Privacy policy
A plain-language disclosure of how the MemeDrop private beta handles information, and which hosted-provider and billing details remain to be finalized before public launch.
Effective date: August 31, 2026
What this covers
This notice applies to the MemeDrop website, its Chrome extension, and the current meme-suggestion and meme-generation services. It does not replace the privacy policies of third-party sites where you may post a generated meme.
Information MemeDrop processes
Submitted content
When someone asks MemeDrop to suggest or generate a meme, the service processes the submitted post or text and any optional creative direction. That content is used to rank templates and create caption text. Do not submit passwords, financial details, health information, or other sensitive personal information.
Generated media
MemeDrop stores rendered meme images in the configured object-storage service so they can be returned to the authenticated user. Each durable generated asset expires 30 days after generation. Expired media is no longer served; a protected daily cleanup job deletes its exact stored object and keeps failures visible for operator retry. Rendered pixels necessarily contain the generated caption even though caption text is not stored as a separate application field.
Technical and operational data
The service and its infrastructure may process standard request and diagnostic data, such as timestamps, response status, latency, network metadata, browser or device information, and rate-limit signals. The implementation excludes raw submitted text, optional creative direction, plaintext captions, API-key secrets, and request bodies from application persistence and telemetry. Request identity uses a one-way SHA-256 fingerprint rather than stored plaintext. A full hosted-infrastructure log and retention audit has not been completed yet.
Account, API, and billing data
Google sign-in establishes a web session. MemeDrop uses the provider account identifier and email to associate your account with its API keys and credits. The authenticated dashboard shows your balance and lets you issue or revoke keys. MemeDrop stores compact IDs, key names, key-use and revocation timestamps, signed credit movements, and generation/asset lifecycle metadata. API-key secrets are shown once at issuance and stored only as one-way SHA-256 hashes. Payments, recharging, and self-service billing are not implemented; Dodo Payments is the planned payment provider, but its checkout is not connected and this website does not currently send payment information to it. Payment-data handling and billing-record retention will be documented before paid checkout opens.
Service providers
MemeDrop uses OpenRouter to reach the model used for template selection and caption generation. A generation request can therefore send submitted text, relevant template constraints, and bounded trend context to OpenRouter for processing.
MemeDrop uses Tavily to discover broadly relevant social and internet-culture trends from fixed, curated discovery queries. Individual meme-generation input is not used as a Tavily search query. Tavily evidence may be sent to OpenRouter in bounded batches to create normalized trend cards.
The website uses Vercel Analytics. Meme media is stored through the configured object-storage provider. These providers process data under their own terms and privacy notices. Their hosted production configuration, provider-side input retention, model training controls, log retention, deletion propagation, and subprocessors are still being verified; the application-level exclusions above do not control provider-held copies.
How information is used
- To generate, render, deliver, and troubleshoot meme suggestions.
- To maintain service reliability, security, rate limits, and abuse protections.
- To understand aggregate service performance and cost without intentionally retaining raw submitted text in application telemetry.
- To comply with legal obligations and respond to valid requests where required.
Sharing and disclosure
MemeDrop does not sell submitted content. Information is shared with the service providers described above only as needed to run the service, and may be disclosed when required by law or to protect the service, its users, or the public. A public launch will include verified provider-specific retention details and a complete list of material processors.
Retention and your choices
Generated images expire 30 days after successful generation. Authenticated media access stops at expiry, and the implemented scheduled cleanup deletes exact stored objects in bounded batches. Retryable and blocked cleanup backlogs remain visible to operators so a deletion failure does not disappear silently. Durable user, key, credit-transaction, and categorical generation records are retained for private-beta operations and auditing.
Final hosted retention periods for application and infrastructure logs, PostgreSQL, Redis, OpenRouter, Tavily, analytics, and object storage still require verification. Billing retention is not yet applicable because payments are not implemented. API keys can be revoked from the authenticated dashboard or by an operator; general account self-service, early asset deletion, and a generated-content complaint workflow remain pending. Contact us for a request.
Security
We use reasonable technical measures appropriate to the current stage of the product, but no internet service can promise absolute security. Private-beta generation and media are tenant-authenticated, API-key secrets are one-way hashed, credits are transactionally accounted, and generated assets have a scheduled lifecycle job. Public launch still depends on hosted observability, incident-response, and production security verification.
Changes to this notice
We may update this notice as MemeDrop moves from development to private beta and public access. The effective date above will change when we do. Material changes to retention, providers, or billing will be reflected here before they apply to public users.
Privacy and support contact
For privacy, support, deletion, or data questions, email moyezrabbani.work@gmail.com.