โ† Back / Voltar
๐Ÿง Memorion ยท Zevora

Privacy Policy

Last updated: September 21, 2026

This Privacy Policy explains how Zevora, Inc. ("Zevora", "we", "us") collects, uses, and protects information from users of the Memorion app โ€” a cognitive training application available on iOS, Android, and the web.

It applies from the moment you open the app, not from the moment you sign up. The onboarding questionnaire โ€” the questions about your memory, your sleep and your routine โ€” is recorded on our servers as you answer it, before any account exists, and it stays recorded even if you stop halfway and never come back. Section 2 says exactly what is collected there, and section 3 explains why some of those answers deserve extra care.

1. Who we are

Memorion is developed and operated by Zevora, Inc., a company incorporated in the United States. For privacy-related questions or requests, contact us at: [email protected]

2. Data we collect

We collect only what is necessary to operate the app โ€” but that is more than it may look like, so here it is in full:

Onboarding questionnaire โ€” recorded before you have an account

This is the part people are most often surprised by, so we state it first and plainly: your answers are sent to our servers screen by screen, as you give them. You do not have to finish the questionnaire, create an account, give us an email address or pay anything for this to happen. If you answer three questions and close the app, those three answers are already on our servers.

What the onboarding record contains:

  • Your name โ€” as typed on the name screen
  • Your date of birth โ€” see the next card
  • Your answers to the questionnaire โ€” see section 3
  • How far you got โ€” the last screen you reached, its position, and the total number of screens
  • Whether and when you finished
  • Your app language and platform (iOS or Android)
  • A random identifier generated by your device โ€” it ties one screen to the next so your answers form a single record. It is not your phone number, not your device serial, not an advertising ID, and it is not derived from anything about you or your hardware
  • A link to your account and to your email lead, if and when either of those comes to exist

Near the end of the onboarding, so it can save your result and let you start training, the app creates an anonymous guest account for you without asking for an email address or a password. If you later give us your email, that account becomes yours.

Your email address is notpart of this record. It is stored separately, and only if you type it in (see "Email leads" below).

Date of birth

  • Asked once, in the onboarding, on the same screen as your name โ€” the questionnaire cannot be continued without it, because your real age is the reference the memory-age result is compared against
  • Stored on your account and on the onboarding record described above
  • We accept it only if it puts you between 13 and 99 years old. Anything outside that range is discarded by the server and never written down โ€” see section 11
  • It is also sent to Paywallo, our attribution provider โ€” see section 7

Your photo (the selfie in the onboarding)

The onboarding offers to show you what your memory age looks like on your own face. If you add a photo there โ€” or change your picture later in Settings โ€” this is what happens to it:

  • Your device shrinks it to a small square and uploads it. It becomes your profile picture and stays stored as such. Replacing it deletes the previous file; deleting your account removes the address that points at it, and section 8 says what that leaves behind
  • The file is kept on DigitalOcean Spaces and served from our CDN at an address with a long random name. That address is not listed anywhere and is not shown to other users in the app, but it is not password-protected either: anyone holding the exact link can open the image
  • That is the normal path. There is a second one: when our object storage is not configured, the image is written into our own database instead, inside your account row, and never becomes a file with a public address. When your photo took that path, deleting your account deletes the image itself along with the row
  • A copy is sent to OpenAIthree times: once to a small model that is asked only "is there a human face in this image?", once to OpenAI's content moderation check, and once to the image model that generates the aged or rejuvenated portrait
  • The generated portrait is stored as a separate file, alongside the memory-age target it was drawn for. Your original photo is not replaced by it
  • We do not use your photo to identify or recognise you, we do not build a face template or any other biometric signature from it, and we never use it to match you against anyone else

Account data

  • Full name โ€” provided at sign-up or carried over from the onboarding; shown on your profile
  • Email address โ€” used for login and communications
  • Password โ€” stored only as a cryptographic hash (bcrypt); never in plain text
  • Profile picture โ€” optional, described in the card above
  • Your memory age at the end of the questionnaire, and your real age at that moment โ€” written once and never overwritten; they are what your training progress is measured against

Email leads

  • If you type your email address into the onboarding, we store it with your name, your discount code and the questionnaire answers you had given by then
  • If you then start a checkout on the website, we also store, on that same record, your IP address, your browser user-agent string and the Meta advertising cookies (_fbp, _fbc) present in your browser, so that a completed purchase can be matched back to the ad that brought you. This happens on the web checkout only โ€” the iOS and Android apps do not use it

Usage and progress data

  • Which games were played and when
  • Score and duration of each session
  • History of the 20 most recent sessions
  • Best score per game
  • Total plays per game (used to enforce the free-tier limit)

Preferences

  • Sound, vibration, notification settings (on/off)
  • Language selection

Push notification token (mobile apps only, opt-in)

  • An opaque Firebase Cloud Messaging (FCM) token issued by Apple Push Notification service (APNs) or Google Play Services
  • Linked only to your authenticated account โ€” used solely to deliver daily reminders and subscription-related notifications
  • Only collected if you explicitly opt in via the in-app prompt; removed when you disable notifications in device settings

We do not collect your device location: the apps never ask for the location permission and no GPS coordinate ever reaches us. We do work out which country you are in, from your IP address, to show prices in your currency โ€” that is described in the IP card below, including the three companies involved. We do not collect your contacts, your health app data, or any biometric identifier, and we do not read anything else from your photo library โ€” only the single image you pick.

Advertising identifier and install attribution (native apps only)

The iOS and Android apps collect an advertising identifier โ€” the IDFA on iOS, the Google Advertising ID (GAID) on Android โ€” together with the Google Play install referrer on Android, your device model, operating system version, language and country. We also record events describing your journey through the app: onboarding steps completed, paywall views, checkout started, and purchases.

This exists for one purpose: to know which marketing campaign brought you to Memorion, and how the app is used in aggregate. It is not used to build an advertising profile of you, and we do not sell it.

On iOS, the advertising identifier is collected only if you allow trackingwhen the system asks. If you decline, no advertising identifier is collected and the app works exactly the same. On Android you can reset or delete your advertising ID at any time in Settings > Google > Ads. The website at memorionapp.com collects no advertising identifier at all.

The only other device-level identifiers we collect are the FCM push token described above, used exclusively for notification delivery, and the random onboarding identifier described in the first card.

About IP addresses

Your IP address is not stored on your account, and it is not part of the onboarding record described above. Most of the time our servers only read it while they are answering the request โ€” to apply rate limits and stop abuse โ€” and nothing is written down. There are three exceptions, and they are the whole list:

  • Creating an account. Every attempt to sign up โ€” successful or not โ€” writes one line to a fraud log: the IP address of the request, your browser or device user-agent string, the email address that was typed into the form, and what happened (created, rejected, rate-limited). This is what stops one machine from creating accounts in bulk, and it is how we reconstructed a fake-install attack in June 2026. Each of those lines is deleted once it is more than 90 days old, by a sweep that runs off the app's ordinary traffic, once an hour, and off a scheduled endpoint as well. Deleting your account removes your email address from those lines immediately; the IP address and the user-agent stay until the line expires, and that part is deliberate โ€” the rate limit counts sign-ups per IP address, so a log you can wipe by deleting the account you just made would stop being a defense against the person most interested in wiping it. Section 8 repeats this where the deletion rules are listed.
  • Working out which country you are in, so we can show prices in your currency. When the request does not already tell us the country, our server sends your IP address to one of three lookup services โ€” ipapi.co, ipwho.is and ipinfo.io, tried in that order until one answers. They receive the IP address and nothing else, and they return a two-letter country code, which we keep in memory for a day so the same address is not looked up again and again. This happens in the iOS and Android apps too, not only on the website. Section 7 lists these three among the companies that receive something from us.
  • Starting a checkout on the website. That writes the IP address of the request onto your lead record, and sends it to Meta with the purchase event so the sale can be matched to the campaign. The iOS and Android apps do not do this.

3. Your questionnaire answers, and why they need extra care

In the iOS and Android apps, the onboarding asks eight questions and then runs five short tests. The questions are about how often you forget things, what you forget most (names, where you put things, appointments, passwords, what you were about to say), how your memory compares to five years ago, how many hours you sleep per night, how much screen time you have outside work, how often you do physical activity, and what motivates you to look after your memory. The tests measure verbal memory, visual memory, working memory, attention and reaction speed.

The questionnaire on the website is a different, shorter set: it asks about your mood, your mental energy, what distracts you when you learn, how often you forget important information, what you forget most, which areas you want to work on, your gender, and includes a few short writing, vocabulary and arithmetic exercises.

From those answers and those results, both versions compute a score presented as your "memory age", compare it to your real age, and store both.

We treat this as health-related data

We are not doctors and Memorion is not a diagnostic tool โ€” nothing here is a medical opinion, and a memory-age number is a training score, not a finding about your health. But answers about forgetting, sleep and physical activity, combined into a cognitive score, are close enough to information about a person's health that pretending otherwise would be dishonest. So we treat them as sensitive personal dataunder Brazil's LGPD (art. 5, II) and as a special category of personal data under the GDPR (art. 9).

What we use them for

Two things, and only two. First, to produce the result you came for: your memory age, the breakdown of which skills came out weakest, and the training plan built from them. Second, in aggregate, to understand who our users are and where the onboarding loses people โ€” how the answers are distributed across everyone who takes the questionnaire, not what any one person answered. That second use is why the answers outlive your identity in our database; section 9 explains how.

Legal basis

Our legal basis for these answers is your consent โ€” LGPD art. 11, I and GDPR art. 9(2)(a) โ€” given by taking the questionnaire. Two facts about how that works today, stated plainly rather than buried: the questionnaire is how a new user enters Memorion (the opening screen has a sign-in link for people who already have an account, but there is no way to reach the training without going through the questions), and the app links to this policy and to the Terms of Use on the screens that ask for an email address or create an account, and on the paywall โ€” all of which come after the questions. You can withdraw your consent at any time, and section 8 describes how.

What we never do with them

Your answers about memory, sleep, screen time and physical activity, your test results, your memory age, your scores and your photographs are never shared with advertising networks, analytics providers, data brokers, insurers or employers. They are not used to target ads at you. They are not sold.

Two things do leave us, and neither goes to an advertiser. The first is the gender selected in the website questionnaire, which goes to our attribution provider. The second is part of your result: if you ask for the portrait, the image model is told how old the face should look, and that number isyour memory age. It travels with the photo and with nothing else โ€” no name, no email, no date of birth, not your real age, no answer you gave. We could have hidden the number behind a phrase like "about twenty years older", and we decided not to: the part of our service that talks to the image model is never given your real age โ€” the app sends it the target age and a single up-or-down bit, and nothing else about how old you are โ€” so writing that phrase would mean handing it your date of birth as well. That would be collecting more about you in order to look like we collect less. The full list of companies that receive anything from us, and exactly what each one receives, is in section 7.

4. How we use your data

  • Compute and show your memory age, your weakest skills and your training plan
  • Generate your portrait from the photo you chose, if you chose one
  • Create and authenticate your account
  • Save and display your progress and scores
  • Enforce the free-tier limit of 3 plays per game
  • Manage your Premium subscription status
  • Apply your language and in-app preferences
  • Send daily training reminders and subscription-related notifications (opt-in only)
  • Understand, in aggregate, how people answer the questionnaire and where they abandon the onboarding
  • Measure which marketing campaign brought you to Memorion

We do not use your data for advertising beyond the attribution measurement described in sections 2 and 7, we do not sell data to third parties, and we do not build behavioral profiles for commercial purposes beyond operating the app itself.

5. Session and cookies

When you log in, we create a secure cookie called auth-token. It is:

  • HTTP-only โ€” inaccessible to JavaScript, protecting against XSS attacks
  • Secure โ€” sent only over HTTPS in production
  • Expires in 30 days โ€” or immediately on logout

We do not use advertising cookies or tracking pixels of our own on this website, but the Meta cookies described in section 2 are read from your browser at checkout if they are already there. The native apps embed one third-party analytics SDK โ€” Paywallo, described in section 7 โ€” used for install attribution and product analytics.

6. Subscriptions and payments

Premium subscriptions are processed by RevenueCat in partnership with the Apple App Store (iOS) or Google Play (Android), and by Stripe for purchases made on the website. Zevora does not store or access credit card numbers or any payment instrument details.

What comes back to us from RevenueCat is a notification for each subscription event: which product, which store, the store's transaction identifiers, the country the store reports, and when the period starts and expires. It is identified by your Memorion account number โ€” not by your email address, which we do not send to RevenueCat. We keep each of those notifications as it arrived.

For purchases made on the website, the same role is played by Stripe, and Stripe's version of the event does carry the name and email address you typed at checkout. We keep those events too, as the record of the payment. Section 8 says what happens to both when you delete your account.

To cancel, visit your device's app store subscription settings.

7. Data sharing

Your data is shared only with the infrastructure providers strictly needed to run the app:

  • Neon (database) โ€” secure storage of account, onboarding and progress data (PostgreSQL, serverless)
  • DigitalOcean โ€” hosting of the application, and storage of profile pictures and generated portraits on DigitalOcean Spaces
  • OpenAIโ€” generation of the portrait. Receives a copy of the photo you chose and one number: the age the portrait should look, which is your memory age. That number is written into the instruction sent with the image ("the same person, at 52"), together with a single bit saying whether to age or rejuvenate. Nothing else goes with it: no name, no email, no date of birth, not your real age, no questionnaire answer. The photo makes that trip three times โ€” the face check, the moderation check and the image generation. We keep no copy of either image at OpenAI: the portrait that comes back is stored on our own infrastructure, and what OpenAI retains on its side is governed by its API terms, not by us
  • ipapi.co, ipwho.is and ipinfo.io โ€” country detection, so prices appear in your currency. When the request itself does not tell us your country, our server sends your IP address to one of these three, tried in that order until one answers, and gets back a two-letter country code. They receive the IP address and nothing else โ€” no account, no identifier of ours, nothing about the questionnaire. This runs on the pricing, checkout and attribution endpoints, in the apps as well as on the website
  • RevenueCat โ€” subscription management in the iOS and Android apps. It receives your Memorion account number and what the app store tells it about the purchase. We do not send it your name, your email address or anything from the questionnaire
  • Stripe โ€” payment processing for purchases made on the website
  • Paywallo โ€” marketing attribution and product analytics, in the iOS and Android apps and on the website funnel. It receives your advertising identifier (IDFA/GAID) when available, the Google Play install referrer, device model, operating system, language and country, and events describing your progress through onboarding, the paywall and checkout. It also receives, to match you across those events and improve ad measurement, your name, email address and date of birth โ€” and the gender you picked, if you took the website questionnaire, which is the one questionnaire answer that leaves us โ€” along with your subscription status. Data is sent to paywallo.com.br and panel.lucasqueiroga.shop
  • Meta (Facebook) โ€” conversion measurement. When a purchase is completed through the website checkout, we send Meta a Purchase event containing your email address and name hashed with SHA-256, your country hashed the same way, plus your IP address, browser user-agent and the Meta cookies described in section 2
  • Firebase Cloud Messaging (Google) โ€” push notification delivery infrastructure. We send your FCM token (an opaque identifier) and notification content (e.g., "Daily reminder") to Firebase for routing to Apple Push Notification service (APNs) or Google Play Services. Notification content is generic โ€” no personal data is included in the push payload. Used only if you opt in to notifications

We do not sell your data. The attribution data described above is shared with Paywallo, and through Paywallo with the advertising platform that referred you โ€” for example Meta โ€” for the single purpose of measuring which campaign led to your install or your purchase. Apart from the gender answer noted above, no questionnaire answer, no test result, no memory age, no score and no photograph is ever sent to Paywallo, to Meta, or to any other advertising or analytics company. OpenAI is none of those things, and what it receives โ€” the photo and the age the portrait should look โ€” is spelled out in its entry above. The only company that ever sees your photo is OpenAI, and only to draw the portrait. The three country-lookup services receive an IP address and nothing else.

8. Your rights

Regardless of where you live, you may:

  • Access โ€” request a copy of all data we hold about you
  • Correct โ€” update your name from your profile settings, or write to us for anything else
  • Delete progress โ€” erase all game history from the Settings screen in the app
  • Delete your account โ€” from inside the app, described below
  • Portability โ€” receive your data in a machine-readable format
  • Withdraw consent โ€” stop using the app and request deletion at any time

Deleting your account, and what that actually erases

In the app: Settings โ†’ Danger zone โ†’ Delete account, with two confirmations. It takes effect immediately, and you do not have to email anyone to do it.

The moment you confirm, we:

  • Delete your account row โ€” name, email, password hash, profile picture address, dates of birth and age, subscription identifiers, and your push notification token
  • Delete your game history โ€” every session, every score, your daily play counters and your settings
  • Delete the record of your generated portrait
  • Strip your onboarding record โ€” your name, your date of birth, the age band derived from it, your questionnaire answers, and the links to your account and to your email lead are all removed from it. This reaches the record tied to your account and any record tied only to the email lead we hold for you โ€” the usual shape of things if you answered the questionnaire on the web, or on a device where you never signed in. What survives is an anonymous row that says someone reached a given screen on a given platform on a given day, with no way back to you. Note that this goes further than the 90-day rule in section 9: asking to be deleted erases the answers too
  • Strip your contact details out of the RevenueCat events โ€” RevenueCat attaches the email address, display name and phone number it holds for a subscriber to the events it sends us. Those are removed from our copies of those events, which otherwise stay for the reason given below
  • Remove your email address from the sign-up fraud log described in section 2

What deletion does not reach on its own, stated so you are not surprised. This list is meant to be complete; if you find something on our side that is not on it, tell us and we will both fix the product and fix this page.

  • The lead record created if you typed your email into the onboarding. It keeps that email, your name and the answers you had given at that point, because it is also the record of a commercial transaction
  • The image files themselves. Deleting your account removes the addresses that point at your profile picture and your portrait, but the files stay in our object storage until we remove them by hand. (If your picture took the second path described in section 2 โ€” stored inside the database rather than as a file โ€” it goes with the row and nothing is left behind)
  • The subscription events themselves, from Stripe, RevenueCat and Paywallo. We keep each event as the provider sent it, because that is the accounting record of a payment and deleting an account does not undo a charge. From the RevenueCat ones we remove your contact details, as described above; what remains is the product, the store, the transaction identifiers and your former account number, which after deletion points at nothing. The Stripe ones still carry the name and email address you typed at checkout, buried inside the invoice object at a path that changes with the type of event โ€” cutting that out blindly would risk damaging the accounting record itself, so we do it by hand when you ask. What deletion does cut on its own is the link from the event to your account
  • The sign-up fraud log described in section 2. Your email address is removed from it when you delete your account; what stays is the IP address, the user-agent and the outcome, because the rate limit counts sign-ups per IP address and a log that can be wiped by deleting the account that produced it stops being a defense. Every line in it is deleted 90 days after it was written
  • Any copy already sent to Paywallo, Meta, RevenueCat or Stripe

Write to [email protected] and we will erase the lead record and the image files, strip your email address and name out of the stored billing events, and pass the deletion request on to those providers.

EU / EEA users (GDPR)

Our legal basis for processing is contract performance (account and subscription management), legitimate interest (operating, securing and improving the app, and measuring which campaign brought you here), and โ€” for the memory, sleep and activity answers described in section 3 โ€” your explicit consent under art. 9(2)(a). You have the right to lodge a complaint with your local data protection authority. We will respond to verified requests within 30 days.

Brazil (LGPD)

The questionnaire answers are sensitive personal data under art. 5, II, processed on the basis of your consent under art. 11, I. You may at any time ask us to confirm what we hold, to correct it, to anonymize or delete it, to tell you with whom we shared it, and to withdraw your consent โ€” by writing to [email protected].

California residents (CCPA)

We do not sell your personal information. California residents may request disclosure of categories of personal information collected, the purpose of collection, and any third parties with whom it is shared. Submit requests to [email protected].

9. Data retention

We retain your account and progress data for as long as your account is active. If you delete your account, the effects are the ones listed in section 8, and they are immediate. If you ask us by email instead, we complete the deletion within 30 days.

Onboarding records: the identity expires, the answers stay

The onboarding record described in section 2 has a retention rule of its own, and it is the rule that lets us keep what is useful without keeping what is risky.

The identity โ€” your name, your date of birth, and the link to your account or to your email lead โ€” is erased from the onboarding records after 90 days. The clock runs from the last time you touched the onboarding, not from when you started it. Just before your date of birth is erased, we save the age band it falls in โ€” 13โ€“17, 18โ€“24, 25โ€“34, 35โ€“44, 45โ€“54, 55โ€“64, 65โ€“74 or 75+ โ€” and a single yes-or-no flag recording whether that person had left an email address or created an account. Neither of those points back at you.

The answers remain, in anonymous and aggregated form, for an indefinite period, for statistical purposes. What is left after 90 days is a row saying that someone in a given age band, on a given platform, in a given language, answered the questionnaire a certain way and stopped at a certain screen. That is what we count, and counting is the entire point: it tells us who uses Memorion and where the onboarding fails people. It no longer tells anyone who you are.

You do not have to wait 90 days, and you can ask for more than this rule gives. Deleting your account strips the record immediately โ€” and, unlike the 90-day rule, it erases your answers as well, because a request to be deleted is not a request to be counted. Section 8 has the details.

One other record keeps a clock of its own: the sign-up fraud log described in section 2 โ€” one line per attempt to create an account, holding the IP address, the user-agent and the email address that was typed into the form. Each line is deleted once it is more than 90 days old, whether or not an account came out of that attempt, and whether or not that account still exists.

10. Security

We apply the following technical measures to protect your data:

  • Passwords stored as bcrypt hashes (cost factor 10) โ€” never in plain text
  • All traffic encrypted via HTTPS/TLS
  • JWT tokens with 30-day expiry stored in HTTP-only, secure cookies
  • Database access restricted by credential isolation
  • Rate limits and size limits on the public endpoints that write onboarding data, so the funnel records cannot be flooded with junk

In the event of a data breach that affects your personal data, we will notify affected users by email within the timeframes required by applicable law (72 hours for GDPR, as promptly as feasible for others).

11. Children

Memorion is intended for users 13 years of age or older, and this is enforced in code rather than merely asserted: our servers accept a date of birth only if it puts the person between 13 and 99 years old. A date outside that range is thrown away โ€” it is never written to your account and never written to the onboarding record.

Refusing the date was not enough on its own, and we say so because the fix is recent. A date of birth arrives on the second screen of the onboarding; the answers arrive over the thirty screens after it. So when the date that arrives says the person is under 13, the onboarding record for that installation stops holding anything personal at all: the name, the questionnaire answers, the age band and the links to an email lead or to an account are removed from it and refused from then on. What is left is the funnel metric โ€” which screen was reached, on which platform, in which language โ€” and one flag remembering that this installation declared an age under 13, which is what makes the refusal hold for the screens that come later. A date of 13 or over declared afterwards lifts it, because the commonest reason for an impossible date is a year typed wrong, and a typo should not silently erase the rest of someone's session.

Being precise about the limits of all this, because it matters: it stops us from storing a child's date of birth, name and answers, but it is not an age gate. It does not stop someone under 13 from using the app, and someone who states an age over 13 passes โ€” after that there is nothing for us to know. We do not knowingly collect personal data from children under 13. If you believe a child has used Memorion or created an account without parental consent, contact us at [email protected] and we will promptly delete the account and the associated records.

12. International data transfers

Zevora is based in the United States. If you access Memorion from the EU, EEA, UK, or other regions with data protection laws, your data is transferred to and processed in the United States. We rely on standard contractual clauses and other lawful transfer mechanisms to protect data transferred internationally.

13. Changes to this policy

We may update this policy periodically. For material changes, we will notify you by email or via an in-app notice. The "Last updated" date at the top of this page always reflects the current version. Continued use of the app after changes constitutes acceptance of the updated policy.

14. Contact

Zevora, Inc.

United States

Privacy inquiries: [email protected]