MemoWho

Privacy Policy

Last updated 23 July 2026

This Privacy Policy describes how personal information is handled in connection with MemoWho, a mobile application for iOS and Android (the "App"). The App is developed and operated by Adam Bridges, an independent developer based in Canada, who is the individual accountable for the practices described in this Policy.

This Policy is prepared with reference to Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and its ten fair information principles, which govern the collection, use, and disclosure of personal information by private-sector organizations in Canada. Because the App may be used by individuals outside Canada, this Policy also addresses relevant obligations under the UK and EU General Data Protection Regulation and applicable United States state privacy laws, set out in section 12.

Summary of data flows
Device onlyNotes recorded within the AppNames, context of meeting, and any other details a user records, including location where enabled. Not transmitted to the developer.
TransmittedCrash diagnostics, to Firebase CrashlyticsTechnical information sent automatically if the App crashes. See section 5.
TransmittedBackup files, at the user's initiationTo local device storage, or to the user's own Google Drive. Not accessible to the developer. See section 6.

1. Accountable individual

Adam Bridges is accountable for compliance with this Policy and with applicable privacy law, including personal information transferred to third-party service providers for processing on his behalf. Inquiries, requests, and complaints concerning this Policy should be directed to the contact provided in section 16.

2. Information recorded in the App

The App allows a user to record information about people they have met, including names, the context in which they met, and any additional notes the user chooses to add. This information is stored in a database on the user's own device.

The App does not require account creation or sign-in. Information recorded by one user is not accessible to other users, and the App does not maintain any index or directory linking entries across devices or users. Uninstalling the App removes the information stored on that device.

3. Location information

The App may request access to device location in order to record where a user met a contact. This feature is optional; the App functions without it, and a user may decline the permission request when prompted.

Where enabled, location is accessed only while the App is in active use. The App does not perform background or continuous location tracking. Any location associated with a saved entry is stored on the device together with the rest of that entry and is treated as part of the information described in section 2, including for the purposes of backup and export under section 6.

A user may withdraw this permission at any time through device settings — under Settings → Privacy & Security → Location Services on iOS, or Settings → Location → App permissions on Android. Withdrawing the permission does not remove location information already saved to an existing entry.

4. Purposes and consent

Personal information is collected within the App for the purpose of allowing a user to record and later retrieve their own notes about people they have met. Location information, where enabled, is collected for the purposes described in section 3. Crash diagnostics are collected for the purpose described in section 5.

Consent for location access is obtained through the applicable operating system permission prompt at the time the feature is first used. No other collection described in this Policy requires a separate consent mechanism, as it either occurs entirely on the user's device or is necessary to operate and maintain the App.

5. Crash diagnostics

The App uses Firebase Crashlytics, a service provided by Google, to receive diagnostic reports when the App crashes. Google processes this information on the developer's behalf, as a service provider, under the Firebase Data Processing and Security Terms.

A crash report may include:

Crashlytics relies on Google's Firebase sessions component, which records that the App was launched and in use in order to calculate crash rates.

Crash reports do not include the notes described in section 2, any location information recorded by a user, or a user's name or email address. This information is not used to construct a profile of any individual, is not used for advertising, and is not sold. Google Analytics is not enabled within the App.

The current version of the App does not provide an in-app control to disable crash reporting. Crash diagnostics are the primary means by which the developer becomes aware of technical faults, as the App does not otherwise collect usage or analytics data. A user who wishes to object to this processing may do so as described in sections 11 and 13.

Data received by Crashlytics may be stored or processed on servers outside Canada, as described in section 7.

6. Backups and export

The App does not operate a cloud storage service. A backup is created only at the user's initiation, and the user determines its destination.

Local file. The App can write a backup file to the device's local storage. Once created, this file is stored outside the App's protected storage area and is managed by the user in the same manner as any other file on the device.

Google Drive. If a user connects a Google account, the App can save a backup file to that user's Google Drive. This file remains in the user's own Drive and Google account and is governed by Google's privacy policy in respect of that storage. The developer has no access to files stored in a user's Google Drive. A user may disconnect this integration within the App or through their Google account permissions.

The App requests the drive.file scope for this integration, which is limited to files the App has created or that a user has explicitly selected for it, and does not permit access to other content in a user's Drive.

Use of information obtained through Google APIs is subject to the Google API Services User Data Policy, including its Limited Use requirements. Information accessed under this integration is used solely to store and retrieve a user's own backup files, and is not transferred to any other party, used for advertising, or sold.

Encryption. A user may optionally apply a passphrase to a backup before it is created. Where applied, the backup file is encrypted on the device and remains encrypted at its destination, including in Google Drive. The developer has no ability to decrypt a passphrase-protected backup and no mechanism to recover a lost passphrase; a backup created without this option is stored as an unencrypted file. Application of encryption is optional and is the user's choice.

Independently of this feature, a device's own backup system — for example, Android's automatic backup — may copy application data to a user's account according to device-level settings not controlled by the App. This can be managed under Settings → Google → Backup on Android.

7. Cross-border processing

Crash diagnostics and, where a user enables it, Google Drive backup data may be processed by Google on infrastructure located outside Canada. PIPEDA's accountability principle requires that comparable protection be maintained when personal information is transferred to a third party for processing, including outside Canada. Where personal data is transferred from the UK or EEA in this context, that transfer relies on the European Commission's Standard Contractual Clauses.

8. Information about third parties

Because the App is designed to record information about people other than its user, entries created by a user will typically contain personal information about others. In Canada, information handled by an individual for personal purposes and not in connection with a commercial activity generally falls outside PIPEDA's application. A similar exemption exists in the UK and EU for purely personal or household activity. Neither exemption extends to use of the App in a professional, commercial, or employment-related context, and a user who uses the App for such purposes assumes responsibility for that information, including anything exported under section 6.

The developer has no access to any user's stored entries and cannot respond to requests from third parties concerning information a user may have recorded about them.

9. Safeguards

Information recorded within the App is stored in the operating system's private storage area for the App, which is isolated from other applications, and is protected by the device's passcode, Face ID, or fingerprint authentication. Data transmitted to Crashlytics and Google Drive is encrypted in transit.

Maintaining a device passcode or biometric lock, keeping the operating system current, and applying encryption to exported backup files under section 6 are safeguards within the user's control. No method of electronic storage or transmission can be guaranteed to be completely secure.

10. Retention

Information described in section 2, and any backup file created under section 6, is retained on the user's device or chosen storage location until deleted by the user. The developer does not hold this information and accordingly has no ability to retain or delete it independently of the user.

Crash traces and their associated identifiers are retained by Crashlytics for 90 days before deletion.

11. Access, correction, and complaints

Under PIPEDA, an individual has the right to be informed of the existence, use, and disclosure of personal information held about them, to request access to it, and to challenge its accuracy. The only personal information held by the developer, as distinct from information stored on a user's own device, is crash diagnostic data described in section 5, associated with a randomly generated installation identifier rather than with an identified individual.

A request concerning crash diagnostic data may be submitted using the contact details in section 16. Because the associated identifier is not linked to an identified individual, a request should include the approximate date and time of the relevant crash and the device model, to permit the record to be located. Where a record cannot reasonably be linked to the individual making the request, PIPEDA permits the developer to be unable to act on that request.

An individual may also direct a complaint regarding compliance with PIPEDA to the Office of the Privacy Commissioner of Canada at priv.gc.ca.

12. Breach notification

PIPEDA requires an organization to report to the Office of the Privacy Commissioner of Canada, and to notify affected individuals, of any breach of security safeguards involving personal information under its control where it is reasonable to conclude that the breach creates a real risk of significant harm to an individual. PIPEDA further requires that a record be kept of every such breach, regardless of whether that threshold is met, for a minimum of 24 months. These obligations apply to the developer's handling of the information described in this Policy and are followed in accordance with the Act and its regulations.

13. Additional jurisdictions

United Kingdom and European Union

For crash diagnostics processed under the UK GDPR or EU GDPR, the developer relies on legitimate interests under Article 6(1)(f) as the legal basis for processing, on the basis that this processing is limited to technical fault diagnosis, does not involve information described in section 2, and is not used to identify or profile an individual. An individual has the right to object to this processing under Article 21 by contacting the developer as set out in section 16. No special category data within the meaning of Article 9 is transmitted to the developer.

A complaint may also be directed to the Information Commissioner's Office at ico.org.uk.

United States

In the preceding twelve months, the developer has collected one category of personal information within the meaning of applicable US state privacy laws: internet or electronic network activity information, consisting of crash diagnostics. This information is collected from a user's device, used solely to diagnose and address technical faults, and disclosed only to Google as a service provider. Location information enabled under section 3 is not collected by the developer and remains on the user's device.

Personal information is not sold, and is not shared for purposes of cross-context behavioural advertising. A resident of an applicable state may request access to or deletion of the information described in this section using the contact details in section 16.

14. Children

The App is intended for users aged 16 and over and is not directed to children under 16. The developer does not knowingly collect personal information from children under 16. A person who believes a child under 16 has provided personal information to the developer may contact the developer using the details in section 16 so that it can be deleted.

15. Changes to this Policy

This Policy may be revised from time to time, including to reflect changes to the App's functionality, such as the introduction of a synchronization or account feature. Any revision will be reflected in an updated effective date at the top of this Policy. Where a change materially affects how personal information is handled, reasonable efforts will be made to bring it to users' attention within the App in advance of the change taking effect.

16. Contact

Questions, requests, or complaints concerning this Policy or the handling of personal information in connection with the App may be directed to:

Adam Bridges
memowho@adambridges.ca