Privacy policy · draft for private alpha
Your family's memories belong to your family.
What we store
Account email, the names and optional birthdays you add for family members, the photos, videos, captions, comments, and gatherings you choose to keep here, and the technical records needed to run the service (audit logs, job history, hashed IP addresses for abuse prevention).
Who can see it
Only the people you share with. Every memory has an explicit audience: your home, chosen family homes, specific people, or only you. Being related to someone never gives them access. Connected homes never see each other's content.
Where it lives
Photos and videos are stored in a private bucket in Canada with short-lived signed links. Originals are copied to an independent backup. Database backups are kept separately. No content is used to train AI models and no advertising or tracking pixels are used.
Children
Children exist as profiles managed by the adults who add them. A child profile can belong to more than one home (for example, both parents' homes) without either parent seeing the other's private memories. Child profiles are never publicly discoverable.
Your choices
You can export everything you authored from Settings → Export, and request account deletion from Settings → Privacy. Deletion is staged over 30 days so a mistake can be undone; after that your credentials and personal data are removed. Memories you shared into a family home stay with that home unless you delete them first. This shared-content rule will be reviewed by counsel before public beta.
Contact
Questions about privacy: hello@example.com.
This document is a working draft for the private alpha and requires legal review before public beta. The items awaiting counsel (shared-content retention, backup deletion timing, child profiles, export contents, jurisdiction) are listed in docs/legal-review.md.