Legal
Privacy Policy
Effective 3 September 2026
Memo is an iOS app developed and operated by Talgat Kussainov, a sole proprietor. In this policy, “Memo”, “we” and “us” mean that business. The policy covers the app “Memo” on the App Store (listed as “Memo - AI Summarize, Recorder”, App Store ID 6450138660) on iOS 26 and later, and the website withmemo.app. It explains what we collect, what stays on your iPhone, who processes your data, how long we keep it and how you can delete it. It takes effect on 3 September 2026 and replaces the privacy policy previously published on the xrlab.ai website.
The promise in one sentence: with On-device AI, nothing leaves your phone; with Cloud AI, your audio is uploaded to produce the transcript and summary, and the app asks before every upload.
The two ways Memo processes audio
Memo can process a recording with one of two engines. You choose for each recording, and the app tells you what will happen to the audio before it happens.
With On-device AI, Memo transcribes with Apple’s speech model and summarises with Apple Intelligence. The audio, the transcript, the summary and any chat about the memo stay on your iPhone. Nothing is uploaded to Memo or to anyone else, and we never see it. On-device AI works without an account. It is available on iPhones that support Apple Intelligence, with Apple Intelligence turned on, and in the languages Apple supports.
With Cloud AI, Memo uploads the audio file to our backend, where it is transcribed and summarised by the providers listed under “Who processes your data” below. The audio and the results are stored in your account until you delete them. Cloud AI requires signing in with Apple or Google. The app asks before every upload. It works on every iPhone that runs iOS 26 and in more than 99 languages.
If you only ever use On-device AI, Memo’s servers hold none of your audio, transcripts or summaries.
What we collect
Account
You can use Memo without an account. In that case an anonymous Firebase user ID is created on your device. It identifies the installation and is not linked to your name or e-mail address. On-device AI works in this state. Cloud AI requires signing in.
When you sign in with Apple or Google, Firebase Authentication creates your account. We store your user ID, your e-mail address and your name if the sign-in provider shares it. We do not receive your password.
Audio, transcripts and summaries
With On-device AI, your audio, transcript, summary and chat are stored only on your iPhone. We never receive them.
With Cloud AI, the audio file is uploaded to Memo’s backend, which runs on Google Cloud Storage and Firebase Firestore in the us-central1 region in the United States. Memo’s Cloud Functions send the audio to Replicate, which transcribes it with an open-source Whisper model. If that transcription fails, the audio is sent to OpenAI instead. The transcript is then sent to OpenAI to produce the summary and the title. The audio, the transcript, the summary and the title are stored in your account so that you can open the memo on your phone.
Your audio and text are used only to produce your results. We do not use them to train AI models. The providers’ own terms apply while they process the data.
Chat
You can ask questions about a memo. If the memo was processed with On-device AI, the chat runs on your iPhone and nothing is sent anywhere. If you choose Cloud AI for chat, your question and the text of the memo are sent to OpenAI to produce the answer, and the conversation is stored with the memo in your account.
Onboarding preferences
When you first open Memo, it asks what you mostly record, which language your memos are in and whether Memo should extract tasks from them. Your answers are stored in your profile and are used to set defaults in the app.
Purchases
Memo Pro is billed by Apple through your Apple ID. We do not receive your payment details. To check what you are entitled to, the app sends the App Store receipt and your Memo user ID to RevenueCat, which manages entitlements for us. We store the entitlement state, that is whether Memo Pro is active and when it expires, next to your user ID.
Analytics, attribution and crash reports
We use Firebase Analytics and Amplitude to understand how Memo is used, for example which features are opened and where people stop. These events are keyed by Memo’s own user ID, not by an advertising identifier. Crash reports are collected through Firebase so that we can find and fix bugs.
We use Adjust to learn which campaign an install came from. How this works depends on the version of Memo you have.
- Versions up to 1.102, including the version on the App Store when this policy took effect, ask your permission to track through Apple’s App Tracking Transparency prompt. If you allow it, Adjust receives your device’s advertising identifier (IDFA) to attribute the install. If you decline, no advertising identifier is used. You can change your choice at any time in iOS Settings under Privacy and Security, then Tracking.
- From version 2.0, Memo does not show that prompt and does not use any advertising identifier. Adjust receives attribution only through Apple’s SKAdNetwork, which tells advertisers how a campaign performed without identifying you or your device. From version 2.0, Memo does not track you across other companies’ apps or websites.
The data types declared in Memo’s App Store privacy label for version 2.0 are purchase history, user ID, e-mail address, name, audio data, product interaction, user content (not linked to your identity) and crash data. None of them is used for tracking.
Notifications
If you allow notifications, the app registers a Firebase Cloud Messaging push token so that we can tell you when a Cloud AI memo is ready. Notifications are optional. You can turn them off at any time in iOS Settings.
Shared memo links
You can share a memo as a link on withmemo.app. When you do, the memo’s title, emoji and summary, and the transcript if you choose to include it, are stored on Memo’s servers and are visible to anyone who has the link. The audio is not shared. The page stays available until you revoke the link in the app. Shared pages are not indexed by search engines, but anyone who receives the link, directly from you or forwarded by someone else, can read it. You are responsible for what you share.
The website
withmemo.app sets no cookies and runs no analytics or tracking scripts. The site, including shared memo pages, is served by Firebase Hosting, a Google service. Like any web server it records requests, including the IP address and the page requested, in server logs that Google keeps for a limited period for security and operations. We do not use these logs to identify visitors.
Support requests
If you e-mail support@withmemo.app, we keep your message and our replies so that we can answer you and follow up if needed. We keep support e-mails for a reasonable period after the request is closed and then delete them.
Who processes your data
Memo runs on services from the providers below. Each receives only what it needs for its task.
| Provider | What it does for Memo | What it receives | Where |
|---|---|---|---|
| Google (Firebase and Google Cloud) | Authentication, database, file storage, Cloud Functions, analytics, crash reports, push notifications | Account details, Cloud AI audio, transcripts, summaries and chat, onboarding preferences, entitlement state, push token, usage events, crash reports | United States (region us-central1) |
| OpenAI | Summaries, titles and chat answers for Cloud AI; transcription when Replicate fails | Cloud AI audio (fallback transcription only), transcripts, memo text and chat questions | United States |
| Replicate | Primary transcription for Cloud AI with an open-source Whisper model | Cloud AI audio | United States |
| RevenueCat | Subscription entitlements | App Store receipt and your Memo user ID | United States |
| Amplitude | Product analytics | Usage events keyed by your Memo user ID | United States |
| Adjust | Install attribution | SKAdNetwork data; in versions before 2.0, the advertising identifier only if you allowed tracking | Germany |
| Apple | App Store billing, Sign in with Apple, on-device speech recognition and Apple Intelligence | Billing and sign-in are handled by Apple under Apple’s own terms; speech recognition and Apple Intelligence run on your iPhone and send nothing to Memo | On your iPhone for speech and Apple Intelligence; Apple’s systems for billing and sign-in |
These providers process data only to provide their service to Memo. We do not use your audio or text to train AI models. While a provider processes your data, its own terms apply to that processing.
How we use your data
We use your data to:
- provide the service: record, transcribe, summarise, chat with, export and share your memos;
- keep your account and store your Cloud AI memos in it;
- check your Memo Pro entitlement and apply the free tier limits;
- notify you when a Cloud AI memo is ready;
- understand how Memo is used and fix crashes;
- answer your support requests.
We do not sell your data.
Legal bases
Where the law requires a legal basis for processing, for example in the EU and the UK, we rely on the following.
- Contract. Providing the service you asked for, keeping your account, storing your Cloud AI memos and billing Memo Pro.
- Legitimate interests. Understanding how Memo is used, fixing crashes, keeping the service secure and preventing abuse. We keep this processing to what a user would reasonably expect.
- Consent. Where the law requires it, for example the App Tracking Transparency prompt in versions before 2.0 and push notifications. You can withdraw consent at any time in iOS Settings. Withdrawing it does not affect processing that happened before.
Retention and deletion
- Cloud AI memos, including the audio, transcript, summary and chat, are kept in your account until you delete the memo or your account.
- To delete a memo, delete it in the app. To delete everything, open Settings in the app and choose Delete account. This removes your account, its memos and its audio files.
- On-device AI data stays on your iPhone until you delete the memo or the app. We cannot delete it for you because we never receive it.
- Server logs are kept for about 30 days, the standard Google Cloud logging retention.
- Analytics and crash data are kept for the default retention period of each provider.
- Shared memo links stay available until you revoke them in the app.
- Support e-mails are kept for a reasonable period after the request is closed.
International transfers
Memo’s backend and most of the providers above process data in the United States. Adjust processes data in Germany. If you live in the EU, the UK or another place whose law restricts transfers abroad, we rely on standard contractual clauses or equivalent safeguards where the law requires them.
Security
- Every request to Memo’s backend carries your Firebase identity token, so the backend knows which user is asking.
- Storage and database rules restrict each user to their own data. One user cannot read another user’s memos.
- Firebase App Check attests that requests come from the genuine Memo app.
- Data travels over TLS. Google Cloud encrypts it at rest.
No system is completely secure. If you believe your account has been accessed without permission, or you have found a security problem, e-mail support@withmemo.app.
Children
Memo is not directed at children under 13, or under 16 where the law sets that age, for example in the EU. We do not knowingly collect personal data from children below that age. If you believe a child has given us personal data, e-mail us and we will delete it.
Your rights
Depending on where you live, you have the right to:
- access the personal data we hold about you;
- correct it if it is wrong;
- delete it;
- receive a copy in a portable form;
- object to, or ask us to restrict, certain processing;
- withdraw consent you have given;
- complain to a supervisory authority.
You can do most of this yourself in the app. Export a memo by copying it, sharing it, saving it as a PDF, printing it or downloading the audio from the memo menu. Delete a memo in the app, or delete your account and everything in it from Settings. Turn notifications off in iOS Settings. In versions before 2.0, change your tracking choice in iOS Settings under Privacy and Security, then Tracking.
For anything else, e-mail support@withmemo.app. We may ask you to confirm that you own the account before we act. We respond within the time the applicable law requires.
If you live in the European Economic Area or the United Kingdom, you have these rights under the GDPR and the UK GDPR, and you can complain to your national data protection authority. If you live in California, you have the rights to know, delete and correct your personal information and not to be discriminated against for exercising them; we do not sell or share your personal information as those terms are defined in California law. If you live in the United Arab Emirates, you have rights under the UAE Personal Data Protection Law, including access, correction, deletion and objection. Residents of other places may have similar rights under their own laws. Wherever you live, write to the same address and we will apply the rights that your law gives you.
We do not sell personal data.
Changes to this policy
We will update this policy when Memo changes, for example when we add a feature or change a provider. The date at the top of this page shows when the current version took effect. If a change is significant, we will tell you in the app before it takes effect.
Contact
Memo is developed and operated by Talgat Kussainov, a sole proprietor. For questions about this policy or your data, e-mail support@withmemo.app. Help with the app is at /support. Our Terms of Use are at /terms.