In short
- Family Memory is a private family memory keeper. What you upload can only be seen by the people you invite to your family.
- No ads. We don’t sell or rent your data, we don’t build advertising profiles about you, and we don’t use tracking tools.
- Children’s photos and details are uploaded by their parents, and we handle them with extra care: no face recognition, no biometric identification.
- The AI only receives the photos and text you choose, so it can suggest a title and a short story. You accept or rewrite the suggestion.
- You can download and delete your account and your data in the app at any time.
This policy explains, under Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”) and Hungarian Act CXII of 2011 on informational self-determination and freedom of information, how we process personal data in the Family Memory iOS app, the family web viewer and our website (together: the “Service”).
1. The controller
- Name
- [Provider name]
- Registered office
- [Registered office]
- Registration number
- [Company registration number]
- Tax number
- [Tax number]
- [Contact email]
For privacy questions and to exercise your rights, contact us at the email address above. Given the nature and scale of our activities we are not required to appoint a data protection officer; if that changes, we will publish their contact details here.
2. Whose data we process
- Parents and family members who create an account in the iOS app (owner and parent roles). Only people aged 18 or over may use the Service with an account.
- Invited family members (e.g. grandparents, relatives) who join the web viewer through an invite link (viewer role).
- Children whose profiles, photos and stories are recorded by a parent. Children do not use the Service themselves.
- Other people who appear in uploaded photos, videos, audio recordings or texts (e.g. relatives, friends).
- Waitlist subscribers and website visitors.
3. What data we process
| Category | What it includes | Source |
|---|---|---|
| Account data | display name, email address (if you provide it or Apple shares it – this may be an Apple-generated relay address), the user identifier issued by Apple, language, hashed identifiers of your sign-in sessions | you, or Sign in with Apple |
| Family data | family name and language, members, their roles (owner / parent / viewer) and relationship labels, invites (name, role, expiry) | you and your family members |
| Child profile | name, nickname, date of birth, profile picture | the parent |
| Memory content | photos, videos, audio recordings, title, story, personal note, the text transcript from “Tell it”, date, place name, tags, event type, the title and story suggested by the AI | the parent, or the AI suggestion |
| Reactions and comments | hearts (❤️) and short comments that family members add to memories, with their author and time | your family members |
| Media metadata | file type, size, resolution, duration, capture time and – if the photo contains it and you share it – its location (GPS coordinates) | read from the selected files on your device |
| Subscription data | purchased plan, Apple transaction identifiers, subscription status and expiry. We never receive card or payment details; Apple handles those. | Apple App Store notifications |
| Notification data | your device’s push notification token (APNs token), the notification language and your notification settings (new memory, comment), if you enable notifications | your device |
| Waitlist | email address, language, source and time of sign-up, and a keyed, non-reversible hash of your IP address (the raw IP address is not stored) | you |
| Technical data | IP address, time and path of requests, error logs, short-lived counters used for abuse prevention (rate limiting) | automatically, from your use of the Service |
| Correspondence | messages you send us and our replies | you |
With “Tell it”, speech is converted to text by the iOS system speech recogniser. We receive the transcript and – if you keep it as part of the memory – the audio recording. Depending on your device settings, system speech recognition may also run on Apple’s servers; Apple’s privacy terms apply to that.
We do not ask for or intentionally collect special categories of data (e.g. health data). If a story nevertheless contains such data, we store it solely at your request to provide the Service and do not analyse your content for it.
4. Children’s data
The Service is for parents; children do not create accounts and the Service is not offered to them directly. Children’s data (name, date of birth, photos, videos, audio recordings, stories) is recorded by a parent exercising parental responsibility. We handle this data with extra care:
- We do not perform face recognition, create biometric templates or automatically identify anyone from images. The parent chooses which child a memory belongs to.
- We do not use children’s data for advertising or profiling, and we do not share it with third parties for their own purposes.
- Media files are stored privately; there are no public links. Viewing uses short-lived signed links, issued only to family members.
- Family members with the viewer role only see memories the parent has published, never drafts.
The parent is responsible for ensuring that uploading serves the child’s interests and – where parental responsibility is shared – that the other parent agrees. A child can exercise their rights through their legal representative and, once they come of age, themselves; at their request we delete content about them.
5. Purposes and legal bases
| Purpose | Data | Legal basis (GDPR Art. 6(1)) |
|---|---|---|
| Creating an account, signing in (Sign in with Apple, email sign-in link) | account data, session | (b) performance of a contract |
| Family space, invites, sharing with family members, reactions and comments | family data, account data, reactions and comments | (b) performance of a contract |
| Storing, organising and displaying memories on the timeline | child profile, memory content, media metadata | (b) performance of a contract (towards the account holder); for other people in the content (children, relatives): (f) legitimate interests – the parent’s and family’s interest in preserving family memories, exercised by the parent within parental responsibility |
| AI title and story suggestion | selected photos, note, transcript, the child’s first name and age, date, place name | (b) performance of a contract (a core feature of the Service) |
| Managing subscriptions | subscription data | (b) performance of a contract; (c) legal obligation (accounting and consumer protection rules) |
| Push notifications (e.g. a new memory in the family) | notification data | (a) consent – given through the iOS notification permission and revocable there at any time |
| Service emails (sign-in link, security and account notices) | email address, language | (b) performance of a contract |
| Waitlist: notifying you about the launch | waitlist data | (a) consent – given by signing up, revocable at any time |
| Security, abuse prevention, debugging | technical data, the waitlist IP hash | (f) legitimate interests: protecting the Service and users’ data |
| Backups and recovery | database contents | (f) legitimate interests, and the security obligation under GDPR Art. 32 |
| Contact, support, complaints | correspondence | (b) performance of a contract or (f) legitimate interests; (c) legal obligation for consumer complaints |
| Establishing or defending legal claims, responding to authorities | data needed for the matter | (c) legal obligation, (f) legitimate interests |
Where we rely on legitimate interests we have carried out a balancing test; we will send you a summary on request. You may object to processing based on legitimate interests (see section 11).
There is no automated decision-making that produces legal effects concerning you or similarly significantly affects you (GDPR Art. 22). The AI’s output is only a suggestion; the parent decides.
6. AI processing
Memory titles and short stories are suggested by a large language model. For this we use Anthropic’s service (Claude) as a processor.
- What the AI receives: the photos selected for that memory (up to 8 images, via a short-lived private link or sent directly), the parent’s note and the “Tell it” transcript, the first name and age of the child(ren) concerned, the date and the place name.
- What it does not receive: videos, audio recordings, email addresses, the family’s other memories, or anything you didn’t select for that memory.
- What it’s used for: only to produce the suggestion. The provider’s commercial terms state that data sent through its API is not used to train its models and may be retained only for a limited period for abuse monitoring.
- We don’t use your content to train AI models either.
- Suggestions can be wrong: the parent reviews them and accepts or rewrites them before the memory is shown to the family.
7. Processors and recipients
We use the following providers to run the Service. As processors they may process data only on our instructions, under a written data processing agreement.
| Provider | Task | Data | Location |
|---|---|---|---|
| [Hosting provider name, address, contact] | server hosting (application, database) | all account and family data except media files | [Server location (country)] |
| Cloudflare, Inc. (R2 storage) | storage of media files (photos, videos, audio) and database backups | media files, encrypted backups | EU jurisdiction storage (data stays in the EU) |
| Anthropic (Claude API) | AI title and story suggestions | as listed in section 6 | USA |
| Resend | delivery of service emails (sign-in link, notices) | email address, name, message content | USA |
| Apple (Apple Push Notification service) | delivery of push notifications | notification token, notification text | USA / EU |
Independent controllers. For Sign in with Apple and purchases through the App Store, Apple (in the EU: Apple Distribution International Ltd., Ireland) acts as an independent controller under its own privacy policy. Apple processes the payment; we only receive the subscription status.
Your family members see the memories you share with them – viewers only see published ones. The app always shows who has access to your family.
We disclose data to authorities or courts only where required by law, and only to the extent necessary. We do not sell or rent personal data or share it for advertising.
8. Transfers outside the EEA
Some of our processors operate in the United States (sections 6 and 7). Such transfers rely on the European Commission’s adequacy decision on the EU–US Data Privacy Framework where the provider is certified, and otherwise on the Standard Contractual Clauses adopted by the Commission (Decision (EU) 2021/914) together with supplementary measures (e.g. encryption in transit). You can request information about, or a copy of, these safeguards at the email address above.
9. How long we keep data
| Data | Retention |
|---|---|
| Account data, family data, child profiles, memories and media files | as long as your account or the family exists; on deletion, removed from live systems without delay and media files within 30 days at the latest |
| Backups | rolling retention: 7 daily, 4 weekly and 6 monthly backups, so deleted data may persist in encrypted backups for up to about 6 months; backups are read only for recovery, and after a recovery previously deleted data is deleted again |
| Sign-in link (email) | 15 minutes, single use |
| Invite link | valid for 14 days (until used or revoked); invite records are deleted after 30 days |
| Sign-in session | until you sign out, or it expires after 90 days of inactivity |
| Unfinished upload | deleted automatically after 24 hours |
| Uploaded file never attached to a memory | deleted automatically after 7 days |
| Push notification token | while notifications are enabled, or until you sign out |
| Subscription data | for the duration of the subscription, then until the civil-law limitation period ends (5 years) or as long as accounting rules require |
| Waitlist | until you unsubscribe, but no longer than 12 months after the launch notification |
| Technical logs | up to 30 days; rate-limit counters up to 1 hour |
| Correspondence, complaints | 1 year after the matter is closed; consumer complaint records 3 years (Hungarian Consumer Protection Act, s. 17/A) |
10. Security
- All connections are encrypted (HTTPS / TLS).
- Media files are stored privately; uploads and viewing use signed links valid for a short time (15 minutes and 1 hour respectively), issued only to authorised family members.
- Every request checks family membership and role; sign-in identifiers are stored only in hashed form.
- The database and cache are not reachable from the internet; backups are encrypted and stored separately.
- Access by our staff is limited to the minimum their tasks require.
If a personal data breach occurs that poses a risk, we will notify the Hungarian National Authority for Data Protection and Freedom of Information within 72 hours of becoming aware of it, and if the breach is likely to result in a high risk to your rights, we will inform you without undue delay.
11. Your rights
- Access (GDPR Art. 15): you can request information about and a copy of the data we hold about you.
- Rectification (Art. 16): you can correct your profile and memories yourself in the app.
- Erasure (Art. 17): you can delete memories, child profiles, family members and your whole account in the app.
- Restriction (Art. 18) and objection (Art. 21) to processing based on legitimate interests.
- Portability (Art. 20): you can download your own account data, or the family’s complete data set (memories and texts as machine-readable JSON, with download links for media files valid for 24 hours), in the app.
- Withdrawing consent at any time, without affecting the lawfulness of earlier processing (push notifications: iOS Settings; waitlist: the unsubscribe link in our emails or an email to us).
Account deletion and data export in the app
You can delete your account at any time in Settings, and download your data beforehand. When you delete it:
- we delete your account data, your sign-ins, your devices’ notification tokens, and your comments and reactions;
- if you are the only owner of a family and it has another parent, the owner role passes to the parent who joined earliest; if there is no other parent, the family is deleted with all of its memories and media files;
- in families that remain, memories you created and files you uploaded stay with the family as shared family memories, but are no longer linked to your name. If you want these deleted too, delete them before deleting your account, or ask the family owner.
An owner can also delete the whole family. A subscription bought through Apple must be cancelled separately in your Apple ID settings.
How to make a request
Write to [Contact email]. We will respond within one month at the latest; where justified this can be extended by two further months, and we will tell you within the original deadline. Responding is free of charge. To prevent abuse we may ask you to verify your identity (e.g. by writing from the email address linked to your account or by signing in to the app).
13. Waitlist
If you sign up on our website, we store your email address, language, the source and time of sign-up and – to filter out bulk abuse – a keyed hash of your IP address (not the raw IP address) so we can tell you when the app is available (and about any launch discount). We don’t use it for anything else or share it with third parties for their own purposes. You can withdraw your consent at any time using the unsubscribe link in our emails or by emailing [Contact email].
14. Complaints and remedies
If you feel we have infringed your data protection rights, please contact us first – we will try to resolve it quickly. You can also lodge a complaint with the supervisory authority:
- Authority
- Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH – Hungarian National Authority for Data Protection and Freedom of Information)
- Address
- Falk Miksa utca 9–11, 1055 Budapest, Hungary
- Postal address
- 1363 Budapest, Pf. 9., Hungary
- ugyfelszolgalat@naih.hu
- Web
- naih.hu
You may also go to court; you can bring proceedings before the regional court of your place of residence or stay. If you live in another EU member state, you can also complain to the data protection authority there.
15. Changes to this policy
If this policy changes materially (e.g. a new processor or a new purpose), we will notify you in the app or by email before the change takes effect. Earlier versions are available on request.