At MEMVORY, privacy isn't a feature — it is our foundation. We believe your memories are yours alone. This Privacy Policy outlines what information we collect, how we protect it, and the strict guidelines we follow to ensure your photos, videos, and stories remain confidential and secure.
1. Information We Collect
We collect only the minimum amount of data required to provide a secure, personal, and reliable timeline experience:
- Account Information: When you join our waitlist, register, or create an account, we collect your name, email address, username, and password.
- Media Content: We store the photos, videos, documents, and text stories you upload. Standard albums are hosted privately and only shared with the specific circles you explicitly authorize.
- Billing Details: If you purchase storage subscriptions, payment processing is handled securely by our external payment partners: **Razorpay**, **Creem**, and **Paddle**. We do not collect or store credit card details or bank credentials on our servers.
- Application & PWA Device Permissions: If you use the MEMVORY app on mobile devices or browsers, we request access to standard device permissions to enable core features:
- *Storage/Photo Library:* Needed to select and upload your images/videos.
- *Camera:* Needed if you decide to capture photos directly inside the app.
- *Push Notifications:* Used strictly to notify you about shared circle activity or account alerts.
- *Geolocation:* Used optionally to associate a location with your memories (only if explicitly enabled).
- Log & System Data: We automatically record diagnostic server logs (IP address, operating system, browser type, device identifiers, and request timestamps) to diagnose security issues, prevent fraud, and ensure platform health.
2. How We Use Information
Your information is strictly utilized to operate, protect, and deliver the core MEMVORY experience:
- To render your personal timeline and safely share albums with your selected circles.
- To process subscription payments and manage storage limits.
- To send platform announcements, security alerts, and respond to customer support inquiries.
- To power our private, optional in-house organizational features (see Section 6).
4. Data Security
We employ industry-standard safety measures to protect your account and media. This includes TLS/SSL encryption for all data in transit (uploads/downloads), database encryption at rest, secure API design with correlation tracking, and strict internal firewalls.
5. Zero-Knowledge Encryption (The Vault)
Media placed inside your "Vault" is end-to-end encrypted (E2EE) on your local device before it is transmitted. This zero-knowledge architecture ensures that:
- Your device generates the keys, and your vault passcode is never sent to our servers.
- ClyoraLabs developers, database hosts, and external partners have absolute zero access to your Vault contents.
6. AI Features (Optional & Self-Hosted)
To help you search, tag, and organize your photos and memories, MEMVORY plans to introduce private, smart organization tools (such as automated image tagging, face detection/recognition, auto description writing, and embedding generation for search). We approach AI with your absolute privacy as our core constraint:
- 100% Opt-In Only: These features are completely optional. We will explicitly ask for your permission before any AI tools are activated on your account. If you choose not to opt in, no AI processing will ever run on your media.
- Self-Hosted & In-House: Unlike other services that send your photos to external companies (such as OpenAI/ChatGPT or third-party cloud APIs), we run open-source models on our own secure, private self-hosted servers (VPS FastAPI environment with ONNX).
- Data Never Leaves Our Infrastructure: Your photos, videos, and texts are processed locally on our self-hosted servers. They are never transmitted to third parties.
- Zero Training: We use pre-trained open-source models solely for inference (processing on-the-fly). We **never** use your personal media, photos, or descriptions to train, fine-tune, or improve machine learning models or artificial intelligence algorithms.
7. Data Retention & Deletion
We retain your data only for as long as your account remains active. We respect your right to delete your data at any time:
- Content Deletion: If you delete a photo or album, it is immediately soft-deleted and placed in your trash. It is permanently erased from our operational servers and databases after a brief recovery window in accordance with our deletion policies.
- Account Deletion: You can delete your account from your profile settings. Upon deletion, your profile metadata and all uploaded media (including Vault contents) are queued for permanent deletion and completely erased from backups within our standard 30-day retention cycle.
9. Global Privacy Rights
Depending on where you live (such as the European Economic Area, United Kingdom, Switzerland, or Canada), you have specific data protection rights under applicable laws (including GDPR and PIPEDA):
- Right to Access: You can request copy of the personal data we hold about you.
- Right to Rectification: You can correct incomplete or inaccurate data in your profile settings.
- Right to Erasure (Decline/Deletion): You can request that we delete your account and associated media files.
- Right to Portability: You can export copies of your albums and stories at any time from your settings console.
To exercise any of these rights, please email us at support@memvory.com. We will respond to your request within the legally required timeframe.
If you reside in the EEA or UK and believe we are processing your data unlawfully, you have the right to lodge a complaint with your local Data Protection Authority. Residents of Switzerland may contact the Federal Data Protection and Information Commissioner (FDPIC).
10. US State Disclosures & DNT
This section provides disclosures required under US State privacy laws (including California's CCPA/CPRA, Virginia, and Colorado):
| Data Category | Examples Collected | Collected in Past 12 Months? |
|---|---|---|
| A. Identifiers | Name, alias, email address, username, IP address, device ID | Yes |
| B. Personal Information (Cal. Customer Records) | Name, email, contact details, payment information | Yes |
| C. Commercial Information | Transaction history, subscriptions, invoices | Yes |
| D. Sensory Data | Uploaded photos, videos, and audio stories | Yes |
| E. Inferences | Locally generated tagging parameters (if AI is enabled) | Yes |
We do not sell or share your personal information or media to third parties for commercial gain or targeted advertising.
Do-Not-Track (DNT) Signals: California law requires us to state how we respond to browser DNT signals. Because there is currently no industry-wide standard for recognizing DNT signals, we do not respond to them at this time.
11. International Transfers
MEMVORY servers and databases are located in Singapore and globally. If you access our Services from Europe or other jurisdictions, your personal information will be transferred to and stored in these secure facilities. We implement the European Commission's Standard Contractual Clauses (SCCs) to ensure that your personal information receives the same level of data protection as it would in your home country.
12. Contact & Legal Information
If you have questions, concerns, or requests regarding this Privacy Policy, please contact our team:
Privacy & Security Team
Submit privacy rights queries, GDPR/CCPA requests, data exports, or account deletion inquiries directly to our team at support@memvory.com or use our Contact Form.