Privacy policy
What we collect, why, who else ever sees it, and the choices you have. Last updated [DATE].
Who this is
Our Living Memory is operated by Digirelevance Limited, a company based in the United Kingdom and registered with the Information Commissioner’s Office. For the purposes of data protection law, Digirelevance Limited is the data controllerfor the personal data described below - the organisation that decides why and how it’s processed.
This is a small, part-time operation - one person, building for real families, not a large company with a dedicated privacy team. That’s worth knowing because it shapes some of the honest answers below: some things (like permanently deleting your data) are a real, working process rather than an instant, automated button - see Your rights.
What we collect
To create your account:your email address, and a display name (it defaults to part of your email, and you can change it). There’s no password - signing in works by emailing you a one-time link, so we never hold a password to lose.
What you add to an archive: stories, photographs, audio recordings and video, their transcripts, captions, dates and places, and anything you type - the content of the archive itself.
Where a photograph was taken.Phones record the exact spot inside the picture file, and almost nobody realises it’s there. So we don’t keep it unless the archive’s owner has asked us to - it’s off until they turn it on. When it’s on, we round it to about 100 metres before saving, so it says the neighbourhood rather than the doorstep, and the capture screen says so before you choose a photograph. Anyone who can edit a photograph can add a place by hand or remove one, and a pin placed by hand is kept exactly where it was put, because that was a decision rather than a by-product. One honest limit, and it applies to photographs only: the picture file you uploaded is never altered afterwards, so a coordinate inside it stays inside it, and would still be there in a copy you download. We leave it alone because reading it once is what lets the map work at all, and because on an old scan the date hidden in the file is sometimes the only date anybody has. Recordings and videos are the other way round - those are cleaned before they are stored, so nothing is hidden inside them by the time anyone, including you, gets a copy.
People you tell us about: names, approximate dates, places and notes for the relatives an archive is about - most of whom never sign up themselves. See People who aren’t members below; this is the one part of the app that isn’t just about our own account holders.
What you tell us directly: feedback you send us (its text, plus the page you were on, the app version, and your browser - attached automatically so a bug report is useful), and anything you write in your own private notepad (which, by design, not even an archive owner can read).
Billing, if an archive subscribes:we never see or store your card details. Payment is handled entirely by Stripe on its own hosted pages; we only keep a subscription status and Stripe’s own reference IDs for that archive, plus the email address used to set up billing.
That you confirmed your age, if you ever go to pay.Before subscribing, managing billing or contributing, we ask you to confirm you’re 18 or over and that the card is yours to use. All we keep is the fact that you answered, and when - not your date of birth, which we never ask for, and no document of any kind. We also look at one thing we already have: if you’ve linked yourself to your own person in the family tree and the birth year recorded there would make you under 18, we don’t offer you a payment page. That year was put there by a relative as family history, not by us for this purpose, and we only ever use it to withhold something, never to permit it.
What we don’t collect:no advertising identifiers, no analytics profile built from your behaviour, no biometric data - tagging who’s in a photograph is something a person does by hand, tapping a face, never automatic face recognition.
People who aren't members
A family archive is unusual: most of the people it’s about- a great-grandparent, a child too young to sign in, a relative who’s simply not interested - never open the app and never agree to anything themselves. Their name, dates, and the stories told about them are added by a relative who already has access to the archive, the same way a family would once have written those things in a photo album or a family Bible.
We treat this content the same way as everything else here: it stays inside that one family’s archive, visible only to the members that archive’s owner has invited, never public, never used for advertising, never matched against any other archive. If a living person named in an archive wants to see what’s recorded about them, join in themselves, or ask for something to be corrected or removed, an existing member can add or invite them - and if that’s not possible, they can contact usdirectly and we’ll do what we reasonably can, including asking the archive’s owner to help.
Children
Our Living Memory is a family product, and contributors genuinely range from young grandchildren to great-grandparents. There is no separate under-18 sign-up flow, and we don’t ask anyone their age to read, add or record - a parent, guardian, or the family member who set the archive up is expected to use their own judgement about what’s appropriate for a younger relative to add or see, the same judgement they’d use handing them a family photo album.
Paying is the exception, because it’s the one thing here that isn’t for everybody. Before anyone subscribes, manages billing or contributes, we ask them to confirm they’re 18 or over and that the card is theirs to use, and we withhold the payment pages entirely from someone whose own record in the family tree says they’re under 18 (see What we collect). It’s a question we ask rather than a check we perform - we don’t collect dates of birth or identity documents from families, and we think collecting them in order to protect children would be worse for those children than the risk it addresses.
If you’re a parent or guardian and want something involving a child corrected or removed, contact usand we’ll treat it as a priority.
Why we process it
Mostly because it’s the whole point of the service: we can’t run a family archive without storing the stories, photos and recordings you put in it, or sign you in without your email address. That’s processing under a contract - the one you agree to just by using the app.
A few things rest on our own or a member’s legitimate interest: sending an occasional service notice (planned maintenance, an important change), keeping backups so a family’s stories survive a mistake or a failure, reading feedback so the app can actually improve, and recording that someone confirmed they were old enough to pay before they did (see Children). We never use any of this for marketing, and never sell or rent it to anyone.
Two things rest on consent, and are off unless you or an archive owner switches them on: the AI question-suggestion feature (see AI features), and, for the archives that reach that point, billing communications tied to a paid subscription.
AI features
Transcription happens automatically.When you add a voice recording, the audio is sent to our transcription provider (OpenAI’s Whisper) to produce the written version you see underneath it. This isn’t a separate switch to turn on - it’s how recordings work - but the correction you make afterwards stays entirely inside the archive, and the sound itself has any hidden tags taken out before it goes (see Who else sees it).
We also send a short list of names.Machine transcription is poor at surnames and small place names - it will happily turn “Harrogate” into “Harrow Gate” - so along with the recording we send a list of the names and places already in that archive, to help it get them right. They are names that are being spoken aloud in the recording anyway; sending them as text doesn’t tell anyone anything new about your family, it just means the writing comes back with them spelled properly. The list never leaves the archive it came from, and it is never mixed with another family’s.
Question suggestions are opt-in, per archive, off by default.An owner can switch this on in archive settings; when it’s on, adding a photograph sends a shrunk copy of it to the same AI provider, which suggests a few gentle questions to help you write about it. The copy is made fresh and carries none of the original’s hidden information - no location, no camera details. It only ever suggests questions - it never writes your story, never guesses who’s in the photo, and nothing it sees is kept afterwards. Leave the switch off and a photo never leaves the archive for this purpose at all.
Neither feature is used to build a profile of you, and neither provider is given more than the one file needed for that one job.
Where it's processed
The archive itself is stored in Ireland. Your stories, photographs, recordings, family tree and account all live in a database and file storage hosted in the European Union (Supabase, Ireland) - not scattered, and not in the United States.
The other services listed above each receive one narrow thing, and some of them are US-based or global: the company that runs the application itself (Vercel), the one that plays video (Cloudflare), the one that writes transcripts (OpenAI), and those that send email, take payment, check for bots and draw maps. Where data reaches them outside the UK, it’s covered by those providers’ own standard safeguards for international transfers (such as the UK’s International Data Transfer Addendum or equivalent standard contractual clauses), and we hold a data processing agreement with our transcription provider. [This section should be checked against each provider’s current data-processing terms during legal review, and the remaining agreements confirmed.]
How long we keep it
While an archive is active, we keep its content for as long as the archive exists - a family history isn’t something with a natural expiry date. Deleting a story, photo, or person moves it to a recycle bin the archive’s owner can see and restore from; it stops being visible to anyone else straight away. Emptying that bin permanently is a manual step today rather than automatic - see Your rights if you want something gone for good rather than just out of sight.
When a video is permanently deleted, it’s deleted from the company that stores and plays it as well as from here, and we checkafterwards rather than assuming - we ask for the video again, and only a “not found” counts as gone. On the rare occasion we can’t confirm it, the fact is written down so it can be finished by hand, and whoever asked for the deletion is told then and there rather than left to assume it worked. We also check the whole account periodically for anything that should have gone and didn’t.
We keep off-site backups of original files so a technical failure can’t erase a family’s history; a permanent deletion is reflected in those backups too, on the same rolling schedule rather than instantly.
Your rights
Under UK data protection law you can ask to see the personal data we hold about you, have it corrected, object to certain uses of it, or ask for it to be deleted. In practice, here’s what that looks like in this app:
- Take a full copy, any time, for free.An archive owner can request a complete export - every story, photo, recording, video and the family tree - as plain files that open with no login and no software from us, plus a family-tree file any genealogy program reads. This is never limited by whether the archive is paying, and it’s the most direct way to exercise your right to data portability.
- Ask us to erase your data.This isn’t yet a self-service button in the app - email us (see Contact) and we’ll action it by hand. In practice this means: your own account and everything you authored yourself is genuinely deleted, including the original files. If you co-authored something with other people - a story someone else also added photos or memories to - we’ll remove your part of it but keep what belongs to the others, the same way we’d never delete someone else’s contribution on your say-so alone. We’ll tell you plainly what we could and couldn’t remove.
- Correct something.Most content is editable directly by whoever added it, or by an archive owner. For anything you can’t reach yourself, contact us.
If you’re unhappy with how we’ve handled a request, you can complain to the UK’s data protection regulator, the Information Commissioner’s Office(ico.org.uk) - we’d genuinely rather you told us first, so we have a chance to put it right.
Keeping it safe
Every family’s archive is walled off from every other family’s at the database level - not a setting, a structural rule enforced on every single row of data, so an application mistake can’t leak one family’s archive into another’s. Signing in uses a one-time emailed link rather than a password, so there’s no password of yours for us - or anyone who broke in - to expose. Original files are never edited or overwritten after upload, and connections to the app are encrypted in transit.
No system is unbreakable, and we’d rather be honest about that than promise otherwise. If something ever went wrong in a way that affected your data, we’d tell you.
Changes to this policy
If this policy changes in a way that matters, we’ll say so here and, for a significant change, tell members directly by email rather than leaving it to be noticed.
Contact
Questions about this policy, or a request about your data: [privacy contact email]. For everyday feedback about the app itself, use the Send feedback link in the footer instead - it reaches the same place faster.