Privacy Policy
Last updated: August 25, 2026. This is the current policy.
1. Controller
The controller is Individual Entrepreneur ERIK FARUKSHIN, registration number 347004886, registered in Georgia at Georgia, Kobuleti Municipality, Tsikhisdziri Village, 10th Street, No. 2. Send privacy questions and rights requests to support@membleai.com.
2. Information we process
At signup we process your email address, derived password credentials, language, and account timestamps. When you use Memble we process session data, lecture ownership, uploaded video, audio and PDFs, extracted slides and text, transcripts and summaries, job status, credit usage, and error records. We may also process basic network and request information such as IP address, request time, and route to deliver and secure the service and prevent abuse. During authentication, the IP address is used to create a hashed rate-limit key. Product analytics may record display/device capabilities, page and feature use, slide exposure and zoom, media playback intervals/seeks/rates/errors, normalized API outcomes, connection state, and de-identified error categories. It does not store input values, lecture content, filenames, query strings, error messages, or stacks. The request IP address and User-Agent are transformed into a secret-keyed HMAC identifier to estimate returning visitors; the raw IP and full User-Agent are not stored in product analytics. Paddle may provide customer and transaction identifiers, product, amount, currency, tax, and payment status for fulfillment. Memble does not store complete card numbers.
3. Purposes and legal bases
We process data to perform our contract by authenticating accounts, processing files, storing and delivering results, accounting for credits, and providing support. We rely on legitimate interests or applicable law for service security, abuse prevention, troubleshooting, and improvement. We ask for consent where a use, such as certain marketing, requires it.
4. Retention and deletion
Sessions remain valid for up to 400 days after recent use and may be renewed while you continue using the service. Logging out or revoking a session ends it sooner. Email-verification tokens expire after 24 hours. Detailed product-analytics source facts that have not been linked to an account are deleted after 30 days. Hourly product-analytics aggregates and pseudonymous visitor identifiers have no fixed automatic expiry and may be retained until they are no longer needed for service analysis and improvement. Account data, linked analytics facts/aggregates, and lecture content are generally kept until you delete them or your account is deleted. After a deletion request, removal may take a reasonable period for recovery safeguards and backup rotation. Transaction, dispute, and security records may be isolated and retained as required by law or to protect legal rights, then deleted.
5. Processors and international processing
We use Cloudflare (D1, R2, and Workers for hosting, storage, security, and operational request logs), OpenRouter and selected AI model providers (slide, audio, and text processing), Resend (email), and Paddle (payment, tax, fraud prevention, and buyer support). Telegram may receive operational alerts containing an account email, internal user or lecture identifier, processing state, and error details. These providers may process data outside your country. We use contracts and provider controls to apply appropriate safeguards.
6. Cookies and device storage
A required HTTP-only cookie named memble_session keeps you signed in. The app may use browser localStorage for language choices, onboarding completion, view preferences, and upload-mode settings. Product analytics does not write a visitor identifier to cookies, localStorage, or sessionStorage and does not collect advertising profiles, input values, or lecture content. The landing page currently uses no advertising tracking cookies. Blocking the required cookie prevents sign-in.
7. Lecture content and sensitive information
Recordings may contain voices, names, health information, or other sensitive material. Upload only material you are authorized to process and avoid unnecessary personal information. Memble does not use lecture content to build advertising profiles.
8. Your rights
You may ask to access, correct, delete, restrict, or object to processing of your personal data, withdraw consent, and, where applicable, receive a copy or request portability. Email support from your account address. We verify identity before acting and explain any limit required by law or another person’s rights.
9. Security
Memble stores passwords as one-way derived values, stores hashed session tokens, uses encryption in transit, enforces access controls and per-user lecture ownership, and limits administrative access. No internet service can guarantee absolute security.
10. Changes and contact
We will announce material changes before they take effect through the page or account email. Send privacy complaints or requests to support@membleai.com. Korean users may also contact the KISA Privacy Infringement Report Center at privacy.kisa.or.kr or 118, or the Personal Information Dispute Mediation Committee at kopico.go.kr or 1833-6972.