Legal

Privacy policy

Effective: 1 October 2026 · Version 1.0

This policy explains what data we process, why, who we share it with, how long we keep it, and how you can exercise your rights.

In short

  • Family Memory is a private family memory keeper. What you upload can only be seen by the people you invite to your family.
  • No ads. We don’t sell or rent your data, we don’t build advertising profiles about you, and we don’t use tracking tools.
  • Children’s photos and details are uploaded by their parents, and we handle them with extra care: no face recognition, no biometric identification.
  • The AI only receives the photos and text you choose, so it can suggest a title and a short story. You accept or rewrite the suggestion.
  • You can download and delete your account and your data in the app at any time.

This policy explains, under Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”) and Hungarian Act CXII of 2011 on informational self-determination and freedom of information, how we process personal data in the Family Memory iOS app, the family web viewer and our website (together: the “Service”).

1. The controller

Name
[Provider name]
Registered office
[Registered office]
Registration number
[Company registration number]
Tax number
[Tax number]
Email
[Contact email]

For privacy questions and to exercise your rights, contact us at the email address above. Given the nature and scale of our activities we are not required to appoint a data protection officer; if that changes, we will publish their contact details here.

2. Whose data we process

  • Parents and family members who create an account in the iOS app (owner and parent roles). Only people aged 18 or over may use the Service with an account.
  • Invited family members (e.g. grandparents, relatives) who join the web viewer through an invite link (viewer role).
  • Children whose profiles, photos and stories are recorded by a parent. Children do not use the Service themselves.
  • Other people who appear in uploaded photos, videos, audio recordings or texts (e.g. relatives, friends).
  • Waitlist subscribers and website visitors.

3. What data we process

CategoryWhat it includesSource
Account datadisplay name, email address (if you provide it or Apple shares it – this may be an Apple-generated relay address), the user identifier issued by Apple, language, hashed identifiers of your sign-in sessionsyou, or Sign in with Apple
Family datafamily name and language, members, their roles (owner / parent / viewer) and relationship labels, invites (name, role, expiry)you and your family members
Child profilename, nickname, date of birth, profile picturethe parent
Memory contentphotos, videos, audio recordings, title, story, personal note, the text transcript from “Tell it”, date, place name, tags, event type, the title and story suggested by the AIthe parent, or the AI suggestion
Reactions and commentshearts (❤️) and short comments that family members add to memories, with their author and timeyour family members
Media metadatafile type, size, resolution, duration, capture time and – if the photo contains it and you share it – its location (GPS coordinates)read from the selected files on your device
Subscription datapurchased plan, Apple transaction identifiers, subscription status and expiry. We never receive card or payment details; Apple handles those.Apple App Store notifications
Notification datayour device’s push notification token (APNs token), the notification language and your notification settings (new memory, comment), if you enable notificationsyour device
Waitlistemail address, language, source and time of sign-up, and a keyed, non-reversible hash of your IP address (the raw IP address is not stored)you
Technical dataIP address, time and path of requests, error logs, short-lived counters used for abuse prevention (rate limiting)automatically, from your use of the Service
Correspondencemessages you send us and our repliesyou

With “Tell it”, speech is converted to text by the iOS system speech recogniser. We receive the transcript and – if you keep it as part of the memory – the audio recording. Depending on your device settings, system speech recognition may also run on Apple’s servers; Apple’s privacy terms apply to that.

We do not ask for or intentionally collect special categories of data (e.g. health data). If a story nevertheless contains such data, we store it solely at your request to provide the Service and do not analyse your content for it.

4. Children’s data

The Service is for parents; children do not create accounts and the Service is not offered to them directly. Children’s data (name, date of birth, photos, videos, audio recordings, stories) is recorded by a parent exercising parental responsibility. We handle this data with extra care:

  • We do not perform face recognition, create biometric templates or automatically identify anyone from images. The parent chooses which child a memory belongs to.
  • We do not use children’s data for advertising or profiling, and we do not share it with third parties for their own purposes.
  • Media files are stored privately; there are no public links. Viewing uses short-lived signed links, issued only to family members.
  • Family members with the viewer role only see memories the parent has published, never drafts.

The parent is responsible for ensuring that uploading serves the child’s interests and – where parental responsibility is shared – that the other parent agrees. A child can exercise their rights through their legal representative and, once they come of age, themselves; at their request we delete content about them.

5. Purposes and legal bases

PurposeDataLegal basis (GDPR Art. 6(1))
Creating an account, signing in (Sign in with Apple, email sign-in link)account data, session(b) performance of a contract
Family space, invites, sharing with family members, reactions and commentsfamily data, account data, reactions and comments(b) performance of a contract
Storing, organising and displaying memories on the timelinechild profile, memory content, media metadata(b) performance of a contract (towards the account holder); for other people in the content (children, relatives): (f) legitimate interests – the parent’s and family’s interest in preserving family memories, exercised by the parent within parental responsibility
AI title and story suggestionselected photos, note, transcript, the child’s first name and age, date, place name(b) performance of a contract (a core feature of the Service)
Managing subscriptionssubscription data(b) performance of a contract; (c) legal obligation (accounting and consumer protection rules)
Push notifications (e.g. a new memory in the family)notification data(a) consent – given through the iOS notification permission and revocable there at any time
Service emails (sign-in link, security and account notices)email address, language(b) performance of a contract
Waitlist: notifying you about the launchwaitlist data(a) consent – given by signing up, revocable at any time
Security, abuse prevention, debuggingtechnical data, the waitlist IP hash(f) legitimate interests: protecting the Service and users’ data
Backups and recoverydatabase contents(f) legitimate interests, and the security obligation under GDPR Art. 32
Contact, support, complaintscorrespondence(b) performance of a contract or (f) legitimate interests; (c) legal obligation for consumer complaints
Establishing or defending legal claims, responding to authoritiesdata needed for the matter(c) legal obligation, (f) legitimate interests

Where we rely on legitimate interests we have carried out a balancing test; we will send you a summary on request. You may object to processing based on legitimate interests (see section 11).

There is no automated decision-making that produces legal effects concerning you or similarly significantly affects you (GDPR Art. 22). The AI’s output is only a suggestion; the parent decides.

6. AI processing

Memory titles and short stories are suggested by a large language model. For this we use Anthropic’s service (Claude) as a processor.

  • What the AI receives: the photos selected for that memory (up to 8 images, via a short-lived private link or sent directly), the parent’s note and the “Tell it” transcript, the first name and age of the child(ren) concerned, the date and the place name.
  • What it does not receive: videos, audio recordings, email addresses, the family’s other memories, or anything you didn’t select for that memory.
  • What it’s used for: only to produce the suggestion. The provider’s commercial terms state that data sent through its API is not used to train its models and may be retained only for a limited period for abuse monitoring.
  • We don’t use your content to train AI models either.
  • Suggestions can be wrong: the parent reviews them and accepts or rewrites them before the memory is shown to the family.

7. Processors and recipients

We use the following providers to run the Service. As processors they may process data only on our instructions, under a written data processing agreement.

ProviderTaskDataLocation
[Hosting provider name, address, contact]server hosting (application, database)all account and family data except media files[Server location (country)]
Cloudflare, Inc. (R2 storage)storage of media files (photos, videos, audio) and database backupsmedia files, encrypted backupsEU jurisdiction storage (data stays in the EU)
Anthropic (Claude API)AI title and story suggestionsas listed in section 6USA
Resenddelivery of service emails (sign-in link, notices)email address, name, message contentUSA
Apple (Apple Push Notification service)delivery of push notificationsnotification token, notification textUSA / EU

Independent controllers. For Sign in with Apple and purchases through the App Store, Apple (in the EU: Apple Distribution International Ltd., Ireland) acts as an independent controller under its own privacy policy. Apple processes the payment; we only receive the subscription status.

Your family members see the memories you share with them – viewers only see published ones. The app always shows who has access to your family.

We disclose data to authorities or courts only where required by law, and only to the extent necessary. We do not sell or rent personal data or share it for advertising.

8. Transfers outside the EEA

Some of our processors operate in the United States (sections 6 and 7). Such transfers rely on the European Commission’s adequacy decision on the EU–US Data Privacy Framework where the provider is certified, and otherwise on the Standard Contractual Clauses adopted by the Commission (Decision (EU) 2021/914) together with supplementary measures (e.g. encryption in transit). You can request information about, or a copy of, these safeguards at the email address above.

9. How long we keep data

DataRetention
Account data, family data, child profiles, memories and media filesas long as your account or the family exists; on deletion, removed from live systems without delay and media files within 30 days at the latest
Backupsrolling retention: 7 daily, 4 weekly and 6 monthly backups, so deleted data may persist in encrypted backups for up to about 6 months; backups are read only for recovery, and after a recovery previously deleted data is deleted again
Sign-in link (email)15 minutes, single use
Invite linkvalid for 14 days (until used or revoked); invite records are deleted after 30 days
Sign-in sessionuntil you sign out, or it expires after 90 days of inactivity
Unfinished uploaddeleted automatically after 24 hours
Uploaded file never attached to a memorydeleted automatically after 7 days
Push notification tokenwhile notifications are enabled, or until you sign out
Subscription datafor the duration of the subscription, then until the civil-law limitation period ends (5 years) or as long as accounting rules require
Waitlistuntil you unsubscribe, but no longer than 12 months after the launch notification
Technical logsup to 30 days; rate-limit counters up to 1 hour
Correspondence, complaints1 year after the matter is closed; consumer complaint records 3 years (Hungarian Consumer Protection Act, s. 17/A)

10. Security

  • All connections are encrypted (HTTPS / TLS).
  • Media files are stored privately; uploads and viewing use signed links valid for a short time (15 minutes and 1 hour respectively), issued only to authorised family members.
  • Every request checks family membership and role; sign-in identifiers are stored only in hashed form.
  • The database and cache are not reachable from the internet; backups are encrypted and stored separately.
  • Access by our staff is limited to the minimum their tasks require.

If a personal data breach occurs that poses a risk, we will notify the Hungarian National Authority for Data Protection and Freedom of Information within 72 hours of becoming aware of it, and if the breach is likely to result in a high risk to your rights, we will inform you without undue delay.

11. Your rights

  • Access (GDPR Art. 15): you can request information about and a copy of the data we hold about you.
  • Rectification (Art. 16): you can correct your profile and memories yourself in the app.
  • Erasure (Art. 17): you can delete memories, child profiles, family members and your whole account in the app.
  • Restriction (Art. 18) and objection (Art. 21) to processing based on legitimate interests.
  • Portability (Art. 20): you can download your own account data, or the family’s complete data set (memories and texts as machine-readable JSON, with download links for media files valid for 24 hours), in the app.
  • Withdrawing consent at any time, without affecting the lawfulness of earlier processing (push notifications: iOS Settings; waitlist: the unsubscribe link in our emails or an email to us).

Account deletion and data export in the app

You can delete your account at any time in Settings, and download your data beforehand. When you delete it:

  • we delete your account data, your sign-ins, your devices’ notification tokens, and your comments and reactions;
  • if you are the only owner of a family and it has another parent, the owner role passes to the parent who joined earliest; if there is no other parent, the family is deleted with all of its memories and media files;
  • in families that remain, memories you created and files you uploaded stay with the family as shared family memories, but are no longer linked to your name. If you want these deleted too, delete them before deleting your account, or ask the family owner.

An owner can also delete the whole family. A subscription bought through Apple must be cancelled separately in your Apple ID settings.

How to make a request

Write to [Contact email]. We will respond within one month at the latest; where justified this can be extended by two further months, and we will tell you within the original deadline. Responding is free of charge. To prevent abuse we may ask you to verify your identity (e.g. by writing from the email address linked to your account or by signing in to the app).

12. Cookies and local storage

  • Website (landing page): uses no cookies, no analytics and no tracking code, and loads nothing from third parties (no fonts, images or scripts). The waitlist form only sends data when you submit it.
  • Family web viewer: stores two items in your browser’s local storage (localStorage): your sign-in session identifier and your chosen language. These are strictly necessary for the Service to work, so no consent is required (Article 5(3) of the ePrivacy Directive, as implemented in s. 155(4) of Hungarian Act C of 2003). The session identifier is removed when you sign out.
  • iOS app: keeps your sign-in identifier in the device Keychain and your preferences in local device storage. It contains no advertising or tracking SDKs, does not use the advertising identifier (IDFA), and does not track you across other companies’ apps or websites.

13. Waitlist

If you sign up on our website, we store your email address, language, the source and time of sign-up and – to filter out bulk abuse – a keyed hash of your IP address (not the raw IP address) so we can tell you when the app is available (and about any launch discount). We don’t use it for anything else or share it with third parties for their own purposes. You can withdraw your consent at any time using the unsubscribe link in our emails or by emailing [Contact email].

14. Complaints and remedies

If you feel we have infringed your data protection rights, please contact us first – we will try to resolve it quickly. You can also lodge a complaint with the supervisory authority:

Authority
Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH – Hungarian National Authority for Data Protection and Freedom of Information)
Address
Falk Miksa utca 9–11, 1055 Budapest, Hungary
Postal address
1363 Budapest, Pf. 9., Hungary
Email
ugyfelszolgalat@naih.hu
Web
naih.hu

You may also go to court; you can bring proceedings before the regional court of your place of residence or stay. If you live in another EU member state, you can also complain to the data protection authority there.

15. Changes to this policy

If this policy changes materially (e.g. a new processor or a new purpose), we will notify you in the app or by email before the change takes effect. Earlier versions are available on request.