Privacy Policy

Last updated: June 21, 2026

At MEMVORY, privacy isn't a feature — it is our foundation. We believe your memories are yours alone. This Privacy Policy outlines what information we collect, how we protect it, and the strict guidelines we follow to ensure your photos, videos, and stories remain confidential and secure.

1. Information We Collect

We collect only the minimum amount of data required to provide a secure, personal, and reliable timeline experience:

  • Account Information: When you join our waitlist, register, or create an account, we collect your name, email address, username, and password.
  • Media Content: We store the photos, videos, documents, and text stories you upload. Standard albums are hosted privately and only shared with the specific circles you explicitly authorize.
  • Billing Details: If you purchase storage subscriptions, payment processing is handled securely by our external payment partners: **Razorpay**, **Creem**, and **Paddle**. We do not collect or store credit card details or bank credentials on our servers.
  • Application & PWA Device Permissions: If you use the MEMVORY app on mobile devices or browsers, we request access to standard device permissions to enable core features:
    • *Storage/Photo Library:* Needed to select and upload your images/videos.
    • *Camera:* Needed if you decide to capture photos directly inside the app.
    • *Push Notifications:* Used strictly to notify you about shared circle activity or account alerts.
    • *Geolocation:* Used optionally to associate a location with your memories (only if explicitly enabled).
  • Log & System Data: We automatically record diagnostic server logs (IP address, operating system, browser type, device identifiers, and request timestamps) to diagnose security issues, prevent fraud, and ensure platform health.

2. How We Use Information

Your information is strictly utilized to operate, protect, and deliver the core MEMVORY experience:

  • To render your personal timeline and safely share albums with your selected circles.
  • To process subscription payments and manage storage limits.
  • To send platform announcements, security alerts, and respond to customer support inquiries.
  • To power our private, optional in-house organizational features (see Section 6).
Strict No-Ads & No-AI Training PolicyWe never sell your personal information or media. We do not run ads, and your photos are never used to train machine learning models or artificial intelligence algorithms.

3. Sharing of Information

We do not share, sell, lease, or distribute your private media or account data to third parties, except in the following limited circumstances:

  • Service Providers: With trusted infrastructure and hosting vendors (such as Cloudflare R2 for storage, MongoDB Atlas for databases, and authentication handlers) solely to operate the Platform services under strict data privacy agreements.
  • Legal Requirements: If required to do so by law, court order, or official government regulation, we will disclose information only to the minimum extent legally required.

4. Data Security

We employ industry-standard safety measures to protect your account and media. This includes TLS/SSL encryption for all data in transit (uploads/downloads), database encryption at rest, secure API design with correlation tracking, and strict internal firewalls.

5. Zero-Knowledge Encryption (The Vault)

Media placed inside your "Vault" is end-to-end encrypted (E2EE) on your local device before it is transmitted. This zero-knowledge architecture ensures that:

  • Your device generates the keys, and your vault passcode is never sent to our servers.
  • ClyoraLabs developers, database hosts, and external partners have absolute zero access to your Vault contents.
Passcode OwnershipSince we do not hold your decryption keys, you are solely responsible for remembering your Vault passcode. Lost passcodes cannot be reset, recovered, or bypassed under any circumstances.

6. AI Features (Optional & Self-Hosted)

To help you search, tag, and organize your photos and memories, MEMVORY plans to introduce private, smart organization tools (such as automated image tagging, face detection/recognition, auto description writing, and embedding generation for search). We approach AI with your absolute privacy as our core constraint:

  • 100% Opt-In Only: These features are completely optional. We will explicitly ask for your permission before any AI tools are activated on your account. If you choose not to opt in, no AI processing will ever run on your media.
  • Self-Hosted & In-House: Unlike other services that send your photos to external companies (such as OpenAI/ChatGPT or third-party cloud APIs), we run open-source models on our own secure, private self-hosted servers (VPS FastAPI environment with ONNX).
  • Data Never Leaves Our Infrastructure: Your photos, videos, and texts are processed locally on our self-hosted servers. They are never transmitted to third parties.
  • Zero Training: We use pre-trained open-source models solely for inference (processing on-the-fly). We **never** use your personal media, photos, or descriptions to train, fine-tune, or improve machine learning models or artificial intelligence algorithms.
Self-Hosted Private AIAll smart search and tagging models are open-source and run entirely on our self-hosted infrastructure. No external APIs, no data sharing, and no model training.

7. Data Retention & Deletion

We retain your data only for as long as your account remains active. We respect your right to delete your data at any time:

  • Content Deletion: If you delete a photo or album, it is immediately soft-deleted and placed in your trash. It is permanently erased from our operational servers and databases after a brief recovery window in accordance with our deletion policies.
  • Account Deletion: You can delete your account from your profile settings. Upon deletion, your profile metadata and all uploaded media (including Vault contents) are queued for permanent deletion and completely erased from backups within our standard 30-day retention cycle.

8. Cookies & Analytics

We use cookies and similar technologies to manage sessions and understand how users interact with our site:

  • Essential Cookies: We use secure, first-party session cookies to authenticate your account and remember your preferences. These are required for the basic operation of the Platform.
  • Third-Party Analytics: We use Google Analytics to gather general, non-identifying performance statistics (such as page views and scroll depths). You can opt out of Google Analytics tracking at any time by visiting: https://tools.google.com/dlpage/gaoptout.
  • No Ad Trackers: Because MEMVORY is an ad-free platform, we do not use, permit, or host third-party tracking pixels, advertising cookies, or remarketing beacons.

9. Global Privacy Rights

Depending on where you live (such as the European Economic Area, United Kingdom, Switzerland, or Canada), you have specific data protection rights under applicable laws (including GDPR and PIPEDA):

  • Right to Access: You can request copy of the personal data we hold about you.
  • Right to Rectification: You can correct incomplete or inaccurate data in your profile settings.
  • Right to Erasure (Decline/Deletion): You can request that we delete your account and associated media files.
  • Right to Portability: You can export copies of your albums and stories at any time from your settings console.

To exercise any of these rights, please email us at support@memvory.com. We will respond to your request within the legally required timeframe.

If you reside in the EEA or UK and believe we are processing your data unlawfully, you have the right to lodge a complaint with your local Data Protection Authority. Residents of Switzerland may contact the Federal Data Protection and Information Commissioner (FDPIC).

10. US State Disclosures & DNT

This section provides disclosures required under US State privacy laws (including California's CCPA/CPRA, Virginia, and Colorado):

Data CategoryExamples CollectedCollected in Past 12 Months?
A. IdentifiersName, alias, email address, username, IP address, device IDYes
B. Personal Information (Cal. Customer Records)Name, email, contact details, payment informationYes
C. Commercial InformationTransaction history, subscriptions, invoicesYes
D. Sensory DataUploaded photos, videos, and audio storiesYes
E. InferencesLocally generated tagging parameters (if AI is enabled)Yes

We do not sell or share your personal information or media to third parties for commercial gain or targeted advertising.

Do-Not-Track (DNT) Signals: California law requires us to state how we respond to browser DNT signals. Because there is currently no industry-wide standard for recognizing DNT signals, we do not respond to them at this time.

11. International Transfers

MEMVORY servers and databases are located in Singapore and globally. If you access our Services from Europe or other jurisdictions, your personal information will be transferred to and stored in these secure facilities. We implement the European Commission's Standard Contractual Clauses (SCCs) to ensure that your personal information receives the same level of data protection as it would in your home country.

12. Contact & Legal Information

If you have questions, concerns, or requests regarding this Privacy Policy, please contact our team:

Privacy & Security Team

Submit privacy rights queries, GDPR/CCPA requests, data exports, or account deletion inquiries directly to our team at support@memvory.com or use our Contact Form.