How MemoryApp handles account, gameplay, analytics, monitoring, and billing data.
This Privacy Policy explains what information we collect when you use MemoryApp, where it is stored, which service providers handle it, and what privacy rights may apply to you. This policy reflects all data collection, monitoring, analytics, and third-party integrations currently active in the product. If local law gives you stronger protections than this policy, those protections control to the extent required.
What this policy covers.
This policy applies to the public website, account system, dashboard, gameplay features, blog articles, testimonials collection, analytics dashboards, billing flows, error monitoring, support channels, and related communications for MemoryApp.
For privacy-law purposes, the MemoryApp operator acts as the controller for the personal data described here, except where a third-party provider acts as an independent controller for its own services and legal obligations.
What we collect.
- Account and identity data such as email address, password credentials managed by Supabase Auth, and unique username.
- Authentication and session data such as access tokens, login state, email-confirmation state, and password-reset state.
- Profile details you choose to add, including display name, avatar URL, birth date, gender identity, country or region, primary language, occupation, focus goal, dominant hand, and time zone, stored as flexible profile context data.
- Subscription and billing records such as plan selected (monthly, annual), subscription status, renewal or expiry state, trial state, payment event identifiers, coupon usage, payment amount, currency, payment failure reasons, and related audit records.
- Gameplay and progress data such as game history, scores, reaction times, streaks, level reached, cognitive progress metrics across five cognitive dimensions (working memory, pattern recognition, visual reasoning, processing speed, spatial memory), and other performance metrics generated through use of the product.
- Game performance records such as best round, best score, total plays per game, and last played timestamp.
- Daily activity data such as session counts and XP earned per day for retention and engagement tracking.
- Testimonial and feedback data such as name, email, role, rating (1-5 scale), testimonial content, publication consent, reward status, and submission timestamp from users who voluntarily submit testimonials.
- Admin activity and audit trail data such as admin actions, actor role, entity types modified, before/after state snapshots, and reason for changes made by administrative users.
- Support and communications data such as the content of messages you send to support, billing, or partnership inboxes.
- Device, browser, and technical data that may appear in routine logs, security monitoring, or error telemetry, including approximate technical environment information, crash reports, error messages, performance metrics, browser type, operating system, IP address, and session replay data captured by Sentry when monitoring is enabled.
- Sentry monitoring data including error stack traces, breadcrumbs (user actions leading to errors), performance data, browser environment details, and session replays captured at different sample rates (20% for general performance, 5% for normal sessions, 100% on error).
- Rate limiting and API abuse prevention data such as request counts per IP address or user ID used to enforce rate limits on public endpoints.
- Local browser data such as theme preference, certain gameplay progress caches, and temporary session information stored in browser storage on your device.
- Blog and content interaction data such as article views, reading time, and article engagement metrics for SEO and content optimization purposes.
What we do not intentionally collect.
- We do not intentionally collect full payment card numbers, card CVV values, or bank account credentials. Payment entry is handled by Razorpay.
- We do not ask users to submit medical records, diagnoses, or treatment information through normal product flows.
- We do not intentionally sell personal data in exchange for money.
- We do not use behavioral advertising cookies or third-party ad tracking pixels by default.
Where the information comes from.
- Directly from you when you create an account, update profile details, use the games, request support, submit testimonials, or submit billing questions.
- Automatically from your use of the service, such as score events, session state, security events, technical diagnostics, and performance data.
- From error and performance monitoring when Sentry captures crashes, errors, performance metrics, and session replay data during app usage in production.
- From service providers involved in authentication, hosting, payment processing, error monitoring, and analytics, such as Supabase, Razorpay, Sentry, and Vercel.
Why we process personal data.
- To create and secure your account, sign you in, confirm your email, reset your password, and maintain session continuity.
- To deliver the core service, including gameplay, progress tracking, cognitive insights, leaderboard rankings, and subscription-gated access.
- To process payments, verify completed purchases, manage free trials, prevent fraud, and keep billing records.
- To personalize the service, including optional profile-based configuration such as local time zone, interface timing, or future age-aware baselines.
- To monitor service reliability and diagnose issues through crash analysis, error tracking, and performance monitoring via Sentry.
- To provide customer support, troubleshoot bugs, respond to complaints, and maintain security.
- To enforce our Terms, investigate abuse, maintain audit trails, and comply with legal obligations.
- To analyze user engagement, retention, and gameplay patterns for product improvement and analytics purposes.
- To manage admin operations, track administrative actions, and maintain internal audit logs for security and compliance.
- To collect and publish user testimonials with explicit consent for marketing and social proof purposes.
- To enforce rate limits on public API endpoints to prevent abuse and ensure service availability.
How we frame legality across regions.
Depending on your location, we process personal data based on one or more lawful grounds, including performance of a contract with you, compliance with legal obligations, your consent where required (such as for Sentry monitoring and testimonial publication), and our legitimate interests in operating, securing, supporting, improving, and analyzing the service.
If you are in a jurisdiction that gives you specific privacy rights, such as the European Economic Area, the United Kingdom, Switzerland, California, or other U.S. states with privacy laws, we will aim to honor those rights to the extent they apply to our business and processing activities.
Where data is routed and stored.
- Authentication data such as email and password credentials is routed to and stored by Supabase Auth.
- Profile details, subscription state, gameplay records, cognitive scores, daily activity, and admin audit logs are stored in Supabase-hosted database tables located in the Asia Pacific region (India/APAC) in compliance with data localization requirements.
- Testimonials and moderation data are stored in Supabase database (Asia Pacific region).
- Payment events and subscription history are stored in Supabase (Asia Pacific region) with metadata including payment provider responses.
- Paid checkout is processed by Razorpay, an Indian payment processor. We store payment-related metadata such as order identifiers, verification status, plan, amount, and coupon state, but not card numbers.
- Error, crash, and performance telemetry are routed to Sentry when monitoring is enabled, including stack traces, breadcrumbs, performance data, and session replays (subject to Sentry's data processing location terms).
- Website delivery and edge hosting are handled through Vercel infrastructure, which uses global CDN with India region support.
- Rate limit counters are stored temporarily in the Supabase database (Asia Pacific region) for abuse prevention.
- Some preferences and cached progress are stored locally in your browser through local storage or session storage on your own device.
How crash reports and session replay work.
- When enabled in production, Sentry captures application errors, crashes, and performance data automatically when something goes wrong.
- Sentry collects error stack traces, breadcrumbs (sequence of user actions before an error), browser/device information, and HTTP request details.
- Performance monitoring is enabled at 20% sample rate, capturing timing data for browser navigation and resource loading.
- Session replay captures video-like recordings of user sessions at 5% sample rate under normal conditions, and 100% sample rate whenever an error occurs, to help us debug issues.
- Session replays use Sentry's default PII redaction to automatically mask password fields, payment card numbers, authentication tokens, SSNs, credit card expirations, and other sensitive input fields. Replays never capture unredacted card data or authentication credentials.
- Error telemetry is sent only when an error or exception occurs; normal gameplay does not trigger Sentry data transmission.
- Sentry data is retained according to Sentry's data retention policies and is used for debugging, monitoring product reliability, and improving service stability.
- Sentry monitoring runs only in production environments. You can completely opt out by disabling the VITE_SENTRY_DSN environment variable in deployment configuration. End users cannot disable Sentry monitoring on the client side once it is enabled in production.
How engagement and performance data is tracked.
- We track gameplay metrics including scores, reaction times, levels reached, and session history to show you personalized progress insights.
- We track cognitive performance across five dimensions (working memory, pattern recognition, visual reasoning, processing speed, spatial memory) and assign performance tiers to indicate your cognitive status.
- We track daily activity (session counts and XP earned) to analyze engagement patterns and retention.
- We track game-specific records (best score, best round, total plays, last played) to support leaderboard rankings and personal statistics.
- Administrative users with appropriate roles can access aggregated analytics including user engagement, game performance metrics, retention rates, subscription data, and payment history.
- Admin audit logs record all administrative actions (who did what, when, and why) for internal compliance and security review.
- All admin access is restricted by role-based permissions (owner, ops, support, finance, marketing) and tracked for accountability.
How we treat optional profile information.
Some optional profile fields can be sensitive in certain jurisdictions, especially data about birth date or gender identity. You do not have to provide these fields to create an account or use the core service.
Please do not submit medical data, government identification numbers, financial account credentials, or other highly sensitive information through profile fields or support channels unless we explicitly request it for a specific support or legal reason.
How testimonial data is handled.
- When you submit a testimonial through our testimonials page, we collect your name, email, optional role, rating (1-5), testimonial text, and your consent to publish.
- Testimonials are moderated by our team and stored in our database with status tracking (pending, approved, rejected).
- If you consent to publication (allowPublish = true), we may use your name, role, rating, and testimonial text on the website, social media, or marketing materials.
- You can always contact us to request removal of your testimonial from public display or to delete your testimonial data entirely.
- Testimonial submissions are rate-limited to prevent spam (maximum 5 submissions per IP address per hour).
Cookies, local storage, and similar technologies.
- We use browser storage and session persistence to keep you signed in and preserve certain preferences or local progress states.
- Theme preferences, selected UI state, and some local gameplay helpers may be stored on your device.
- Sentry may set cookies for session tracking related to error monitoring and session replay functionality.
- If future analytics, advertising, or non-essential cookies are added, we may update this policy and any required notices before materially different tracking begins.
When information may be shared.
- We share data with service providers that help us operate the service, including providers for authentication, hosting, monitoring, payments, and error tracking.
- Sentry receives error reports, crash data, performance metrics, and session replays as part of error monitoring services.
- We may disclose information when reasonably necessary to protect users, investigate fraud or abuse, enforce our Terms, or comply with valid legal process.
- Testimonials you consent to publish may be shared on our website, in marketing materials, or on social media with your name and role visible.
- We may disclose information in connection with a merger, acquisition, financing, restructuring, sale of assets, or similar corporate transaction, subject to applicable law.
- We do not describe the service as selling personal data for money, and we do not knowingly share personal data for third-party behavioral advertising through the current product codebase.
Cross-border processing.
MemoryApp may be accessed globally, and our service providers may process data in countries other than the country where you live. Where applicable, we rely on contractual protections, provider safeguards, or other lawful transfer mechanisms recognized by relevant law.
How long information may be kept.
- We keep account and profile data for as long as your account remains active and for a reasonable period afterward as needed for security, support, legal, tax, accounting, or dispute-resolution purposes.
- We keep subscription, audit, and payment-related records for as long as needed to document transactions, enforce rights, prevent fraud, and comply with legal obligations (typically 7 years for financial records).
- Admin audit logs are retained for operational and compliance purposes for a minimum of 1 year.
- Gameplay data and progress metrics are retained for as long as your account is active and for a reasonable period afterward for support purposes.
- Testimonial data is retained indefinitely unless you request deletion, even if your account is closed.
- Sentry error and session data is retained according to Sentry's data retention policies (typically 90 days for errors, 30 days for replays).
- Rate limiting data is retained temporarily (typically hours to days) for abuse prevention purposes only.
- We may delete or anonymize certain data earlier when it is no longer needed for the purposes described in this policy.
- Data stored in your own browser remains on your device until it expires, is overwritten, or you clear it.
How we reduce risk.
- We use role-restricted server-side access for administrative workflows and keep server secrets outside the public client bundle.
- We deploy browser security headers, transport protections, and authentication controls intended to reduce common web risks.
- We limit public client exposure to publishable keys and use server-side verification for payment confirmation.
- We implement rate limiting on public API endpoints to prevent abuse and brute-force attacks.
- We use Sentry to monitor errors and performance issues that could indicate security problems.
- No method of storage or transmission is perfectly secure, so we cannot guarantee absolute security.
Your privacy rights.
- You may have the right to access, correct, update, delete, or receive a copy of certain personal data we hold about you.
- You may have the right to object to or restrict certain processing, withdraw consent where consent is the legal basis, or appeal a denied request where local law provides that right.
- You may have the right to know the categories of personal information collected, sources, purposes, and categories of recipients.
- You may have the right to non-discrimination for exercising privacy rights where local law provides that protection.
- You may have the right to opt out of certain data processing like Sentry monitoring where legally permitted.
To exercise a request, contact hello@memoryapp.co.in or use the details on the contact page. We may need to verify your identity before completing certain requests.
Children and age-related use.
MemoryApp is not intended for children who are below the minimum age required to consent to digital services in their location. If you believe a child provided personal data without appropriate authorization, contact us and we will review the request.
Third-party services and links.
Our service may link to or rely on third-party services including Supabase, Razorpay, Sentry, and Vercel. Those providers may have their own privacy notices, contracts, and legal duties. We encourage you to review their documentation when appropriate.
We maintain Data Processing Agreements (DPA) with all data processors and service providers, including Supabase for database hosting and authentication, Sentry for error monitoring, Razorpay for payment processing, and Vercel for website hosting. These agreements ensure processors comply with applicable data protection laws, including GDPR, CCPA, and India's data protection requirements. You may request copies of these agreements by contacting us.
- Supabase: Authentication and database hosting. See Supabase Privacy Policy
- Razorpay: Payment processing. See Razorpay Privacy Policy
- Sentry: Error and performance monitoring. See Sentry Privacy Policy
- Vercel: Website hosting and deployment. See Vercel Privacy Policy
How this policy may change.
We may update this policy from time to time to reflect service changes, new features, legal requirements, or operational needs. When required, we will post an updated effective date or provide additional notice.
Where to send privacy and data requests.
- Privacy requests: hello@memoryapp.co.in
- General support: hello@memoryapp.co.in
- Billing issues: hello@memoryapp.co.in
- Data deletion requests: hello@memoryapp.co.in
Last updated: August 10, 2026.