Legal

Privacy policy

How Memir collects and uses analytics about the way you use the service — what we collect, why, how long we keep it, and how to get in touch about your data.

Memir is operated by MetadataWorks. This policy covers the first-party analytics built into Memir and is governed by UK data protection law (the UK GDPR and the Data Protection Act 2018).

What we collect

To understand how Memir is used — and to make it work better — we record a fixed set of product-usage events as you move through the service:

Each event records a timestamp, the type of action, and — where relevant — the search text and the identifier of the dataset or result involved. Page-view and time-on-page recording applies only to pages within Memir — we never track your browsing on other websites — and these analytics do not store your IP address or a device fingerprint.

Signed-in users and guests

If you are signed in, these events are associated with your account. That lets us show you your own search history and understand how signed-in researchers use Memir. Events also record whether the acting user is an administrator, so internal usage can be excluded from product metrics.

If you are a guest (not signed in), your activity is associated only with a random session identifier your browser generates for the current visit. It contains no personal information and is discarded when you close the tab or browser — we never set a persistent guest identifier, so a new visit starts with a fresh identifier. It simply lets us tie together a single journey — for example, a search followed by the results you open.

If you sign in or sign up during a visit, we record a link between that visit's session identifier and your account, so the actions you took just before signing in are associated with your account as one continuous journey. Guest activity from earlier, separate visits is not linked — each visit's identifier is new.

Why we collect it — and the lawful basis

We use this data for one purpose: to understand how people use Memir so we can improve the service — which searches work, which results are useful, and where the discovery journey breaks down.

Our lawful basis under Article 6(1)(f) of the UK GDPR is legitimate interests: operating and improving a service you are using. The data is first-party and kept to the minimum needed for that purpose — we do not use it to advertise to you, to make automated decisions about you, or to build a profile for any other purpose.

Cookies and tracking

We use no advertising or tracking cookies, and we do not track you across other websites. Because we do not set any persistent tracking identifier on guests, Memir does not need a cookie-consent banner.

The only information Memir stores in your browser is functional: your sign-in token when you are signed in, and the short-lived session identifier described above. None of it is used for advertising.

Third parties and where your data lives

We do not use any third-party analytics provider. Analytics data is stored in our own database within our infrastructure — it does not leave it, and we do not sell it, share it, or send it to advertising networks or data brokers.

How long we keep it

Analytics events are automatically deleted 12 months after they are recorded, so we only ever hold a rolling year of usage data.

There are two exceptions, neither of which is used for behavioural analysis:

Your rights and contacting us

Under UK data protection law you can ask us to access, correct, or delete personal data we hold about you, and to object to or restrict how we process it. For signed-in users, the analytics described here are tied to your account.

To make a data request or ask a question about this policy, email privacy@metadataworks.co.uk.