: texts, photos, audio, videos and documents you add as memories; these may contain data about third parties. (4) AI interactions: text or audio fragments sent to OpenAI to generate responses, voice synthesis or transcriptions. (5) Payments: billing data managed entirely by Stripe; Memoora never stores card data. (6) Technical: session tokens and activity logs required for security. (7) Preferences: your marketing communications consent status.
Purposes and Legal Basis
We process your data for: account management and authentication (Art. 6.1.b GDPR — contract); memory storage and retrieval (Art. 6.1.b); AI processing, TTS and STT (Art. 6.1.b); welcome email and transactional notifications (Art. 6.1.b); payment processing and tax obligations (Art. 6.1.b and 6.1.c); marketing communications only with your consent (Art. 6.1.a — withdrawable at any time); aggregated measurement of website use and performance through Vercel Analytics and Vercel Speed Insights, and optional analytics through Metricool only with your consent where required (Art. 6.1.a); social media advertising via Meta Pixel only with your explicit consent (Art. 6.1.a).
Providers and International Transfers
We share data only with the providers necessary to deliver the service: Supabase, Inc. — database and file storage; the primary region depends on the project configuration and transfers are governed by its DPA. OpenAI, Inc. (USA) — text, audio and voice processing; API data is not used to train models, although abuse monitoring logs may be retained for up to 30 days by default depending on the endpoint and retention settings. Vercel, Inc. — hosting, Vercel Analytics and Vercel Speed Insights; transfers and retention depend on the service configuration and its DPA. Stripe Payments Europe Ltd. and its affiliates — payments, subscriptions, billing and taxes; international transfers, including to the USA, may occur under its DPA. Resend, Inc. (USA) — transactional email, audience contacts and marketing automations; its DPA provides for deletion of customer data from the service within 90 days after account termination, except where legally required. Metricool Software, S.L. — optional analytics with consent. Meta Platforms, Inc. (USA) — optional advertising with consent. We do not sell, rent or share your data with third parties for commercial purposes.
Data Retention and Your Rights
We retain your data for as long as your account is active and for legally required periods (up to 5 years for tax obligations). When you request account deletion, we delete account data and associated content during the deletion process, except where required by law. Backups, technical logs and data retained by providers may remain for their own retention periods. As a data subject you have the right to: access, rectification, erasure ('right to be forgotten'), objection, portability, and restriction of processing. Email hello@memoora.app to exercise any right (we respond within 30 days). You may lodge a complaint with the Spanish Data Protection Authority at www.aepd.es.
Special Data, Third Parties and Minors
Special categories: Your memories may contain health information, religious or political beliefs, or biometric data (photos with faces). Memoora treats this exclusively as user-provided content, without additional analysis. Third-party data: By uploading content about family members or others, you take responsibility for having a lawful basis under GDPR; Memoora acts as data processor for such content. Images: stored without any biometric processing. Minors: the service is exclusively for users aged 18 and over. Digital legacy: in the event of the account holder’s death, data remains available for 3 years from last activity. Cookies: essential (no consent needed), Metricool (with consent) and Meta Pixel (with consent).
Your Control, Your Narrative
Privacy is not a legal footnote — it is the foundation of Memoora. If you have any questions about how we handle your data, write to us at hello@memoora.app. We are here to answer clearly and without jargon.

