Go to App
FeaturesPricingHelpBlogGo to App

Privacy Policy

Last updated: 5 July 2026

This Privacy Policy explains how Memrary collects, uses, stores, and protects personal data when you use Memrary's websites, apps, and related services (the "Service").

Memrary is designed for private and family memory keeping. We do not sell your personal data, we do not use advertising trackers, and we do not use your content to train AI models.

Who we are

The Service is operated by Memrary UG (in formation), Germany ("Memrary", "we", "us", or "our").

For privacy questions or requests, contact us at legal@memrary.com. For customer support, contact support@memrary.com.

Memrary is the controller of personal data we process for our own purposes, such as account management, security, billing, and providing the Service.

Who may use Memrary

Memrary is intended for personal and family use by people who are at least 16 years old. It is not directed to children under 16, and children under 16 may not create their own accounts or books.

Parents and legal guardians may create memory books that include memories about their children, provided they have the necessary rights, authority, and consent to do so.

What data we collect

We collect only the data needed to provide, secure, improve, and support the Service.

Account data

When you create or use an account, we may collect:

  • email address;
  • display name;
  • language or locale preference;
  • age-confirmation status;
  • account settings and plan information;
  • records showing that you accepted the Terms of Use and this Privacy Policy, including the accepted version and timestamp.

We use magic-link authentication, so a valid email address is required to access your account.

Content you choose to store

Memrary stores the memories and related information you choose to create or upload, including:

  • text posts;
  • photos, videos, and audio;
  • comments, where available;
  • tags and post metadata;
  • location information, if you add it;
  • book settings, sharing circles, invitations, public sharing settings, and co-owner/follower relationships.

Content is private by default. You decide whether to share it with circles, invited people, co-owners, followers, or the public.

Technical and security data

To operate and protect the Service, we may process:

  • IP address;
  • browser or user-agent information;
  • request timestamps;
  • login and magic-link events;
  • failed login attempts;
  • server logs and error information generated by AWS infrastructure.

Security logs containing IP addresses, user-agent information, timestamps, and failed-attempt records are generally retained for 7 days unless we need to keep them longer for abuse prevention, security investigations, legal compliance, or dispute resolution.

Billing data

Paid plans are planned but not yet generally available. When paid plans are introduced, payments will be processed by Stripe or another disclosed payment processor. We do not intend to store full payment-card details on Memrary systems. We may receive billing status, plan, invoice, tax, and transaction metadata needed to manage subscriptions and comply with legal obligations.

Support communications

If you contact us, we may process the information you provide in your message and any related account or diagnostic information needed to respond.

What we do not collect or do

Memrary does not:

  • sell or rent your personal data;
  • share your personal data for advertising or cross-context behavioral advertising;
  • use advertising cookies;
  • use third-party tracking scripts;
  • use your content to train AI models;
  • use your private content for marketing;
  • collect arbitrary files such as PDFs as a general file-storage service;
  • operate as a business, enterprise, or professional records-management service.

How we use data

We use personal data for the following purposes:

  • creating and authenticating accounts;
  • storing, displaying, sharing, exporting, and deleting memory books and posts according to your settings;
  • processing media files, including thumbnails, previews, derivatives, and delivery URLs;
  • providing invitations, circles, follows, co-ownership, and public sharing features;
  • preventing abuse, enforcing our Terms of Use, and detecting prohibited or illegal content;
  • maintaining security, integrity, backups, and service reliability;
  • responding to support, legal, privacy, or security requests;
  • sending service, security, product, support, billing, and account-related communications;
  • sending marketing or newsletter emails only where you have separately opted in;
  • complying with legal obligations and protecting rights, safety, and property.

Legal bases for EU/UK users

For users in the EU, EEA, UK, and similar jurisdictions, we rely on the following legal bases:

  • Contract: to provide the Service you request, including account access, content storage, sharing, export, deletion, and billing.
  • Consent: for optional marketing emails and optional device or feature permissions where applicable.
  • Legitimate interests: to secure the Service, prevent abuse, maintain logs, improve reliability, respond to support requests, and enforce our Terms, provided those interests are not overridden by your rights.
  • Legal obligation: to comply with tax, accounting, consumer protection, privacy, safety, law-enforcement, and other legal requirements.
  • Vital or public-interest reasons where applicable: for exceptional safety or legally required reporting situations, such as child sexual abuse material or credible threats.

Cookies and analytics

Memrary uses necessary cookies or similar technologies for authentication and session management. We do not use advertising cookies or behavioral tracking cookies.

At launch, Memrary relies on AWS logs and operational infrastructure logs for security and reliability. We do not use third-party advertising analytics or tracking scripts.

If we later add privacy-friendly analytics, we will update this policy and avoid using analytics for advertising or cross-site tracking.

AI and automated content moderation

Memrary may use automated systems to detect, reject, restrict, or remove illegal or prohibited content, including during upload.

For privacy reasons:

  • we do not use your content to train AI models;
  • we do not route your content to third-party foundation model providers through AWS Bedrock;
  • moderation models are AWS-owned, open-weight, or custom models hosted within our AWS environment or AWS perimeter;
  • automated processing is used only to provide, secure, moderate, and enforce the Service.

Automated systems can make mistakes. Where appropriate, you may appeal moderation or account-enforcement decisions by contacting legal@memrary.com.

Human review

Memrary staff do not review private content as a routine practice. We may manually review content or account information only when reasonably necessary for:

  • safety, abuse, or security investigations;
  • enforcing the Terms of Use;
  • responding to user support requests or user consent;
  • complying with legal obligations;
  • protecting the rights, safety, or property of users, Memrary, or others.

Sharing and public content

Content is private by default. You may choose to share content with circles, invited people, co-owners, followers, or the public.

When you make content public, it may be accessible to anyone on the internet. Public content may be indexed, cached, copied, archived, or redistributed by search engines and other third parties outside Memrary's control. Even if public access is later removed, copies may remain elsewhere.

Only book owners can export or download a full book export from Memrary. Other viewers may view shared content inside Memrary according to the permissions you set.

Providers and subprocessors

We use trusted service providers to operate the Service. They process personal data only as needed to provide services to Memrary and under contractual or legal safeguards.

Current or planned providers include:

  • Amazon Web Services (AWS): hosting, storage, databases, backups, logs, email or infrastructure services, media processing, and AWS-hosted AI/moderation systems;
  • Cloudflare: DNS, CDN, security, caching, and related network services;
  • Stripe: payment processing and subscription billing when paid plans become available.

We may update this list as the Service evolves. If we add providers that materially change how personal data is processed, we will update this Privacy Policy.

International data transfers and storage location

Memrary's primary production infrastructure is intended to be hosted in AWS eu-west-1 (Ireland). This supports EU data residency for primary storage.

We may process data in other locations where our providers, staff, or support operations are located, including where necessary for security, support, billing, legal compliance, or provider operations. Where required, we use appropriate safeguards such as data-processing agreements, Standard Contractual Clauses, the UK international data transfer framework, or other legally recognized transfer mechanisms.

Backups and snapshots may be retained for up to 30 days. Backup storage is designed for security and disaster recovery, not routine access.

Data retention

We keep personal data only as long as needed for the purposes described in this policy, unless a longer period is required or permitted by law.

Typical retention periods are:

  • Account data: until account deletion, plus any legally required retention.
  • User content: until you delete it, your account is deleted, or enforcement/legal obligations require otherwise.
  • Deleted/trash posts: generally 30 days.
  • Edit/version history: generally 30 days.
  • Security logs with IP address, user-agent information, timestamps, and failed-attempt records: generally 7 days.
  • Backups and snapshots: up to 30 days.
  • Support correspondence: as long as needed for support, legal, security, or dispute-resolution purposes.
  • Billing, tax, and accounting records: as required by applicable law.
  • Terms and policy acceptance records: as long as needed to administer the account and demonstrate compliance.

When you delete data, it may remain temporarily in backups until those backups expire. We may also retain limited information where necessary for legal compliance, security, fraud prevention, abuse investigations, accounting, dispute resolution, or enforcement of our Terms.

Your privacy rights

Depending on where you live, you may have rights to:

  • access personal data we hold about you;
  • correct inaccurate data;
  • delete personal data;
  • export or receive a copy of your data;
  • object to or restrict certain processing;
  • withdraw consent where processing is based on consent;
  • opt out of marketing emails;
  • complain to a data-protection authority.

You can export your book data from the Service where export tools are available. You can request account deletion through self-service account controls where available or by contacting legal@memrary.com.

We may need to verify your identity before fulfilling certain requests. We aim to respond within the time required by applicable law, including within one month for GDPR/UK GDPR requests and within 45 days for applicable California privacy requests.

California and US state privacy notices

Memrary does not sell personal information and does not share personal information for cross-context behavioral advertising. We do not use sensitive personal information to infer characteristics or for advertising.

If you are a California resident or live in a US state with similar privacy laws, you may have rights to know, access, correct, delete, and receive a copy of certain personal information, and to be free from discrimination for exercising those rights. Because Memrary does not sell personal information or share it for behavioral advertising, we do not currently provide a "Do Not Sell or Share" mechanism.

Security

We use reasonable technical and organizational measures to protect personal data, including HTTPS/TLS in transit, AWS infrastructure controls, access controls, backups, and security monitoring appropriate to the Service.

No online service can guarantee absolute security. Memrary is intended for personal memories, but you should avoid storing information whose unauthorized disclosure would cause serious harm unless you are comfortable with that residual risk.

Memrary is not currently end-to-end encrypted. This means that, where technically and legally necessary, Memrary systems and authorized personnel may be able to process content to provide the Service, secure the platform, comply with law, or enforce the Terms.

If we become aware of a data breach requiring notification, we will notify affected users, regulators, or other parties as required by applicable law.

Account deletion

You may delete your account through self-service controls where available or by contacting legal@memrary.com.

Account deletion generally deletes your account, owned books, posts, media, sharing links, invitations, sessions, and related service data, subject to temporary backup retention and legal, security, billing, abuse-prevention, or dispute-resolution exceptions.

Changes to this policy

We may update this Privacy Policy as the Service evolves. For material changes, we will provide at least 30 days' notice where practical, for example by email, in-app notice, or website notice. Changes needed for legal, safety, or security reasons may take effect sooner.

Contact

Privacy and legal requests: legal@memrary.com

Support requests: support@memrary.com