Privacy
Version 2026-08-11.1. This describes what the software actually does today, not what we intend it to do later.
Who is responsible
Memoza is operated from the Netherlands and is the controller for the personal data described here. Questions, requests, or complaints: [email protected]. You also have the right to complain to the Autoriteit Persoonsgegevens.
We are the sole controller. Memoza is used directly by students; no university, faculty, or institution directs this processing, receives your data from us, or decides what happens to it.
Memoza is in beta. This policy describes what the software actually does today, and is versioned so you can see when it changes.
What we collect
You can practise without an account. Doing so creates a guest record with no name and no email — just an identifier so your progress belongs to you.
- Account
- Email address and a password, if you create an account. The password is stored only as a one-way bcrypt hash — we cannot see or recover it — and there is no self-service password reset, because the product has no route that changes or resets a password at all: if you lose it, write to [email protected] and a person verifies you and resets it by hand. The software can also sign you in by an emailed link, but that path is currently switched off — this deployment does not accept an email address from anyone new, for the reason given under Who else processes your data; where such a link is issued, we store a hash of it, never the link itself. We offer no third-party sign-in and store no identifier from one.
- Your work
- The answers you type. In medicine, that includes short written clinical reasoning about fictional teaching cases — up to six labelled sections of 400 characters each. If you scan handwritten work, the photograph is sent for text extraction and is never stored by us. On the practice screen in use today the extracted text is saved to your scan session as soon as the page uploads, before you have reviewed it, and the version you review and confirm is saved alongside it; both are kept.
- Grading records
- Points awarded, which grader produced them, the per-step breakdown, which concepts your work showed, how long you spent, whether you opened a hint, and whether the attempt was a retry. Grading also produces written feedback, which may quote your own words back to you. On the older question engine your mistakes are also filed into one of fifteen fixed error categories.
- Learning model
- A per-skill mastery estimate, and the prediction the model made about your chance of answering correctly before you answered. This is profiling in the GDPR sense: it decides which question you are shown next. It has no legal or similarly significant effect on you.
- Course context
- The courses you enrol in, your exam date, and any target grade you set.
- Course waitlist
- If you ask to be told about a course we do not have yet: the university, programme and course you typed, the exam period if you gave one, and when you joined. It is stored against your account so it can be counted as one person rather than one form submission, and so you can take yourself off the list — the entry is deleted outright when you do, and when you ask us to erase your data. We do not email waitlisters; the count is read by the people deciding which course to build next. If you gave an email address at the same time it is stored unverified, because the confirmation email is currently switched off.
Why, and on what legal basis
To provide the service — serving questions, grading them, and tracking mastery — because that is the contract you enter when you use Memoza (Art. 6(1)(b)).
To keep the service working and safe: rate limiting, abuse prevention, and error diagnosis, on the basis of our legitimate interest (Art. 6(1)(f)).
To improve how the engine teaches, described under Research below.
We do not sell personal data, we do not use it for advertising, and we do not make automated decisions producing legal or similarly significant effects.
Your mastery score is an adaptive learning estimate, never an official academic judgement. It exists to decide what you practise next. Our terms prohibit formal academic use of Memoza results — for grades, credit, admission, or progression — until that use has been separately assessed.
How AI is involved in your grade
An AI model read your written work to decide which steps earned points. Calculations are still checked deterministically, never by the AI. If you think this grade is wrong, retake the question — it stays on your record as a separate attempt.
Calculations, algebraic answers, and numeric work are verified deterministically by a computer-algebra system — no AI is involved in deciding whether they are right. AI is used in two places: written proofs in mathematics, and written clinical reasoning in medicine. In both, the model judges which steps of the marking rubric your argument evidences.
For medicine the model never assigns a score — the points come from the rubric alone. Only for a mathematics proof that takes a valid route the rubric did not anticipate may the model award a score itself, and that score is shown as a range and labelled AI-judged.
Every grade records which grader produced it, so an AI-produced grade is distinguishable from a deterministic one for as long as the record exists. On the practice screen in use today, an AI-produced grade carries the notice quoted above; a newer practice interface still in development shows which grader produced the grade but does not yet carry that notice, and will not serve students until it does.
Who else processes your data
Mathpix, OpenAI, Railway and Cloudflare are United States companies, and Zoho Mail is an Indian-seated vendor whose European region holds our mailbox. We have not yet completed the processor agreements or the transfer mechanisms for any of them. Those are a condition of Memoza holding the data of real students, so this deployment refuses to capture an email address at all: creating an account, or asking for a sign-in link, is declined for every address other than any we have explicitly allow-listed to test the mail path. The site itself is public and live — anyone can practise as a guest, and that practice is stored in the production database described above.
- Mathpix (United States)
- Receives photographs of handwritten work to extract the text. Students often write their name on exam paper, so a scan can contain personal data even though we never store the image. We send the setting that opts out of the vendor keeping images for its own quality work.
- OpenAI (United States)
- Receives the question, your written work, and the wording of the marking rubric where one applies — for a proof graded without a rubric, the number of points the question is worth instead. This covers written proofs in mathematics and written clinical reasoning in medicine. It does not receive your name, your email, or any account identifier.
- Zoho Mail (European Union region)
- Hosts our mailbox and delivers what mail the product can send: the sign-in link, and the study-plan reminders you can switch on for a course you are working through. It receives the recipient address and the message, and a copy of what was sent stays in our sending mailbox. No sign-in mail goes out today, because this deployment does not accept an email address from anyone new; a reminder is sent only for a course where you ticked the box asking for one. Writing to [email protected] also reaches a mailbox there.
- Railway (United States)
- Runs the application and the PostgreSQL database that holds everything described above. This is live: Memoza has been served from Railway since 10 August 2026, so your account, your answers and your mastery record are held in a managed database there — not, as this notice said until today, only on a development machine. Railway is a United States company and its people can reach that infrastructure in order to operate it. Our own deployment instructions specify a European region; what that guarantees about where the data physically sits, and who at the provider may reach it, is part of the agreement described below, which is not done.
- Cloudflare (United States)
- Sits in front of both memoza.app and api.memoza.app, and runs the DNS for the domain. Every request between your browser and us arrives at Cloudflare first, and is decrypted there before it is passed on, so it handles your sign-in token and everything you type on the way through. It is there to terminate the encrypted connection, serve our public pages quickly and absorb attacks. We store nothing of yours with it today; it is on the path itself rather than something we send data to, which is exactly why it went unlisted here until now.
Research
Memoza exists to test whether deterministic, exam-weighted practice helps people learn. We analyse attempt data to answer that, and may publish results.
Research analysis uses a pseudonymised export: no email address, no account identifier, and no absolute dates leave the database. Learners and questions become salted hashes, and the salt is regenerated for every export, so records cannot be linked between exports or back to you.
This is compatible further processing for research purposes under Art. 5(1)(b) and Art. 89. We are telling you at collection time because that is the condition for relying on it — it cannot be added afterwards.
We have not yet run a research export. Before any dataset is published rather than shared with named collaborators, we check that individuals cannot be picked out of it.
Product telemetry
The application records five narrowly defined product events: a practice session page opened without any activity being started, an explanation opened, the scan flow entered, the scan flow left without a submission, and an error screen shown. They exist to answer one question — where the product loses people — and each event carries only identifiers this system already issued, values from closed lists, and numbers. There is no free text in a telemetry event.
These events go to our own server and to no one else: no analytics vendor, no tag manager, no third-party script. Recording them touches nothing on your device — no cookie and no browser storage is written or read for telemetry. If an event fails to send, it is simply lost.
Each event is stamped with the version of this notice that was current when it was recorded, so what you had been told at the time is always on the record. The legal basis is our legitimate interest in understanding whether the product works (Art. 6(1)(f)); you can object at any time under Your rights below.
How long we keep things
Your account and learning record are kept while your account exists, because your mastery estimate is built by replaying your whole attempt history — deleting parts of it would silently corrupt what the engine believes about you.
Everything else is currently kept indefinitely too. That includes scan sessions and the text extracted from them, and guest records that never produced an answer. We have written a retention schedule giving each of these a defined lifetime, but nothing enforces it yet — and we would rather say so than describe a tidying-up that does not happen.
Until it is enforced, ask us and we will delete your data by hand.
Your rights
You can ask for a copy of your data, ask us to correct it, ask us to delete it, object to processing based on legitimate interest, and ask for your data in a portable form. Write to [email protected] and we will respond within one month.
A copy of your data includes the mastery estimates we hold about you and the predictions the model made about your chance of answering each question — not only your account details and your scores.
Attempt records are append-only — they are evidence, and the learning model is only correct if the record is complete, so individual attempts are never silently edited. Deletion removes the record; it does not rewrite it.
Self-service export and deletion are being built. Until they exist, email us and we will do it manually. Your rights do not depend on the button existing.
Security
Your password is stored only as a one-way bcrypt hash, sign-in links are stored hashed too, and neither hash is included when account data is read or exported. Your scan sessions are scoped to your account, and the live channel that streams your grade to your laptop is authenticated and checks that the session is yours.
Signing in stores a token on that device. It is valid for up to 365 days, and is renewed while you keep studying, so what ends a session is signing out rather than the clock. Signing out ends the session on our side, immediately and on every device you are signed in on — not only the one you clicked it on — and changing your password does the same, so a copy of your token taken by somebody else stops working too. The token is held in your browser in two places — browser storage, and a companion cookie that page scripts can read by design, because parts of the site are rendered on the server and need it; signing out clears both. On a shared computer, sign out rather than just closing the tab. We have recorded the script-readable cookie as an accepted risk rather than an unexamined one, and the reasoning is written down; we load no third-party scripts on any page, which is the main way a token in browser storage gets stolen.
Changes
This policy is versioned. If we change what we collect or why, we update the version and the date at the top, and — where the change is material — tell you in the product rather than only here.
Questions or requests: [email protected]