Privacy policy
Last updated: 10/09/2026
This policy explains what personal data Memento collects, why, how long it is kept and what your rights are, under Regulation (EU) 2016/679 (“GDPR”) and French data protection law.
1. Data controller
OCVP Solutions — [address]. Contact for data matters: cyrilperard13@gmail.com (data protection officer details, if any).
2. Data collected, purposes and legal bases
| Data | Purpose | Legal basis |
|---|---|---|
| Email address, password (hashed with argon2id) | Create and manage the account, sign in | Performance of the contract (Art. 6(1)(b)) |
| Email verification token, password reset token | Secure the account | Legitimate interest / security duty |
| Preferred language, display preferences | Adapt the interface | Performance of the contract |
| Reading history, favourites, sheets marked “known” | Provide progress tracking and favourites | Performance of the contract |
| Monthly counter of unlocked Premium sheets | Enforce the free-plan quota | Performance of the contract |
| Subscription status, Stripe identifiers, period dates | Manage the subscription and Premium access | Performance of the contract |
| Card data | Charge the subscription | Performance of the contract — handled by Stripe, never stored by us |
| Invoices and accounting records | Accounting and tax obligations | Legal obligation (Art. 6(1)(c)) |
| IP address (transient), user agent, technical logs, rate-limit counters | Security, abuse and fraud prevention | Legitimate interest (Art. 6(1)(f)) |
| Search queries (text, language, result count) — no account identifier | Improve the catalogue and search relevance | Legitimate interest |
| Sheet feedback (“helpful” yes/no, comment, salted client fingerprint) | Improve sheet quality, limit repeat votes | Legitimate interest |
| Back-office action log | Traceability and back-office security | Legitimate interest |
3. Cookies
Memento only uses cookies that are strictly necessary and exempt from consent:
- session cookie (keeps you signed in during the visit);
memento_locale: remembers your language;REMEMBERME: only if you tick “keep me signed in”;- anti-CSRF token: protects forms.
No advertising cookies, no third-party analytics and no sharing for marketing. During payment, Stripe’s domain may set its own technical cookies needed for transaction security.
4. Recipients and processors
- Host: [name, country] — website and database hosting.
- Stripe Payments Europe, Ltd. — payment processing and subscription management (Stripe privacy policy).
- Transactional email provider: [name] — verification, reset and billing emails.
We do not sell your data and do not share it with third parties for commercial purposes.
5. Transfers outside the EU
Some processors (in particular Stripe) may process data outside the EU, notably in the United States. Such transfers are covered by appropriate safeguards: the European Commission’s standard contractual clauses and/or certification under the Data Privacy Framework.
6. Retention periods
- Account and related data: for the life of the account, then deleted when it is closed. Accounts inactive for [24 months] get a warning email and are then deleted.
- Invoices and accounting data: 10 years (French Commercial Code, Art. L.123-22).
- Verification / reset tokens: from 1 hour to a few hours.
- Security logs and IP addresses: up to 12 months.
- Search logs: [13 months], then deleted or anonymised.
- Payment events (Stripe webhooks): [90 days].
- Back-office audit log: [3 years].
7. Your rights
You have the following rights over your data:
- access and a copy;
- rectification;
- erasure;
- restriction and objection (for processing based on legitimate interest);
- data portability;
- to give instructions about your data after your death.
You can exercise the access and erasure rights yourself from My account → Privacy & data (JSON export and account deletion). For any other request, email cyrilperard13@gmail.com; proof of identity may be requested in case of reasonable doubt. We reply within one month.
8. Complaints
You may lodge a complaint with the French data protection authority (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — cnil.fr, or with your local supervisory authority.
9. Security
Traffic is encrypted (HTTPS/TLS), passwords are hashed (argon2id), the app enforces a nonce-based Content Security Policy, rate limiting on sensitive endpoints, and regular database backups.
10. Minors
The Service is not intended for people under 15 without parental authorisation.
11. Changes to this policy
This policy may change. Material changes are communicated to Members and the “last updated” date at the top of the page is revised.