Privacy Policy for MemoCard
Last updated: September 11, 2026
This policy covers MemoCard at app.memocard.org, the @memo_card_bot
Telegram bot and mini app, and connected clients such as ChatGPT
MemoCard is responsible for the personal information it processes to
provide this service. Contact
support@memocard.org or
MemoCard support on Telegram
about your data or this policy
Information we collect and why
-
Account information: Your Telegram identifier, name,
username and language, or the account information supplied by Google
sign-in, to identify your account and provide the service
-
Library and learning data: Your folders, decks, card
text, examples, uploaded content, study settings and review history,
to save your material and schedule spaced repetition
-
App settings and technical data: Language, timezone,
platform, browser and app information, activity timestamps and error
information, to operate the app, schedule reminders and diagnose problems
-
Connection information: OAuth client and grant records,
authorization credentials and temporary login state, to connect clients
you approve and let you revoke their access
-
Integration activity: Changes made through connected
clients, including before/after copies of affected folders, decks and
cards, to investigate errors and provide support
-
Payments: Payment and subscription identifiers, status,
plan and billing period, to provide paid features. Stripe or Telegram
processes the payment; MemoCard does not receive your full payment card
number
-
Support messages: Information you choose to send us
so that we can respond to your request
ChatGPT and other connected clients
Connecting ChatGPT gives it access to read and manage your MemoCard library.
When it calls MemoCard tools, OpenAI receives the returned folder and deck
names, descriptions, card contents, examples and identifiers needed to
work with those items. Material that you ask ChatGPT to save or change is
sent to MemoCard as tool input
MemoCard receives the specific inputs supplied to its tools, not your full
ChatGPT conversation. The integration does not independently send your
library to an AI model. ChatGPT processes the content exchanged with it
under OpenAI's applicable terms, privacy policy and your account settings
OAuth read tools do not store raw tool arguments in MemoCard's integration
activity log. Write tools store before/after change records. The older
manual MCP connection also records tool names and arguments for support
and diagnostics
To stop future access, open Settings → ChatGPT in MemoCard and disconnect
the connection. Disconnecting does not delete your MemoCard library or
information already received by ChatGPT. Manage or delete your ChatGPT
conversations through OpenAI's controls
Who receives information
-
Telegram and
Google handle the
sign-in and messaging services you choose to use
-
OpenAI receives
content exchanged with ChatGPT when you connect and use the integration
-
Cloudflare and
Supabase provide hosting,
storage and database services
-
Rollbar receives technical
error reports to help us diagnose app failures
-
Stripe or Telegram processes
payments using the payment method you choose
We do not sell your personal information. We may disclose information when
legally required or necessary to protect users and the service. If you
publish or share library content, the people you share it with can access
that content
Retention and deletion
-
Library data and learning history remain while you use your account,
until you remove them or request account deletion
-
Deleting a card removes it from your current library and deletes its
scheduling and review history. Its contents can remain in an integration
change record. Account-linked database logs, including change records,
have no scheduled expiry and remain until account deletion or a support
request to remove them
-
Incomplete OAuth login sessions are valid for 15 minutes. Expired
records are removed when subsequent login requests are created
-
OAuth access tokens last one hour. Refresh credentials and connection
grants are kept until you disconnect, revoke access or have your account
and its connections removed. This lets you stay connected without
repeated sign-in
-
Hosting, error-reporting and payment providers may retain technical,
backup or billing records according to their configured retention and
legal obligations. Their policies are linked above
Request removal of your Telegram-based MemoCard account, connection records
or retained integration history through support. Where account deletion is
available in the app, you can also use that control. We may need to verify
account ownership before fulfilling a request. Deletion from MemoCard does
not delete copies already held by an external client or people with whom
you shared content
Your controls and rights
You can edit or remove library content, change app settings and reminders,
disconnect integrations, and ask support for access, correction, export or
deletion of your information. Where applicable law provides these rights,
you may also object to processing, request restriction, withdraw consent
and complain to your data protection authority
We process information to provide the service you request, maintain its
reliability and security, comply with legal obligations, and act on your
choices when you connect another service. We will update this page when
our data practices change