日本語English
Privacy policyTerms of service

Privacy Policy

Last updated: October 7, 2026

In case of any discrepancy, the Japanese version prevails.

Memen (the “Service”) is a service run by an individual, in which invited people keep a record of their own daily life and look back on it. This page explains, exactly as implemented, what the Service records, what it does not record, and where it sends data.

1. Three founding policies

  • Recordings of conversations never leave your device. Transcription runs entirely on the device, and only the resulting text is sent to the server (the server-side audio endpoint was retired on August 17, 2026). There is exactly one exception. Your own voice used for voice enrollment (about 30 seconds) is stored only if you choose so, and only after being encrypted on your device. The decryption key exists only on your devices, so the operator cannot listen to it. (“Voice enrollment” in Section 2)
  • We do not take screenshots. From the screen we take only text such as window and tab names.
  • Not a single byte of screen content read by the ad-hiding feature (Android accessibility service) is stored or sent. It is used on the spot only to find and cover ad slots, then discarded. It is treated as separate from the recording features and is never mixed with them.

2. Information we collect

The apps on your devices (iPhone / Mac / Android) record only within the features you have turned on and the permissions you have granted to the OS.

TypeContents
AccountThe email address and display name obtained through Google sign-in. A key that identifies you is derived from the email address.
App usageApp name, package name or bundle ID, window title, titles of open browser tabs, and start and end times. On Mac we also record the browser URL (not collected on Android).
TranscriptsConversation text generated on the device, speaker labels (A / B / C…), the name of the speech recognition model used, and timestamps. Audio files are not included.
Voice enrollment (encrypted)Only if you choose “store encrypted” when enrolling “my voice”, the passage you read aloud (about 30 seconds) is stored after being encrypted on your device, so that you can use it on another device or after an app update without enrolling again. The decryption key is kept only on your devices and is never sent to the server (on another device, you enter the “recovery code” shown on screen). All the operator can see is the encrypted data, a fingerprint of the key (not the key itself), the length of the voice, and the date and time. The “voiceprint” (a numeric representation of voice characteristics) stays only on your device, as before, and is never sent.
LocationLatitude, longitude and movement state (still, walking, vehicle, etc.) while you allow the location permission.
Domains visitedHost names seen through on-device DNS (e.g. example.com) and the app in the foreground at the time. URL paths and query strings cannot be obtained. Off by default; recorded only when you turn it on in settings.
Things you writeTODOs, daily notes, weekly reviews, manual memos, and Pomodoro intervals.
Screen time limitsLimit settings (target apps, caps, release waiting time, etc.) and usage time counted on the device. On iPhone, you pick the apps and sites to limit in the iPhone Screen Time interface, and that selection and the usage time stay on the iPhone only (what is sent is only the group name, domains you typed, time ranges, caps and the content of the commitment).
Notification address (iPhone)The notification address (a per-device value issued by Apple) used to switch iPhone limits immediately when you start a Pomodoro on Mac or in the browser. It is not used for notifications shown on screen.
Events and work logsOnly if you set up the integration: Google Calendar events (name, start and end times, color) and Toggl work logs. Toggl is read-only. We write to Google Calendar only when you add, change or delete an event on the time-boxing screen.
DiagnosticsError details when recording or speech recognition fails (to trace causes without opening your device).

3. What we do not collect

  • Recordings or video of conversations themselves (they do not leave your device; the voice enrollment exception is, as described in Section 2, stored only in encrypted form that the operator cannot listen to)
  • Screenshots or images of the screen
  • Screen content read through accessibility
  • Contacts, call history, SMS, photos
  • Payment information (the Service has no billing mechanism)

4. How we use it

  • To show it back to you (timeline, hourly breakdown, weekly review, search)
  • To pass to generative AI (LLM) for summarization and classification (details in Section 5)
  • To investigate and fix problems. The operator may check operating status and database rows.

We do not use it for advertising delivery. We do not sell or provide it to third parties in a form that identifies you.

5. Information passed to generative AI (LLM)

To create hourly summaries and summaries of recorded conversations, part of your records is sent to an external generative AI. This is the widest extent to which data leaves the Service.

What is passed

  • The transcript text for the relevant period, with speaker labels (A / B / C…)
  • Display names of apps and browser tabs, with their usage minutes and times
  • Classification options (the list of genres you have edited)

What is not passed

  • Location
  • Domains visited, browser URLs
  • The text of TODOs, notes and weekly reviews
  • Account information such as email address and name
  • Audio files (this includes encrypted voice enrollment, which is not passed because even the operator cannot decrypt it)

Destination

The summarization worker runs on a free-tier virtual machine on Google Compute Engine (United States) and sends prompts to OpenAI’s service through the Codex CLI. In other words, conversation transcripts and the display names of apps and tabs are sent to a generative AI provider in the United States. Handling at the destination (retention period, whether data is used for training) follows that provider’s terms.

Anything beyond 1,200 characters per item and 24,000 characters in total per run is not sent. This worker does not connect to the database and handles only the text it is given.

6. Storage locations and transfer abroad

WhatWhere
DatabaseSupabase (PostgreSQL / Tokyo region)
Web appGoogle Cloud Run (Tokyo region)
Summarization workerGoogle Compute Engine (US region)
Generative AIOpenAI (United States)

The records themselves are stored in a database in Japan, but what is described in Section 5 is transferred to the United States.

7. Provision to third parties

We do not provide or sell your data to third parties without your consent. To the extent necessary for operation, we use the following providers.

  • Google Cloud (running the web app, the summarization worker’s virtual machine, and storing secrets)
  • Supabase (database)
  • OpenAI (summarization and classification; the scope in Section 5)
  • Google (sign-in; reading the calendar if you set up the integration; and writing events you operate on)
  • Toggl (only if you set up the integration; read-only)

This does not apply where disclosure is required by law.

7-2. Handling of Google user data

For the Google Calendar integration, we request only the following two permissions (scopes) from your Google account. They do not allow creating or deleting calendars themselves or changing sharing settings.

PermissionUse
calendar.events
(view, create, change and delete events)
Read to show your Google Calendar events in the left (planned) column of the time-boxing screen. Only when you add, change or delete an event on this screen do we reflect that single event in Google Calendar. We never rewrite events without your action.
calendar.calendarlist.readonly
(read the calendar list and colors)
Read to give you the list for choosing which calendars to show, and to paint events in the same colors as Google Calendar.
  • Google user data we obtain (event names, times, colors, calendar names) is used to show you the time-boxing screen and to create the plan-versus-actual comparison and daily and weekly reports. It is not used for advertising and is not sold or provided to third parties.
  • As described in Section 5, event names and times may be passed to generative AI as material for daily and weekly summaries. They are not used to train generative AI or to develop models.
  • The operator reads the content of events only when needed to investigate a problem (Section 8).
  • Memen’s use of information received from Google APIs, and its transfer to other apps, adheres to the Google API Services User Data Policy, including the Limited Use requirements.
  • You can disconnect at any time. Revoke the permission from “Third-party access” in your Google account, or ask us at the contact in Section 14, and we will delete the stored Google tokens and the events imported from the calendar.

8. Separation between users, and what the operator can see

All users’ records are in one database, separated by the per-row user_id and PostgreSQL row-level security (RLS). The app connects only with a dedicated role, and from that role only your own rows are visible.

However, the operator, who holds database administrator privileges, can technically view the records. The Service is a personally operated, invitation-only service; please use it with this in mind. The encryption that makes data unreadable even to the operator is used for voice enrollment only (Section 2). For other records we have no mechanism that makes them unreadable to the operator.

9. Retention and deletion

  • Records are kept until you delete them (there is no automatic expiry).
  • When you leave the Service, we delete the rows tied to you in all tables (including encrypted voice enrollment) and the full-text search index.
  • You can delete encrypted voice enrollment at any time with “Delete stored voice” in the app settings. If you lose the recovery code and every device holding the key, even the operator cannot restore it (please enroll again).
  • Backups retain pre-deletion data for up to 7 generations. It disappears as generations rotate out. Backups are encrypted with public-key encryption (age), and the decryption key is not kept on the server.
  • In the iPhone app you can leave at any time from Settings → Delete account (this deletes everything in the scope above, and also removes the sign-in information).
  • To request disclosure, correction or deletion of your records, contact us at the address in Section 14.

10. Security measures

  • Communication between devices and the server, and between the server and the database, is encrypted with TLS.
  • Only email addresses approved in advance can sign in.
  • Database connections are limited to a role to which row-level security applies.
  • Backups are encrypted with public-key encryption, and processing stops if encryption fails.

11. Recordings that include other people’s voices

Recordings of conversations also capture the voices of people other than you. Obtain the consent of the people present before recording. Recording can be paused. Please use the Service in a way that lets you explain to those present that the transcribed content is passed to generative AI as described in Section 5.

12. Permissions requested on devices

Each is requested only when you use the relevant feature. If you decline, other features remain usable.

iPhone

  • Microphone / Speech recognition … recording conversations (transcribed on the iPhone; audio is not sent) and voice enrollment (stored encrypted, only if you choose)
  • Location / Motion … recording departures, movement and arrivals (only when turned on in settings)
  • Screen Time … limits on the apps and sites you choose. The chosen apps and usage time do not leave the iPhone
  • Notifications … reminders to look back on records, and receiving focus start and end

Mac

  • Microphone / Screen and audio capture … recording conversations (transcribed on the Mac)
  • Accessibility / Automation … recording the foreground app, window and browser tab
  • Administrator privileges (first time only) … the resident component for screen time limits and site blocking

Android (development halted)

  • Microphone … recording conversations (transcribed on the device)
  • Location … recording movement
  • Usage access … recording app usage time, and screen time limits
  • Notifications … a persistent indicator that recording is in progress
  • Accessibility … screen time limits (closes a limited app or site when it comes to the foreground)
  • VPN … on-device blocking of sites and ads. It does not connect to any external VPN server, and the content of traffic does not leave the device

13. Revisions

When we change this policy, we will update this page and rewrite the last-updated date. When items we record or destinations increase, we will make the difference clear before and after the update.

  • October 7, 2026: Your own voice used for voice enrollment is now stored, only if you choose, after being encrypted on your device (Sections 1, 2, 8 and 9). Until then we stated that “audio itself does not leave the device”; this is unchanged for recordings of conversations.

14. Contact

For disclosure, correction or deletion of your records, or any other inquiry, please email:

bizkaiki@gmail.com

Back to Memen