Legal

Memelut Privacy Policy

Last updated: 7 October 2026

1. Who processes your data

Controller: Memelut Ltd., a company incorporated in the British Virgin Islands, with its registered office in Tortola, British Virgin Islands. Privacy contact: support@memelut.com. We have not appointed a data protection officer: write to support@memelut.com for any question about your data.

2. The most important point

Your wallet's private key and recovery phrase never reach Memelut. We do not receive or store them. Our server only gets the wallet's public address and a signature proving it is yours.

When the wallet is created, the app saves an end-to-end encrypted backup of the recovery phrase in your own iCloud Keychain (iPhone) or Google Block Store (Android). That backup is in your Apple or Google account, under their terms; Memelut cannot read it.

3. What data we process

Account

  • email (to log in with a code and for service messages);
  • if you log in with Apple or Google: the identifier and the email they pass us (Apple may give a private relay address);
  • phone number, only if your account already has one from the previous version;
  • username, profile photo, bio;
  • invite code, if you used one.

If you browse the feed without an account, we only process the technical data needed to show you the videos (for example IP address and app version).

Wallet and activity

  • your wallet's public address and, if you come from the previous version, the address of your old wallet;
  • the transactions we prepare and submit for you, and their outcome;
  • your in-app history: buys, sells, fundraise contributions and sell-backs, gifts, sends, creator fees;
  • comments, likes, followers, blocked users.

Content

  • videos, images, names and descriptions of the coins you create;
  • messages and files you send in chat;
  • reports you submit.

Device and usage

  • a device identifier (on Android the Android ID; on iOS the identifier for vendor or a random code created by the app);
  • the push notification token;
  • app version, operating system, IP address;
  • what you watch in the feed (viewed, rewatched, skipped, shared, copied): used to choose which videos to show you.

Contacts. Only if you choose to send to a contact: the app reads the address book on your phone to show it to you. We send our server only the number of the contact you pick, to check whether they are on Memelut. Your address book is not uploaded.

Camera, photos, Face ID / fingerprint. Only when you use the features that need them (profile photo, content, QR code scanning, unlocking the app). Biometric checks happen on your phone: we receive no biometric data.

4. The blockchain is public

Transactions on Solana are public and permanent: anyone can see an address and its transactions. In the app your username is linked to your wallet, so whoever views your profile can connect the two. What is written on the blockchain (including a coin's details at launch) cannot be deleted, even if you close your account.

5. Why we use data

Purpose Data Legal basis
Create your account, log you in, run the wallet, buys, fundraises, gifts, chat and notificationsaccount, wallet and activity, content, devicecontract
Security and abuse prevention: per-person limits, one gift per person, device and network, blocking fake accountsemail, device identifier, IP, activitylegitimate interest; legal obligation where applicable
Moderation: coin images and videos are checked automatically (AWS Rekognition) to find prohibited contentcontentlegitimate interest
Choosing feed videosviewing eventslegitimate interest
Answering authorities and keeping records the law requireswhat is requiredlegal obligation

We do not sell your data and we do not use it for advertising tracking.

Some checks are automatic: for example, whether you can receive a Gift Bank gift depends on rules such as a verified email, the age of your account and one gift per device and network. These checks do not produce legal effects on you. If you think a decision is wrong, write to support@memelut.com and a person will review it.

6. Who we share data with

Providers processing data on our behalf:

Provider For what
Amazon Web Services (Frankfurt region, eu-central-1)servers, database, storage and delivery of videos and images, video processing, automated moderation
Google Firebasestorage of profile photos and chat files; receiving notifications
Exposending push notifications
Heliusaccess to the Solana network and balance reads: receives addresses and transactions
Pinata (IPFS)publishing a coin's details at launch (name, symbol, description, image link)
Privywallets of previous-version users, only until their funds are moved to the new wallet
Gmail (Google Workspace)sending login codes and service emails; receiving reports sent from the app
Telegraminternal operational alerts to our team (for example when a Gift Bank is full)

Services you use directly, acting as independent controllers: Apple and Google (if you log in with their account, and for the cloud backup of your wallet), MoonPay and Coinbase (if you buy SOL by card: you give them your payment and identity data; we pass them your wallet address).

Other users see what is public by nature: username, photo, bio, videos, coins created, comments, followers and, on the blockchain, your wallet's transactions.

We may also disclose data to authorities when the law requires it.

7. Transfers outside the European Union

Our servers are in the European Union (Frankfurt). Memelut Ltd. is based in the British Virgin Islands, and some providers are based in the United States or process data outside the EU. When data leaves the European Economic Area, we rely on an adequacy decision of the European Commission (including the EU-US Data Privacy Framework, for certified providers) or on the European Commission's standard contractual clauses. You can ask for more information at support@memelut.com.

8. How long we keep data

Data How long
Account data, content, chatsfor the life of the account, plus 30 days after deletion
Reduced copy kept after deletion (see below)12 months after deletion
Security logs (for example IP addresses and login events)12 months
Records of payments and transactionsas long as the law requires, and at most 5 years
Support emails and reports24 months
Data on the blockchain and on IPFSpermanently: it cannot be deleted

When you delete your account we delete your profile, videos, comments and chats. We keep a reduced copy (email, phone, username, device identifiers, IP address, invite code, any ban) for 12 months, to prevent abuse and to restore the account if you sign up again with the same email or phone. Data on the blockchain remains.

9. Your rights

You can ask us to access, correct or delete your data, restrict its use, receive it in a readable format, and object to processing based on legitimate interest. You can withdraw any consent at any time. Write to support@memelut.com. You can also complain to your data protection authority (in Italy, the Garante per la protezione dei dati personali).

We cannot delete data written on the blockchain or act on your wallet: only you control it.

10. Minors

Memelut is not for anyone under 18 (or under the age of majority where they live, if higher). If we find an account belonging to a minor, we close it.

11. Security

The app session uses a technical cookie and a token kept only in memory. The recovery phrase is kept in the phone's secure storage and, as a backup, end-to-end encrypted in your iCloud Keychain or Google Block Store. No system is 100% secure: protect your phone and your Apple or Google account with a passcode, and never share your recovery phrase.

12. Notifications

You can turn push notifications off in your phone's or the app's settings.

13. Changes

If we change this policy in an important way, we will tell you in the app.