Privacy Policy
Last updated: 2 October 2026 · momomemo by malalo studio
This policy explains what personal data momomemo collects, why, who it goes to, how long we keep it, and your rights under Thailand’s Personal Data Protection Act B.E. 2562 (2019) (“PDPA”).
1. Who we are
momomemo is the Instagram account @momomemo.app and its website, run by malalo studio, a small business operated by an individual in Thailand. malalo studio is the data controller of your personal data. Contact: momoplugin.help@gmail.com
momomemo is not owned, endorsed or operated by, or affiliated with, Instagram or Meta.
2. What momomemo does
When you share a Reel or post with @momomemo.app in a direct message (DM), our system fetches its video and caption from Instagram, has AI analyze it, and replies with a summary and the tools mentioned, plus a link to the summary’s web page, which shows where to get the things the Reel points to. The Reels you save are listed on your own private web page. You can also paste the link of an Instagram Reel or post, or a TikTok video link, as a normal chat message: we fetch its video and caption from that page (from Instagram or TikTok) and process it the same way, with our server visiting the link directly.
3. What we collect
- Instagram user ID: a number Instagram gives us when you message the bot. It identifies you only within our app.
- Instagram username: only when the bot offers you help (for example, you ask for help or seem stuck), so the email to our team is filled in for you.
- What you share: the link and caption of each Reel, post or TikTok video you send or paste, and your list of saved Reels with the date, the credits used, and the time you first opened each Reel’s summary page while signed in (for the “not opened yet” dot in your library).
- Settings: language, preferred summary length for each type of content, plan and credit balance.
- Your answer about plans: if you use up your free credits and the bot asks whether you would want a plan with more summaries, we keep your answer, when you were asked and answered, and how many credits you had used that month with your account, to count how many people are interested. If the bot asks whether you would like faster replies (an add-on plan), we keep that answer and when you were asked and answered in the same way.
- Votes: your 👍 / 🤔 on summaries. We use them as totals to spot summaries that need a recheck; they are never shown with your name.
- Technical data: Instagram message IDs (with no message text) to avoid processing a message twice, a count of recent messages that were not Reels, per-minute and per-hour counts of messages and Reels you send, to stop spam (counts only, never message text, deleted within a few hours), the time until which the bot pauses replying if you send too many too fast, short per-minute counts of calls to some web endpoints keyed by a hash of your IP address (salted with a server secret and changed daily: we never store the raw IP address, the hash cannot be turned back into one, and it is deleted within a few hours), a sign-in cookie, the records of the short sign-in links the bot sent you (a random code, the account and page the link opens, when it was created and used; kept 31 days so each link works once and expires in 30 days) and the IDs of older-style links already used, when the bot sent you its welcome card, the time of your last message to the bot (Instagram lets the bot reply only within 24 hours of your last message), the version of the Terms you accepted and when, how many times you sent a clip the system declined as sexual content involving children, the time your account was suspended (if ever), and short-lived server logs.
- Reels waiting in the queue: when the service is busy, our AI has reached its daily limit, or a clip cannot be fetched for the moment, we keep that Reel’s link and caption with your account, plus its queue status and number of tries, so we can summarize it and send it later. It is deleted as soon as the summary is sent, when we stop trying, or once 24 hours have passed since your last message (when the bot can no longer reply).
- Requests and feedback sent through the Feedback / requests page (no sign-in): the topic, your message, the Reel link (if given), your Instagram username and email (if given), and an IP hash as above for rate limiting; kept 12 months (requests: 2 years). We also log when a summary is hidden or removed on a request (Reel ID, kind of request, action and time, nothing about who shared the Reel) and keep that log for at least 2 years.
- Aggregate statistics: outbound links on our web pages (including the Follow on Instagram button, and links in older chat replies) go through our /go page before the destination. For each tap we record only the time, the Reel the link is on, the kind of link, the shop, the destination domain, the country, and whether it came from the web or the chat. We also count how many times each kind of page is opened per day and country (including whether it was opened from a shared link) and how many times the share button is tapped. This data contains no Instagram user ID or username, no IP address and no browser details, and uses no cookies. We count it ourselves and use no third-party analytics service.
We do not store messages that are not Reels or the video files, and we have no access to your password, contacts, followers or other chats. We do not intend to collect sensitive data (such as health or religion); please do not send it to the bot.
4. How we use it and our legal basis
- To provide the service you ask for: analyze Reels, reply, keep your saved list, settings and credits, count your monthly free quota, and sign you in to your page. Basis: contract (our Terms).
- To keep the service working, safe and fair: stop duplicates, rate-limit spam and misuse, fix errors, offer help when you seem stuck, and use votes to recheck wrong summaries. Basis: legitimate interests.
- To show shop links for your country: we read your country from your IP address when you open a page or tap a link, and do not store the IP address (only the country code, in the aggregate statistics). Basis: legitimate interests.
- To gauge interest in a paid plan: from your answer about plans in section 3. Basis: legitimate interests.
- To improve the service and choose shops: see which links, shops and pages are used, from the aggregate statistics in section 3. Basis: legitimate interests.
- To recommend products: “Momo’s picks” come from the products in the Reel, products the AI thinks often go with it, and saves and link taps counted in aggregate across all users (for example, popular products in the same category, or products from Reels that people who saved this one also saved). Recommendations never show who saved what, and ones based on users’ saves appear only when at least 3 people are involved. Basis: legitimate interests.
- To comply with the law: for example, keeping payment records for tax once paid plans exist, or answering lawful requests from authorities. Basis: legal obligation.
We do not sell personal data and do not use your data to build advertising profiles. If we ever need your consent for a use, we will ask first, and you can withdraw it at any time.
5. Service providers that process data for us
- Google Gemini API (Google, USA) receives the Reel’s video, images and caption to write the summary. We use Gemini’s free (unpaid) service: under Google’s terms, Google may use this content to improve its products and AI, and Google staff may read it.
- OpenRouter (USA) and the AI model provider it routes to translate summaries, make them shorter or longer, and translate transcripts. Free model providers may log what they receive and use it to train AI. If OpenRouter is unavailable, Google Gemini does this instead.
- Supabase (database, Singapore) stores the data in section 3.
- Vercel (servers in Singapore) runs the website and the bot and keeps short-lived technical logs.
- Meta (Instagram) carries messages between you and the bot. Your chat is also kept by Instagram under Meta’s own privacy policy.
- AniList (anilist.co) receives only the names of anime that a Reel mentions, so we can look up the title and cover image. Nothing about you is sent. Anime covers in your library and on summary pages load straight from AniList’s servers (we keep no copies), so your browser contacts AniList, which sees your IP address like on any website.
- Google’s website-icon service (www.google.com/s2/favicons): the small tool icons in the library’s “Top 5” load from this service by the tool’s domain name, so your browser contacts Google (it sees your IP address and the domain requested). We send nothing else about you.
AI providers receive Reel content only, never your Instagram user ID or username.
6. Transfers outside Thailand
These providers process data in Singapore, the USA and possibly other countries, whose data protection standards may differ from Thailand’s. We transfer data abroad only as needed to provide the service you ask for (PDPA section 28) and use providers that maintain their own security safeguards.
7. Shared summaries
A summary describes the public Reel, not you. Everyone who shares the same Reel gets the same summary, so each Reel is analyzed only once, and a summary contains nothing about who shared it.
We also sort each summary into one category automatically (for example AI & tools, recipes, places) using AI and a word list, so your library can be filtered; the category describes the Reel, not you, and can be wrong. We also note the anime, films, series, books, games and songs a Reel mentions or recommends, to rank the most-saved titles. Your own ranking is visible only to you. The ranking across everyone shows totals only, includes only titles saved by at least 3 people, and never says who saved what.
Each summary has its own web page that anyone with the link can open. The full transcript is shown only to people who saved that Reel and are signed in (including the copy-everything button and transcript translations); other readers see the beginning of the transcript (about 1,200 characters) and an invitation to send the Reel to Momo. Summary pages saved by fewer than 2 people are not indexed by search engines. The “Share with friends” button shares only that page’s link, which contains nothing about you. Summaries stay when an account is deleted. A summary that nobody has saved and nobody has shared for 6 months is deleted automatically (checked weekly).
When the original clip disappears: we check from time to time whether the original Reel or TikTok video can still be opened (when it is shared again, when its summary page is opened, at most once a day per Reel, and in a small daily pass; our server opens the clip’s public page and downloads no video). When we find that the original was deleted or made private, we hide its summary and page at once (people who saved it see “the original clip is not available”) and check again about weekly. If the clip is back within 30 days, the summary shows again; if not, we delete that summary and transcript and keep only the clip’s ID and link. We cannot promise to notice immediately.
People in clips: our AI is instructed not to transcribe the full name, address, phone number, licence plate, ID number, school or workplace of private individuals who appear in a clip (public figures, creators presenting their own content, brands and fictional characters keep their names). When a clip features an identifiable private person or centres on a minor, we store no transcript for it, its page has no share button, and search engines are told not to index it. We keep only flags describing the clip (health/money/law topic, unverified claims, private person or minor present), which are about the clip, not about you. If you find your personal data in a summary, file a request on the Feedback / requests page (section 8).
Reels we do not summarize (see section 5 of our Terms) are still checked by AI first, but we keep no summary, links or content for them and do not add them to your saved list. We keep only the Reel ID, a “declined” status and the content category, so re-shares are not checked again. This record contains nothing about who shared the Reel.
8. For Reel creators
If you made a Reel, hold its copyright or appear in it, and do not want a summary of it on momomemo, file a request on the Feedback / requests page (“File a request”) or email the Reel link to momoplugin.help@gmail.com. On a creator, copyright or illegal-content request that identifies the Reel, its summary page is hidden at once while we review (people who saved it see only that it is hidden). We acknowledge within 1 business day through the contact you gave, and decide to remove it for good or restore it within 3 business days (illegal content: within 24 hours). After removal we keep only the Reel ID, so the Reel is not summarized again when someone shares it. We keep a log of requests and actions for at least 2 years, with nothing about who shared the Reel.
9. Your saved-Reels page and cookies
The bot sends you a private link to your saved-Reels page. Each link works within 30 days of when the bot sent it, and for a short time (about 15 minutes, because some chat apps open links in advance to draw a preview) after it is first opened; then it stops working (opening it again in a browser that is already signed in is fine, but a link forwarded later stops working); the “full details” link under every Reel summary is such a link too (it signs you in and opens that summary page; once expired or used, the public summary page still opens without signing in), and you can type “link” to the bot to get a link to your list. An expired link does not delete anything: your saved Reels stay. Opening a link sets a cookie named mm_me in your browser for 90 days to keep you signed in. This cookie is needed for the page to work. We use no advertising or analytics cookies.
When you open our web pages while signed in (for example your saved-Reels page), we ask you to confirm that you are 18 or older and accept the Terms of Service and this policy, if you have not already. People who are not signed in (for example a friend opening a summary link you shared) can read Reel summary pages without accepting, and see a note that using this site is subject to the Terms and this policy. When you tap accept, the site sets a cookie named mm_ok for 1 year so we remember which version you accepted and do not ask again; if you are signed in, we also store the accepted version and the time of acceptance on your account. If the terms change in an important way, we will ask you to accept again.
You can also accept in the Instagram chat. The first time you message the bot, it sends a welcome card with links to the Terms of Service and this policy and an “I am 18+, accept” button. Until you accept, the bot does not summarize Reels or act on any message except the delete-my-data command. When you accept in the chat, we store the accepted version and the time of acceptance on your account, the same as accepting on the web (accepting in one place is enough). If you send a Reel before accepting, we keep the link and caption of that latest Reel on your account, without sending it to AI, and summarize it right after you accept.
Whoever opens the link first can see your saved list, and that browser stays signed in for the life of the cookie, so do not forward it. Tap “Log out” on your saved-Reels page to remove the cookie. To share, use the share button: it shares only that Reel’s public summary page, never your list.
The library shows the categories of your saved Reels with counts, a “not opened yet” dot on Reels whose summary page you have not opened, and, when a category is chosen, a “Top 5” of the titles, tools, products or places the Reels in that category mention most — counted from your own saved Reels only and visible only to you. Items link to the title’s AniList page, the tool’s website, a shop (through our /go page, section 10), a map or a web search. Covers and icons load from the providers in section 5.
10. Shop and affiliate links
Some shop links (for example Shopee and Lazada) are affiliate links through affiliate networks (such as Involve Asia). If you buy, momomemo may earn a commission at no extra cost to you. When you tap one, the shop and the network may set their own cookies under their own policies. We do not give them your Instagram user ID or username, and we never turn a link the creator gave into an affiliate link. Links that appear in the clip or its caption are shown first under “Links in the caption”; ours are shown separately under “Momo’s picks”. Every link goes through our /go page so taps can be counted in aggregate (section 3). These links are shown on the summary’s web page; chat replies contain only a link to that page.
Links under “Links in the caption” appear in that Reel’s clip or caption; we did not choose them. We do not show links to adult or gambling sites or to risky domains, but we do not vouch for the safety or content of the destination. Before you leave for a site we do not know, our /go page shows a warning first; known sites (for example Shopee, YouTube, GitHub) open at once.
11. How long we keep data
- Account, saved list, settings and votes: while you use momomemo. If you do not use it for 12 months, we may delete your account, and will tell you first where we can.
- Reels waiting in the queue: no longer than about 24 hours after your last message, then deleted automatically (see section 3).
- Shared summaries: as in section 7.
- Requests and feedback: 12 months (requests: 2 years). Log of summaries hidden or removed on request: at least 2 years (sections 3 and 8).
- Server logs: a short time, as set by our hosting provider.
- Payment records (once paid plans exist): as long as tax law requires.
If momomemo shuts down, we will delete personal data except what the law requires us to keep.
12. Deleting your data
Send “delete my data” or “ลบข้อมูล” to @momomemo.app and tap to confirm. Your account, saved list, settings and votes are deleted right away (vote totals on summaries stay as anonymous numbers). You can also email us or use the Feedback / requests page (“Delete my data”); we act on those requests within 30 days. See data deletion.
13. Your rights
Under the PDPA you can ask us to:
- give you access to, and a copy of, your data;
- give you your data in a commonly used format, or send it to another service;
- correct inaccurate data;
- delete your data;
- restrict the use of your data;
- stop using your data where we rely on legitimate interests (object);
- withdraw any consent you gave.
Email momoplugin.help@gmail.com or use the Feedback / requests page. We reply within 30 days and may ask you to confirm the account is yours (for example, through the bot chat). We may refuse a request where the law allows and will tell you why.
You can complain to Thailand’s Office of the Personal Data Protection Committee (PDPC): www.pdpc.or.th.
14. Security
The database can be reached only from our servers, data travels over HTTPS, and sign-in links are signed with a secret key. No system is 100% secure. If a data breach is likely to affect your rights, we will notify the PDPC and you as the law requires.
15. Age
momomemo is for people aged 18 and over. If you know of someone under 18 using it, tell us at momoplugin.help@gmail.com or on the Feedback / requests page and we will delete their data.
16. Changes to this policy
When we change this policy, we update the date at the top. For important changes, we will also tell you through the bot or on this website before they take effect.
17. Contact
malalo studio · momoplugin.help@gmail.com