Privacy
Last updated 18 August 2026.
Memono is built so that this page can be short.
Nothing is collected
There is no account, no analytics, no tracking, and no third-party SDK. Nothing about you or your things is gathered, and nothing is sent anywhere on its own. There are exactly five things that reach the network, every one of them because you asked: handing or lending something to another person, sharing a home with somebody, iCloud sync, which is off until you turn it on and goes to your iCloud rather than to us, the feedback form, which carries what you typed into it and nothing else, and asking what a thing is worth, which is the only one of the five that sends a photograph.
Everything stays on your phone
Your photos, the cutouts made from them, and the names, boxes, and categories you give them are stored in the app's own database on your device. The cutting out, the guess at what a thing is, the reading of any words printed on it, and the recognising of something you have photographed before all run on the phone's own hardware.
Camera and photo library
Memono asks for the camera or your photo library when you add an item, and uses them to take or choose the picture you asked for. Scanning a room uses the camera in the same way, and what it keeps is the shape of the room rather than a picture of it: walls, doors, and the furniture standing in it. All of it is processed on the device and none of it leaves.
Holding the camera up to something and asking whether you already own one, or where it goes, is the one place the camera is used without a photograph being taken. While that screen is open the app reads the picture the lens is showing, several times a second, to compare what it can see against the things you have already filed. Every frame is read on the phone and thrown away immediately: none of them is saved, added to your things, put in your photo library, or sent anywhere. Nothing is filed by pointing at it. Close the screen and the reading stops.
iCloud sync
Off unless you switch it on in Settings. On, your things are kept in your own private iCloud database, which is Apple's and yours: we have no access to it and no way to ask for one. It exists because nothing written on a phone survives the app being deleted, and a copy in your own iCloud is the only copy worth having.
Switch it off and the phone goes back to keeping everything locally. Nothing about sync is ever turned on for you.
Locking the app
You can put Face ID, Touch ID, or your passcode in front of the app, and mark individual things as private so they are kept off the screens until it is unlocked. This is handled by the system: Memono is told yes or no, and never sees your face, your fingerprint, or your passcode.
Giving or lending something to someone
You can hand an item to another person two ways, and they work differently. This is one of the three places Memono puts anything on a machine of ours. The others are the introduction you send when joining somebody's home, and the picture you send when asking what a thing is worth. All three are worth being exact about.
As a file, over AirDrop or as an attachment, the item goes straight from your phone to theirs. Nothing is uploaded and nothing is stored anywhere in between.
As a link, the item is put somewhere the other phone can fetch it from, because that is the only way a link can be short enough to send. Before it leaves your phone it is encrypted, and the key to open it is placed in the part of the web address after the #: the one part of a URL that no browser or app ever transmits to a server. The key travels to whoever you sent the link to and reaches nobody else, ourselves included. What is stored is a file of random-looking bytes under a random name, which we cannot read and could not hand to anyone in a useful form.
It is deleted as soon as the other person collects it, and in any case after thirty days. Until it is collected the item is still yours: it stays in its box, and you can take it back at any point, which stops the link working.
Once someone has collected it, what they do with it is up to them, the same as anything else you put in a message.
Lending works the same way, with a different ending: the link files the thing on the other phone as borrowed from you, and the original never leaves your own. The parcel is sealed exactly as a given one is. One extra thing rides inside it: the first name you chose in Memono, because "borrowed from Aki" is what the other person's screen exists to say. It goes to them and to nobody else, ourselves included.
A nudge about a lent thing is one more sealed file on the same shelf, under a random-looking name that only the two phones can work out, and there is deliberately nothing inside it: an encrypted timestamp, and no message. The words the borrower reads are composed by their own phone from what it already holds. While something borrowed is with you, Memono checks that one spot now and then, including in the background, so the owner's knock can reach you as a notification; each check carries the random name and nothing else, and tells us nothing about either phone. A nudge comes off the shelf the moment it is seen, and in any case after thirty days.
Saying a borrowed thing went home travels the same road the other way, once. When the borrower taps I Gave It Back, their phone leaves one more sealed timestamp on the shelf, under a second name that only the two phones can derive. While something of yours is out on loan, your Memono checks that spot the same way, and when the word is there it ends the loan on your side and tells you the thing is back; the words on your screen are composed by your own phone, from the name you wrote on the lend yourself. The same rules hold throughout: nothing readable inside, each check carrying the random name and nothing else, and the file gone the moment it is collected, or in any case after thirty days.
Sharing a home with somebody
Two people can keep one home between them, and you can lend a single box to a friend. Both work through iCloud, so both need sync switched on, and what is shared stays in the iCloud of whoever owns it: their photos, counted against their storage, on Apple's machines rather than ours.
What the other person gets is what was shared and nothing more. A household shares the whole home. A friend lent one box receives that box and what is in it. The room it stands in, and therefore where in your home it is, is deliberately left out of what travels.
A link alone lets nobody in. The invitation is an address rather than a key, and the share never accepts "anyone who has it". Beside the link the owner reads out a six-digit code that exists on their screen and nowhere else. Whoever is joining types that code and writes their name, and what they send is encrypted with a key made from the code before it leaves their phone. The owner sees the name and decides. Only then is that person written onto the share, and only from that moment does the link mean anything to their phone.
That introduction is the second of the three things Memono puts on a machine of ours, and it is a name and the anonymous identifier iCloud already files that person under: no email address, no phone number. It goes to the same shelf a given item goes to, sealed the same way and just as unreadable to us. A code is good for a day, and is retired the moment it has let somebody in.
A reply from somebody let in to look. When someone in a home can't find a thing, anyone in the household can answer, including a member whose phone is only allowed to look at what is shared. Their words go as one more sealed file on the same shelf, under a random-looking name that only phones inside the household can work out, encrypted with a key grown from the thing's own identity, which nobody outside the home knows: we could not read a word of it if we wanted to. Inside is the sentence they typed and the same anonymous identifier the introduction carries, so the reply can say who answered. The phone that raised the search collects it and the file comes off the shelf; uncollected, it is gone in thirty days like everything else there.
Anybody can leave a shared home whenever they like, and the owner can take anybody out of it. Either way that phone's copy of what was shared is cleared off it. The one thing that does not come back is a box somebody moved into your home: it was given to the home, and leaving does not take it away again. The app says so before you go.
The feedback form
There is a page in Settings for telling us what you think, and it goes only when you press Send. What travels is the words you typed, which of the three kinds of message you picked, the version of the app, and the language it is set to. Nothing else: no name, no account, no identifier of any sort, and nothing at all about your boxes or the things in them.
It does not go through Mail. A mail composer would send it from your own address whether or not you wanted it to, and would not work at all on a phone with no mail account set up. Instead the app hands the message to a form relay, Formspree, which turns it into an email and forwards it to us. Their servers see the message on its way through, and nothing of yours is stored there beyond it.
If you would like a reply there is a field for an address, and it is the only way we would have one. Leave it empty and the message arrives with no way back to you, which is how it arrives unless you decide otherwise.
Asking what a thing is worth
Memono can ask Google what a thing is, and there are two places it offers to. There is a button on the item itself, and there is a card that comes up when you throw something across the pile, which asks whether you still want it and offers to look up what it sells for. Both are offers: nothing goes anywhere until you press the one that asks. You can switch the card off in Settings under Privacy, and the button is only ever a button.
This is the one thing in Memono that sends a photograph anywhere, and it is worth understanding why it has to.
Google Lens shows its answer only to whoever asked the question, and a phone cannot ask on a browser's behalf: the picture has to be at an address the browser can point Google at. So the cutout goes to a machine of ours under a random name, Safari opens Google Lens on that address, and Google fetches it once. What travels is the cutout of the thing and nothing else. Not its name, not the box or room it lives in, not the household, not your other pictures, and nothing that identifies you or the phone.
This picture is not encrypted, because the point of sending it is that a stranger's computer can read it. Anyone holding the address can read it too, and the address is a hundred and twenty-eight random bits that exists in one link. Once Google has looked, what it does with the picture is governed by Google's privacy policy rather than by this one.
The picture is deleted within thirty days whether or not you ever ask again. Nothing is kept about which items you asked about, or when, or what came back.
Deleting
Delete an item and it is gone. Delete the app and everything on the phone goes with it. A copy exists elsewhere only where you put one, and there are four ways to have done that: whatever is in your own iCloud, if you turned sync on, which is yours to delete; a thing you handed to somebody, which we cannot read and which deletes itself within thirty days; a picture you sent to ask what something is worth, which goes the same way within thirty days; and whatever you are sharing with another person, which sits on their phone for as long as you go on sharing it. Stop sharing, or take a lent box back, and their copy goes when the share does.
If any of this changes in a future version, this page changes first.