Privacy Policy

Privacy, without the maze.

This policy explains the information Memr.is handles across this website and the pre-release Memr.is product, including the extra rules that apply to young quizzers.

Effective: July 27, 2026

Memr.is, Inc. is a Kansas corporation. In this policy, “Memr.is,” “we,” “us,” and “our” mean Memr.is, Inc. This policy applies to memr.is, the Memr.is web and mobile applications when made available, and related beta, support, and account services that link to it.

Some product features are available only during pre-release testing. If a feature is not enabled, we do not collect information through that feature. A separate event organizer, church, team, identity provider, browser, or device service may have its own privacy practices.

Information we collect

The information we handle depends on how you use Memr.is. It can include the following categories:

  • Website and interest forms: name, email, age range, role, church or team, city, quizzing program, devices, skills, portfolio link, phone number, firm, self-attested investor status, giving or investment interest, and messages you choose to submit.
  • Account and identity data: email, password hash, display name, role, age tier derived from birth year, guardian email, connected sign-in provider identifiers, account status, accessibility preferences, and session information.
  • Family and consent data: guardian relationship, invitation and consent status, policy version and required acknowledgements, verification decision and method, revocation or expiration history, and redacted audit references. The identity service is designed not to store raw guardian identity documents.
  • Organization and team data: organization, church, and team names; contact email; memberships; invitations; roles; season context; and coach or parent relationships.
  • Learning data: assigned content, decks, reviews, study time, streaks, achievements, quiz answers, response times, missed words, mastery, reflections, study plans, assignments, and readiness summaries.
  • Match and competition data: guest or account display name, team, join code, submitted answers, buzz timestamps, clock and network-quality measurements, host verdicts, scores, ruleset, and event history.
  • Support and administrative data: support reason, status, bounded notes, escalation and follow-up history, lifecycle actions, and redacted audit records.
  • Technical and security data: IP and user-agent information or hashes, request identifiers, device and client type, cookies and session tokens, login-abuse counters, error and security events, and Turnstile abuse-prevention signals.
  • Marketing-site analytics: outside Europe, Google Analytics starts automatically when the public site loads. In Europe, it starts only after you select “Allow analytics.” When active, Google Analytics receives the page URL and title, referrer, interaction events, approximate location derived from IP, browser and device details, first-party Analytics identifiers, and the applicable regional activation or consent state. We do not intentionally send form answers, account data, or a Memr.is user ID to Google Analytics.
  • Marketing-site advertising and experience measurement: Google Tag Manager may deliver Microsoft Advertising (Bing Ads), ChatGPT Ads, Meta Pixel, X Pixel, LinkedIn Insight Tag, and Microsoft Clarity. Depending on the tag, these providers may receive page URLs, referrer and campaign parameters, clicks and conversion events, browser and device details, IP-derived approximate location, and provider cookies or advertising identifiers. Clarity may also create heatmaps and session replays from page interactions. We configure these tools not to intentionally capture form-field values, account data, or a Memr.is user ID.
  • AI-assisted business content: authorized personnel may use OpenAI's ChatGPT and Anthropic's Claude to draft, edit, summarize, research, and otherwise assist with marketing, support, operational, or product content. Those services receive the prompts, drafts, reference material, and instructions submitted to them and produce generated output. Personnel are instructed not to submit passwords, authentication secrets, raw identity documents, or unnecessary child or customer personal information.

Information that deserves extra care

Church or team information may reveal religious affiliation. Guardian and consent records concern family relationships and a child's participation. Investor or giving-interest forms may reveal financial interests. We use these details only for the purpose described when they are submitted, service operation, safety, security, and lawful administration.

Please do not put raw identity documents, passwords, access tokens, unnecessary health information, or a child's full legal name into a free-text form or support message. Coaches and other adults should use their own contact information on this marketing site unless they are a verified parent or legal guardian using an approved product flow.

How we use information

  • Provide, authenticate, personalize, and secure the website and product.
  • Create accounts, apply age-tier protections, obtain and record guardian consent, and manage family relationships.
  • Deliver study tools, track learning progress, run assignments, and show scoped progress summaries.
  • Run live matches, calculate scores, rank buzzes, keep event history, resolve disputes, and enforce fair-play rules.
  • Manage organizations, churches, teams, roles, invitations, and permitted dashboards.
  • Respond to interest forms, beta requests, support requests, safety reports, and business inquiries.
  • Measure aggregate traffic and page usefulness on the public marketing site, automatically outside Europe and after the visitor allows analytics in Europe.
  • Attribute campaigns, measure advertising conversions and audiences, diagnose site behavior, and improve the public marketing experience.
  • Draft, edit, summarize, research, and review business and product content with approved AI assistance and human oversight.
  • Prevent spam, abuse, fraud, unauthorized access, and violations of our policies.
  • Comply with legal obligations, protect users and the service, and establish or defend legal claims.

When information is disclosed

We do not sell personal information. The public marketing site uses advertising-measurement pixels and related campaign tools, but the current Memr.is product does not display third-party ads or include an in-product advertising SDK. We disclose information only as needed for the service and the situations below.

  • To service providers acting for Memr.is, as described in our Subprocessor Register.
  • To analytics, advertising-measurement, session-replay, and campaign providers when their public-site tags are active, as described in this policy and the Subprocessor Register.
  • To approved AI providers when authorized personnel use them for content generation or related business assistance, subject to internal limits on the information that may be submitted.
  • To a sign-in provider you choose, and to the browser or device service you activate, under that provider's own terms.
  • Within the role and scope of the service: for example, a verified guardian may see a linked child's safe progress and consent controls; a coach may see team-scoped roster and readiness information; an organizer and match participants may see display names, teams, answers, verdicts, and scores needed to run a match.
  • To authorities or other parties when reasonably necessary to comply with law, protect safety or rights, investigate abuse, or respond to valid legal process.
  • In a merger, financing, reorganization, sale, or transfer of all or part of the business, subject to appropriate confidentiality and notice requirements.

Public and scoped visibility

Memr.is is designed around scoped roles, but some information is visible to other people. Organization records may include an organization contact email. An unauthenticated profile can show limited display information; child names are intended to be masked to first name and last initial. Match participants can see the information needed to play and adjudicate a match.

The pre-release guest match path accepts a display name without creating an account age tier. Guests should use a non-identifying nickname, and organizers must not invite a child under 13 through guest access.

Speech recognition and recite-aloud

When recite-aloud is available and enabled, the browser or operating system's speech-recognition service may process microphone audio under its own privacy terms. Memr.is does not intentionally persist the raw microphone recording. Memr.is receives the resulting transcript for grading and may retain derived learning results such as accuracy, response time, and missed words.

Recite-aloud is unavailable for child accounts and starts off for teen accounts unless a verified guardian enables it. Browser and device behavior varies, so review the speech-service settings and notices on the device before turning the feature on.

Children, teens, and guardian rights

The interest and beta forms ask for an age range and reject a self-declared under-13 submission. Other website forms do not currently verify age and must not be used by children. A parent or legal guardian may submit their own contact information to ask about a younger quizzer. Do not submit a child's personal information in open text fields.

Under-13 product access is unavailable unless Memr.is expressly approves a flow that provides notice to the parent or legal guardian, verifies guardian authority, obtains verifiable consent tied to the current policy version, activates the family relationship, and completes legal clearance. The current calendar-year age estimate is not approved as age assurance for under-13 access. Coaches, team leaders, and event organizers cannot substitute for a parent or legal guardian unless they independently hold documented legal authority.

A verified parent or legal guardian may ask to review the child's information, correct it, withdraw consent, stop further collection, or request deletion. Withdrawing consent restricts the child's access where the information is necessary to provide the service. Teen accounts also use a guardian-consent path in the current pre-release product.

Retention and deletion

We keep information only while it is reasonably needed for the purpose described, service operation, safety, security, dispute resolution, consent evidence, legal obligations, or a valid retention hold. Depending on the record and request, we may delete it, de-identify it, restrict it, or retain a limited pseudonymized tombstone needed for match or audit integrity.

The current pre-release account-deletion flow revokes sessions and closes an eligible adult's core identity account. Complete cross-service erasure and minor deletion are not available, so under-13 product access remains closed unless Memr.is expressly approves the required deletion handling.

Current retention approach by category
CategoryWhy it is keptCurrent rule
Marketing and inquiry formsRespond to the request and keep the requested contact relationshipKept only while the inquiry and reasonable follow-up remain active; deleted on a verified request unless a legal need requires more
Marketing-site analyticsUnderstand public-site traffic and page usefulnessHandled under the retention settings configured for the Google Analytics property; aggregate reports may remain after event-level or identifier-level data is deleted
Advertising measurement, pixels, and ClarityAttribute campaigns, measure conversions, understand audiences, diagnose behavior, and improve the public siteHandled under Memr.is settings and each provider's applicable retention controls; aggregate, campaign, or audience reports may remain after event-level identifiers expire or are deleted
AI prompts, drafts, and generated contentCreate, edit, research, summarize, and review approved business and product contentKept only for the business purpose, review history, and provider settings that apply to the authorized workspace; unnecessary personal information must not be submitted
Account, learning, organization, and match recordsProvide the account, progress, teams, results, disputes, and integrity historyGenerally kept while the account or relevant relationship is active and as needed for disputes, integrity, security, or legal obligations
Guardian, consent, and verification metadataProve authority, consent, revocation, and child legal clearanceKept only as needed for the child relationship, consent history, and required legal evidence
Security, abuse, support, and audit recordsProtect accounts, investigate incidents, enforce policy, and preserve accountable operationsKept for the investigation or operational need and any valid legal or security hold
BackupsResilience and recoveryHandled under the applicable backup schedule; under-13 access remains unavailable unless supported deletion propagation is in place

Cookies, analytics choices, and abuse prevention

The marketing site uses Cloudflare Turnstile on forms to distinguish people from automated abuse. It loads Google Analytics directly and uses Google Tag Manager to manage other approved tags, including Microsoft Advertising (Bing Ads), ChatGPT Ads, Microsoft Clarity, Meta Pixel, X Pixel, and LinkedIn Insight Tag. When active, these tools may use cookies, pixels, local storage, or comparable identifiers for traffic, campaign, conversion, audience, heatmap, and session-replay measurement.

For visitors outside Europe, including visitors in the United States, these measurement tools start automatically. In Europe, the scripts do not load until the visitor selects “Allow analytics,” and the allow-or-decline choice is stored in that browser. Cloudflare's edge location signal determines whether the European choice applies; the site receives only the coarse regional decision needed for that purpose. European visitors can change their choice at any time with “Analytics choices” in the footer. Declining sends the available consent-denied signals and removes first-party cookies whose names begin with _ga where the browser permits it; provider cookies already set may also need to be cleared with browser or provider controls.

The product uses essential session and CSRF cookies, along with browser storage for preferences, workspace state, onboarding state, and temporary social-signup continuity. You can restrict browser storage, but essential account and security features may stop working. Turnstile and identity-provider features may place or read their own necessary data under their policies.

Your choices and requests

Depending on where you live and your relationship to the account, you may have rights to access, correct, delete, restrict, or obtain information, and to withdraw consent. You can also disconnect a social sign-in provider when another sign-in method remains available.

For visitors in Europe, use “Analytics choices” in the footer to allow or decline the public site's analytics, advertising-measurement, and experience-measurement tags on this browser. Declining later sends available consent-denied signals and removes first-party _ga cookies where the browser permits it. Outside Europe, these tools start automatically; browser privacy controls, provider privacy controls, and Google's Analytics opt-out browser add-on remain available.

Email hello@memr.is with the account email, the request, and enough context for us to locate the record. We may verify identity or guardian authority before acting. We will not ask for a password by email. Some information may remain where retention is legally required or necessary for safety, security, dispute resolution, or non-identifying integrity records.

Security and processing locations

We use administrative, technical, and organizational safeguards appropriate to the service, including scoped permissions, hashed credentials and session material, audit records, rate limits, and security review. No system can promise perfect security.

The website and its providers may process information in the United States and other locations where they operate, subject to the provider terms and safeguards described in the Subprocessor Register.

Changes and contact

We may update this policy as the service, providers, or law changes. We will update the date above and provide additional notice or obtain renewed consent when required. Material changes affecting child information will be handled through the guardian-consent process where required.

Questions, privacy requests, and concerns about a child's information can be sent to Memr.is, Inc. at hello@memr.is.