Memmaros 🦣

Privacy policy

Last updated: 1 September 2026

Memmaros is a teammate that lives in your WhatsApp group, sorts out what gets said and hands you back a board. This policy is written against the code that is actually published, not copied from a template: if it says here that something is not stored, it means there is not a single line that stores it.

Who the controller is

Fina Fred Technologies LLC

A limited liability company incorporated in the State of Wyoming (United States), filing ID 2026-001915961.
Registered address: 5830 E 2nd St, Ste 7000 #33939, Casper, WY 82609, United States.
Owner and sole manager: Inaki Marzo Diaz.

Data contact: team@memmaros.com

Where this document says "we", it means that company. Where it says "Memmaros", it means memmaros.com, its subdomains and the WhatsApp number that joins your group.

Roles. When a team adds Memmaros to its group, that team is the data controller for the data flowing through its conversation and Memmaros acts as the processor, handling it only to provide the service. For their own account data and for the waiting list, we are the controller.

What data we process, when and what for

WhatWhenWhat forLegal basis
Your email address, the date and which part of the site you signed up from When you join the waiting list Letting you know when access opens Your consent (art. 6.1.a GDPR)
Your email address, your name and your password When you create an account Giving you access and letting you recover it. The password is not stored: what is stored is an argon2id hash, which cannot be reversed Performance of the contract (art. 6.1.b GDPR)
The messages in the group where Memmaros is, and the transcript of voice notes For as long as Memmaros is in the group Building the team's board, memory and summaries Performance of the contract with the team (art. 6.1.b GDPR), and each person's consent on day one
Whether you open a product news email we send you On opening it, through an invisible one pixel image Knowing in aggregate how many people open them, so we write less and better Legitimate interest in measuring what works (art. 6.1.f GDPR)
The page you visit, where you came from and the campaign tags in the address When a public page of the site loads Counting visits. No cookies and no identifying you: exactly what is stored is explained below Legitimate interest in knowing whether anyone cares about this (art. 6.1.f GDPR)

Whoever does not want to be there, is not there

Every person in the group gives their consent on day one. Anyone who does not accept gets no profile and is not analysed, and anyone can write "olvídame" (forget me) in the group and disappear entirely. Their boss does not have to ask for it and neither do you have to write to us: it happens from the chat itself.

What an email of ours measures

Service emails (confirmation, password recovery, account notices) measure nothing at all: they are sent from mail.memmaros.com, which is the transactional mailbox, and there is no measurement there.

Product news emails, when there are any, measure one single thing: whether you open them. The open is detected with an invisible one pixel image and looked at in aggregate, to know whether the subject line works. Links are neither measured nor rewritten: they go straight to their destination, without passing through any redirector of ours or of anyone else, so the address you see when you hover over them is the real one. If you would rather the open was not measured either, your email client can block images and nothing gets recorded. Every email of ours also carries the List-Unsubscribe header, so your email client offers you a one button unsubscribe.

How we count visits

We use no Google Analytics, no cookies and no third party pixels. The counter is ours and works the way Plausible does: the identifier for the day is a cryptographic hash of a salt that changes daily, the domain, your IP address and your browser. Neither the IP address nor the browser is stored raw, and because the salt rotates every day, tomorrow you are already a different visitor. What stays stored is a structure that counts how many there were, not who they were: it is mathematically incapable of saying whether you were one of them.

Who we share data with

What does not leave here: we do not sell personal data, we do not pass it to advertisers or data brokers, and we never train models on your conversations. Voice notes are transcribed locally, before the message even enters the system.

Where your data is processed

The Memmaros server and database sit in Railway's Amsterdam (Netherlands) region, so your data is processed inside the European Union. The controlling company is a US one, so there can be access from the United States to run and support the service; those transfers are covered by the safeguards provided for in applicable law, such as standard contractual clauses. That is worth knowing before you add Memmaros to your team's group, which is why it is here and not in a footnote.

Two details that belong here rather than hidden away. The disk holding the database is encrypted at rest by the infrastructure provider. And the fragment sent to the language model to write a reply may be processed outside the European Union, at that model provider: it is a fragment, not the whole conversation, and that provider is named above.

How long we keep it

A team's conversations and board are kept for as long as the team keeps its space open. When the owner deletes the team, the deletion is real, not an archive: the messages, the profiles and the summaries all go. A waiting list email is kept until we give you access or until you ask us to remove it.

Your rights

You can request access to, rectification of, erasure of, restriction of, objection to and portability of your data, and withdraw your consent where the processing is based on it. Before writing to us, two of those happen on their own in one click: taking everything with you (Markdown, Jira compatible CSV or JSON) and deleting the whole team. For anything else, write to team@memmaros.com from the very address you want to query or delete. You may also lodge a complaint with the competent supervisory authority (in Spain, the Agencia Española de Protección de Datos).

Changes to this policy

If anything said here changes, the date at the top changes. If the change affects what we do with data you already gave us, we tell you by email before applying it.