YOUR DATA
Privacy Policy
Last updated: 27 August 2026
Who is responsible
Yalma Studio operates Memolines and is responsible for the processing described in this policy. Privacy questions and requests can be sent to contact@memolines.app.
This policy covers the Memolines mobile application and the Memolines website.
A service for parents
Memolines is intended for parents and guardians who preserve children’s artwork. Children do not create or manage accounts. The parent controls the information entered about each child and the use of child mode.
Data kept on the device
The local library may contain a child’s first name and birth date, a drawn avatar, scanned artwork, titles, dates, anecdotes and text recognised on the sheet. This library is stored in the application’s private space on the parent’s device.
On the Free plan, the library remains local. Scanning and text recognition are performed on the device. Yalma Studio does not receive the contents of this local library.
Optional account and cloud backup
When a parent starts a Premium or Ultra purchase, restores a purchase, enables cloud backup or links an email address, Memolines may create a technical account. The service then processes an account identifier, session information, an optional email address, subscription status, library metadata and the artwork files selected for backup.
The device remains the primary copy. Cloud backup is a recoverable copy used to restore the library on another installation.
Why the data is used
Data is used only to provide the requested features: maintain the local library, scan and recognise text, manage optional reminders, process subscriptions, back up and restore a Premium library, recover an account, answer support requests, protect the service from abuse and anonymously measure the steps people use so the application can be improved.
Depending on the feature, processing is necessary to provide the service requested by the parent, follows an explicit choice or permission, meets a legal obligation, or protects Yalma Studio’s legitimate interest in securing the service.
Service providers and sharing
Yalma Studio does not sell family data and does not use it for advertising. Data is shared only with providers needed to operate the selected feature.
- Supabase provides account authentication and stores backed-up library metadata.
- Cloudflare R2 stores encrypted-in-transit private artwork copies in the European Union.
- RevenueCat processes subscription identifiers, products and entitlement status.
- Aptabase processes anonymous usage events, the application version and the phone system in the European Union. No family content or account identifier is sent to it.
- Google Play or the Apple App Store processes payments and store receipts. Yalma Studio does not receive full payment-card details.
- Resend delivers account-linking and recovery emails when an address is provided.
Permissions and tracking
Camera access is requested only when the parent starts a scan. Local notifications are requested only after a reminder is chosen. Memolines does not request location or contacts and does not record audio.
The application uses Aptabase for anonymous usage statistics without a persistent identifier or cross-app matching. A parent can disable them at any time under Privacy. The website uses Umami for anonymous, cookie-free audience measurement with no personal data. Neither the application nor the website uses advertising trackers. Artwork is not used to train artificial-intelligence models.
Retention and deletion
Local data remains on the device until the parent deletes a memory, deletes the local library, removes the application or clears its data.
A cloud copy remains while the account and backup exist. If a subscription expires, cloud access is suspended but the local library is not deleted. The parent may request deletion of the account and its associated cloud data at any time from the account-deletion page or by contacting Yalma Studio.
Store operators and billing providers may retain transaction records for fraud prevention, accounting or legal obligations under their own policies.
Security and international processing
Local files are kept in the application’s private storage. Cloud metadata is access-controlled, artwork storage is private, transfers use encrypted connections and file access uses short-lived signed links.
The main cloud storage is located in the European Union. Some providers may process account, support or billing information in other countries under their own safeguards. No security measure can eliminate every risk.
Your choices and rights
Depending on applicable law, a parent may request access, correction, deletion, restriction or portability of personal data, and may object to or withdraw consent for optional processing. A complaint may also be made to the competent data-protection authority.
This policy may change when Memolines changes. The date above identifies the current version. Material changes will be communicated through the application or website when appropriate.