Privacy Policy
Effective 3 September 2026
This Privacy Policy explains how RexiMemo handles information when you use the RexiMemo website, Flipnote Studio/DSi service, DNS, NAS/Auth compatibility services, community features and moderation systems. It is written to cover both the web and DSi sides of the Service.
1. Who is responsible for your information
The person or organisation operating the RexiMemo deployment you use (the Operator) is responsible for the server-side personal information processed by that deployment and, where applicable, acts as the data controller. The developers of open-source components used by RexiMemo are not automatically controllers merely because their software is installed.
Privacy questions and rights requests should be directed to the Operator using the contact method published for the deployment. A public deployment should publish a current administrative/privacy contact method.
2. Information RexiMemo collects or receives
Account and profile information
- username and internal account ID;
- password salt and password hash (RexiMemo does not intentionally store your account password in plaintext);
- account creation and last-login times;
- profile bio, avatar selection, theme and notification preferences;
- public jump/command codes and account statistics;
- administrator/moderator status and required-password-change status where applicable.
Console and FSID information
- Flipnote creator FSIDs linked to the account;
- which FSID is the Primary Console;
- console name, selected device model, whether the model has been confirmed, and first/last-seen times;
- pending FSID information during the mini-Flipnote sign-in/linking flow;
- whether a NAS connection appears to use the known melonDS BSSID. RexiMemo currently stores the resulting emulator flag; NAS fields can also exist transiently while authentication is processed.
Public visibility: linked FSIDs and Primary status may be shown publicly on web and DSi Creator’s Rooms/profiles. Console names/models are primarily account/staff settings information unless a particular interface explicitly displays them.
Session, browser and network information
- web and DSi session identifiers, creation/expiry/last-seen times and session history;
- IP address associated with sessions and requests;
- web browser User-Agent, and browser/platform information derived from it;
- DSi-linked FSID and emulator flag associated with a session;
- DNS queries received while your console is configured to use RexiMemo as DNS, including queries that RexiMemo forwards to an upstream resolver;
- connection and server logs such as timestamps, requested paths, response status and protocol diagnostics.
Content and community activity
- uploaded Flipnote/PPM files and derived thumbnails/previews;
- Flipnote title, channel, creator FSID, original creator/filename metadata, editor name, timestamps, comment settings, view/download counts and moderation state;
- text comments, memo/Flipnote comments, replies and their creator/account information;
- stars and coloured-star balances, favorites, follows, channel membership and other community interactions;
- notifications generated from comments, stars, follows, favorites and related activity;
- search/activity information that is inherent in the records above.
Moderation and safety information
- suspensions/bans, reasons, dates and issuer information;
- private moderator notes about accounts;
- incident records, severity/category/status, summaries and actions taken;
- moderation actions, including who acted, the target and reason;
- swear-filter configuration and the fact that a submission matched a configured filter when the request is rejected or reviewed.
Diagnostic packet captures
RexiMemo includes a built-in tcpdump packet capture which, in the reference build, may start automatically unless the Operator disables it. It writes timestamped .pcap files and tcpdump diagnostics under the server’s logs directory. A packet capture can contain IP addresses, DNS queries, protocol headers, session identifiers and raw network payloads. Because parts of the historical Flipnote Studio service use plain HTTP, a diagnostic capture can potentially contain URLs, request headers, comments, uploaded Flipnote data or other content sent during the capture. Captures are intended for troubleshooting and should be protected and deleted when no longer needed.
3. How information is collected
We collect information directly from you when you create an account, change settings, upload or interact with content, and from your browser or DSi when it communicates with the Service. We also receive information from other users when they interact with you or your content. Some metadata comes from Flipnote files themselves, such as creator FSIDs and original-author fields. Technical information is generated automatically by the server, DNS/NAS/Auth layer, sessions and logs.
4. Why RexiMemo uses this information
RexiMemo uses information to:
- create, authenticate and secure accounts;
- link DSi identities/FSIDs to the correct account and enforce Primary Console upload rules;
- serve Flipnote Studio through the legacy DNS/NAS/Auth/Hatena protocol flow;
- provide profiles, uploads, playback, comments, stars, favorites, follows, notifications, channels, search and rankings;
- remember preferences and maintain active/session-history views;
- moderate content, enforce rules, investigate incidents, prevent abuse and maintain staff audit records;
- operate the swear filter and other safety controls;
- debug networking, compatibility, crashes, security problems and DSi protocol failures;
- maintain, improve, test, preserve and develop RexiMemo;
- comply with legal obligations and respond to valid legal or rights requests.
5. Legal bases where data-protection law requires them
Depending on the country and the Operator, processing may rely on one or more of the following:
- Contract / requested service: information necessary to create your account and provide the features you request.
- Legitimate interests: operating a community service, securing accounts, preventing abuse, moderating content, keeping incident records, diagnosing faults and maintaining compatibility, balanced against users’ rights.
- Legal obligation: processing needed to comply with law, court orders or valid regulatory requirements.
- Consent: only where RexiMemo specifically asks for consent for an optional use and consent is an appropriate legal basis. You may withdraw that consent where applicable.
RexiMemo does not use consent as a blanket justification for all core service processing.
6. Younger users
RexiMemo does not currently collect date of birth and therefore does not independently verify age. If you are not old enough to make privacy/account decisions on your own where you live, use RexiMemo with a parent or guardian. Where UK law applies and an optional online-service activity relies specifically on a child’s consent, additional parental-consent rules can apply to children under 13.
Do not include your real-world address, school, phone number, precise location, passwords or other sensitive personal information in public Flipnotes, comments, usernames or profile text.
7. Cookies and local web sessions
The web client uses an essential reximemo_session cookie to keep you signed in and protect forms. The cookie is marked HttpOnly and SameSite=Lax, and is marked Secure on the public HTTPS site. RexiMemo does not currently operate an advertising or behavioural-tracking cookie system. A deployment may add infrastructure outside the core software, and any such additions should be disclosed by its Operator.
8. Third-party network and asset providers
RexiMemo can interact with third parties as part of normal operation:
- DNS queries that are not answered locally may be forwarded to the Operator’s configured upstream DNS resolver (the reference build defaults to
1.1.1.1unless changed); - the web player can load flipnote.js from a public CDN such as jsDelivr, with fallback CDN support, and the web branding may load an externally hosted image;
- hosting providers, operating-system/network providers or other infrastructure used by the Operator may process standard connection data.
When your browser or console contacts a third party directly, that third party can receive ordinary connection information such as IP address, User-Agent and request time under its own privacy practices.
9. Who can see or receive information
- Everyone: public profiles, usernames, bios, public Flipnotes/comments, public activity/statistics, linked FSIDs/Primary status and other material presented as public.
- Other signed-in users: community interactions and information needed to provide them.
- Moderators and administrators: account, console, session, content and moderation information reasonably needed to operate, secure and moderate the Service.
- Infrastructure/service providers: information necessary to host, route, store, back up, diagnose or deliver RexiMemo.
- Authorities or affected parties: information where disclosure is reasonably necessary to comply with law, protect rights/safety, investigate serious abuse or respond to a valid legal request.
- A successor Operator: information may move with the Service if RexiMemo is transferred, reorganised or handed to another operator, subject to applicable law and this Policy or an updated notice.
RexiMemo does not sell personal information or use personal information for targeted advertising in the current Service. The broad User Content licence in the Terms is separate from selling users’ private account/session/moderation data.
10. What is public and what is private
Assume Flipnotes, text/memo comments, usernames, profile text, profile statistics and linked FSIDs shown in Creator’s Rooms are public. Session IDs, password hashes, IP addresses, browser User-Agents, private moderation notes and ordinary moderation incident records are not intended to be public, although staff may access them and disclosure can occur where legally required.
11. Automated filtering and decisions
RexiMemo may automatically compare public text and published Flipnote metadata with a moderator-configured swear list. A match can block a submission. This is simple content filtering, can produce false positives and is not intended to make legal or similarly significant decisions about you without human involvement. Account suspensions and other significant moderation actions are staff actions or otherwise subject to staff administration.
12. Retention
RexiMemo does not use one universal retention period for every category. In general:
- account/profile and linked-console information is kept while the account is active and for as long afterward as reasonably necessary to administer deletion, security or moderation;
- active sessions expire or end on logout/revocation, while session history may be kept for account security and diagnostics;
- public Flipnotes/comments and related community records are kept until deleted, removed or no longer needed, but file copies, caches, legacy indexes, backups and other users’ copies can persist afterward;
- moderation notes, incidents, suspensions and staff-action records may be kept longer where reasonably necessary to identify repeat abuse, maintain moderation consistency, resolve disputes or meet legal requirements;
- server logs and packet captures are kept according to the Operator’s operational needs. Diagnostic captures should be deleted when they are no longer needed;
- backups may retain deleted information for a limited period until they are rotated or overwritten.
The Operator should avoid keeping identifiable information longer than reasonably necessary for the purposes described above.
13. Security
RexiMemo uses salted PBKDF2 password hashing and server-side sessions, and the web session cookie is HttpOnly/SameSite=Lax. However, no system is perfectly secure.
Important legacy-protocol warning: unmodified Flipnote Studio depends on obsolete Nintendo/Hatena-era networking. RexiMemo’s compatibility layer can use SSLv3 for NAS/Auth and plain HTTP for later DSi traffic. SSLv3 and HTTP do not meet modern transport-security standards. A web deployment may also be served over plain HTTP unless the Operator places it behind HTTPS. Do not reuse a sensitive password and do not send unrelated confidential information through the DSi connection.
14. International processing
RexiMemo can be self-hosted and accessed internationally. The Operator, hosting provider, upstream DNS resolver or web CDN may be located in a different country from you. Where applicable law requires safeguards for international transfers, the Operator is responsible for putting appropriate safeguards in place.
15. Your choices and controls
Depending on the feature, you can change profile information, password, notification preferences, console name/model and Primary Console, and you can delete certain content through the web interface. You can stop using the Service and clear your web session by logging out. Because FSIDs are part of the DSi identity system, unlinking or changing consoles can affect your ability to upload from that console.
16. Your privacy rights
Depending on where you live, you may have rights to request access to personal information, correction, deletion, restriction, objection, or a portable copy, and to withdraw consent where processing is based on consent. These rights can have legal exceptions—for example where information must be retained for another person’s rights, security, moderation evidence or legal obligations.
Send a request to the Operator using the contact method published for the deployment. The Operator may need to verify that you control the account before acting on a request. If UK data-protection law applies, you may also have the right to complain to the Information Commissioner’s Office (ICO). Other countries have their own supervisory authorities.
17. Account/content deletion and public copies
Deleting or hiding a public post does not guarantee deletion of screenshots, downloads, reposts or other copies made by users. RexiMemo may also retain limited copies in backups, caches or moderation evidence where reasonably necessary. Requests to erase personal information will be handled subject to applicable law and the rights of other people.
18. Open source and privacy
RexiMemo’s use of open-source software does not make user data open source. Publishing or distributing source code does not by itself include the user database, passwords, session records, private moderation records or diagnostic captures. Third-party software licences continue to apply to the software itself.
19. Changes to this Policy
We may update this Policy as RexiMemo, its moderation tools or its network architecture changes. The current version will be posted here with a new effective date. Where a new use of personal information materially differs from what users were previously told, the Operator should give reasonable notice before or when that new processing begins.
20. Contact
For privacy questions, account-data requests or complaints, contact the person or organisation operating the RexiMemo deployment using the administrative/privacy contact method they publish. If a public deployment has not published a usable contact method, ask the Operator to provide one before submitting sensitive information.