Memori
Privacy Policy
Last updated: 19 August 2026
Memori ("we", "us", "our") is a journal and memory book app designed to help you capture, store, and revisit your memories. We are committed to protecting your privacy and handling your data transparently and responsibly.
This policy explains what data we collect, why we collect it, how we use it, and your rights.
1. Who We Are (Data Controller)
Memori is operated by Memori App (UK).
We act as the data controller for your personal data.
If you have any questions about this policy or your data, you can contact us at:
memorispaces@gmail.com
2. Information We Collect
We only collect the data necessary to provide and improve the app.
Account Information
- Email address (required for sign-in via magic link, Google OAuth, or Apple Sign-In)
- Display name (from your Google or Apple profile, or set by you)
- Apple User ID (if you sign in with Apple - Apple may provide a private relay email address)
- Profile photo (optional, stored securely if provided)
Content You Create
- Journal entries (title, body text, date, tags, favourites)
- Photos (stored securely in cloud storage)
- Voice recordings (used only for transcription and not stored on our servers)
- Location (only if you grant permission, used to tag entries)
Account and Subscription Data
- Trial start and expiry dates
- Subscription status (managed by Apple/Google or our payment provider)
Setup and Referral
- Your answers to the two optional setup questions (what you find hardest about keeping photos, and who you are keeping your journal for). You can skip either question
- How you arrived at Memori (an invite link, a referral link, or directly), and the journal an invite pointed you to, so we can set up your access and any joining offer correctly
Waitlist Information
- Email address (only if you choose to join a waitlist, such as the Memori Events waitlist, so we can let you know when a feature launches). You do not need a Memori account to join a waitlist, and you can ask us to remove your email at any time.
Usage Data (Pseudonymised)
- App interaction events (e.g. "entry created", "journal shared")
- Onboarding progress and feature usage
This data is pseudonymised and does not include your journal content, photos, or identifiable personal text.
What We Do NOT Collect
- We do not collect financial information (handled by Apple/Google)
- We do not use advertising SDKs
- We do not track you across apps or websites
- We do not sell, rent, or trade your personal data
3. How We Use Your Information
We use your data strictly to operate and improve the app:
| Purpose | Data Used |
| Account authentication | Email, profile data, Apple User ID |
| Store and display memories | Entries, photos, location |
| Voice-to-text transcription | Temporary audio |
| Generate Memory Books (PDF) | Selected entries and photos |
| Share journals | Email of invited users |
| Manage subscriptions | Trial and subscription data |
| Send waitlist confirmations and launch updates | Email address |
| Send notifications (optional) | Device token, preferences |
| Improve the app | Pseudonymised usage data |
4. Legal Basis for Processing (UK GDPR / EU GDPR)
We rely on the following legal bases:
- Contract - to provide and operate the app
- Legitimate Interests - to improve the app through analytics
- Consent - for optional features (location, microphone, notifications)
You can withdraw consent at any time via your device settings or by contacting us.
5. Third-Party Services
We use trusted service providers to operate the app. We only share the minimum data necessary.
| Service | Data Shared | Purpose |
| Supabase (EU) | Account data, entries, photos | Authentication, database, storage, and backups |
| Vercel | Requests to our website and backend | Website and backend hosting |
| Apple (Sign in with Apple) | Apple User ID, email, name | Authentication (data stays with Apple) |
| Stripe | Payment details and delivery contact for book orders | Process payments for printed books |
| RevenueCat | Subscription and purchase status, device identifiers | Manage app subscriptions and access |
| Gelato | Your Memory Book file and delivery name, address, and contact details | Print and deliver your Memory Book |
| OpenAI | Audio recordings | Voice transcription (not retained) |
| BigDataCloud | GPS coordinates | Convert coordinates into place names |
| Resend | Email address | Send account, sharing, and waitlist emails |
| EmailJS | Name, email, message | Send feedback and bug reports |
| Sentry | Pseudonymised diagnostic and crash data (no journal content) | Error monitoring |
| PostHog (EU) | Pseudonymised usage data | Product analytics |
All providers act as data processors under contract and do not use your data for their own purposes.
We also keep internal operational records needed to run the service reliably and securely, such as system and webhook logs, service usage logs, waitlist entries, and pending journal invitations. These are used only to operate and secure the service. Encrypted database backups are held by our hosting providers and expire automatically on their standard backup cycle.
6. International Data Transfers
Some services we use (such as OpenAI) may process data outside the UK or European Economic Area (EEA).
Where this occurs, we ensure appropriate safeguards are in place, such as:
- Standard Contractual Clauses (SCCs)
- Providers with strong security and data protection commitments
7. Device Permissions
Memori requests optional permissions:
- Microphone - to record voice memos for transcription
- Photo library - to attach images to entries
- Location - to tag entries with a place
- Notifications - to send reminders and alerts
You can disable any permission in your device settings. The app will continue to function with reduced features.
8. Data Storage and Security
We take security seriously and implement:
- Encryption in transit (HTTPS/TLS)
- Secure storage of authentication tokens (iOS Keychain / Android Keystore)
- Row Level Security (RLS) to restrict access to your data
- Private storage buckets with time-limited access URLs
- Server-side processing for sensitive operations
- Access controls and regular security reviews
Voice recordings are deleted immediately after transcription and never stored on our servers.
9. Data Sharing Within Journals
If you share a journal, other members can see:
- Entries (text, photos, dates, tags, location)
- Display names and avatars of members
You control access and can remove members at any time.
When a member leaves or is removed from a journal, they keep read access and can export their contributions for 7 days, after which their access ends. The memories they added remain in the journal for its other members.
10. Free Trial and Subscription
- 14-day free trial with full access
- After trial expiry: read-only access
If no subscription is started:
- Your account may be disabled after around 90 days of inactivity, and we will give you advance warning before that happens
- If your account is disabled, your entries and photos may then be permanently deleted
- You can restore full access at any time before deletion by subscribing
Your data is yours.
11. Data Retention
- Active accounts - retained while your account is active
- Deleted entries - retained for up to 1 hour so you can recover them, then permanently deleted
- Expired trial accounts - your account may be disabled after around 90 days of inactivity, with advance warning beforehand; if that happens, your entries and photos may then be permanently deleted
- Deleted accounts - your account and content are permanently erased. Memories you added to someone else's shared journal remain in that journal for its other members, with your name removed. We keep a minimal record of the deletion itself, your account ID and email address, for legal and security purposes
- Members who leave or are removed from a journal - you keep read access and can export your contributions for 7 days, then your access ends. The memories you added remain in the journal for its other members
- Dormant shared journals - if a shared journal has no active members, it is permanently deleted after 90 days, with advance warning emails beforehand. Everything in it, including memories and photos, is removed
- Printed book files - we keep a copy of your printed book file for 90 days after delivery to support reprints and quality issues, then delete it
Analytics data is retained only as long as necessary for product improvement.
12. Your Rights
You have the right to:
- Access your data
- Export your data (available in-app)
- Correct your data
- Delete your account and data
- Withdraw consent
- Object to processing
You can exercise these rights via the app or by contacting us.
We respond to all requests within one month.
13. Children's Privacy
Memori is not intended for children under 13, and we do not knowingly collect their data.
If you believe a child has created an account, please contact us and we will delete it promptly.
14. Changes to This Policy
We may update this policy occasionally. We will update the "Last updated" date and notify users of significant changes.
15. Contact Us
If you have any questions:
memorispaces@gmail.com
memoriapp.co.uk
Memori is built to help you keep your memories, privately, securely, and entirely under your control.