Privacy Policy
Last updated: 22 September 2026. Publisher: Alexis Breuvart, public developer name Igin, France; contact: support@igin.fr.
Self-hosted by design
Mnemoid connects to an API instance you choose. Information sent to example-instance.tld is processed by that instance’s operator according to its own policy/configuration. The publisher may not operate, access or be able to delete data on independently operated instances.
Data used to provide the service
The application keeps selected-instance/account settings locally and protects mobile credentials with Android security facilities. A selected instance can process accounts, projects and memberships, issues, ideas, documents, comments, activity, attachments/logos/avatars, authentication records, notifications and push registrations.
Push, MCP and optional providers
Push is optional and uses a UnifiedPush distributor selected on your device, such as ntfy. Notification payloads are encrypted for the subscription before delivery; delivery/network metadata remains visible to the distributor. OAuth/MCP access is limited to scopes you approve. An instance may configure email, diagnostics or other integrations; its operator should identify them.
Controls and account deletion
You can edit permitted content, revoke credentials, disable push and remove an account from this device. Local removal does not erase the server account. Where the instance has deployed it, permanent server deletion is available in-app and through /account/delete. Shared project records and audit history may be retained or anonymized where necessary for collaboration and lawful obligations.
Diagnostics and retention
The official application automatically sends privacy-minimized Crash logs and technical Diagnostics to an Igin-operated Bugsink service for Analytics, meaning the identification, investigation and correction of application errors. Automatic diagnostics are required; sending a report through the feedback form is optional. Reports can include an exception, sanitized stack trace, application release and OS/runtime context. Identity, request data, credentials, cookies, breadcrumbs, local variables and sensitive context are removed before transmission. Session replay, performance tracing, profiling, screenshots, advertising and behavioral tracking are not used. Production Bugsink connections must use HTTPS. Igin-operated Bugsink events are retained for no more than 30 days and are then deleted. When a separate infrastructure provider processes these events solely on Igin’s behalf, it acts as a service provider and may not use them for its own purposes. This website may use Vercel Analytics and optional Umami. Each instance operator controls database, backup and log retention.
Contact
Official-app privacy contact: support@igin.fr. For data on a selected instance, contact that instance’s operator.