Memura

Privacy Policy

IT · EN

Last updated: June 8, 2026

The short version: your memories are encrypted on your device and saved to your personal cloud — Google Drive if you sign in with Google, iCloud (CloudKit Private Database) if you sign in with Apple. We never see them. The only external processing happens through AI APIs, forwarded by a proxy (Cloudflare Worker) that does not retain content, at the moment you create a memory.

1. Data Controller

The data controller is Matteo Palmieri, based in Mondragone (CE), Italy ("the Controller").

For any privacy-related question you can contact the Controller at: legal@memuraapp.it

2. Data We Collect

2.1 Authentication data

To use the app you choose between two authentication methods: Google Sign-In (available on iOS and Android) or Sign in with Apple (available on iOS only). The two methods are mutually exclusive: each user is associated with a single identity provider.

2.1.a Google Sign-In

If you sign in with Google, the Controller receives the following data from Google:

2.1.b Sign in with Apple

If you sign in with Apple, the Controller receives the following data from Apple:

In addition, to comply with Apple's account-revocation requirement, the backend (Cloudflare Worker) receives server-to-server notifications from Apple when the user revokes consent to Memura from their Apple ID settings or deletes the Apple ID itself. Such notifications contain only your anonymous Apple identifier and a timestamp, no content. On the next launch the app detects the revocation, deletes all local data and returns you to the login screen.

None of the authentication data, regardless of the provider, is stored on Memura servers. The claims (sub, email, name) remain on your device to derive the encryption key and identify your cloud container; tokens are kept in memory or in the Keychain, never sent to backends operated by the Controller (the Cloudflare Worker verifies token signatures statelessly, without storing them).

2.2 Your memories (app content)

The text, extracted entities and metadata of your memories are your personal content. A single principle applies to this data, regardless of the authentication provider:

2.3 Data transmitted to the AI service

When you create a memory or ask a question inside the app, the text is temporarily transmitted — in unencrypted form — to the AI service for processing:

Requests do not hit the AI API directly from your device: they are routed through a stateless proxy implemented as a Cloudflare Worker (edge compute), which merely forwards the request to the AI provider and authenticates it by verifying your token signature (Google or Apple). The Worker does not persist or log content of memories or queries.

Regarding AI API keys, Memura adopts a hybrid Bring Your Own Key model:

The AI provider does not retain requests beyond the limits set out in its own terms of service. We encourage you to read the privacy notices of Google and Cloudflare.

2.4 Optional integrations (on-demand access)

Memura can access certain external sources on your device to enrich AI responses. All these integrations are optional, require your explicit consent through the operating system's native prompt and can be revoked at any time from the app or device settings.

A single principle applies to all of them: access is always on-demand. The content read is never saved in the Controller's databases or in your personal cloud: it stays at the source and is used only when needed to formulate a response, then discarded from memory.

2.4.a Google Calendar

If you sign in with Google and authorize the calendar OAuth scope, the app reads your Google Calendar events to provide context to the AI and, optionally, to create events from memories with a future date. Access is read/write limited to the primary calendar. When an AI feature requires calendar context, the relevant event details may be transmitted to the AI provider as described in section 3. You can revoke consent at myaccount.google.com/permissions.

2.4.b Apple Calendar and Reminders (EventKit, iOS only)

On iOS, regardless of the authentication provider, the app can access your Apple Calendar and Reminders through the system framework EventKit. The framework is initialized only after your explicit consent through the iOS prompt. The data read stays on the device: it does not transit via the Worker, does not reach Memura servers, and is passed to the AI model only if relevant to your current request. You can revoke at any time from Settings → Privacy & Security → Calendars / Reminders → Memura.

2.4.c Contacts

If you authorize access to the operating system Contacts, the app uses names to disambiguate the people mentioned in your memories (e.g. distinguishing "Marco" the colleague from "Marco" the brother). Only the minimum necessary is read (first and last name); phone numbers, emails and other fields are never collected. Contacts are not duplicated in a Controller archive. You can revoke from Settings → Privacy & Security → Contacts → Memura (iOS) or from the application settings (Android).

2.4.d Photos (iOS, on-device processing)

On iOS, if you authorize access to the Photos library, the app can analyze the metadata and text present in images (e.g. text on signs, faces of the people involved, ticket dates) to enrich the context of a memory. The analysis is performed entirely on your device through Apple's Vision and Core ML frameworks: no image is sent to Memura servers, to the Cloudflare Worker or to the AI provider. You can revoke from Settings → Privacy & Security → Photos → Memura.

2.4.e Microphone (voice dictation)

If you use voice input, the audio is transcribed by a speech-recognition model running entirely on your device. The audio is never saved or sent to external servers: only the transcribed text is stored as memory content. You can revoke microphone access from the operating system settings.

2.5 Diagnostics and analytics data

To improve the stability and quality of the app, the Controller uses Google LLC's Firebase services. Enabling each service requires your explicit consent (toggle in the app settings, off by default). Without consent, no diagnostics data is collected.

The data is processed by Google according to the Firebase Privacy Policy. Firebase Analytics and Crashlytics never have access to the text of your memories, to the content of your AI queries or to the images in your Photos library, nor to any data obtained through the Google APIs.

3. Sharing and Transfer of Google User Data

This section explicitly summarizes with whom Memura shares, transfers or discloses the data obtained through your Google Account — that is, the data received through Google Sign-In and the Google Drive and Google Calendar APIs.

Memura does not sell your Google data and does not use it for advertising purposes. The data obtained from the Google APIs is handled as follows:

The third parties (sub-processors) that may process the data obtained through the Google APIs are exclusively the following:

Memura does not share, transfer or disclose the data obtained through the Google APIs to any other party, except as may be required by law or for security purposes. In particular, the diagnostics services (Firebase Analytics and Firebase Crashlytics) never receive data obtained through the Google APIs.

4. Limited Use of Google API Data

Memura's use and transfer of information received from the Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

In compliance with these requirements, Memura:

Memura's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

5. Purposes and Legal Bases of Processing

6. Data Retention

Memories remain in your personal cloud (Google Drive or CloudKit iCloud) until you delete them.

Diagnostics and analytics data (Firebase Analytics and Crashlytics, if enabled by the user) is retained by Google according to the service's default retention — typically up to 14 months for analytics events and up to 90 days for crash reports — in aggregated or pseudonymous form.

7. International Data Transfers

The AI API (Google Gemini) and the Cloudflare Worker proxy may process data in transit on servers in the United States and Europe. Firebase Analytics and Crashlytics process data on Google's globally distributed infrastructure. These transfers take place in compliance with the safeguards provided by the GDPR (Standard Contractual Clauses or United States adequacy decisions — EU-U.S. Data Privacy Framework).

The data saved in CloudKit remains within the iCloud infrastructure of your Apple ID, managed by Apple Inc. according to the Apple Privacy Policy, and is not replicated elsewhere by the Controller.

8. Your Rights (GDPR)

As a data subject you have the right to:

To exercise your rights, write to legal@memuraapp.it. You also have the right to lodge a complaint with the supervisory authority of your country (in Italy: Garante per la protezione dei dati personali).

9. Security

Your memories are protected by AES-256-GCM encryption with a key derived on the device and wrapped per device: each installation keeps its own encrypted copy of the master key, stored in the iOS Keychain or Android Keystore. The local database is encrypted with SQLCipher. The app supports access with Face ID, Touch ID or PIN.

The content stored in the CloudKit Private Database is accessible exclusively to your Apple ID and, on the Controller's side, is always encrypted before upload: even Apple, while hosting the blob, cannot read the content. The same applies to data in the Google Drive Application Data Folder.

No user data — neither in clear text nor encrypted — transits or resides on servers directly operated by the Controller. The only server-side component under the Controller's control is the Cloudflare Worker proxy, which verifies token signatures and forwards AI requests statelessly, without logging content.

10. Minors

The app is not intended for persons under 13 years of age. The Controller does not knowingly collect data from minors. If you believe a minor has used the app, contact the Controller to have the data deleted.

11. Changes to the Privacy Policy

Any material changes to this notice will be communicated through an in-app notice. The updated version will always be available at this address.

12. Contact

legal@memuraapp.it