The short version
- Chart images you scan are never stored. They are sent to our analysis provider, read, and discarded. We keep a fingerprint of the image, not the image.
- We do not sell your data, and there is no advertising or tracking SDK in the app.
- We never ask for a wallet, a seed phrase, a private key, or an exchange login. Nothing in the product needs one.
- You can delete your account and everything attached to it from inside the app, without emailing anyone.
Who we are
MemeIQ is operated by Kannon Rhodes. For anything about your data, write to kannonrhodes5@gmail.com. We are the data controller for the information described below.
What we collect, and why
Everything in these tables is something the product actually stores. There is no separate analytics pipeline collecting anything else.
| What | Why | Kept |
|---|---|---|
| Email address | Identifies your account and is how we reach you about it. | Until you delete your account. |
| Password | Signing in. Stored only as a bcrypt hash — we cannot read it, and cannot tell you what it is. | Until you delete your account. |
| Display name | Optional. Used to greet you in the app. | Until you delete your account. |
| Onboarding answers | Five multiple-choice answers that shape the wording you see. They change copy, not analysis. | Until you delete your account. |
| Scan results | Your history: the risk score, the band, the checks behind it, and when it ran. | Until you delete your account. |
| A hash of each scanned image | A SHA-256 fingerprint, so a re-upload of the same screenshot is recognisable. The image itself is not kept. | Until you delete your account. |
| Subscription state | Whether you are on a trial, active, or lapsed, plus the identifiers our payment providers use. | Until you delete your account, then as long as tax and accounting law requires. |
| IP address and request metadata | Rate limiting, blocking brute-force sign-in attempts, and investigating abuse. | In server logs, on a rolling short-term basis. |
| Crash reports | An error message, a stack trace, and a small amount of technical context, so we can fix what broke. | In server logs, on a rolling short-term basis. |
| What | Why | Kept |
|---|---|---|
| Saved scans | Your history list, so it works offline. | Until you remove them or uninstall. |
| Scan streak and calendar | Counting the days you checked a chart. | Until you uninstall. |
| Academy progress | Which lessons you have finished. | Until you uninstall. |
| Profile picture and theme choice | Personalisation. Your picture never leaves the device. | Until you change or uninstall. |
Chart images
This is the part most people want to know about, so it gets its own section.
When you scan a chart, the image is sent to our analysis provider, read, and discarded. We do not write it to a database, a bucket, or a disk. What we keep is a SHA-256 hash — a fixed-length fingerprint that cannot be turned back into the picture — together with the resulting risk assessment.
A screenshot of a chart can still contain more than a chart. If your screenshot includes a portfolio balance, a wallet address, a username, or a notification, that is part of the image we send for analysis. Crop before you scan if that matters to you.
Automated analysis, and how AI is used
Your risk score is produced by an artificial intelligence model, not by a person. No human reviews a scan before you see it. We are telling you this here, and again on every result, because you should know what produced a number you might act on.
How it works, concretely:
- The image you submit is sent to Anthropic, whose model reads it and reports what it can see in a fixed, structured form.
- That structured output is scored by our own code against a published list of checks. The model does not choose your score directly.
- The model is instructed to treat everything inside the image as data and never as instructions, so text in a screenshot cannot redirect it.
- Nothing about your account — your email, your name, your history — is sent with the image. The model sees the picture and nothing else.
It can be wrong. It may misread a chart, miss a signal, or report one that is not there. Every result carries a confidence level and a list of what could not be determined, and an image scan is never reported as high confidence, because a picture cannot answer the questions that decide whether a token is a rug.
Your images are not used to train models, and no automated decision here has a legal or similarly significant effect on you — it is information you choose what to do with. If you would rather not have an image analysed by a model, do not submit it; the app cannot produce a chart read any other way.
How long we keep things, and how deletion works
Submitted images are discarded as soon as they have been read. They are never written to a database, an object store, or a disk, so there is nothing to delete later and no bucket that could be left exposed.
Everything else in the tables above is kept until you delete your account, and deletion is immediate rather than a request queued for review. Profile → Settings → Delete account removes your account row, your scan history, your watchlist, your subscription record, and the image hashes, and clears what the app stored on your device. Records we are legally required to retain — payment and tax records, held by our payment providers — survive, and server logs age out on their own short cycle.
Deleting your account does not cancel an App Store subscription. Apple owns that relationship, and you have to cancel it through Apple, or billing continues. The app says so before you confirm.
Who else sees your data
We use a small number of processors. Each one gets only what it needs to do its job, and none of them are permitted to use your data for their own purposes.
- Anthropic — receives the chart image you submit, in order to read it. It is processed to produce your result and is not used to train models.
- Apple and RevenueCat — handle subscriptions bought inside the app. Apple processes the payment; RevenueCat tells us whether your subscription is active. We never see your card.
- Our email provider — delivers verification codes and account messages. It receives your address and the message, nothing else.
- Our hosting and database providers — store the data described above on our behalf.
We do not sell your personal information, and we do not share it for advertising. There is no advertising SDK, no analytics SDK, and no third-party tracker in the app.
What we never ask for
MemeIQ does not connect to a wallet and does not take custody of anything. We will never ask for a seed phrase, a private key, an exchange API key, or a password to any other service. Nobody legitimately representing us will ask either. If something claiming to be MemeIQ asks for one, it is not us.
Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, take a copy elsewhere, or object to how we use it. You can exercise the main ones directly:
- Delete everything: Profile → Settings → Delete account. This removes your account, your scan history, and your subscription record from our servers, and clears what is stored on the device. It cannot be undone.
- Anything else — a copy of your data, a correction, or a question about how it is used — write to kannonrhodes5@gmail.com and we will respond within 30 days.
If you are in the UK or EU, our lawful bases are: performing our contract with you (your account, your scans, your subscription), our legitimate interest in keeping the service working and secure (rate limiting, abuse prevention, crash reports), and our legal obligations (tax and accounting records). If you are in California, we do not sell or share personal information as those terms are defined by the CCPA.
Children
MemeIQ is not directed at children and is rated 17+. We do not knowingly collect data from anyone under 18. If you believe a child has created an account, write to kannonrhodes5@gmail.com and we will remove it.
Security
Passwords are hashed with bcrypt and never stored in a readable form. Email addresses are verified with a single-use code, which is itself stored hashed. Traffic is encrypted in transit. Access to accounts is rate limited and locked after repeated failed sign-in attempts, and security events are logged so an attack on an account can be seen.
If there is a breach
No system is perfect. If personal information is exposed we will notify you without unreasonable delay, as North Carolina's Identity Theft Protection Act (N.C.G.S. § 75-65) requires. That notice will tell you:
- What happened, and what information was involved.
- What we have done to protect the information from further access.
- A telephone number you can call for more information and help.
- That you should stay vigilant by reviewing account statements and monitoring your free credit reports.
- The toll-free numbers and addresses of the major consumer reporting agencies — Equifax, Experian, and TransUnion.
Where the law requires it we will also notify the Consumer Protection Division of the North Carolina Attorney General's Office, and any other regulator with a claim to be told. We commit to this whether or not you live in North Carolina — running two standards of care would mean deciding whose data mattered less.
Changes
If we change this policy in a way that materially affects you, we will say so in the app before the change takes effect. The date at the top always reflects the current version.