Privacy Policy

Effective 3 September 2026

This Privacy Policy explains how RexiMemo handles information when you use the RexiMemo website, Flipnote Studio/DSi service, DNS, NAS/Auth compatibility services, community features and moderation systems. It is written to cover both the web and DSi sides of the Service.

1. Who is responsible for your information

The person or organisation operating the RexiMemo deployment you use (the Operator) is responsible for the server-side personal information processed by that deployment and, where applicable, acts as the data controller. The developers of open-source components used by RexiMemo are not automatically controllers merely because their software is installed.

Privacy questions and rights requests should be directed to the Operator using the contact method published for the deployment. A public deployment should publish a current administrative/privacy contact method.

2. Information RexiMemo collects or receives

Account and profile information

Console and FSID information

Public visibility: linked FSIDs and Primary status may be shown publicly on web and DSi Creator’s Rooms/profiles. Console names/models are primarily account/staff settings information unless a particular interface explicitly displays them.

Session, browser and network information

Content and community activity

Moderation and safety information

Diagnostic packet captures

RexiMemo includes a built-in tcpdump packet capture which, in the reference build, may start automatically unless the Operator disables it. It writes timestamped .pcap files and tcpdump diagnostics under the server’s logs directory. A packet capture can contain IP addresses, DNS queries, protocol headers, session identifiers and raw network payloads. Because parts of the historical Flipnote Studio service use plain HTTP, a diagnostic capture can potentially contain URLs, request headers, comments, uploaded Flipnote data or other content sent during the capture. Captures are intended for troubleshooting and should be protected and deleted when no longer needed.

3. How information is collected

We collect information directly from you when you create an account, change settings, upload or interact with content, and from your browser or DSi when it communicates with the Service. We also receive information from other users when they interact with you or your content. Some metadata comes from Flipnote files themselves, such as creator FSIDs and original-author fields. Technical information is generated automatically by the server, DNS/NAS/Auth layer, sessions and logs.

4. Why RexiMemo uses this information

RexiMemo uses information to:

5. Legal bases where data-protection law requires them

Depending on the country and the Operator, processing may rely on one or more of the following:

RexiMemo does not use consent as a blanket justification for all core service processing.

6. Younger users

RexiMemo does not currently collect date of birth and therefore does not independently verify age. If you are not old enough to make privacy/account decisions on your own where you live, use RexiMemo with a parent or guardian. Where UK law applies and an optional online-service activity relies specifically on a child’s consent, additional parental-consent rules can apply to children under 13.

Do not include your real-world address, school, phone number, precise location, passwords or other sensitive personal information in public Flipnotes, comments, usernames or profile text.

7. Cookies and local web sessions

The web client uses an essential reximemo_session cookie to keep you signed in and protect forms. The cookie is marked HttpOnly and SameSite=Lax, and is marked Secure on the public HTTPS site. RexiMemo does not currently operate an advertising or behavioural-tracking cookie system. A deployment may add infrastructure outside the core software, and any such additions should be disclosed by its Operator.

8. Third-party network and asset providers

RexiMemo can interact with third parties as part of normal operation:

When your browser or console contacts a third party directly, that third party can receive ordinary connection information such as IP address, User-Agent and request time under its own privacy practices.

9. Who can see or receive information

RexiMemo does not sell personal information or use personal information for targeted advertising in the current Service. The broad User Content licence in the Terms is separate from selling users’ private account/session/moderation data.

10. What is public and what is private

Assume Flipnotes, text/memo comments, usernames, profile text, profile statistics and linked FSIDs shown in Creator’s Rooms are public. Session IDs, password hashes, IP addresses, browser User-Agents, private moderation notes and ordinary moderation incident records are not intended to be public, although staff may access them and disclosure can occur where legally required.

11. Automated filtering and decisions

RexiMemo may automatically compare public text and published Flipnote metadata with a moderator-configured swear list. A match can block a submission. This is simple content filtering, can produce false positives and is not intended to make legal or similarly significant decisions about you without human involvement. Account suspensions and other significant moderation actions are staff actions or otherwise subject to staff administration.

12. Retention

RexiMemo does not use one universal retention period for every category. In general:

The Operator should avoid keeping identifiable information longer than reasonably necessary for the purposes described above.

13. Security

RexiMemo uses salted PBKDF2 password hashing and server-side sessions, and the web session cookie is HttpOnly/SameSite=Lax. However, no system is perfectly secure.

Important legacy-protocol warning: unmodified Flipnote Studio depends on obsolete Nintendo/Hatena-era networking. RexiMemo’s compatibility layer can use SSLv3 for NAS/Auth and plain HTTP for later DSi traffic. SSLv3 and HTTP do not meet modern transport-security standards. A web deployment may also be served over plain HTTP unless the Operator places it behind HTTPS. Do not reuse a sensitive password and do not send unrelated confidential information through the DSi connection.

14. International processing

RexiMemo can be self-hosted and accessed internationally. The Operator, hosting provider, upstream DNS resolver or web CDN may be located in a different country from you. Where applicable law requires safeguards for international transfers, the Operator is responsible for putting appropriate safeguards in place.

15. Your choices and controls

Depending on the feature, you can change profile information, password, notification preferences, console name/model and Primary Console, and you can delete certain content through the web interface. You can stop using the Service and clear your web session by logging out. Because FSIDs are part of the DSi identity system, unlinking or changing consoles can affect your ability to upload from that console.

16. Your privacy rights

Depending on where you live, you may have rights to request access to personal information, correction, deletion, restriction, objection, or a portable copy, and to withdraw consent where processing is based on consent. These rights can have legal exceptions—for example where information must be retained for another person’s rights, security, moderation evidence or legal obligations.

Send a request to the Operator using the contact method published for the deployment. The Operator may need to verify that you control the account before acting on a request. If UK data-protection law applies, you may also have the right to complain to the Information Commissioner’s Office (ICO). Other countries have their own supervisory authorities.

17. Account/content deletion and public copies

Deleting or hiding a public post does not guarantee deletion of screenshots, downloads, reposts or other copies made by users. RexiMemo may also retain limited copies in backups, caches or moderation evidence where reasonably necessary. Requests to erase personal information will be handled subject to applicable law and the rights of other people.

18. Open source and privacy

RexiMemo’s use of open-source software does not make user data open source. Publishing or distributing source code does not by itself include the user database, passwords, session records, private moderation records or diagnostic captures. Third-party software licences continue to apply to the software itself.

19. Changes to this Policy

We may update this Policy as RexiMemo, its moderation tools or its network architecture changes. The current version will be posted here with a new effective date. Where a new use of personal information materially differs from what users were previously told, the Operator should give reasonable notice before or when that new processing begins.

20. Contact

For privacy questions, account-data requests or complaints, contact the person or organisation operating the RexiMemo deployment using the administrative/privacy contact method they publish. If a public deployment has not published a usable contact method, ask the Operator to provide one before submitting sensitive information.