Legal
Privacy Policy
Effective [EFFECTIVE DATE]. This explains what It's Maam (the "Service") collects, why, who else sees it, and your choices. The Service is run by [COMPANY LEGAL NAME], a [STATE OF ORGANIZATION] limited liability company ("we", "us"), [BUSINESS ADDRESS]. Questions: [CONTACT EMAIL].
The short version
- We collect little: your email address if you sign in, an email address if you ask for an invitation, and the memes and settings you create.
- Text you type to make a meme is sent to an AI provider to write the captions. We do not store your private context as text.
- We do not sell your information, show ads, or use analytics or advertising trackers.
- Anything you make public can be seen by anyone, and anyone with a meme's image link can view that image.
What we collect
When you sign in. You type your email address and we email you a one-time sign-in link. We store your email address, and the link only as a one-way hash until it is used or expires 15 minutes later. There is no password.
When you ask for an invitation. The email address you type. We store it and email it to our operator so they can invite you.
What you create. Topics and their settings (theme, subjects, opening line, public name and description), captions you write, template images you upload, the memes the Service makes (captions and images), which memes you publish, your votes, and the labels of your API keys. We store API keys and session tokens only as one-way hashes.
Private context. If you add context to a request, it is sent to the AI provider (below) to write that meme. We do not store the context text. We keep a one-way fingerprint of it so the Service can recognize the same request again. The captions written from it are stored, and they may reveal parts of what you typed.
Visitors who are not signed in. When you open the front page or a public stream, we set a cookie with a random visitor ID. It lets you vote once per meme and hides memes you voted down. We keep your votes against that ID. The page also sends the IDs of memes it already showed you so they are not repeated; we do not store that list for visitors.
Products that use our API. A product calling the Service may send a viewer identifier for its own users, so they do not see repeats. We keep a list of up to 200 memes recently shown to each identifier; entries older than 30 days are dropped when that identifier is next used. Products should send a random or pseudonymous identifier, not a name or email address.
Technical data. To limit abuse, we count requests per IP address in short time windows. We store only a hash of the IP address, in short-lived counters that are routinely deleted. We keep an operations log (what operation ran, the account and topic IDs, timings and errors) for 7 days, 30 days for warnings, or 120 days for errors. We do not write your private context, or captions written from it, to that log.
Cookies and browser storage
- Session cookie (
meme_session): keeps you signed in for up to 7 days. Needed to use your account. - Visitor cookie (
meme_viewer): the random visitor ID described above, for up to 30 days. Needed for voting and for not repeating memes. - Browser storage: the last topic you opened (
meme_last_topic). It stays in your browser and is not sent to us.
The invitation form loads Cloudflare Turnstile, a bot check. Cloudflare may set their own cookies or collect device information under their own privacy policies. We use no advertising or analytics cookies.
How we use it
To provide the Service: sign you in, make and show memes, keep your topics and keys, run public streams and votes, and send invitation emails. To keep it safe: prevent abuse, enforce limits and our Terms, and fix problems. To meet legal duties. We do not use your information for advertising, and we do not sell it or share it for cross-context behavioral advertising.
If you are in the European Economic Area or the UK, our legal bases are: performing our contract with you (running your account and requests), our legitimate interests (security, abuse prevention and fixing faults), and legal obligations.
Who else receives it
- Cloudflare hosts the Service and its database and runs Turnstile. It processes every request, including your IP address.
- OpenRouter routes caption requests to the AI model, and Google runs the model (currently Gemini). They receive the topic, theme, subject, opening line, template details and any context or facts you send for that meme, and return the captions. They handle it under their own terms and privacy policies, which may include keeping it for a time for safety and abuse monitoring. Do not put personal, confidential or sensitive information in prompts or context.
- Resend delivers our emails, so it receives the recipient's email address and the message.
- The public, for anything you make public, and anyone with an image link, which works even for memes in private topics.
- Others when required: to comply with law or valid legal process, to protect rights and safety, or as part of a merger or sale of the Service.
These providers may process data in the United States and other countries.
How long we keep it
Account information, topics and memes: until you delete them or ask us to delete your account. Sessions: up to 7 days. Visitor cookie: up to 30 days. Operations log: 7 to 120 days as above. Rate-limit counters: briefly. Invitation requests: until handled or you ask us to delete them.
When you delete a meme or a topic, it is removed from our database. Its image link may keep working for up to 5 minutes in caches, and our database provider's recovery copies may hold it for up to 30 days. We cannot recall copies other people have already made.
Your choices and rights
You can delete memes, topics and uploaded templates, and revoke API keys, yourself. To see a copy of your information, correct it, or delete your account, email [CONTACT EMAIL] from the address on your account. We will not treat you differently for making a request.
Depending on where you live (for example the EEA, the UK, California and other U.S. states), you may have rights to access, correct, delete or receive a copy of your personal information, to object to or restrict some processing, to appeal our decision on a request, and to complain to your data protection authority. We will answer within the time the law requires and may need to confirm your identity first.
Children
The Service is for people 18 and older. We do not knowingly collect information from anyone under 18. If you believe a minor has given us information, email [CONTACT EMAIL] and we will delete it.
Security
We use HTTPS, store keys and session tokens only as hashes, and limit who can reach stored data. No system is perfectly secure, and we cannot guarantee the security of information you send.
Changes and contact
We will post changes to this policy here with a new effective date and, for material changes, tell signed-in users. Contact: [COMPANY LEGAL NAME], [BUSINESS ADDRESS], [CONTACT EMAIL].