Privacy Policy

Last updated: March 2025

1. Who we are

Mnemos ("we", "our") is a service that helps you collect, organize and share invoices and receipts with your accountant. This Privacy Policy explains what personal data we collect, how we use it, and your rights regarding that data. We process data in line with the EU General Data Protection Regulation (GDPR) and applicable Greek law.

2. Data we collect

Account data: When you register, we store your email address, company or business name, VAT number (with country code), and a hashed password. Invoice data: When you upload or import invoices (PDFs, images), we store the files and metadata we extract from them (e.g. dates, amounts, vendor names, VAT numbers) to provide the service and to allow your linked accountant to view and export them. Usage data: We may log technical data such as IP address, browser type and timestamps for security and operation of the service. We do not sell your data.

3. How we use your data

We use your data to: provide and operate the Mnemos service; process and store your invoices and extracted metadata; allow accountants you have linked to view and export your invoices as part of the service; authenticate you (e.g. via session tokens); improve the service and fix issues; and comply with legal obligations. Invoice documents and extracted data are used only to deliver the service you signed up for.

4. OCR and third-party processing

To extract text and data from your invoice images and PDFs, we use automated tools that may involve sending document content to third-party services (e.g. OpenAI) for optical character recognition (OCR). Such processing is done only to provide the extraction feature. We choose providers that comply with applicable data protection standards. By using the upload and extraction features, you consent to this processing.

5. Google Drive

If you use the "Import from Google Drive" feature, we request read-only access to the files you select. We do not store your Google credentials. Selected files are downloaded for upload into Mnemos and are then processed like any other upload. Google's own privacy policy applies to your use of Google Drive.

6. Storage, retention and security

Your data is stored on servers we use to run the service. We keep your account and invoice data for as long as your account is active and as needed to provide the service and meet legal obligations. If you delete your account, we will delete or anonymize your personal data in line with our retention policy. We apply appropriate technical and organizational measures to protect your data against unauthorized access, loss or misuse.

7. Your rights (GDPR)

You have the right to: access your personal data; correct inaccurate data; request deletion of your data; restrict or object to certain processing; and, where applicable, data portability. You may also withdraw consent where processing is based on consent. To exercise these rights or ask questions about your data, contact us at the email address given below. You have the right to lodge a complaint with a supervisory authority (e.g. the Hellenic Data Protection Authority if you are in Greece).

8. Contact

For privacy-related questions or to exercise your rights, contact us at the email address provided on the Mnemos website or in the app. We will respond within a reasonable time.