Legal

Privacy Policy

Last updated: 4 September 2026

MemFrog is a personal networking memory: it helps you remember the people you meet. This policy explains what personal data we collect, why, who we share it with, and what rights you have under the EU General Data Protection Regulation (GDPR) and Slovenian data-protection law. It covers the memfrog.com website, the web app at app.memfrog.com, the billing portal at my.memfrog.com, the MemFrog iOS and Android apps, and the public card and photo pages we host.

1. Who is responsible

The data controller is Inoqube d.o.o. (registration no. 9804056000, VAT ID SI21298190), Celovška cesta 150, 1000 Ljubljana, Slovenia. For anything privacy-related, email quack@memfrog.com. We don't have a data protection officer; the law doesn't require one at our size.

2. What we collect

Your account

Your name, email address and profile photo (if you sign in with Google or Apple, they pass these to us), your sign-in method, and your plan. Firebase, our sign-in provider, handles passwords; they don't reach our servers.

What you save about the people you meet

Contact details (name, company, title, email, phone and WhatsApp number, LinkedIn URL, website, where you met), profile photos and selfies, business-card images, voice recordings and their transcripts, typed notes, AI summaries, attachments, and how you organise people (spaces, tags, roles, Pond tiers, and a log of when you last met, called or messaged them).

Imported from your phone

In the mobile app you can import contacts from your address book. The app reads the address book on your device to show a picker and uploads nothing until you pick people and tap Import. Then we save their name, company, job title, first phone number and first email address.

Your digital business card

Whatever you put on it (name, title, company, photo, logo, contact methods) plus a view count. Card pages are public: anyone with the link or QR code can see them.

Billing

If you subscribe on the web, Stripe processes your payment; we store your Stripe customer and subscription IDs and your plan status, and not your card number. If you subscribe in the app, Apple or Google process the payment and RevenueCat tells us whether your subscription is active, on which platform, and for which product.

Device, usage and logs

The mobile app reports its platform, app version and OS version once per session. Our servers keep standard request logs (IP address, timestamps, endpoints called) for security and debugging. On the website and web app we use Google Analytics to count page views and key actions such as sign-ups, contact additions and upgrade clicks. We also record why you signed up (on your own, from a shared photo link, or from a scanned card) in a short-lived first-party cookie.

Emails

We send a welcome email, email verification, password reset and change-of-email messages, and, if a visitor asks, a copy of a business card. We don't send marketing email unless you opt in.

On your device

The mobile app keeps an offline copy of your contacts, and of any changes you make while offline, on your device, so MemFrog works at events with bad reception. The app clears it when you sign out, and uninstalling removes it.

3. People who aren't MemFrog users

Contacts saved by our users. If a MemFrog user has saved your details, that user is the controller of the data and we process it on their instructions alone. We don't use it to contact you or for anything of our own. If you'd like to know what a user holds about you, or want it deleted, ask them; if you can't reach them, email us and we'll help.

Visitors to a card page. If you scan someone's card and choose to share your details back, we save what you enter (and a selfie, if you take one) as a contact in that person's account. If you ask us to email you the card, we send that one email and don't keep your address for anything else. If you download the card as a contact file, we store nothing. These pages use Cloudflare Turnstile to check you're human, and Turnstile may process your IP address and browser signals.

Photo links. Anyone with a photo link sees the selfie and the name of the person who shared it. Links expire after 365 days.

Invite links. If you sign up through someone's invite link, we add their business card to your contacts so you can find them, unless they've turned that off.

4. Why we use your data and on what basis

  • To provide MemFrog (storing your network, syncing across devices, running the AI features you trigger, hosting your cards and photo links, sending account emails): performance of our contract with you.
  • To bill you and keep the records the law requires: contract and legal obligation.
  • To keep the Service secure (logs, rate limits, abuse prevention on public pages, fraud checks): our legitimate interest in running a safe service.
  • To see how people use MemFrog and improve it (analytics, sign-up attribution): our legitimate interest, or your consent where the law requires it for cookies.
  • To send you product news: with your consent alone, which you can withdraw any time.

5. AI processing

Some features send your content to AI providers, and they do so when you use the feature and for that purpose alone. Business-card and name photos go to Anthropic (Claude) to read the text. Voice notes and dictation go to Soniox for transcription. Your notes and transcripts go to Anthropic to write a summary or answer an Ask question. A short profile text per contact (no emails, phone numbers or links) goes to OpenAI to compute the embeddings behind Ask's search. Our agreements with these providers bar them from training models on your data, and we don't train any model on it either.

6. Who we share data with

We share personal data with the service providers that help us run MemFrog, and with no one else, and each one gets what it needs and no more. We don't sell personal data or share it with advertisers.

ProviderWhat it doesWhere
HetznerHosts our application servers and databaseEU
Google FirebaseSign-in (email/password, Google, Apple) and session tokensEU / US
CloudflareStores files (R2, EU jurisdiction) and checks visitors are human (Turnstile) on public card pagesEU / US
AnthropicReads business cards and names from photos, writes note summaries, answers AskUS
SonioxTranscribes voice notes and dictationUS
OpenAIComputes the text embeddings behind Ask's semantic searchUS
StripeWeb subscription payments, invoices and the billing portalEU / US
RevenueCatReports subscription status for App Store and Google Play purchasesUS
Apple, GoogleProcess in-app purchases (we don't see card details)EU / US
Mailtrap (Railsware)Delivers the emails we send (welcome, verification, password reset, card emails)EU / US
MapboxSuggests places when you type where you met someone (sees the text you type, nothing else)US
Google AnalyticsAggregated usage analytics for the website and the web appEU / US

Our application servers and database run on Hetzner in the European Union, and we take encrypted backups every day. We may also disclose data if the law requires it, to protect our rights or users' safety, or as part of a merger or acquisition (this policy keeps applying in that case).

7. International transfers

Several providers above are in the United States. Where data leaves the EU/EEA we rely on the European Commission's Standard Contractual Clauses and, for providers certified under it, the EU-US Data Privacy Framework. Email us if you'd like a copy of the safeguards in place.

8. How long we keep data

  • Your account and network: for as long as your account exists. When you delete your account (Settings → Account), we erase your contacts, notes, media, cards and profile from our database and file storage at once, revoke your sessions, and delete your login and your record at RevenueCat. We keep daily backups for 7 days, so a copy can linger in a backup for up to 7 days after deletion.
  • Photo links: 365 days from creation, then they stop working.
  • Billing records: we keep invoices and payment records for as long as Slovenian tax and accounting law requires (10 years at present); most of them sit with Stripe.
  • Server logs and analytics: we keep logs for a short period for security. Google keeps Analytics data for up to 14 months, in aggregated form.

9. Your rights

You can access, correct, export, restrict or delete your personal data, object to processing based on our legitimate interests, and withdraw consent at any time. Most of this you can do yourself in the app (edit or delete anything, delete your account). For the rest, email quack@memfrog.com; we answer within a month. You can also complain to a supervisory authority. Ours is the Information Commissioner of the Republic of Slovenia (Informacijski pooblaščenec), Dunajska cesta 22, 1000 Ljubljana, ip-rs.si, and you can also go to the authority where you live.

10. Security

We encrypt all traffic in transit (TLS). Cloudflare encrypts stored files at rest, and our servers run in ISO 27001-certified data centres. We serve files through short-lived signed links, not from public buckets. The few people who run MemFrog are the only ones with access to production data, and human verification and rate limits guard the public endpoints. No system is watertight; if we find a breach that puts your data at risk, we'll tell you, and the authority, as the law requires.

11. Cookies

We use a session cookie to keep you signed in on the web, a short-lived cookie that remembers how you found us (so we know which growth loops work), and Google Analytics cookies on memfrog.com and app.memfrog.com. We don't use analytics cookies to build advertising profiles. You can block them in your browser or with Google's opt-out add-on; MemFrog works without them. The mobile apps don't use cookies.

12. Children

MemFrog is for people aged 16 and over. We don't set out to collect data from children; if you think a child has an account, email us and we'll remove it.

13. Changes

If we change this policy in a way that affects you, we'll email you or tell you in-app before it takes effect. The date at the top shows the last revision.

14. Contact

For any privacy question or to exercise your rights, email quack@memfrog.com or write to Inoqube d.o.o., Celovška cesta 150, 1000 Ljubljana, Slovenia. See also our Terms of Service.