Privacy Policy
Last updated 19 July 2026
The short version
We collect your email (to sign you in), the prompts and captions you write, and the memes you generate. Memes and captions are public when you post them; your prompts stay private to you. We do not run ads, trackers, or analytics, and we never sell your data. Email privacy@memefeed.app to get your account and content deleted.
This policy explains how Sachin MS, a sole proprietorship based in Thiruvananthapuram, Kerala, India (“MemeFeed”, “we”, “us”) handles personal data for the service at memefeed.app. We are the data fiduciary under India’s Digital Personal Data Protection Act, 2023 (DPDP) and the controller under the GDPR where it applies.
1. What we collect
Account data
When you sign in with Google we receive your email address and display name from Google. If you sign up with email and password, we receive your email address. We never request access to your contacts, files, or anything else in your Google account. The standard sign-in response also includes a link to your Google profile picture, which is retained in our authentication provider’s records but never displayed or used by MemeFeed. MemeFeed’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Your credentials are held by our authentication provider (Supabase), not in our own application tables. We never see your Google password, and email/password credentials are stored only as a salted hash by Supabase.
Date of birth. During registration we ask for your date of birth to confirm you are 18 or older (MemeFeed is an adults-only service) and to enable age-based account features. It is stored with your profile, is never shown publicly or to other users, and is deleted with your account. If the date you provide shows you are under 18, the account is closed.
Your handle is derived from your email. When your account is created we generate a public handle from the part of your email address before the “@”, plus a short random suffix (for example, priya → priya_4f2a). This handle is visible to everyone. You can change it at any time from your own profile page.
Content you create
- Prompts — the text you type to generate a meme.
- Captions and comments — the text you add to posts.
- Generated images — the memes produced from your prompts.
- Interactions — likes (which are publicly visible), and any reports you submit about other people’s content.
Prompts stay private to you. The prompt that produced a meme is not published with it. It remains visible to you, to administrators reviewing a report about the post (section 4), and to the generation systems described in section 3. Even so, avoid putting personal or sensitive information in a prompt.
Payment data
Credit purchases are processed by Razorpay. Your card, UPI, or bank details are entered directly into Razorpay’s checkout and never reach our servers. We store only the record of the transaction: Razorpay’s order and payment identifiers, the amount, the currency, the credits purchased, and the status. We do not store card numbers, the last four digits, cardholder names, or billing addresses.
We pass your internal account identifier to Razorpay as order metadata so we can credit the right account. Razorpay separately collects your name and contact details as the payer, under its own privacy policy.
Technical data
We set a session cookie to keep you signed in and a mf-theme cookie to remember your light/dark preference. Both are strictly functional. We do not use analytics, advertising, or tracking cookies, and there is no third-party analytics or error-tracking service in the product. We do not collect your location, phone number, or device fingerprint.
Our web server and hosting provider keep standard access logs (including IP addresses) for security and abuse prevention, as any web server does.
2. Why we process it, and on what basis
| Purpose | Data | Legal basis |
|---|---|---|
| Create and secure your account | Email, display name, handle | Performance of contract |
| Confirm you are 18+ and enable age-based features | Date of birth | Legal obligation; performance of contract |
| Generate and publish memes | Prompts, captions, images | Performance of contract |
| Process credit purchases | Transaction records | Performance of contract; legal obligation (tax records) |
| Moderate content and handle reports | Prompts, captions, comments, images, reports | Legitimate interests; legal obligation |
| Prevent abuse and rate-limit | Account identifier, usage counts | Legitimate interests |
3. Who we share it with
We do not sell your personal data and we do not share it for advertising. We use these processors:
| Processor | What it handles | Where |
|---|---|---|
| Supabase | Authentication, database, image storage | Mumbai, India (ap-south-1) |
| Sign-in, if you choose Google | Global | |
| Razorpay | Payments | India |
| fal.ai | Overflow image generation — prompt text only (see below) | United States |
Where your memes are generated
Most memes are generated on our own GPU hardware, not a third-party AI service. Only the prompt text is sent to that system — no name, email, or account identifier travels with it.
If you have purchased credits, your requests may spill over to fal.ai, a third-party generation service in the United States, when our own hardware is busy or unavailable. In that case your prompt text is transmitted to fal.ai, again with no account identifier attached. fal.ai processes it under its own privacy policy. This is an international transfer outside India and the EEA; we rely on your consent and on the necessity of the transfer to provide the service you have paid for.
We will also disclose data where we are legally required to — for example, a valid order from a court or law-enforcement authority — or where it is necessary to investigate abuse, fraud, or a threat to someone’s safety.
4. Moderation and staff access
Prompts, captions, and comments are checked automatically against a blocklist before they are accepted, and generated images are checked by an automated classifier before publication; where the check cannot run, we rely on user reports. Images that the classifier flags are withheld from the public feed.
When someone reports a post or comment, an administrator reviews it. That review shows the administrator the reported content, including the prompt that generated it, the author’s handle, and the reporter’s handle. Reports are not anonymous to us.
5. How long we keep it
- Account, posts, prompts, and images — kept until you ask us to delete them (see section 6).
- Withheld or hidden content — images flagged before publication are never publicly served. When we hide content after publication, it is removed from the feed and its public image file is deleted; a private copy is retained so that we can respond to disputes and legal requests.
- Transaction and credit records — retained for at least eight years after the financial year they relate to, as Indian tax and accounting law requires. These survive account deletion, and are the one category we cannot erase on request.
6. Your rights, and how to use them
You can ask us to:
- tell you what personal data we hold about you;
- correct anything inaccurate, including your handle;
- delete your account, your posts, and your generated images;
- provide a copy of your data in a portable format;
- withdraw consent, or object to a particular use.
Email privacy@memefeed.app from the address on your account. Deletion is handled manually and we will complete it within 30 days — there is no self-service delete button in the app yet. Deletion removes your posts, comments, drafts, and stored image files, and erases your profile (your handle and display name). If you have made purchases, the retained transaction records are kept against an anonymized account identifier, as described above.
If you are unhappy with how we have handled a request, you may complain to the Data Protection Board of India, or to your local supervisory authority if you are in the EEA or UK.
7. Security
Traffic is encrypted with TLS. Row-level security restricts your payment, credit, draft, and prompt records to your own account; your public profile record and likes are readable by anyone, as described in section 1. Administrative access is limited to accounts we provision by hand. No system is perfectly secure, and we cannot guarantee absolute security — but if a breach affects your personal data, we will notify you and the Data Protection Board as the DPDP Act requires.
8. Children
MemeFeed is for adults. You must be 18 or older to use it, and we do not knowingly collect data from anyone under 18. If you believe a minor has created an account, email privacy@memefeed.app and we will remove it.
9. Changes
If we change this policy we will update the date at the top, and for significant changes we will notify you in the app or by email before they take effect.
10. Contact
Privacy and deletion requests: privacy@memefeed.app
General support: support@memefeed.app
Grievance Officer (DPDP): Sachin MS, privacy@memefeed.app
Postal address: we are based in Thiruvananthapuram, Kerala, India; our full postal address is available on request via privacy@memefeed.app
See also our Terms of Service.