Privacy Policy
Last updated: July 26, 2026
Your memories belong to you. Memoirely never sells your personal data, recordings, or voice to advertisers or third parties. Your content is processed only to provide the features you choose to use.
1. Data We Collect
We collect only the data necessary to provide and improve our service:
- Account information — name, email address, and authentication credentials.
- Audio recordings — voice recordings you create using the microphone or upload.
- Transcripts — machine-generated transcriptions of your audio recordings.
- AI summaries and reflections — AI-generated summaries, metadata, and journal reflections.
- Embeddings — vector representations of your content used for semantic search.
- Metadata — extracted people, places, topics, emotions, and keywords from your memories.
- Chat messages — questions and AI responses from the Memory Chat feature.
- Journal entries — your daily journal responses and streak data.
- Login information — timestamps and method of authentication, recorded by our authentication provider (Supabase Auth) for security purposes.
- IP address — collected for security auditing and stored in audit logs for admin review.
- Usage analytics — AI feature usage metrics (transcription minutes, embeddings generated, chat queries). This data is used for billing quota tracking and service improvement. We do not use third-party analytics platforms.
2. How We Use Your Data
Your data is used exclusively to provide the features you choose to use:
- Preserve memories — store and organise your recordings, transcripts, and media in your personal archive.
- AI search — enable semantic search across your memories using vector embeddings.
- AI summaries and insights — generate title suggestions, summaries, metadata extraction, and journal reflections.
- Memory Chat — answer your questions about past memories using retrieval-augmented generation.
- Voice cloning — create a personalised text-to-speech voice only when you explicitly choose to clone your voice.
- Notifications — send you journal reminders, achievement alerts, and sharing invitations.
- Platform security — protect your account from unauthorised access and abuse.
We never sell your personal data to advertisers or third parties.
3. AI Processing & Transparency
Memoirely uses artificial intelligence to power several features. Here is exactly how AI processes your data and what you should know:
- AI is used to generate transcriptions (via Whisper), summaries, metadata, journal reflections, and chat answers (via GPT-4o-mini), and vector embeddings (via text-embedding-3-small).
- Voice cloning only happens after you explicitly record voice samples and submit them for cloning via ElevenLabs.
- AI responses may occasionally be inaccurate. You should review AI-generated content before relying on it.
- You remain responsible for what you choose to store, share, or publish through the service.
- You can opt out of AI training uses of your data at any time via Settings → Privacy & Data → AI Training Opt-Out.
4. Voice & Sensitive Data
Memoirely stores voice recordings, life stories, family history, and AI-generated insights. This is sensitive data, and we treat it with particular care:
- Voice recordings are stored in encrypted private storage and accessed only via time-limited signed URLs.
- Voice cloning is opt-in only — we never clone your voice without your explicit action.
- Your memories default to Private. You control the visibility of each memory.
- We do not analyse your voice or content for advertising, profiling, or any purpose beyond the features you use.
5. Data Sharing & Processors
We share data only with trusted service providers who are contractually obligated to protect your data under GDPR-compliant Data Processing Agreements:
- Supabase (Ireland) — database hosting, authentication, file storage. Your primary data resides in the EU (Ireland).
- OpenAI (US/global) — AI transcription (Whisper), text generation (GPT-4o-mini), and embedding generation (text-embedding-3-small).
- ElevenLabs (global) — text-to-speech synthesis and voice cloning (only when you opt in).
- Resend (EU) — transactional email delivery (notifications, sharing invites).
- Stripe (global) — payment processing for paid subscriptions. Stripe handles payment data; we never store credit card details.
Each provider is contractually obliged to process your data only for the purposes we instruct and to maintain appropriate security measures.
6. Cross-Border Data Transfers
Your data is stored primarily in the EU (Ireland) via Supabase. However, some processing — particularly AI inference and voice synthesis — may occur outside the European Economic Area (EEA) through our service providers (OpenAI, ElevenLabs).
Transfers outside the EEA are governed by:
- Standard Contractual Clauses (SCCs) adopted by the European Commission, or
- Other appropriate transfer safeguards recognised under applicable data protection law.
You can request a copy of the relevant safeguards by contacting us at contact@memoirely.com.
7. Data Retention
We retain your data for as long as your account is active and you continue to use the service. Our retention practices are:
- Active accounts: data is kept indefinitely to preserve your memories. You may delete individual items at any time.
- Account deletion: when you delete your account, all associated data is permanently removed within 30 days. Backup copies are purged within 90 days.
- Inactivity: we currently do not auto-delete data due to inactivity. If we introduce such a policy, we will notify you in advance and allow you to opt out.
- You decide: you can export your data at any time and delete your account whenever you choose.
8. Your Rights
Under the General Data Protection Regulation (GDPR) and equivalent laws, you have the following rights:
- Right to access — request a copy of all data we hold about you.
- Right to rectification — correct inaccurate or incomplete data (edit your memories, profile, and AI content inline).
- Right to erasure — request deletion of your data (Settings → Privacy & Data → Delete Account).
- Right to restrict processing — limit how we process your data.
- Right to data portability — receive your data in a structured, machine-readable format (JSON export).
- Right to object — object to processing based on legitimate interests. You can also opt out of AI training in Settings.
- Right to withdraw consent — withdraw consent for AI processing, voice cloning, and marketing emails at any time.
- Right to be informed — you are reading this policy now.
You can exercise most rights directly from your account. See our GDPR & Data Requests page for detailed instructions.
9. Consent
We ask for your explicit consent before processing your data in certain ways:
- AI processing — you consent to AI processing by using the service. You can opt out of AI training in Settings.
- Voice cloning — explicit opt-in consent is required before we submit voice samples for cloning.
- Marketing emails — we will only send marketing emails with your explicit consent.
- Cookies — strictly necessary cookies are set automatically. Functional cookies respect your browser preferences.
10. Data Minimisation
We collect only the data we actually need to provide each feature. We do not collect:
- Government-issued identifiers
- Financial information (handled entirely by Stripe)
- Precise geolocation
- Contact lists or social graph data
- Biometric data other than voice recordings (which you explicitly create)
11. Security
We implement the following security measures to protect your data:
- Encryption at rest (database and storage) and in transit (HTTPS/TLS).
- Supabase Authentication with secure HTTP-only cookies via @supabase/ssr.
- Row-Level Security (RLS) on all database tables — users can only access their own data.
- Time-limited signed URLs (1-hour max) for accessing private media files.
- Rate limiting on all API endpoints to prevent abuse.
- Regular security audits and dependency updates.
- No service-role keys exposed to client-side code.
While we follow industry best practices, no online service is 100% secure. We recommend using a strong, unique password and enabling any additional security measures your authentication provider offers.
12. Changes to This Policy
We may update this Privacy Policy when we add new features, change service providers, or as required by law. We will update the "Last updated" date above. For material changes, we will notify you via email and may ask you to re-confirm your consent where required.
13. Contact
For privacy-related inquiries, data subject requests, or to contact our Data Protection Officer:
- Email: contact@memoirely.com
- Data Protection Officer: contact@memoirely.com
We will respond to your request within 30 days. If you are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority.