MemoryProof home Track your brain health Start your free month

Privacy Notice

Last updated 6 October 2026

The short version

To use MemoryProof, you need an account. Your check-ins, tags, sleep data, lab values and settings are stored on your device and on our own server (hosted by Cloudflare), under your account. We use them to run MemoryProof — and, only if you agree, to improve our tests and analyses. We never sell your data and never share it with advertisers, data brokers or social networks such as Facebook, and we use no advertising or analytics trackers. MemoryProof is for people aged 16 and over, in every country.

What we collect

For your account: your email address, a scrambled (hashed) form of your password — never the password itself — whether you have confirmed your email address, your subscription status and, for each purchase of a membership, the plan, the price and the date (on our website also your confirmation that you are 18 or older, and when you gave it), the country you created your account from (read from your internet connection), your confirmation that you are 16 or older, and which version of our terms you agreed to, and when. If you buy a membership in the iPhone or Android app: from Apple or Google we receive which store it was, the plan, the transaction or order number (for Google Play also the purchase token), the amount and currency, the purchase date, when the paid period ends, any grace period, whether it renews, any refund or cancellation, and whether it was a test purchase — never your name, email address or payment details. We need this to give you your membership under our contract with you (GDPR Art. 6(1)(b)) and keep it until you delete your account. Apple ads: outside the EU, the EEA, Switzerland and the UK, when you install the iPhone app, Apple tells us whether one of our ads in the App Store brought you — and if one did, which campaign, ad group and search word it belonged to and the campaign's country. If no ad brought you, we record only “no ad”. Apple tells us nothing that identifies you. We store this with your account to count which ads bring people and how many of them buy a subscription (our legitimate interest in knowing which ads work); it is never shared. Until you create your account, the answer stays on your phone. Your data: your check-in scores, daily logs, tags, supplement experiments, sleep ratings, sleep data from Oura if you connect it (each night's sleep score, sleep time and stages, heart rate, heart rate variability, and readiness score), sleep from Apple Health if you connect it in the iPhone app, or from Health Connect if you connect it in the Android app (for each night: time asleep, deep and REM sleep, and time in bed), lab values you add (value, unit, date, the lab's range and flag, and your note), the kind of device each test was done on (phone, tablet or computer; touch or mouse; app or browser), and your settings. It is kept on your device and on our server. Your full name stays on your device; only your initials are sent to our server. To protect sign-in from abuse, our server also keeps a short-lived counter linked to your internet (IP) address, which deletes itself within minutes. If you send feedback: your message, whether we may reply by email, and the app version, language, kind of device and screen size sent with it. For reminders: see “Reminders” below. If you withdraw from a purchase: when you did it, the plan, when you bought it and the name you give, to handle your refund (a legal obligation). If you cancel or withdraw on our website: the email address and name you enter, what you declare (for a cancellation: the kind, the end you ask for and your reason, if you give one), when you sent it, and whether we found a subscription or purchase — to carry it out and confirm it to you by email (a legal obligation). Against misuse, our server counts these requests per email address (in a scrambled form) and per internet (IP) address; the counts delete themselves within two days. If no account has that email address, we keep nothing but the confirmation email until it is sent.

What we use it for

To run MemoryProof: to keep your data safe and let you use it on more than one device. To help improve MemoryProof — only if you agree: we look at the data of everyone who has agreed — check-ins, tags, experiments, sleep data and lab values — labelled with initials, never with your name or email address, for example to check and improve how the check-ins and charts work. You choose when you create your account and can change it at any time under You ▸ Your data. For the library: votes and supplement suggestions you send are stored on our server to decide what the library covers next (our legitimate interest). We never use your data for advertising and never sell it.

Why — your legal basis

Your check-in scores, sleep data and lab values are health-related data. We process them only with your explicit consent: to store check-ins and sleep data — including the check-ins already on your device — when you create your account; to use them to improve our tests and analyses, only if you tick that separate box or switch it on later under You ▸ Your data; for lab values, when you first add one; and for reading a lab-report photo, when you first use it. If you're 16 or 17, you give these consents yourself. You can withdraw your consent at any time — for helping improve MemoryProof with the switch under You ▸ Your data, otherwise by deleting the data or your account. We use your email address to run your account (our contract with you, GDPR Art. 6(1)(b)) and to send you confirmation codes, password-reset links, a confirmation of each purchase in the iPhone or Android app made outside the EU, and a reminder 40 days before a yearly plan renews. Unless you said no, we also send you a weekly email (legal basis: our legitimate interest in keeping you informed about your own use of MemoryProof, GDPR Art. 6(1)(f); for sending it by email, EU ePrivacy Directive Art. 13(2)): every Sunday evening in your time zone, saying on how many days you did a check-in that week, whether new insights are waiting in Trends (never what they are), and the title of one entry from the evidence library. In Poland, the UK, Austria and Switzerland, we send it only if you said yes (your consent). Every weekly email has a link that stops it, and you can switch it off under You ▸ Reminders. We send occasional product emails only if you opt in. We keep your feedback messages to answer them and improve the app (our legitimate interest). Withdrawing your consent doesn't affect what we did with your data before. To protect sign-in from abuse (the short-lived counter linked to your IP address), we rely on our legitimate interest in keeping accounts safe. You don't have to give us any data — but without an account and your check-ins, MemoryProof can't work. We make no automated decisions about you that have legal or similarly significant effects: the comparisons in the app are calculations shown only to you.

Who we share it with

We don't sell or rent your data and don't share it with advertisers or analytics companies. A few service providers handle data only to run MemoryProof for us: Cloudflare hosts the app and our server, where your data is stored; it also runs the AI model that reads a lab-report photo when you ask for that (see “Lab values and photos”); and it sends our emails, such as confirmation codes, password-reset links and the reminders you choose (it receives your email address and the message). On our website, you buy your membership from us; Stripe (Sold through Link, LLC) handles the payment and the VAT, under its own privacy policy (it receives your email address and payment details, never your check-ins). In the iPhone and Android apps, Apple (App Store) and Google (Google Play) handle the payment under their own privacy policies: they receive your payment details, we never do. We give them only a random code that links the purchase to your account (for Google, in a scrambled form) — never your email address, name or results. If you email us, Cloudflare forwards your email to our mailbox at Google (Google Workspace), which stores it for us (see “If you email us”). If you connect Oura, your sleep data passes through our server on its way from Oura to your device, and your sleep data from Oura is then stored with the rest of your data. It is never passed to any AI tool.

Lab values and photos

Lab values you add are stored like the rest of your data: on your device and on our server, under your account. MemoryProof shows them back to you as entered and never interprets them. If you use “Read from a photo”, the photo goes to our server and is read by an AI model run by Cloudflare (Workers AI). The photo is not stored after reading and is not used to train any AI model; only the values you confirm are saved. Sleep data from Oura is never sent to any AI model.

Apple Health

If you connect Apple Health in the iPhone app, MemoryProof reads only your sleep and never writes anything to Apple Health. Your sleep from Apple Health is stored like the rest of your data — on your device and on our server, under your account — and shown to you next to your check-ins. Only if you agreed to “Help improve MemoryProof” is it part of our analyses too, labelled with initials only. It is never used for advertising or marketing, never sold, never shared with anyone else and never sent to any AI model. You can end MemoryProof's access at any time in Apple Health's settings.

Health Connect

If you connect Health Connect in the Android app, MemoryProof reads only your sleep and never writes anything to Health Connect. Your sleep from Health Connect is stored like the rest of your data — on your device and on our server, under your account — and shown to you next to your check-ins. Only if you agreed to “Help improve MemoryProof” is it part of our analyses too, labelled with initials only. It is never used for advertising or marketing, never sold, never shared with anyone else and never sent to any AI model. You can end MemoryProof's access at any time in Health Connect's settings.

How long we keep it, and where

We keep your data until you delete it or your account. Deleting your account removes your server copy, your feedback messages and your reminder settings straight away; the sign-in counter linked to your IP address deletes itself within minutes. Stripe keeps payment records for as long as tax law requires; Apple and Google keep their own records of purchases in the apps. If you withdraw from a purchase or cancel a subscription, we keep a record of it for as long as tax and consumer law require — also after you delete your account. Cloudflare, Stripe, Google and Apple are US companies and may handle data outside the EU and UK; this is protected by the EU–US Data Privacy Framework or the EU Standard Contractual Clauses (and the UK equivalents).

What the app stores on your device

MemoryProof keeps your data and settings in your browser's storage on your device, so the app works — even offline — and you stay signed in, plus a copy of the app's own files for offline use. Nothing else: no cookies for tracking or advertising. Only while you connect Oura, our server sets a short security cookie that expires after 10 minutes at the latest. All of this is needed for the app to work, which is why there is no cookie banner.

Our website, memoryproofapp.com

Our website loads nothing from other companies, sets no cookies, uses no trackers and saves nothing in your browser's storage. Cloudflare hosts it and, to deliver its pages and protect it against attacks, technically processes your IP address and browser details; we rely on our legitimate interest in a website that works and is safe. We keep no logs of these visits ourselves; Cloudflare keeps its network logs for as long as it needs them for that purpose, under its data processing agreement with us. If you create your account on the website, its sign-up form sends our server your email address, a scrambled (hashed) form of your password — never the password itself — your choices on the form and the page's language. If you arrive through a link with a campaign code, we store that code with your account so we can count which posts bring people and how many of them buy a membership (our legitimate interest in knowing which posts work). No trackers. The website doesn't ask for your name; the name you can add in the app stays on your device.

If you email us

Emails to hello@memoryproofapp.com are forwarded by Cloudflare to our mailbox at Google (Google Workspace), which stores them for us under its data processing terms. We use your email only to answer you and to follow up on your request (our legitimate interest), and keep it for as long as that takes.

Reminders

The daily reminder is off until you switch it on. The weekly email is on unless you ticked “No weekly email” at sign-up (in Poland, the UK, Austria and Switzerland: off until you switch it on). For accounts created before 30 September 2026, the weekly email stays off unless you switched it on. You can switch both off at any time under You ▸ Reminders; the email also has a one-tap stop link. They never mention your results. For the weekly email we keep your time zone, so it arrives on Sunday evening your time, the week it last went out, and a mark the app sets when new insights are waiting in Trends — the email says only that something is new, never what. For the daily reminder we keep, for each device, the push address your browser gives us, the reminder time (the one you chose, or your usual check-in time), your time zone and language, and on which days a reminder went out. It is delivered by your device's own push service (for example Apple, Google, Mozilla or Microsoft), which sees only that our server sends your device a message, and when — never the text, which is encrypted. In the iPhone and Android apps, your phone plans and shows the daily reminder itself: no push address is created and no push service is involved. To decide whether to send it, our server looks only at which days you did a check-in, never at your scores.

Your rights (GDPR)

Any time, you can export all your data, delete your account and its server copy, and erase everything on your device — all under You. You also have the right to access and correct your data, to take it with you, to restrict or object to how we use it, and to complain to your data protection authority.

If you live in the United States

Some US states — for example Washington (My Health My Data Act), Nevada and Connecticut — give you extra rights over your consumer health data. The consumer health data we collect: your check-in scores, tags, sleep data, lab values, and the comparisons the app works out from them (see “What we collect”). We get it from you, and from Apple Health, Health Connect or Oura if you connect them. We use it only for the purposes described above and let only the service providers named above handle it. We never sell it. You can ask us to confirm whether we hold your consumer health data, to see it together with a list of every company that received it and how to contact them, and to delete it — we then also have it deleted by our service providers. You can withdraw your consent at any time by deleting your data or your account in the app. We answer requests within 45 days. If we turn down a request, you can appeal by replying to our answer; we decide within 45 days, and if you still disagree you can contact your state's Attorney General. After a data breach we tell you and, where the law requires, the US Federal Trade Commission. In the iPhone and Android apps, where a US state law requires it, the app asks Apple or Google for your age group. The app uses the answer only for this check and never stores or sends it. If you're 16 or 17 there, you use MemoryProof with a parent's consent given through the App Store or Google Play. The app then links your Apple or Google account to your MemoryProof account, so that we learn if a parent withdraws their consent. We keep only this link (for Google, in a scrambled form) and, if a parent withdraws their consent, when that happened and when they agreed again. When you delete your account, the link goes with it; a withdrawal stays with the Apple or Google account for up to 400 days, so that a new MemoryProof account there stays locked too. We do all this to follow that state's law (our legitimate interest, GDPR Art. 6(1)(f)).

If you live in Canada

The person in charge of protecting your personal information is Simon Bechtel, owner of Simon Bechtel Engineering (hello@memoryproofapp.com). Your data is stored on Cloudflare's worldwide network and handled by the service providers named above, so also outside Canada and outside Quebec, for example in the United States and the EU. There, courts, police and security agencies can get access to it under local law. You can ask to see or correct your data, withdraw your consent, and receive your data in a common file format, for yourself or for another company; the export under You ▸ Your data gives you all of it at once. We answer within 30 days. If you have a complaint, write to us first. You can also complain to the Office of the Privacy Commissioner of Canada or, if you live in Quebec, to the Commission d'accès à l'information du Québec.

Security & breaches

Account data is encrypted in transit and at rest. If a breach ever occurred we would notify affected users and the relevant authority as the law requires.

Contact

MemoryProof is run by Simon Bechtel Engineering, ul. Kolejowa 43/279, 01-210 Warszawa, Poland. Questions or requests: hello@memoryproofapp.com, or Send feedback in the app.

See also: Our values · Terms