Memelut Privacy Policy
Last updated: 7 October 2026
1. Who processes your data
Controller: Memelut Ltd., a company incorporated in the British Virgin Islands, with its registered office in Tortola, British Virgin Islands. Privacy contact: support@memelut.com. We have not appointed a data protection officer: write to support@memelut.com for any question about your data.
2. The most important point
Your wallet's private key and recovery phrase never reach Memelut. We do not receive or store them. Our server only gets the wallet's public address and a signature proving it is yours.
When the wallet is created, the app saves an end-to-end encrypted backup of the recovery phrase in your own iCloud Keychain (iPhone) or Google Block Store (Android). That backup is in your Apple or Google account, under their terms; Memelut cannot read it.
3. What data we process
Account
- email (to log in with a code and for service messages);
- if you log in with Apple or Google: the identifier and the email they pass us (Apple may give a private relay address);
- phone number, only if your account already has one from the previous version;
- username, profile photo, bio;
- invite code, if you used one.
If you browse the feed without an account, we only process the technical data needed to show you the videos (for example IP address and app version).
Wallet and activity
- your wallet's public address and, if you come from the previous version, the address of your old wallet;
- the transactions we prepare and submit for you, and their outcome;
- your in-app history: buys, sells, fundraise contributions and sell-backs, gifts, sends, creator fees;
- comments, likes, followers, blocked users.
Content
- videos, images, names and descriptions of the coins you create;
- messages and files you send in chat;
- reports you submit.
Device and usage
- a device identifier (on Android the Android ID; on iOS the identifier for vendor or a random code created by the app);
- the push notification token;
- app version, operating system, IP address;
- what you watch in the feed (viewed, rewatched, skipped, shared, copied): used to choose which videos to show you.
Contacts. Only if you choose to send to a contact: the app reads the address book on your phone to show it to you. We send our server only the number of the contact you pick, to check whether they are on Memelut. Your address book is not uploaded.
Camera, photos, Face ID / fingerprint. Only when you use the features that need them (profile photo, content, QR code scanning, unlocking the app). Biometric checks happen on your phone: we receive no biometric data.
4. The blockchain is public
Transactions on Solana are public and permanent: anyone can see an address and its transactions. In the app your username is linked to your wallet, so whoever views your profile can connect the two. What is written on the blockchain (including a coin's details at launch) cannot be deleted, even if you close your account.
5. Why we use data
| Purpose | Data | Legal basis |
|---|---|---|
| Create your account, log you in, run the wallet, buys, fundraises, gifts, chat and notifications | account, wallet and activity, content, device | contract |
| Security and abuse prevention: per-person limits, one gift per person, device and network, blocking fake accounts | email, device identifier, IP, activity | legitimate interest; legal obligation where applicable |
| Moderation: coin images and videos are checked automatically (AWS Rekognition) to find prohibited content | content | legitimate interest |
| Choosing feed videos | viewing events | legitimate interest |
| Answering authorities and keeping records the law requires | what is required | legal obligation |
We do not sell your data and we do not use it for advertising tracking.
Some checks are automatic: for example, whether you can receive a Gift Bank gift depends on rules such as a verified email, the age of your account and one gift per device and network. These checks do not produce legal effects on you. If you think a decision is wrong, write to support@memelut.com and a person will review it.
6. Who we share data with
Providers processing data on our behalf:
| Provider | For what |
|---|---|
| Amazon Web Services (Frankfurt region, eu-central-1) | servers, database, storage and delivery of videos and images, video processing, automated moderation |
| Google Firebase | storage of profile photos and chat files; receiving notifications |
| Expo | sending push notifications |
| Helius | access to the Solana network and balance reads: receives addresses and transactions |
| Pinata (IPFS) | publishing a coin's details at launch (name, symbol, description, image link) |
| Privy | wallets of previous-version users, only until their funds are moved to the new wallet |
| Gmail (Google Workspace) | sending login codes and service emails; receiving reports sent from the app |
| Telegram | internal operational alerts to our team (for example when a Gift Bank is full) |
Services you use directly, acting as independent controllers: Apple and Google (if you log in with their account, and for the cloud backup of your wallet), MoonPay and Coinbase (if you buy SOL by card: you give them your payment and identity data; we pass them your wallet address).
Other users see what is public by nature: username, photo, bio, videos, coins created, comments, followers and, on the blockchain, your wallet's transactions.
We may also disclose data to authorities when the law requires it.
7. Transfers outside the European Union
Our servers are in the European Union (Frankfurt). Memelut Ltd. is based in the British Virgin Islands, and some providers are based in the United States or process data outside the EU. When data leaves the European Economic Area, we rely on an adequacy decision of the European Commission (including the EU-US Data Privacy Framework, for certified providers) or on the European Commission's standard contractual clauses. You can ask for more information at support@memelut.com.
8. How long we keep data
| Data | How long |
|---|---|
| Account data, content, chats | for the life of the account, plus 30 days after deletion |
| Reduced copy kept after deletion (see below) | 12 months after deletion |
| Security logs (for example IP addresses and login events) | 12 months |
| Records of payments and transactions | as long as the law requires, and at most 5 years |
| Support emails and reports | 24 months |
| Data on the blockchain and on IPFS | permanently: it cannot be deleted |
When you delete your account we delete your profile, videos, comments and chats. We keep a reduced copy (email, phone, username, device identifiers, IP address, invite code, any ban) for 12 months, to prevent abuse and to restore the account if you sign up again with the same email or phone. Data on the blockchain remains.
9. Your rights
You can ask us to access, correct or delete your data, restrict its use, receive it in a readable format, and object to processing based on legitimate interest. You can withdraw any consent at any time. Write to support@memelut.com. You can also complain to your data protection authority (in Italy, the Garante per la protezione dei dati personali).
We cannot delete data written on the blockchain or act on your wallet: only you control it.
10. Minors
Memelut is not for anyone under 18 (or under the age of majority where they live, if higher). If we find an account belonging to a minor, we close it.
11. Security
The app session uses a technical cookie and a token kept only in memory. The recovery phrase is kept in the phone's secure storage and, as a backup, end-to-end encrypted in your iCloud Keychain or Google Block Store. No system is 100% secure: protect your phone and your Apple or Google account with a passcode, and never share your recovery phrase.
12. Notifications
You can turn push notifications off in your phone's or the app's settings.
13. Changes
If we change this policy in an important way, we will tell you in the app.