MemParcel
Back to website
中EN
Legal·www.memparcel.com

Privacy Policy

Effective: 17 September 2026 Last updated: 17 September 2026 Version: 1.0

This Policy may be updated from time to time. We will revise the dates above, and will give separate notice of material changes (see Section 20).


1. Introduction and Scope

1.1 Issuing entity. This Privacy Policy (this "Policy") is issued by Memparcel Intl Trading Limited (憶安寶有限公司) ("we", "us", "our" or the "Company"), a limited company incorporated under the Companies Ordinance (Cap. 622) of the Hong Kong Special Administrative Region of the People's Republic of China, company number 80587775, with its registered office at ROOM 2253, 22/F, HOI TAI FACTORY ESTATE, TSING YEUNG CIRCUIT, TUEN MUN, HONG KONG. Except as provided in Section 2.2, the Company acts as controller in respect of the processing described in this Policy.

1.2 What this Policy covers.

  1. the memparcel desktop application for macOS, Windows and Linux;
  2. the memparcel.com website and its subdomains; and
  3. the licence key, credit, customer support and email communication services associated with the foregoing.

This Policy applies to the memparcel desktop application and related services that you obtain and use via memparcel.com and its subdomains (the "Services"). If the memparcel product you use was obtained via memparcel.cn, it is operated by a different entity and its model channel, payment channel and data-handling arrangements differ from those of the Services; the handling of personal information in that product is governed by the privacy policy published within that product and on memparcel.cn, and this Policy does not apply to it.

1.3 What this Policy does not cover. (a) third-party model providers you elect to connect (Section 5.1), each of which acts as an independent controller in respect of its own processing; (b) third-party websites, products or services linked from the Services; and (c) any software obtained other than through the Company's official channels.

1.4 Relationship to the Terms of Service. By using the Services you acknowledge that you have read and understood this Policy. This Policy is not a contract; your use of the Services is governed by the Terms of Service. The commitments made in this Policy are nevertheless binding on the Company.

1.5 Defined terms.

TermMeaning
Personal Dataany information relating to an identified or identifiable natural person
Processingany operation performed on Personal Data, including collection, recording, storage, retrieval, use, transmission, erasure or destruction
Controllerthe entity which, alone or jointly with others, determines the purposes and means of Processing
Processor / Sub-processoran entity which Processes Personal Data on behalf of a controller; a sub-processor is engaged by a processor to carry out further Processing
Local Content Datacontent you import or create, and derivative assets generated by the Services on your device (Section 3.1)
Submitted Contentthe specific content you affirmatively submit for AI or transcription processing

1.6 Summary (does not replace the operative text). memparcel is a desktop application. Your content is stored by default on your own computer, and no copy is held on the Company's servers. Organising that content requires an AI model, and that step requires an internet connection. Stated accurately: your data stays local; the model goes online. The Company operates no model of its own — content you submit for processing is handled by a third-party model provider engaged by the Company (currently OpenAI, which processes in the United States; see Section 6.2), or, if you bring your own key (BYOK), by the provider you select. In addition, where you use audio transcription, your audio file is held in the Company's staging storage in Singapore and processed by a speech-to-text provider in Singapore; it is deleted immediately on successful transcription and, where unsuccessful, cleared within no more than 48 hours (see Section 6.3).


2. The Company's Role in Processing

2.1 Local Content Data: the Company is neither controller nor processor. Local Content Data resides on your device. The Company does not collect, receive, store, access or index such data and has no technical means of accessing it. Control rests entirely with you.

There are two exceptions, both of which arise only where you initiate the processing: (a) content you submit for processing (Section 5); and (b) audio files where you use the transcription function, which are under the Company's control while held in staging storage and to which the Company is technically able to gain access during that period (Section 6.3.2). Save for those exceptions, the general rule in this Section is unaffected.

2.2 Submitted Content and transcription audio: the Company acts as processor. Such content is transmitted through the Company's systems and processed by the third-party providers engaged by the Company. The purposes and means of Processing are determined by you through the act of initiating the processing request, and the Company Processes such content solely on your instructions; the Company therefore acts functionally as a processor.

2.3 Account, transaction and website data: the Company acts as controller. In respect of the categories in Sections 3.2 to 3.6, the Company determines the purposes and means of Processing.


3. Categories of Personal Data Processed

3.1 Local Content Data (held on your device; not received by the Company). The conversations, documents, audio files, notes and other materials you import or create, together with the memory, knowledge and cognition assets generated from them by memparcel.

Such data is stored by default in the application data directory on your own device. No copy is held on the Company's servers, and the Company cannot read, browse, search or restore such data.

The exceptions, each arising only where you initiate the processing, are:

  1. AI organisation: the specific portion of content you submit leaves your device by the route described in Section 5; upon completion, the result is returned to your device;
  2. Audio transcription: the audio file you submit leaves your device by the route described in Section 6.3.2 and is held in the Company's staging storage, deleted immediately on successful transcription and, where unsuccessful, cleared within no more than 48 hours; the transcript is returned to your device.

3.2 Authorisation and transaction data (held by the Company). The Services do not use cloud accounts. To provide authorisation, subscription and credit services, the Company processes:

  1. the email address used for payment — to send your licence key and receipts, to process refunds, to verify your identity when re-issuing a key you have lost, and to contact you in connection with customer support;
  2. a hash of the licence key (a one-way cryptographic fingerprint derived from the key, which cannot be reversed to reveal the key itself) — the Company's systems hold only that fingerprint; the plain-text key is neither stored nor recoverable;
  3. the device machine identifier (machineId) — sent by the application with its requests, used to bind the key to a device and to verify that binding;
  4. a region identifier — used to determine the model menu, currency and payment channel applicable to you;
  5. subscription and authorisation status — type (trial or paid), validity period and renewal status;
  6. credit balance, grant records and consumption records;
  7. the type of model provider you configure within the application and related settings (excluding the key itself).

Regarding API keys: where you bring your own key (BYOK), your API key is stored solely in the system keychain of your operating system and is never uploaded to the Company's servers. The Company cannot read that key.

3.2.1 Limits on the use of device identifiers. For authorisation and binding, the only device identifiers the Company processes are: the device machine identifier (machineId), and a group value derived from that identifier and a Company secret by a one-way hash (used solely for the pricing groups described at Section 7.7 of the Terms of Service, so that a given device always falls into the same group).

The Company does not collect operating system versions, application versions or any device content unrelated to that verification in connection with authorisation. The device machine identifier is used only to verify binding and is not proof of entitlement.

3.3 Transaction and billing data (principally handled by the payment processor). The Company does not access, receive or store your card number, card verification value or other payment credentials. Such information is collected and processed directly by Stripe (https://stripe.com/privacy ) and does not pass through, and is not stored on, the Company's systems. The Company receives only what is necessary to perform the contract: order number and status, transaction amount and currency, transaction time, subscription plan, the payment email address and refund status.

Please note: Stripe is a payment processor and is not a Merchant of Record. The seller in respect of your purchase is the Company (see Section 7.2 of the Terms of Service).

3.3.1 Local profiles (held on your device). The Services provide several local profiles on your device for organising the materials held there. Their identifiers and the materials they organise are held on your own device and are not received by the Company.

⚠️ Please note: the absence of a cloud account does not mean that no data leaves your device in the course of use. When you use a cloud model, audio transcription, payment or authorisation verification, the data necessary to perform that function is still transmitted over the network (see Sections 5 and 6). The extent to which files and access are isolated as between local profiles on the same device is as described in the functional documentation for the Services; the Company does not describe the ability to create multiple local profiles as verified cryptographic isolation.

3.3.2 Model call records (server-side). When you call a model or audio transcription through the Services, the Company records on its servers, for that call: the licence key identifier, the model called, usage (token counts or audio duration), the credits deducted, the time taken, and the status returned by the upstream provider.

  • Purposes: billing and credit settlement, balance and usage enquiries, detection of anomalies and abuse, and the investigation of billing disputes;
  • No content: these records do not contain the content you submit for processing, nor the text of any model output;
  • Retention: see Section 9.2.

3.4 Website and advertising measurement data. See Section 12.

3.5 Support and communications data. Where you contact the Company, we Process your email address, the content of the communication and such related information as is necessary to handle your request.

3.6 Technical and diagnostic data. The Services do not currently collect crash logs, error reports or usage statistics. The application does not integrate any crash diagnostics or product analytics service, and no operational logs are generated for the Company.

Should the Company introduce product analytics or crash diagnostics in a future release, it will give notice under Section 20.2 before that functionality is released, and will state in this Section the specific items collected, the provider's name and location, the retention period and the legal basis. Any such collection will be subject to a setting allowing you to turn it on or off.

3.7 Data the Company expressly does not Process. The Company does not:

  1. collect, upload or scan any content on your device other than content you affirmatively submit for processing;
  2. access your contacts, calendar, location or other device-permission data (save to the extent strictly necessary to deliver a function you have initiated and authorised);
  3. collect your biometric data, precise geolocation, political opinions, religious beliefs, health data, sexual orientation or other special categories of personal data, save where you yourself place such information within Local Content Data or Submitted Content; or
  4. profile you for the purpose of selling personal data. Note, however, that this website's advertising cookies transmit advertising identifiers to Google and Meta, which may constitute "sharing" under California law; see Sections 12 and 16.3.

4. Purposes of Processing and Legal Bases

#PurposeDataLegal basis
1Providing the desktop application, account, subscription and credit services§3.2Performance of a contract (Art. 6(1)(b) GDPR)
2Performing AI organisation at your requestSubmitted ContentPerformance of a contract
3Performing audio transcription at your requestAudio (§6.3)Performance of a contract
4Payment collection, invoicing, refunds, tax reporting and accounting records§3.3Performance of a contract and legal obligation (Art. 6(1)(c))
5Delivering transactional notices regarding service changes, security incidents and billing§3.2Performance of a contract
6Providing customer support§3.5Performance of a contract
7Recording model calls for credit settlement and the investigation of billing disputes§3.3.2Performance of a contract
8Preventing fraud, abuse and licence misuse, and maintaining system security§3.2Legitimate interests (Art. 6(1)(f))
9Website and advertising effectiveness measurement§12For EEA and UK users: consent (Art. 6(1)(a)); for others: legitimate interests
10Sending launch or marketing emailsEmail addressConsent, withdrawable at any time
11Establishing, exercising or defending legal claimsRelevant categoriesLegitimate interests
12Complying with applicable laws, regulations, court orders and lawful demands of competent authoritiesRelevant categoriesLegal obligation

4.1 Legitimate interests. Where the Company relies on legitimate interests, it has carried out a balancing assessment weighing those interests against your rights and freedoms. You may object under Section 11.1(6); an objection to direct marketing will be given effect unconditionally.

4.2 Purpose limitation. The Company will not Process Personal Data for new purposes incompatible with those listed above. Should this become necessary, we will inform you in advance and, where required by law, obtain your consent.


5. AI Processing: Two Modes

Organising content requires an AI model. The Services offer two mutually exclusive processing modes. Both require an internet connection, but the destination of your content, the applicable retention position and the responsible party differ. The table below sets out those differences so that you may choose between them. Both modes are selected by you; the Company expresses no preference and makes no recommendation.

AspectMode 1: your own model key (BYOK)Mode 2: the model service provided by the Company
Where content goesThe model provider you selectThe Company's systems → the provider corresponding to the model you select (currently OpenAI, processed in the United States)
Passes through the Company's systemsNoYes
Who bears the model usage chargesSettled between you and that providerBorne by the Company, set off against credits
Retention on the Company's sideDoes not pass through the CompanyPurged from the Company's systems upon completion
Whether the Company uses it for trainingDoes not pass through the CompanyNo — the Company trains no models
Handling on the provider's sideGoverned by your agreement with that providerGoverned by that provider's own terms and policies; see Section 6.2.4
Cross-border transferDetermined by the location of the provider you selectInvolves transfer to the United States; see Section 8.7
Responsible partyThat provider is an independent controllerThe Company acts as processor; that provider as sub-processor
How it appliesSelected by you within the applicationSelected by you within the application

5.1 Mode 1 — Bring your own key (BYOK).

  1. You enter your own model provider's API key in the application;
  2. the content to be processed is transmitted directly from your device to the provider you selected;
  3. such content does not pass through the Company's servers, and the Company has no knowledge of, access to, or ability to retain it;
  4. how such content is handled, whether it is retained, and whether that provider uses it to train its models, are governed by your agreement with that provider and lie outside the Company's control;
  5. model usage charges are settled directly between you and that provider; and
  6. in respect of such Processing, that provider is an independent controller.

Mode 1 equally requires a valid software use authorisation (Sections 4.6.1 and 10.1 of the Terms of Service); this Section concerns data flows and not entitlement to use.

5.2 Mode 2 — Using the model service provided by the Company.

5.2.1 The Company operates no model of its own. The Company neither trains nor operates any AI model of its own. The "model service provided by the Company" means that the Company, on your behalf, engages and calls the model of a third-party model provider, bearing the resulting usage charges, which are set off against your credits.

5.2.2 The current model provider and available models. The model provider currently engaged by the Company is OpenAI, through which the Company makes a choice of models available; you may select the model used for a given operation within the application. See Section 6.2.

5.2.3 The complete data flow. Under Mode 2: (1) you initiate a processing request in the application; (2) the relevant portion of content is transmitted from your device to the Company's systems; (3) the Company's systems forward it to the model provider, whose model performs the cleaning, organisation or retrieval; (4) the result is returned by that provider to the Company's systems; (5) the Company's systems return the result to your device; and (6) the Company's systems immediately purge the content and result relating to that operation.

5.2.4 How the Company handles such content within its own systems.

  1. upon completion of processing, the content and result are purged from the Company's systems, and no persistent copy is created or kept;
  2. such content is used only to provide the Services to you — cleaning and organising your memory assets, retrieving them at your request, and supporting workspace functionality;
  3. the Company trains no models and does not use such content for the training, fine-tuning or optimisation of any model; and
  4. save for the transmission to the model provider identified in Section 5.2.2 that is necessary in order to provide the Services, the Company does not provide, sell, rent, exchange or disclose such content to any other third party, except in the circumstances of legal compulsion described in Section 7.3.

5.2.5 Scope of the foregoing. Section 5.2.4 applies only to the Company's own systems and conduct. Once content you have submitted is transmitted to the model provider, its handling, retention and use on that provider's side are governed by that provider's own terms and policies. The Company does not control that provider's conduct and accordingly makes no representation or warranty as to whether it retains content or uses content for training. That provider's current published policies are reproduced at Section 6.2.

5.3 Training, by responsible party.

PartyWho processesUsed for training?Basis
The CompanyThe Company's systemsNo — the Company trains no modelsSection 5.2.4(3)
The Mode 2 model providerOpenAIAs provided by that provider's terms in forceSee Section 6.2.4
The Mode 1 (BYOK) model providerThe provider you selectAs provided by your agreement with that providerYour agreement with that provider

Statements made by the Company in respect of itself do not extend to any of the third parties above.

5.4 Accuracy of output. AI-generated summaries, organisation results and conclusions may be inaccurate or erroneous, and may appear credible by reason of their specificity. The Services retain a source reference for each conclusion so that you may verify it. You are solely responsible for any judgement or decision you make in reliance on AI output.


6. Third-Party Processing Providers Relied Upon by the Services

6.1 Overview. The Company does not operate an AI model of its own, nor can it perform speech-to-text transcription itself. Both core processing functions must therefore be performed with the assistance of third-party providers: (a) a model provider, for AI cleaning and organisation under Mode 2; and (b) a speech-to-text provider, for audio transcription. Those providers are sub-processors of the Company, and this Section is dedicated to their disclosure.

6.2 The model provider (Mode 2)

6.2.1 Identity. The model provider currently engaged by the Company is OpenAI.

6.2.2 Models available to you. The Company makes a choice of models available through that provider. You may select the model used for a given operation within the application, and the product displays the original name of the model called. Credit rates differ by model; see Section 9 of the Terms of Service.

6.2.3 Where processing takes place. That provider processes requests in the United States. The resulting cross-border transfer is addressed at Section 8.7.

6.2.4 That provider's own terms. Once content you have submitted is transmitted to that provider, its handling, retention and use on that provider's side are governed by that provider's own terms and policies and are outside the Company's control. That provider's privacy policy: https://openai.com/policies/privacy-policy

6.2.5 Data flow under a multi-model architecture. Whether the Company integrates one model provider or several, the data flow described at Section 5.2.3 applies: content you submit is sent from your device to the Company's systems, forwarded by the Company's systems to the provider corresponding to the model you selected for that operation, and purged from the Company's systems once the result is returned. The Company does not forward your content between model providers you have not selected.

6.2.6 Change of model provider. If the Company replaces or adds a model provider, it will update the list under Section 7.2 and give notice under Section 20.2. Where the new provider's location differs from that recorded in this Section, the Company will inform you expressly before the change takes effect.

6.3 The speech-to-text provider, and staging storage of audio files

6.3.1 The function. If you use audio transcription, the audio file you submit is transcribed by the model of a third-party speech-to-text provider. That processing must be performed by that provider's model; the Company cannot perform transcription itself.

6.3.2 Why audio passes through the Company's storage (exception to Section 2.1). Long-form transcription APIs generally require audio to be submitted by way of an accessible link (URL) rather than by direct file upload. To meet that requirement:

  1. your audio file is uploaded from your device to the Company's object storage service (the "staging storage");
  2. the Company generates a pre-signed access link for the speech-to-text provider to read the file;
  3. the provider reads the audio by that link and its model generates the transcript;
  4. the transcript is returned to your device; and
  5. on successful transcription, the Company deletes the audio file from staging storage immediately; and
  6. where transcription is unsuccessful (failure, timeout or termination of the task), the audio file is retained in staging storage for no more than 48 hours, after which it is automatically cleared by the bucket's lifecycle rule.

Accordingly, and by way of exception to the general rule in Section 2.1, your audio file resides in storage controlled by the Company during that period, and the Company is technically able to gain access to it. The exception applies to audio files only and does not extend to your other Local Content Data.

6.3.3 Restrictions applicable to the staging storage. In respect of audio files in staging storage, the Company:

  1. stores and transmits them solely to complete the transcription you have initiated, and for no other purpose;
  2. does not read, analyse, index, archive or manually review their contents;
  3. does not use them for the training, fine-tuning or optimisation of any model;
  4. does not make them available to any third party other than the access strictly necessary for the provider identified in Section 6.3.4 to read the file;
  5. configures the bucket as private with public access blocked, and exposes files only by pre-signed link valid for 48 hours;
  6. applies server-side encryption to stored objects;
  7. does not enable object versioning, does not enable cross-region replication, and does not serve such objects through a content delivery network, so that deletion constitutes actual deletion; and
  8. does not grant routine read access to personnel, permitting access only to an authorised service role, with an audit record retained.

6.3.4 The speech-to-text provider. Volcano Engine, processing in Singapore.

That provider's handling and retention of audio and transcripts on its own side are governed by its own terms and policies and are outside the Company's control.

6.3.5 Provider and location of the staging storage. The staging storage uses the Object Storage Service (OSS) of Alibaba Cloud, with the bucket located in the Singapore region.

Your audio file is held in Singapore while in staging storage, and is read there by the speech-to-text provider, which is also located in Singapore (Section 6.3.4). See Section 8.8.

6.3.6 Consistency of scope. Section 6.3.2(5) and Section 6.3.3 apply only to the Company's staging storage. Once the audio file has been read by the provider, its retention and use on that provider's side are governed by that provider's own terms.

6.4 Retention on the Company's side

ItemRetention on the Company's side
Content and results submitted under Mode 2Not retained — purged upon completion
TranscriptsNot retained — once returned to your device, no copy remains
Audio filesException: held in staging storage during transcription. Deleted immediately on success; where transcription is unsuccessful, retained for no more than 48 hours and then cleared

Each entry is made in respect of the Company's own systems only; see Sections 5.2.5 and 6.3.6.

6.5 Your control

  1. The AI processing mode is selected by you. Under Mode 1 (BYOK), the content you submit does not pass through the Company's systems and is not transmitted to the provider identified in Section 6.2; under Mode 2, Sections 5.2 and 6.2 apply.
  2. Audio transcription is optional. If you do not use it, the upload, staging and transfers described at Section 6.3 do not occur.
  3. If you use neither AI processing nor transcription, your content remains entirely on your device and no external transfer occurs.

6.6 Cross-border transfer and place of processing

If your jurisdiction, or the organisation to which you belong, imposes requirements as to cross-border transfer or the jurisdiction in which data may be processed, the relevant facts are at Section 6.2.3 (model provider processes in the United States) and Sections 6.3.4 and 6.3.5 (transcription and staging storage both in Singapore), and may be read with the comparison table at the head of Section 5.


7. Sharing and Disclosure of Personal Data

7.1 Service providers.

RecipientRolePurposeDataLocation
Stripe (payment processor, not a merchant of record)Independent controller / processorPayment processing, fraud prevention, dispute handling§3.3 transaction and billing dataUnited States and its global facilities
OpenAISub-processorAI cleaning, organisation and retrievalSubmitted Content and resultsUnited States (default); see §6.2.5
Volcano EngineSub-processorAudio transcription§6.3 audio and transcriptsSingapore
Alibaba Cloud (OSS, staging storage)Sub-processorHolding audio files for the provider to read; deleted on successful transcription, otherwise cleared within 48 hoursAudio filesSingapore
Alibaba CloudSub-processorHosting of account and subscription systems§3.2 account dataSingapore
ResendSub-processorDelivery of licence-key emails, receipts and transactional noticesPayment email address, message contentSee its privacy policy
Model provider selected by you (Mode 1, BYOK)Independent controllerAI processingSubmitted Content (does not pass through the Company)Determined by you
Google LLC (Google Ads)Independent or joint controllerWebsite and advertising measurement (uses cookies and advertising identifiers)Data listed in §12United States and its global facilities
Meta Platforms, Inc. (Meta Pixel)Independent or joint controllerWebsite and advertising measurement (uses cookies and advertising identifiers)Data listed in §12United States and its global facilities

7.2 Changes to sub-processors. Where the Company appoints or replaces a sub-processor performing a material processing function, it will update the list above before the change takes effect. Where such a change materially affects your Personal Data (for example, by introducing a new cross-border transfer), separate notice will be given under Section 20.2.

7.3 Legally compelled disclosure. The Company may disclose Personal Data where: (a) required to comply with applicable law, regulation, legal process, court order or a legally binding demand of a competent authority; (b) reasonably necessary to prevent death or serious bodily injury; (c) reasonably necessary to detect, prevent or address fraud, security or technical issues; or (d) necessary to establish, exercise or defend legal claims.

The Company's position is that it will challenge or refuse any demand that is unduly broad, unsupported by legal authority, or a blanket request. Where not prohibited by law from doing so, the Company will notify you a reasonable time before disclosure so that you may seek relief.

7.4 Business transfers. In the event of a merger, acquisition, reorganisation, sale of assets or insolvency proceedings, Personal Data may be transferred as part of the transferred assets. The Company will notify you before such transfer takes effect, and the transferee will be bound by protections no less protective than those in this Policy.

7.5 Sale and sharing.

  1. The Company does not sell your Personal Information (within the meaning of "sale" under the CCPA/CPRA) and has not done so in the twelve (12) months preceding the effective date of this Policy;
  2. as to "sharing" (disclosure for cross-context behavioural advertising): this website uses Google Ads and Meta Pixel, which transmit advertising identifiers to Google and Meta. That activity may constitute "sharing" under the CCPA/CPRA. The Company accordingly provides California residents with an opt-out under Section 16.3.

8. International Data Transfers

8.1 Location of the Company and of data. The Company is established in the Hong Kong Special Administrative Region of the People's Republic of China. Account and subscription data held by the Company is stored in the Singapore region of Alibaba Cloud.

8.2 Occurrence of transfers. Because the Company is established in Hong Kong and certain service providers are located in other jurisdictions, your Personal Data may be transferred outside your country or region for Processing. Data protection laws in those places may differ from those of your own jurisdiction.

8.3 Safeguards for EEA, UK and Swiss users. For transfers from those territories, the Company relies on one or more of: (a) an adequacy decision under Article 45 GDPR; (b) the Standard Contractual Clauses approved under Article 46(2)(c) GDPR, supplemented by the UK International Data Transfer Addendum for UK transfers and by corresponding modifications for Swiss transfers; or (c) in exceptional cases, a derogation under Article 49 GDPR.

8.4 Obtaining information. You may request information regarding the transfer safeguards relied upon by contacting the Company under Section 21.

8.5 Transfers of account and subscription data (Singapore). Account and subscription data is held in the Singapore region of Alibaba Cloud. Singapore is not the subject of an EU adequacy decision, so for EEA, UK and Swiss users that transfer proceeds under the Standard Contractual Clauses at Section 8.3(b), supported by a transfer impact assessment.

8.6 Transfers arising from audio transcription. See Section 8.8.

8.7 Transfers arising from Mode 2 model processing.

  1. If you select Mode 2, the content you submit is transmitted to the model provider identified in Section 6.2 and processed in the United States;
  2. for EEA, UK and Swiss users: that transfer proceeds under the Standard Contractual Clauses at Section 8.3(b), supported by a transfer impact assessment;
  3. for users elsewhere: such content will be processed in the United States and will be subject to local law;
  4. under Mode 1 (BYOK), content does not pass through the Company's systems and the destination is determined by the location of the provider you select.

8.8 Transfers arising from audio transcription.

  1. Staging storage: your audio file is held in the Alibaba Cloud Object Storage Service used by the Company, in the Singapore region;
  2. Transcription: the audio file is read and processed by Volcano Engine, in Singapore;
  3. for EEA, UK and Swiss users: Singapore is not the subject of an EU adequacy decision, and those transfers proceed under the Standard Contractual Clauses at Section 8.3(b), supported by a transfer impact assessment;
  4. no use, no transfer: if you do not use audio transcription, none of these transfers occurs.

9. Retention Periods

9.1 General principle. The Company retains Personal Data only for as long as necessary for the purposes described in this Policy, or for such longer period as applicable law requires or permits. Upon expiry, the Company deletes such data or irreversibly anonymises it.

9.2 Specific retention periods.

CategoryRetention periodBasis
Local Content DataControlled by you; not held by the CompanyNot applicable
Submitted Content (Mode 2) — Company's systemsNot retained — purged upon completionShortest period necessary to perform the contract
Submitted Content (Mode 2) — model provider's systemsGoverned by that provider's own terms (Section 6.2.4)That provider's terms in force
Transcripts — Company's systemsNot retainedSection 6.4
Audio files — Company's staging storageDeleted immediately on successful transcription; where unsuccessful, no more than 48 hoursNecessary to perform the contract
Audio and transcripts — provider's systemsSee Section 6.3.4(4)That provider's terms in force
Account and authorisation dataFor the life of the account; deleted or anonymised within thirty (30) days of closurePerformance of a contract
Transaction and billing recordsSeven (7) years from the date of the transactionSection 51C of the Inland Revenue Ordinance (Cap. 112) of Hong Kong, and other applicable tax and accounting rules
Model call records (§3.3.2)For as long as necessary for billing, credit settlement and the resolution of billing disputesPerformance of a contract, legal obligation
Support communications24 monthsLegitimate interests
Waitlist and marketing email addressesUntil you unsubscribe; thereafter a minimal suppression record onlyConsent; thereafter legal obligation and legitimate interests
Technical and diagnostic dataNot currently applicable — not presently collected (Section 3.6)See Section 3.6
Website and advertising measurement dataRetained by Google and Meta under their respective policiesSee Section 12

9.3 Exceptions. The Company may continue to retain data to the extent necessary to: (a) comply with statutory retention obligations; (b) handle a pending dispute, claim or investigation; (c) enforce agreements between the Company and you; or (d) prevent fraud and abuse.

9.4 Backups.

  1. Local data: the Company does not back up your local data. Backing up local data is your responsibility.
  2. Account and subscription data on the Company's systems: if backups are maintained, data deleted from production systems may persist on backup media until overwritten; no active use is made of such residual data.

10. Security and Personal Data Breaches

10.1 Technical and organisational measures. The Company implements measures appropriate to the risk, including:

  1. industry-standard transport layer encryption (HTTPS/TLS) for data in transit;
  2. least-privilege access controls over the Company's systems;
  3. architectural risk reduction — Local Content Data does not by default enter the Company's systems, eliminating at source the possibility of that category being exposed on the Company's side;
  4. non-persistence of Submitted Content within the Company's systems, narrowing the exposure window on the Company's side;
  5. non-transmission of API keys to the Company's servers; and
  6. in respect of the transcription staging storage: a private bucket, pre-signed access links, server-side encryption, versioning and cross-region replication disabled, least-privilege access with audit logging, deletion immediately on successful transcription, and clearance by lifecycle rule within 48 hours where unsuccessful.

10.2 Encryption of locally stored data (please note). The Services do not currently apply application-level encryption to data stored on your device. That data is held in its original form in the application data directory.

This means that anyone able to access your device, or that directory, can read your content.

The Company therefore recommends that you:

  1. enable the full-disk encryption provided by your operating system (FileVault on macOS, BitLocker on Windows, LUKS on Linux);
  2. set a login password on your device and enable automatic screen locking; and
  3. keep your device secure and avoid using the Services on shared or uncontrolled devices.

The Company does not use vacuous formulations such as "military-grade encryption", and gives no commitment as to encryption that has not been implemented.

10.3 Your responsibilities. You should: (a) safeguard your account credentials and your device; (b) safeguard any API key you supply; and (c) maintain your own backups of local data — the Company cannot recover data lost through failure, loss, damage or accidental deletion on your device.

10.4 No guarantee of absolute security. The Company does not represent that security is absolute. Given the inherent nature of internet transmission and information processing technology, no organisation can guarantee that data will be entirely free from intrusion. What the Company undertakes is to adopt measures appropriate to the risk and to respond truthfully under Section 10.5.

10.5 Notification of personal data breaches.

  1. The Company maintains an incident response process for detection, assessment and handling of personal data breaches;
  2. where required by applicable law, the Company will notify the competent supervisory authority without undue delay and, where feasible, not later than seventy-two (72) hours after becoming aware of the breach, giving reasons for any delay;
  3. where the breach is likely to result in a high risk to your rights and freedoms, the Company will notify you directly without undue delay, describing the nature of the breach, its likely consequences, the measures taken or proposed, and the steps you are advised to take; and
  4. in respect of Hong Kong users, the Company will handle and report the incident in accordance with the guidance issued by the Office of the Privacy Commissioner for Personal Data.

11. Your Rights and How to Exercise Them

11.1 Rights. To the extent provided by applicable law: (1) the right to be informed; (2) access; (3) rectification; (4) erasure; (5) data portability; (6) objection (an objection to direct marketing will be given effect unconditionally); (7) restriction of processing; (8) withdrawal of consent, without affecting the lawfulness of Processing before withdrawal; (9) non-discrimination; and (10) the right to lodge a complaint with a competent supervisory authority.

11.2 Rights exercisable within the product (no request required).

  1. Export — export all of your data as a single package at any time; the format and scope are as described within the application;
  2. Deletion — delete your local data at any time. Deletion is permanent. The Services provide no recycle bin and no grace period; once deleted, data cannot be recovered, and the Company cannot assist in recovering it. The only safeguard is to export before deleting. The Services provide no post-deletion recovery mechanism;
  3. Ceasing transfers — if you do not use AI organisation and audio transcription, none of the transfers described in Sections 5 and 6 occur.

11.3 Account closure. You may request closure of your account and deletion of the account data held by the Company. How to request closure: send an email from the address associated with your account to support@memparcel.com, marked "Account closure". The Company will verify your identity under Section 11.4 and then act. Upon closure: (a) your local data is unaffected; (b) account data is deleted or anonymised under Section 9.2; (c) transaction and billing records subject to statutory retention continue to be held under Section 9.2; and (d) unused credits and any remaining subscription term are handled under Sections 7, 8 and 9 of the Terms of Service.

11.4 Making and handling requests.

  1. How to submit — by the contact details in Section 21;
  2. Verification — the Company verifies requests through the email address associated with your account, and may require supplementary information where the request concerns a sensitive operation or where there is reasonable doubt as to identity. Such information is used solely for verification and deleted once verification is complete;
  3. Response time — within one (1) calendar month of receipt of a verifiable request, extendable by up to a further two (2) months where the request is complex or where a number of requests have been received, with notice of the extension and its reasons within the first month. Requests governed by the CCPA/CPRA are subject to Section 16.5;
  4. Fees — no fee is ordinarily charged. Where a request is manifestly unfounded or excessive, the Company may charge a reasonable fee or refuse to act, giving reasons; and
  5. Refusal — where the Company refuses a request, it will state its reasons and inform you of your right to lodge a complaint with a supervisory authority and to seek a judicial remedy.

11.5 Complaints and remedies. You may lodge a complaint with a competent supervisory authority, including: (a) the supervisory authority of the EU Member State of your habitual residence, place of work or place of the alleged infringement; (b) the Information Commissioner's Office (UK); (c) the Office of the Privacy Commissioner for Personal Data, Hong Kong; and (d) the California Privacy Protection Agency or the California Attorney General.

The Company asks that you contact it first so that it has the opportunity to address your concern directly; this request does not limit your right to complain.


12. Cookies and Similar Technologies

12.1 This website uses cookies and similar technologies. The Company's website stores and reads cookies and similar technologies (including pixel tags, browser local storage and advertising identifiers) in your browser. Those technologies are set and read by the third-party advertising and measurement tools integrated by the Company (Google Ads and Meta Pixel).

12.2 Categories.

CategoryIn useToolsPurpose
Strictly necessaryAs requiredBasic operation of the website, securityNo prior consent required
Advertising and measurementYesGoogle Ads (Google LLC), Meta Pixel (Meta Platforms, Inc.)Measurement of advertising delivery and conversion
FunctionalNo——
AnalyticsNo — no separate web analytics tool is deployed——

12.3 Information involved, and limits on use.

  1. These tools may collect: device information, browser information, IP address, page views and interactions, and advertising identifiers generated by cookies or pixels;
  2. the Company does not use these tools to identify you personally and does not associate the resulting data with your account content or Local Content Data;
  3. however, Google and Meta act as controllers for their own purposes and may associate those identifiers with accounts on their own platforms, enabling cross-site advertising targeting. That processing is governed by their respective privacy policies and is outside the Company's control.

12.4 Your choices. (a) Google Ads Settings; (b) Meta Ad Preferences; (c) blocking third-party cookies in your browser settings, or using an ad-blocking extension; (d) emailing an opt-out request under Section 16.3.

12.5 Prior consent for EEA and UK users. For users in those territories, storing or reading any non-strictly-necessary cookie or similar technology on their terminal equipment requires their prior consent. This website's advertising and measurement cookies fall outside the strictly necessary category.

The measure adopted by the Company in respect of visitors from those territories is as follows: the Company obtains your prior consent through a consent management platform, and does not load Google Ads or Meta Pixel before that consent is given.

12.6 Diagnostic data within the product. The memparcel desktop application does not currently collect crash logs, error reports or usage statistics (Section 3.6). Should the Company introduce such collection, it will be disclosed separately before the functionality is released, together with a setting allowing you to turn it on or off.


13. Automated Decision-Making and Profiling

13.1 No automated decisions with legal effect. The Company does not take decisions based solely on automated Processing, including profiling, which produce legal effects concerning you or similarly significantly affect you.

13.2 AI output is not a decision about you. The AI functionality organises and generates content from your own material, and its output is a work product delivered to you. It is not an assessment, score or decision made by the Company about you, and does not fall within Article 22 GDPR.

13.3 Automated anti-abuse measures. The Company may use automated means to detect anomalous sign-ins, licence misuse or billing abuse and may temporarily restrict functionality. Where such a measure may significantly affect you, you may request human review, express your point of view and contest the decision.


14. Children and Minors

14.1 Minimum age. The Services are not directed to children under 13 years of age, or such higher minimum age as the law of your jurisdiction prescribes.

14.2 Inadvertent collection. The Company does not knowingly collect Personal Data from persons below that age. If it becomes aware that it has done so without a valid basis, it will delete the data and close the associated account without undue delay.

14.3 Parents and guardians. If you are a parent or legal guardian and believe a minor has provided Personal Data to the Company, please contact us under Section 21.


15. Supplementary Provisions for EEA, UK and Swiss Users (GDPR / UK GDPR)

15.1 Controller. Memparcel Intl Trading Limited (憶安寶有限公司), at the address in Section 21.

15.2 Legal bases. See Section 4.

15.3 Data subject rights. See Section 11.1; manner of exercise, verification and response times at Section 11.4.

15.4 International transfers. See Section 8.

15.5 Data Protection Officer. The Company has not appointed a Data Protection Officer. Its core activities do not consist of Processing operations requiring regular and systematic monitoring of data subjects on a large scale, nor of large-scale Processing of special categories of data under Article 9 GDPR or of criminal conviction data under Article 10 GDPR; the mandatory criteria in Article 37(1) GDPR are therefore not met. All data protection matters should be raised through the mailbox in Section 21. Should the scale or nature of Processing change such that the threshold is met, the Company will appoint a DPO and update this Policy.

15.6 EU and UK Representatives (Article 27 GDPR). The Company has not yet appointed an EU Representative or a UK Representative. Once appointed, the representative's name and contact details will be stated in this Section.

15.7 Complaints to supervisory authorities. See Section 11.5.


16. Supplementary Provisions for California Residents (CCPA / CPRA)

16.1 Notice at collection. In the twelve (12) months preceding the effective date of this Policy, the Company has collected or may collect the following statutory categories:

CCPA statutory categoryCollected?Specific itemsSourceBusiness purposeDisclosed to
A. IdentifiersYesPayment email address, licence key hash, device machine identifier, region identifier, IP addressYou; your deviceService delivery, account management, securityStripe, Resend, Alibaba Cloud, Google, Meta
B. Customer recordsYes (limited)Billing name and contact details (collected by Stripe)YouTransaction performance, invoicing, taxStripe
C. Protected classificationsNo————
D. Commercial informationYesSubscription plan and status, purchase records, credit grant and consumption recordsYou; StripePerformance, billing, supportStripe
E. Biometric informationNo————
F. Internet or other electronic network activityYes (limited)Page views, interactions, advertising conversion measurement, and advertising identifiers generated by cookies/pixelsCollected automaticallyWebsite and advertising measurement; cross-context behavioural advertisingGoogle, Meta (constitutes "sharing")
G. Geolocation dataYes (coarse only)Country/region inferred from IP addressCollected automaticallyTax compliance, fraud preventionStripe
H. Audio, electronic, visual and similar informationYes (only where you use transcription)Audio file (deleted on success; no more than 48 hours if unsuccessful) and transcript (not retained)YouPerforming transcription at your requestAlibaba Cloud OSS and Volcano Engine (both in Singapore)
I. Professional or employment-related informationNo————
J. Education informationNo————
K. InferencesNo————
Sensitive Personal InformationNoThe Company does not Process Sensitive Personal Information to infer characteristics———

Diagnostic data: the Company does not presently collect crash logs, error reports or usage statistics (Section 3.6), and no corresponding entry appears above.

Submitted Content: such content is not itself a category of Personal Information affirmatively collected by the Company, but may contain Personal Information falling within several categories above. It is disclosed to the model provider identified in Section 6.2 and is not retained on the Company's systems.

16.2 Retention. See Section 9.2.

16.3 Sale and sharing.

  1. No sale: the Company does not sell Personal Information and has not done so in the twelve (12) months preceding the effective date of this Policy;

  2. Sharing does occur: this website uses Google Ads and Meta Pixel, which transmit advertising identifiers to Google and Meta for cross-context behavioural advertising. That activity constitutes "sharing" under the CCPA/CPRA. The categories involved are Category A and Category F above;

  3. Your right to opt out: California residents may opt out by:

    (a) emailing support@memparcel.com, marked "Do Not Share My Personal Information"; (b) using Google Ads Settings and Meta Ad Preferences to turn off ad personalisation; or (c) blocking third-party cookies in your browser settings, or using an ad-blocking extension.

  4. Minors: the Company does not sell or share the Personal Information of consumers it knows to be under 16 years of age.

16.4 Rights of California residents. (1) to know; (2) to access specific pieces; (3) to delete; (4) to correct; (5) to opt out of sale or sharing — the Company does not sell, but sharing does occur; see Section 16.3(3); (6) to limit the use and disclosure of Sensitive Personal Information (not applicable); and (7) not to be discriminated against — the Company will not deny services, charge different prices, provide a different level of quality, or retaliate because you exercised these rights.

16.5 Exercising these rights.

  1. How to submit — email support@memparcel.com, marked "California Privacy Request";
  2. Verification — through the email address associated with your account; where you have no account, the Company may request reasonable additional information;
  3. Authorised agents — you may designate an authorised agent, who must provide written authorisation signed by you; the Company may require you to confirm the authorisation directly;
  4. Acknowledgement and response — acknowledgement within ten (10) business days, response within forty-five (45) calendar days, extendable by a further forty-five (45) days where reasonably necessary; and
  5. Refusal and complaint — where a request is declined, the Company will state the statutory basis; you may complain as set out in Section 11.5.

16.6 Opt-out preference signals (GPC). Under the CPRA, in respect of the sharing described at Section 16.3(2), the Company should detect and honour the Global Privacy Control (GPC) signal. That detection and compliance is pending technical implementation; until then, please use the other means listed at Section 16.3(3).

16.7 "Shine the Light". The Company does not disclose Personal Information to third parties for those third parties' direct marketing purposes, and is therefore not required to provide the disclosures contemplated by Cal. Civ. Code § 1798.83.


17. Supplementary Provisions for Residents of Other U.S. States

17.1 Scope. If you are a resident of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana or another state with a comprehensive consumer privacy statute in force, you have the following rights to the extent provided by that statute: (1) to confirm processing and access; (2) to correct; (3) to delete; (4) to obtain a portable copy; and (5) to opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions producing legal or similarly significant effects — the Company does not sell personal data and does not conduct such profiling; however, processing for targeted advertising does occur on this website, and you may opt out under Section 16.3(3).

17.2 Exercise and appeal. Rights are exercised as set out in Section 16.5. If the Company declines your request, you have the right to appeal: resubmit marked "Appeal", and the Company will respond in writing within the period prescribed by applicable law. If the appeal is declined, the Company will inform you how to complain to your state Attorney General.

17.3 Consent for sensitive data. The Company does not affirmatively collect sensitive data, and that consent requirement therefore does not arise.


18. Supplementary Provisions for Hong Kong Users (PDPO)

18.1 Applicable law. The Company is incorporated in Hong Kong, and its handling of personal data is regulated by the Personal Data (Privacy) Ordinance (Cap. 486) and the Data Protection Principles thereunder.

18.2 Purpose and voluntariness of collection. Providing the account data described in Section 3.2 is voluntary; however, without an email address the Company cannot create an account or provide subscription services.

18.3 Rights of access and correction. Under sections 18 and 22 of, and Data Protection Principle 6 to, the PDPO, you may ascertain whether the Company holds personal data about you, obtain a copy, and require correction of inaccurate data. The Company may impose a fee that is not excessive and is directly related to and necessary for complying with a data access request, and will respond within forty (40) days.

18.4 Direct marketing. Under Part VIA of the PDPO, before using your personal data in direct marketing the Company will obtain your consent or an indication of no objection, and will inform you on first use that you may request cessation free of charge. You may at any time require the Company to cease such use, and the Company will comply unconditionally.

18.5 Complaints. See Section 11.5(c).


19. Scope of this Policy, and Products Obtained Through Other Channels

19.1 This Policy applies to the Services. This Policy applies to the memparcel desktop application and related services that you obtain and use via memparcel.com and its subdomains. If you are reading this Policy within the Services or on memparcel.com, it applies to the product you are using.

19.2 Products obtained through other channels. If the memparcel product you use was obtained via memparcel.cn, it is operated by a different entity, and its model channel, payment channel and data-handling arrangements differ from those of the Services. The handling of personal information in that product is governed by the privacy policy published within that product and on memparcel.cn; this Policy does not apply to it.

19.3 Authorisations and data are not interchangeable. memparcel products obtained through different channels are not interoperable: an authorisation, credit balance or local data obtained in one does not automatically become available in, or transferable to, the other. If the Company offers a migration route, it will be described separately.


20. Changes to this Policy

20.1 Publication of changes. The Company may update this Policy to reflect changes to the product, legal requirements or business arrangements. The updated Policy will be published on this page, and the "Last updated" date and version number revised accordingly.

20.2 Advance notice of material changes. Where a change materially alters the handling of Personal Data (including the addition of a processing purpose, an expansion of sharing, the introduction of a cross-border transfer, an extension of a retention period, a change to a retention commitment, or a reduction of your rights), the Company will notify you before the change takes effect, by email or in-app notice, with not less than thirty (30) days' notice. The Company will not make such changes silently.

20.3 Your options. If you do not accept a revised Policy, you may cease use and close your account before the change takes effect.


21. Contacting the Company

ItemDetails
Contact emailsupport@memparcel.com (privacy matters, rights requests, refunds and complaints are all handled at this address)
CompanyMemparcel Intl Trading Limited (憶安寶有限公司)
Company number80587775 (Hong Kong)
Registered officeROOM 2253, 22/F, HOI TAI FACTORY ESTATE, TSING YEUNG CIRCUIT, TUEN MUN, HONG KONG
Data Protection OfficerNot appointed (see Section 15.5)
EU / UK RepresentativeNot yet appointed (see Section 15.6)

The Company will respond without undue delay; specific time limits are set out in Sections 11.4(3), 16.5(4) and 18.3.

ViewTerms of Service
Terms of Service
© 2026 Memparcel Intl Trading Limitedsupport@memparcel.com