Privacy Policy
The app needs no account, and nothing you write reaches our
servers. The app contains no analytics or advertising code and
does not track you. With sync off, nothing leaves your device at all. What
does travel when you turn sync on is set out precisely in section 3. If you
create an account on the website for a paid subscription, what we keep is set
out separately in section 4.
Last updated: 21 September 2026
1. What we collect
Starting with what the app does not do:
- You don't need to sign up or sign in to use the app, and the app never asks for your name, email, or phone number. (The website account for a paid subscription is covered in section 4.)
- The app contains no analytics SDK and gathers no usage statistics.
- It shows no ads and does not read any advertising identifier.
- We do not track you, and we never sell data. What we pass to Paddle for payment, and who processes data for us, is set out in section 4.
- Crash reports and usage data are not sent to us automatically.
- The contents of your notes and attachments never reach our servers under any circumstances, and neither does your vault password or key phrase.
There is one exception. When you turn on syncing over the internet, your device sends a device identifier and its connection address (IP and port) to our rendezvous server so that it can find your other devices for the same vault. This is what we declare on the App Store under Identifiers ▸ Device ID for the purpose of App Functionality; it is not linked to your identity and is not used for tracking. The feature is off by default, and section 3 sets out exactly what travels when it is on.
2. Where your writing lives
Every note, attachment, folder, and database you create is stored only in a folder on your own device that you chose — the vault. We cannot see its contents and we hold no copy of it.
What is encrypted, precisely
- Note contents are stored encrypted. Each document is encrypted with a key derived from your vault password (XChaCha20-Poly1305). The search index is kept in an encrypted database.
- Attached files are kept as the original files and are not encrypted. This is deliberate: it is what lets another app open and edit a PDF, Word document, or image in place.
-
Exported
.mmpfiles are not encrypted either. The format exists to be opened without a vault password, so once a file leaves the vault it no longer has the vault's protection.
Your vault password is never sent to us and cannot be recovered. If you forget it, we have no way to open the vault for you.
3. Syncing between your devices
Sync is off by default and runs only if you turn it on.
Same-network sync (LAN)
When your Mac, iPad, iPhone, or Windows PC are on the same LAN/Wi-Fi, they exchange data directly with each other. Nothing passes through our servers. The connection is encrypted (QUIC / TLS 1.3). Turning this on makes the app ask for the Local Network permission so it can announce itself and find your other devices.
Syncing over the internet
This links devices that are on different networks. It is off by default everywhere, and the setting is named differently per platform.
- macOS and Windows — Internet sync in settings, linking devices that have opened the same vault.
- iPhone and iPad — Connect to my host in settings. Leave one of your own computers switched on as the host, and your phone reaches it directly from anywhere. The data goes to your own machine.
When it is on:
-
Your device contacts our rendezvous server
(
rv.memost.app) to find your other devices for the same vault. What the server receives is an opaque identifier derived from the vault's key phrase (it cannot be turned back into the phrase), a device identifier, and the connection address (IP and port). The vault password and the key phrase itself are never sent. - The server's only job is to tell a device where the host is; the data itself travels directly between your devices. Our server does not relay data — relaying is switched off. On networks where your devices cannot connect directly, internet sync therefore does not happen.
- The only thing the server keeps is the registration of a computer you made a host, which is stored in a database. What is stored: a hash of the opaque identifier above (not the identifier itself), that computer's connection address (IP and port), the email address and fixed identifier described below, and the time it last checked in. Registrations from devices that are not hosts are not stored at all. When a host stops checking in, its record is deleted after 30 minutes. The server keeps no connection logs by default.
- Only if you make a computer of yours the host — something you switch on yourself, in the macOS or Windows settings — that computer's registration also carries two things: the vault owner's email address and a fixed identifier unique to the vault. They are there for checking a paid subscription in the future. The identifier is derived from the key phrase but cannot be turned back into it, and unlike the rotating one above it stays the same from day to day — which is what lets a subscription's hosted vaults be counted, and it equally means the server recognises a hosted vault as the same vault over time. iPhone and iPad cannot be a host, so they send neither the email nor this identifier.
-
On macOS and Windows you can change the rendezvous
server address in settings, including running your own so that none of
our servers are used at all. On iPhone and iPad the
address is fixed to
rv.memost.appand cannot be changed.
4. Website accounts and paid subscriptions
The app works without an account. Only if you want a paid subscription (Plus) do you create an account at memost.app. This section is about that account.
What we keep
- When you sign up — your email address, name, password (kept only as a one-way hash), display language, when you agreed to the terms and this policy, and whether you want news by email.
- Subscription and payments — your plan, subscription status and period, and each payment's amount, currency and status, with Paddle's transaction and invoice numbers. We never receive or store card numbers — Paddle takes payment details directly.
- Device authorisation — when you confirm your subscription in the app, we keep that device's identifier (UUID), its name and platform, the app token we issued, and when it last checked in. If you make a computer your host, we also keep its MAC address, a hardware key our server generates, and its connection address (IP and port). This is so that one subscription cannot be shared among many people.
What we use it for
Signing you in and confirming it is you, providing the subscription and keeping payment records, authorising devices, and essential messages such as email confirmation and password resets. We send news only if you opted in when you signed up. The website uses only the cookies needed to keep you signed in and to block forged requests — no analytics or advertising cookies.
Who receives it and who processes it for us
- Paddle.com Market Ltd (United Kingdom) — as Merchant of Record, handles payment, tax, invoices and refunds. When the checkout opens we pass your email address, account number and chosen plan; Paddle collects your card details and billing country itself, in the checkout. What Paddle receives is governed by the Paddle Privacy Policy. The checkout is loaded only on the checkout page.
- Zoho Corporation (United States) — sends essential email such as address confirmation and password resets.
- Amazon Web Services (Seoul region) — runs the website's servers and database.
How long we keep it, and closing your account
We keep account details until you close your account. When you do, we remove your name, replace your email address with an unrecognisable value, disable sign-in, and revoke every app token and device authorisation. Payment and refund records, however, are kept for five years as required by Korea's Act on the Consumer Protection in Electronic Commerce. You can edit your details or close your account at any time from your account page.
5. Permissions the app asks for
- Local Network — to sync with your other devices on the same Wi-Fi. Decline it and everything else in the app still works.
- Camera — used only when you take a photo to put straight into a note. The photo is saved into the vault on your device.
- Files and Photos — used only for files you pick yourself, to attach them to a note or import documents from another app.
6. Children's privacy
The memost app has no accounts and never asks for a name, email address, or age, so it gathers nothing about children either. There is no age restriction on using the app. The website account for a paid subscription does not ask for your age either.
7. Changes to this policy
If this policy changes, we will update this page and the date above. If a change ever widens what the app collects, we will say so in the app as well.
8. Contact
For any question about privacy, write to support@memost.app.
AlphaMatch Inc.