Privacy Policy
What Memo.top does with your data — described from the service's own source code.
This policy explains what data Memo.top collects, why, who it is shared with and how long it is kept. It is written from how the service actually behaves: every statement here matches what the service really does, rather than what would be pleasanter to write.
That is why there are uncomfortable passages in it — about web analytics without a consent banner, about the "encrypted widget" not being end-to-end, and about account deletion still being done by hand. We decided you are better off knowing these things than reading a smooth formulation.
1. The short version
This section collects what you should know before reading the full text — including the things such documents usually leave out. It is a summary, not a replacement for the sections below.
- We do not sell your data, we do not show ads and we do not build advertising profiles. Memo.top has no payments, so we collect neither payment details nor a phone number.
- Your content is not sent to any artificial intelligence provider. The service performs no AI processing of your bookmarks or notes — see section 6.
- There are four external recipients: Yandex.Metrica, Google, Telegram and VK. The full list, with what each one receives, is in section 8.
- The Yandex.Metrica counter loads the first time you open the site. We have no cookie consent banner, so we do not claim that we obtained your consent in advance. How to limit the collection is explained in section 9.
- Genuine client-side encryption exists only for secret notes. The "encrypted widget" works differently: the password is sent to the server, and during the operation the server sees the plaintext. It is not end-to-end — see section 7.
- When you save a bookmark, our server opens that page itself and keeps its full text and a screenshot. No data about you is sent to that site — see section 4.
- There is currently no way to delete your account from the interface, and no one-click export of your data either. Both are done on request to support@memo.top — see section 15.
- The service has no automatic retention periods and no scheduled clean-ups: data is kept until you or we delete it — see section 13.
2. Who we are
The controller of your personal data is PAYMASTER TECHNOLOGIES ELEKTRONIK PAZARLAMA DIS TICARET LIMITED SIRKETI, Turkey, registration number 451893-5. Postal address: Merkez Mah. Kagithane Cad. A, Office No 11/61, Kagithane / Istanbul / Turkey.
The operator is established in Turkey, outside the European Union. The GDPR nevertheless applies to this processing because we offer the service to people in the Union (Art. 3(2) GDPR), and we describe our practices by reference to it throughout this document.
For anything concerning your data, including requests to exercise your rights, write to support@memo.top. This is the only address at which we accept such requests.
- Representative in the Union (Art. 27 GDPR)
- not appointed
- Where the servers and databases are physically located
- Turkey — this is where the servers, databases, search index and file storage are located
Where the servers and databases are physically located is stated above in this section. We make no other statement anywhere in this document about where exactly the data is stored.
Back to top3. What this policy covers
This policy covers everything that forms part of Memo.top as a service, not only the main website.
- The memo.top website and its language versions, together with the related service domains — memo.web.money, beta.memo.top, bxod.com.
- Embeddable pages: the calendar and the user card, which can be placed on a third-party website.
- The extension for the Chrome browser.
- The calendar service behind meetings and booking — this is our own infrastructure, not a third-party supplier.
- Your public profile page at /user/:username, if you have published it.
This policy does not cover the websites you bookmark, nor the services you sign in with (Google, VK, Telegram, WebMoney): when you sign in, their own authentication service processes your data under their own rules. For WebMoney this is said about sign-in specifically. Where WebMoney acts in its other role — as the storage for your files and the channel for service notifications — it is infrastructure of the operator's group and this policy does cover it; see subsection 8.1.
Back to top4. What data we collect
Everything the service actually records is listed below. The list was compiled from the database schema and the source code, not from a template.
4.1. Account data
- Your email address and, if you added one, a secondary address together with its confirmation status.
- Your name, nickname, the avatar link taken from a social network and any avatar file you uploaded.
- Your WMID, if you sign in with WebMoney.
- A username — generated automatically by the service when the account is created.
- Your bio, greeting and meeting topic, if you filled them in.
- Your interface language and the source of your registration.
- Your Telegram chat identifier, if you connected Telegram notifications.
- A hash of your password, the confirmation and password-reset tokens, and the list of your active sessions.
The service holds no phone number — we neither ask for one nor store one.
4.2. Data received from sign-in services
- WebMoney: when you sign in with a ticket, we receive your WMID and the IP address the sign-in came from. In a separate request by WMID, the service retrieves your nickname and avatar and stores them in your profile.
- Google: the account identifier and the account data you allowed to be passed on at sign-in.
- VK: the same — the account data passed on at sign-in.
- Telegram: the data from the Telegram login widget and the chat identifier used for notifications.
4.3. Your content
Everything you create in the service is stored by us: pages and their settings, widgets, bookmarks (title, description, address, icon, preview image and the "login" and "password" fields if you filled them in), notes, secret notes, tasks, RSS feeds, uploaded files and gallery images.
The calendar part stores events with their title, description and comment, busy slots and meeting requests — including the message the sender attached to a request. Notifications are stored together with the text shown in them and with a record of who triggered them.
4.4. What the service generates itself
Some data appears without any action on your part: the service produces it so that a bookmark looks right and can be found again.
- When you save a bookmark, our server opens the address you gave and takes the title, description, icon and preview image from it.
- Beyond that, the server keeps the full text of the saved page, a screenshot of it, and the images and links found on it. This copy stays with us and remains even if the original page changes or disappears.
- Reference information about the site is collected by the bookmark's domain name.
- Your bookmarks, notes and tasks are indexed in our search index together with your account identifier, so that search works.
4.5. Technical data and logs
- Server-side application logs. Request addresses and technical error details may end up in them.
- The IP address received from WebMoney when a sign-in ticket is verified goes into the server log; it is not written to the database.
- The calendar service stores in its database the IP address of the previous and the current sign-in, the number of sign-ins and their dates.
- In-application error tracking is switched off — no error data is sent outside.
4.6. The browser extension
The extension stores your session data and its own settings locally in your browser. It also has an optional permission to access your browser bookmarks.
4.7. What we do not collect
- Phone numbers.
- Payment details and card data — the service has no payments.
- Biometric data.
- Precise device location.
- We do not ask for special categories of data (Art. 9 GDPR). If you place such information in your own notes or bookmarks, it is stored like any other content of yours.
5. How we use the data
- To create and run your account and to recognise you when you sign in.
- To store, display and synchronise your content across your devices and the extension.
- To make search over your bookmarks, notes and tasks work.
- To show the preview image and icon of a saved page.
- To run the calendar: meeting requests, slots, reminders and notifications over the channels you chose.
- To send service email — address confirmation, password recovery, meeting notifications.
- To understand how the site is used, through web analytics.
- To protect the service against abuse and to investigate failures using the logs.
We do not use your data for advertising, we do not pass it to ad networks, and we neither sell nor trade it. We do not build a profile of you in order to make decisions about you — see section 17.
Back to top6. Artificial intelligence
We include this section because it is now the first question people ask. The answer is short.
- Your content is not passed to any artificial intelligence provider. Memo.top has no integrations with such services.
- Your data is not used to train models — neither ours nor anyone else's.
- The service performs no automatic AI categorisation of bookmarks.
- "AI News" is a topical news feed from an external news source. We request a feed on that topic from it; none of your personal data is sent in the process.
7. Encryption: what the server can see
The service has two different password-protection mechanisms, and they work in fundamentally different ways. We describe them separately because what is accessible to us depends on which one you use.
- Secret note — client-side encryption
- The contents are encrypted in your browser before they are sent. The password stays in the form on the page: it is saved neither in browser storage nor on the server. We receive and store ciphertext only and never see the plaintext. The flip side: if you lose the password, neither you nor we can recover the note — there is no way around it.
- Encrypted widget — server-side encryption
- You type the password in the browser and it is sent to the server. The server decrypts the password and uses it to encrypt the widget contents itself. The key that protects the password in transit is issued by the server and stored by the server.
Two more circumstances are better stated plainly. First, in an ordinary, unencrypted widget the bookmark's "login" and "password" fields are stored in the database in the clear. Second, if an account is created for you on another user's initiative, the generated password is emailed to you in plain text — change it immediately after your first sign-in.
Back to top8. Who we share data with
There are four external recipients, and all of them are listed below. We do not sell data and we do not pass it to ad networks or data brokers.
| Service | What is shared | Why | Where it is located |
|---|---|---|---|
| Yandex.Metrica | IP address, User-Agent, the address of the page you are viewing, click map and link clicks | Web analytics: counter 98354174. Loaded on every page of the site | Russia |
| IP address and User-Agent when the web fonts load on any page of the site; your account data if you sign in with Google | Rendering the interface fonts; Google sign-in | USA | |
| Telegram | Chat identifier and the text of a meeting notification | Delivering notifications — only if you connected Telegram yourself | UAE |
| VK | The account data passed on at sign-in | VK sign-in — only if you use it | Russia |
Only the first two rows are unconditional: the analytics counter and the web fonts load on every page. Telegram and VK receive data only if you connected those services yourself. Countries and the legal basis for transfers are covered in section 12.
8.1. Our own infrastructure and the services of our group
What is listed here is not a disclosure to third parties: it is processing inside the service and inside the operator's group. We describe it because you are entitled to know where your data physically ends up. A note on WebMoney: in this subsection it acts as infrastructure of the operator's group — the storage behind the "Files" widget and the service notifications in Keeper. As a sign-in provider WebMoney acts in a different role, external to us: there your data is processed by its own authentication service under its own rules — see section 3.
- The calendar service, the search index, the screenshot generator, the mail server, the databases and the cache are our own infrastructure.
- WebMoney sign-in, our side of the verification: when the ticket is verified we receive your WMID and IP address; the nickname and avatar for your profile are then fetched by WMID. The authentication itself happens on WebMoney's side and under its own rules — see section 3.
- WebMoney Keeper notifications: the recipient receives the notification text only — for example, that you granted them access to a widget. The contents of the widget are not sent anywhere.
- Files you upload to the "Files" widget are stored not on our main server but in a subsidiary service of the operator that runs under a white label. The folder in that storage is named after your account identifier, and access to it is granted to your WMID.
8.2. Reference lookups by domain name
To show a site's icon and information about it, the service makes reference lookups by the domain name of the bookmark you are saving. Such a lookup carries the domain name only — no user identifier, no full page address and nothing about who saved the bookmark. It contains no personal data, so these services are not recipients of personal data.
For the same reason the list does not include the external news feed source, the city-name suggestion service or the weather forecast service: what they receive is, respectively, a feed topic, the city search string you typed and a location name.
8.3. The websites you bookmark
Our server contacts those sites on its own behalf. Your IP address, your account and any other information about you are not sent there, so those sites are not recipients of your data.
The reverse matters: what the server retrieved from such a page — its full text and a screenshot — is stored by us. See subsection 4.4 for details.
9. Cookies and local storage
The service uses cookies and browser storage. Some of it keeps you signed in, some of it makes the interface work, and one item is for web analytics.
| Where it is stored | What exactly | Why | For how long |
|---|---|---|---|
| Cookie | access-token, client, uid, expiry, token-type | The marker that you are signed in. Set when you sign in through Telegram and when the calendar token is exchanged | Until the token expires — see section 13 |
| Cookie | authinfo — encrypted; contains the user identifier, the sign-in method and the domain | Passing sign-in details between the service domains | 1 hour |
| Cookie | The application session cookie | Server-side technical operation | Until you close the browser |
| Cookie | Yandex.Metrica cookies | Web analytics | Set and determined by Yandex |
| localStorage | The access token and the values related to it | So that you do not have to sign in every time you open the site | Until you sign out or clear the storage |
| localStorage | The return address after sign-in, the chosen language, the calendar theme, widget settings | Remembering your interface choices | Until the storage is cleared |
| localStorage | A cache of widget contents — including the list of your bookmarks | Fast rendering without reloading | Until the storage is cleared |
| sessionStorage | The password of an encrypted widget — in the clear | So that you do not have to retype it on every access to the widget | Until you close the tab |
| Service Worker cache | Interface files | Keeping the site usable on a poor connection | Until the version is updated or site data is cleared |
| Extension storage | Session data, settings and — if the permission was granted — a copy of your browser bookmark tree | Running the extension | Until the extension is removed or its data is cleared |
If you disable the cookies responsible for sign-in, you will not be able to stay signed in. That is a technical consequence, not a requirement of ours.
Back to top10. Legal bases for processing
We process personal data on the legal bases set out in Art. 6 GDPR. The basis is stated separately for each purpose.
| Purpose of processing | Legal basis |
|---|---|
| Creating an account, signing in, storing and displaying your content, synchronisation, search, the calendar, meeting notifications, storing uploaded files | Art. 6(1)(b) — performance of our contract with you (the terms of service) |
| Server logs, protecting the service against abuse, investigating failures | Art. 6(1)(f) — our legitimate interest in keeping the service working and secure |
| Automatically retrieving the title, description, icon, preview image, full text and screenshot of a page from your link; reference lookups by domain name | Art. 6(1)(f) — our legitimate interest in displaying bookmarks usefully. You have the right to object to this processing (Art. 21) — see section 15 |
| Publishing your profile on a publicly accessible page | Art. 6(1)(a) — your consent, which you give by a separate action and can withdraw at any time |
| Telegram notifications | Art. 6(1)(a) — your consent: you connect the channel yourself and can disconnect it |
| Web analytics (Yandex.Metrica) | Art. 6(1)(a) — consent. See the caveat below |
| Responding to lawful requests from public authorities | Art. 6(1)(c) — compliance with a legal obligation |
| Creating an account on the initiative of another user who is granting you access | Art. 6(1)(f) — legitimate interest in granting that access. At that moment there is no contract with you yet; you are informed by email (Art. 14) and may object immediately and demand erasure |
Caveat on web analytics: consent is the appropriate basis for this processing, but no mechanism for obtaining it in advance is implemented on our side, and the counter loads before you take any action. We state this plainly and do not claim that consent was obtained. Ways to limit the collection are in section 9.
11. Who else can see your data
By default your content is visible to you alone. Below are all the cases in which someone else can see it, and exactly what happens in each.
11.1. Sharing a widget
You can give another person access to your widget by entering their email address or WMID. The contents of the widget are not sent anywhere: they stay in the service and simply become visible to the person you shared with.
All that person receives is a notification that access has been granted — by email or by messenger. The notification text contains your display name and the name of the widget. In substance it is a message, not a data export.
When you share, remember that whoever receives the access sees the widget contents exactly as you see them.
11.2. If an account was created for you
If someone shares with an email address or a WMID that does not yet correspond to any account, the service creates that account automatically, generates a password and sends you an email or a message. Your consent is not requested at that point — you learn about the account from that message.
You have the right to object to this processing and to demand that the account be erased. Just write to support@memo.top from the address the notification was sent to, and we will delete the account and the data associated with it. You do not have to explain yourself.
11.3. The public profile
A public page at /user/:username opens without signing in — anyone who knows the address can see it, and a search engine can index it. It is published only on your explicit decision, by a separate confirmation.
While the profile is published, the following are visible without signing in: your name, nickname, username, bio, greeting, meeting topic, avatar, interface language, and the availability grid of your calendar — that is, which time slots are busy and which are free.
The titles and descriptions of the events themselves are not shown on the public page — only the busy/free pattern. Your email address is not shown. You can unpublish at any time in the calendar settings; after that the page stops opening, but copies already saved by search engines may remain in their caches for a while, which is outside our control.
11.4. Embedding on third-party sites
A widget or the calendar can be embedded on another website. Technically this works in such a way that the access token ends up in the address of the embedded page and is passed between windows by message, and the wrapper page does not restrict the list of domains it may be placed on.
11.5. Internal access by WMID
The service has an internal programming interface that allows affiliated services of the operator's group to access a user's data by their WMID: pages, widgets, bookmarks, notes, tasks and files. It is used for integration within the group and is not available to outsiders.
11.6. Lawful requests
We may disclose data where the law requires it, on a properly issued request from a competent authority. We disclose only what is expressly requested, and nothing more.
12. International transfers
Some of the recipients in section 8 are located outside the European Economic Area. We name the countries plainly, because that is material for assessing the risk.
| Recipient | Country | European Commission adequacy decision |
|---|---|---|
| Yandex.Metrica | Russia | None |
| VK | Russia | None |
| Telegram | UAE | None |
| USA | The adequacy decision for the USA covers only organisations on the list of entities certified under the EU-U.S. Data Privacy Framework. The operator has not verified whether this recipient is on that list |
There is no European Commission adequacy decision in respect of the Russian Federation. We therefore make no claim about the level of protection that data transferred to Russia enjoys — such a claim would not be correct. The operator itself is established in Turkey, which is likewise a third country not covered by an adequacy decision.
What you can do yourself — which transfers can be avoided:
- Do not connect Telegram — then nothing goes to Telegram.
- Do not sign in with VK or with Google — then no account data is passed to those services.
- Limit web analytics through your browser settings, a blocker, or Yandex's official opt-out (section 9).
- Do not link WebMoney and do not use the "Files" widget if you do not want your files placed in the storage described in section 8.
One transfer cannot be avoided by any means the service offers: the interface web fonts load from Google's servers on every page, and Google receives your IP address and User-Agent when they do. This can only be prevented on the browser side, with a blocker for third-party requests.
Back to top13. Retention periods
Here an honest answer matters more than a tidy one: the service has no fixed retention periods and no automatic clean-ups. Data is kept until you delete it, or until we delete the account at your request.
| What | How long it is kept |
|---|---|
| Account and profile | Indefinitely, until you ask us to delete it (section 15) |
| Bookmarks, notes, tasks, events, files | Until you delete them |
| Widgets | Deleted "softly": the widget disappears from the interface, but its record stays in the database |
| The stored text and screenshot of a page from your link | Indefinitely; there is no automatic clean-up |
| Files from the "Files" widget | Remain in the storage after deletion in the interface — see section 8 |
| The access token (the marker that you are signed in) | 10 years from issue |
| The authinfo cookie | 1 hour |
| Tokens of embeddable pages | No more than three are kept at a time; older ones are pushed out by newer ones |
| Server logs | The log rotation period is not documented |
| Backups | We cannot confirm that regular backups are taken or for how long they are kept — see section 15 |
14. Security
What the service does have:
- Data is transmitted over HTTPS.
- Your account password is stored as a hash — we do not hold it in the clear.
- Secret notes are encrypted in the browser and the server never sees their contents (section 7).
- Access to data is limited to your account; staff access for support purposes is on a need-to-know basis.
What the service does not have, or what is weaker than it may look:
- There is no two-factor authentication. Sign-in is protected by your password or by an external sign-in service only.
- The key that protects an encrypted widget's password in transit is stored in our database.
- While an encrypted widget is open, its password sits in the browser's sessionStorage in the clear.
- The "login" and "password" fields of an ordinary bookmark are stored in the database in the clear.
- The password of an account created for you on someone else's initiative is emailed in plain text.
- The authentication cookies are set without the httpOnly and secure flags.
We list these not because we consider them acceptable, but because you are entitled to know what to count on. Keep particularly sensitive information in secret notes, or do not keep it in the service at all.
If a data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the supervisory authority within 72 hours (Art. 33 GDPR) and inform you if the risk is high (Art. 34 GDPR).
Back to top15. Your rights
You have the rights set out in Art. 15-22 GDPR. Below we describe not only what they are, but how they actually work here today — including the fact that some of them are carried out by hand.
- Access (Art. 15)
- You can obtain a copy of the data we hold about you and information about the processing. There is no ready-made export in the interface — we compile the response on request.
- Rectification (Art. 16)
- Your name, nickname, bio, greeting, avatar and the other profile fields you can correct yourself in the settings. Everything else is corrected on request.
- Erasure (Art. 17)
- Self-service account deletion is currently not available in the interface. Erasure is performed on request to support@memo.top: we delete the account and the content associated with it manually and confirm by email within no more than 30 days. Individual items — bookmarks, notes, tasks, events — you can delete yourself at any time.
- Restriction of processing (Art. 18)
- On request we can stop all processing other than storage — for example, while we consider an objection from you.
- Data portability (Art. 20)
- There is no automatic export in the interface: the service can import bookmarks but not export them. On your request we will provide the data in a structured, commonly used, machine-readable format.
- Objection (Art. 21)
- You have the right to object to processing based on legitimate interests: the automatic retrieval of the title, description, text and screenshot of the pages behind your links, the reference lookups by domain name, and web analytics. On request we will stop the relevant processing for your account.
- Withdrawal of consent (Art. 7(3))
- You can withdraw consent at any time, as easily as you gave it: unpublish your profile in the calendar settings, disconnect Telegram, or limit web analytics in the ways described in section 9. Withdrawal does not affect the lawfulness of processing carried out before it.
- Complaint to a supervisory authority (Art. 77)
- You have the right to lodge a complaint with a supervisory authority: the supervisory authority of your place of residence in the EU. You may also approach the supervisory authority of your habitual residence, place of work, or the place of the alleged infringement.
15.1. What is not deleted automatically
Even after an account is deleted, some data does not disappear by itself. We set this out plainly so that you know where to turn next.
- Files uploaded to the "Files" widget stay in the storage: deleting them in the interface only removes the record in our database. Write to support@memo.top if you need physical deletion.
- Data already transferred to Yandex.Metrica, Google, Telegram or VK is held by them. Deletion has to be requested from the service concerned under its own procedure — we cannot do it on your behalf.
- "Softly" deleted widgets remain as database records until they are cleaned up by hand.
- Stored copies and screenshots of the pages behind your links are deleted together with the account on request; there is no automatic clean-up for them.
- Backups, if they are taken, may contain deleted data for as long as they are kept. We cannot confirm the backup frequency or the retention period for backups, and therefore do not state them.
- Entries in the server logs live until the logs are rotated.
16. Children
Memo.top is not intended for children under 16. If your country in the European Economic Area has set a lower age of digital consent (but not below 13, Art. 8 GDPR), that age applies.
The service has no age verification mechanism — we do not ask for a date of birth and cannot check a user's age. If you are a parent or guardian and believe that a child created an account without your consent, write to support@memo.top: we will delete the account and the data associated with it.
Back to top17. Automated decisions and profiling
We take no decisions based solely on automated processing, including profiling, that would produce legal effects concerning you or similarly significantly affect you (Art. 22 GDPR).
We do not build behavioural profiles, we do not score you algorithmically, and we do not use your data to target advertising.
Back to top18. Changes to this policy
The current version of this document and the date it takes effect are always shown at the top of this page. Changes take effect when they are published.
We announce material changes as follows: the current version is always published on this page; the version number is shown at the top of the document. The service currently has no dedicated mechanism for mailing out change notifications, so we recommend checking this page — it always holds the version in force.
If a change requires your consent, we will ask for it separately; we will not treat your continued use of the service as consent.
Back to top19. Contacts and complaints
For anything about this policy, your data and your rights, write to support@memo.top.
- Controller
- PAYMASTER TECHNOLOGIES ELEKTRONIK PAZARLAMA DIS TICARET LIMITED SIRKETI, Turkey, registration number 451893-5
- Postal address
- Merkez Mah. Kagithane Cad. A, Office No 11/61, Kagithane / Istanbul / Turkey
- support@memo.top
- Representative in the Union (Art. 27)
- not appointed
- Supervisory authority (Art. 77)
- the supervisory authority of your place of residence in the EU
If our answer does not satisfy you, you have the right to lodge a complaint with a data protection supervisory authority — in the country of your habitual residence, your place of work, or the place of the alleged infringement. Contacting us first is not a precondition for such a complaint.
Back to top
