MEMILY PRIVACY POLICY

Last Updated: August 6th, 2026

Our Privacy Principles

We summarize Memily's privacy principles here for easier reference. The Privacy Policy below provides the legal details and binding commitments.

Memily is a private space, not a public platform. Your Circle is a closed group. Your content does not appear in a feed, and we do not use algorithms to promote it.

You own your user content. We hold it as a trusted steward on your behalf. We acquire no ownership interest in your content or personal information through the Service.

For Minor accounts, Guardians govern settings. Guardians configure sharing policies and receive category-level safety alerts about AI Conversations, but cannot view the AI Conversation content itself.

We use your content to run the Service for you. We do not use your User Content for advertising, marketing, or training commercial AI models.

We do not sell your user content or your personal information. We do not share it with third parties for commercial purposes.

We do not use your AI conversations to train AI models. Third-party AI providers that process your conversations are contractually prohibited from training on your content.

We will not disclose your user content to the government without proper legal process. We respond only to law enforcement requests that adhere to established legal process and applicable law, and we do not respond to informal requests that do not meet that standard.


PLEASE READ THIS POLICY CAREFULLY. IT EXPLAINS HOW WE COLLECT, USE, AND SHARE YOUR PERSONAL INFORMATION.


1. Introduction

This Privacy Policy ("Policy") explains what personal information Memily, Inc. ("Memily," "we," "us," or "our") collects, how we use it, when and how we share it, the choices and rights you have, and the special protections that apply to your personal information.

This Policy also contains a Cookie Policy in Section 5 below.

By using Memily's mobile application, websites, and related services (the "Service"), you accept this Privacy Policy. This Policy is incorporated into, and forms part of, our Terms of Service, and the capitalized terms below are defined in the Terms of Service. In the event of a conflict between this Policy and the Terms of Service specifically regarding the handling of personal information, this Policy controls.

2. Who We Are and How to Contact Us

The company responsible for your personal information under this Policy is Memily, Inc., with a mailing address at 7150 Skillman Street, Suite 160, #186, Dallas, Texas 75231.

If you have any questions or concerns about how Memily processes your information or about this Policy, you can email us any time at privacy@memily.com. We respond to all inquiries within the time required by applicable law.

3. Information We Collect

This section explains the information we collect from users. We do not require users to provide information to us. However, Memily collects and processes certain information, such as account log-in data, which is required to provide you with access to the Service, and other information may be collected automatically as you use the Service.

Information You Provide to Create Your Account

Account Information: Name, email address, password, and authentication tokens if you sign in with Google or Apple. The signup flow may also include a display name, avatar, and short bio.

Phone Number: Optional, for SMS notifications when you choose to verify it.

Notification Preferences: Your channel and event configurations.

Subscription Information: The tier purchased and entitlement state for your Circle. Apple or Google process your payment method directly; we receive only a purchase receipt and tier metadata.

Information We Collect Automatically

Device and Technical: Device type and model, OS version, app version, language, IP address, push-notification tokens, generic fingerprints sufficient to identify the device for security and abuse prevention.

Usage: Which features you use, time spent, performance and crash data, in-app navigation, error events.

Cookies and Similar Technologies: On our websites (see Section 5).

Information You Provide to Us

User Content: Posts, reflections, comments, reactions, photos, images, videos, and tags you create, and the date or year associated with Memily.

Circle Data: The Circle name; the people you invite; the Links you propose, accept, and revoke; your sharing policies and tag allowlists per Link; mute-list entries.

Memily AI Conversations: The prompts you receive, your inputs (text and, on supported tiers, images), and the model responses, plus session metadata (timing, prompt category, length).

Archive Content: Items you have saved to your Archive, including saved User Content and Memily-AI-generated insight summaries.

Feedback: About the Services, including information about the effectiveness of the feature and any other relevant information.

Support Communications: Your requests, questions, and responses to us via forms, email, or other means.

Information About a Minor: Provided by a Guardian: the Minor's display name, the birthdate the Guardian enters when generating a Minor invite, the content the Guardian authors for the Minor's Memily AI, and the Memily AI and prompt-category configurations that the Guardian sets.

Other Information: Any other information you choose to provide while using Memily that identifies or can be reasonably associated with you.

Information We Receive from Third Parties

Sign-in Providers: Google, Apple: the email address and basic profile information you authorize them to share when you choose those sign-in options.

Apple/Google In-app Purchase: Subscription state, transaction identifiers, renewal status.

AI Providers: Model outputs returned to your AI Conversations.

Service Providers: Operational data necessary to deliver the Service (for example, delivery-status data from our notification platform).

Sensitive Information

Family memories often touch on sensitive topics: religion, health, family relationships, ethnicity, sexual orientation, mental health. You alone choose what you share with the Service. We do not require you to provide such information, and we treat it with the same confidentiality and access restrictions as all User Content. Where applicable law treats certain categories as "sensitive personal information," we process them only as necessary to provide the Service to you, with the additional protections required by law.

4. How We Use Your Information

We use personal information to:

Provide and Maintain the Service: This includes authentication, hosting, rendering, search, notifications, payment processing, customer support, and security, and includes identifying, troubleshooting, and fixing bugs and errors.

Operate Memily AI: This includes generating prompts, holding AI Conversations, summarizing meaningful insights into your Archive, and assisting with co-authoring. How we handle AI Conversation content is described in Section 6. Outputs that Memily AI generates from your User Content or AI Conversations are treated as User Content and handled accordingly.

Personalize Your Experience: Based on your settings, sharing policies, and AI Conversations within your account.

Apply Your Sharing Policies: We process your sharing configurations to determine what User Content flows to other users.

Communicate With You: About your Account, billing, security, support requests, and product updates.

Send Notifications: You have enabled through the channels you have selected.

Operate the Safety Detection System for Minor Accounts: For Minor accounts, we run an automated detection process for AI Conversations as part of the Service. This process is limited to generating category-level safety alerts for Guardians. It does not involve general review of User Content. This is described in detail in Section 12 of the Terms of Service and in Section 6 below.

Detect, Investigate, and Prevent Fraud: Detect, investigate, and prevent fraud, abuse, harassment, and security incidents, by using the minimum information necessary for these purposes.

Comply With Legal Obligations: In good faith and respond to lawful requests for information, as further described in Section 11.

Enforce Terms of Use: Enforce the Terms of Use, our Acceptable Use Policy, and our other policies.

5. How We Use Cookies and Analytics

Our website and mobile app use cookies (which are small files that are placed on your computer, mobile device or any other device by a website or mobile app, containing details of your browsing history on that website or mobile app) and similar technologies for authentication, security, preferences, and analytics.

Types of Cookies We Use

The length of time that cookies are stored on your device will vary, depending on whether the cookies are temporary or persistent. Persistent cookies remain on your personal computer or mobile device when you go offline, while temporary (or session) cookies are deleted when you close your web browser.

Where required by law, we will request your consent before using cookies that are not strictly necessary. Strictly necessary cookies are used to provide the Services to you, so they cannot be disabled.

We use both persistent and session cookies for the purposes set out below:

Strictly Necessary / Essential Cookies: These cookies are essential to provide the Service through our website and mobile app and to enable you to use some of the Service features. They help authenticate users and prevent fraudulent use of user accounts. Without these cookies, the Service cannot be provided, and we only use these cookies to provide you with those Services.

Performance / Analytics Cookies: These cookies collect information about how you use our website or mobile app. This data may be used to help optimize our website or mobile app and make it easier for you to navigate. These cookies do not collect information that identifies you. All information that these cookies collect is aggregated and anonymous.

Functionality Cookies: These cookies allow us to remember choices you make when you use the website or mobile app, such as remembering your login details. The purpose of these cookies is to provide you with a more personal experience and to avoid your having to re-enter your preferences each time you use the website or mobile app.

Targeting Cookies: We do not use cross-context behavioral-advertising cookies.

Your Choice Regarding Cookies

You have a choice over the use of cookies, and we offer a cookie-management interface allowing you to accept or reject non-essential cookies.

You can disable and/or delete most types of cookies by using your browser settings. As the means by which to activate or deactivate cookies varies from one web browser to another (for example, Safari, Chrome, Mozilla Firefox), you should visit your specific web browser's help menu for more information on cookie preferences.

Please note that if you have disabled one or more cookies, we may continue to use the information that was collected by such cookies before they were deactivated. However, we will cease to collect any new information via the opted-out cookie once a cookie has been deactivated.

If you have any questions about this Cookies policy, you may contact us at privacy@memily.com

Cookie Policy Updates

We may update this Section 5 as necessary to account for changes in our practices or legal requirements. Please revisit this notice regularly to stay informed about our use of cookies.

6. How We Handle Memily AI Conversations

Confidential by Default

AI Conversations are scoped to the user who held the AI Conversations. They are not visible to your Circle, to any linked Circle, to your Guardian (in the case of Minors), or to any other user.

Internal Access is Narrowly Limited and Audited

Memily personnel do not have general access to AI Conversation content, and general review of AI Conversation content is prohibited. Internal access is permitted only in three circumstances:

Trust and Safety review in response to a safety alert. When our safety detection system generates an alert indicating a pattern that indicates a credible safety concern (for example, signals of abuse, harm, or threats), a member of the Trust and Safety team may review the relevant AI Conversation content to assess the concern. Each such access requires a documented written reason and is logged with the reviewer's identity, the time of access, and the session reviewed.

Response to a risk to life. Where there is an urgent and credible risk to a person's life, an authorized emergency responder within Memily may access the relevant AI Conversation content. This access is also documented and logged as described above.

Valid legal process. We may also access, preserve, or disclose the content of a specific user's AI Conversation where required to comply with valid legal process (such as a subpoena, court order, or other compulsory legal demand), as described in Section 11. This is separate from, and does not depend on, a safety alert having been triggered.

No other role (for example, engineering, support, or sales roles) has access to AI Conversation content as a matter of ordinary practice, and Trust and Safety access is not authorized for general review, audits, analytics, product development, or any purpose outside of responding to a specific AI-based safety alert. This restriction is enforced through access controls and logging.

Aggregated, de-identified system telemetry (for example, latency metrics, error rates) is available to operations staff but does not reveal AI Conversation content.

Use to Improve the Service for You

We use the content of your AI Conversations to provide and personalize the Service for you. This includes maintaining context across sessions, generating Archive summaries when a conversation surfaces something meaningful, and suggesting tags or values that reflect your engagement with the Service. Each user's AI Conversation content is used within their account alone and for the user's own benefit.

AI Model Training is Prohibited

We do not use the content of your AI Conversations to train general-purpose AI foundation models. Where we use third-party AI providers to process AI Conversations, such third-party AI providers are bound by contractual obligations that expressly prohibit them from using your content to train their models.

We may use aggregated, de-identified signals (for example, "X% of conversations in the gratitude category continued past one round") to evaluate and improve Service quality. These signals do not reveal the content of any individual AI Conversation.

We may, on a fully opt-in basis, invite users to participate in research programs that involve more specific use of AI Conversation content. Participation is always voluntary and clearly disclosed at the time of invitation.

7. How We Share Information

We share personal information only as described below. We do not share your User Content for any commercial purpose outside of operating the Service for you.

With Other Users as You Direct

User Content that you publish is visible to (a) members of your Circle, (b) members of any Circle linked to your Circle under your active sharing policy for that Link, and (c) anyone you explicitly include (for example, when you re-share an Archive item into your current Circle). Reflections on posts you authored also reach you, even when written by users outside your Circle.

With Service Providers

We share information with vendors who help us operate the Service. This includes cloud hosting and storage, content delivery, push and SMS notification providers, email providers, analytics and error monitoring services, fraud and abuse detection providers, AI model providers, and customer support tools. Service providers act on our instructions under written agreements that limit their use of personal information to providing services to us. They may not use your User Content for their own purposes.

With AI Model Providers

To operate Memily AI we transmit AI Conversation content (your inputs, prompts, and selected context) to one or more AI model providers. These providers are bound by contractual restrictions. They may not use your data to train their AI models, and they delete inputs after a short retention window maintained for abuse prevention.

Our current AI model providers, as of the effective date of this Policy, are:

Google (Gemini)

Anthropic (Claude)

OpenAI

Memily's custom and self-hosted models (operated by Memily)

An up-to-date list, including any subprocessors, is maintained at [/legal/subprocessors URL] and will be updated before any material change. Where an AI Conversation is processed by Memily's custom or self-hosted models, no third-party AI provider receives that content.

With Apple and Google for Billing

Subscription purchases are processed by the Apple App Store or Google Play. We receive purchase receipts and your subscription status. We do not receive your payment-card details.

Mandatory Reporting

Where required by law or when we encounter content suggesting imminent risk to life, we may report relevant information to the National Center for Missing and Exploited Children, to law enforcement, or to similar authorities, in accordance with Section 11, even where this would otherwise conflict with the confidentiality preferences described elsewhere in this Policy. This may include circumstances where we withhold or redirect a Guardian safety-alert notification in favor of reporting to law enforcement or child-protective authorities.

Business Transfers

If Memily is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, your information may be transferred as part of that transaction. In such case, your information will remain subject to this Policy until the acquiring party updates it. If such transfer is subject to additional mandatory restrictions under applicable laws or agreements, Memily will comply with those restrictions.

With Your Consent

We share information for other purposes with your express consent.

What We Do Not Do

We do not "sell" your personal information, as that term is defined under U.S. state privacy laws.

We do not share your User Content or personal information for advertising, marketing, or cross-context behavioral advertising purposes.

We do not allow third parties to access your AI Conversations or your Archive for any commercial purpose.

We do not share your AI Conversations, your Archive, or your mute list with any Circle, linked Circle, or other user.

We do not grant access to your User Content or personal information based on informal law enforcement requests or administrative letters that do not constitute legally enforceable process. Our government access framework is described in Section 11.

8. How We Secure Your Information

We implement and maintain administrative, technical, and physical safeguards designed to protect your personal information against unauthorized access, alteration, disclosure, and destruction. These include encryption in transit (TLS) and at rest, scoped access controls, principle-of-least-privilege engineering practices, audit logging for sensitive access paths, regular security reviews, and incident response procedures. No system is perfectly secure, and we cannot guarantee absolute security. We do not warrant that our measures will prevent every unauthorized access, including sophisticated attacks by adversaries.

If we become aware of a breach affecting your personal information, we will notify you and authorities as required by applicable law.

9. Data Retention

We retain personal information for as long as necessary to provide the Service and as required by law, in accordance with the following parameters:

Active Accounts: Retained while your account exists.

Soft-Deleted Accounts: Your account is deactivated but recoverable by contacting support. User Content you contributed to a Circle may remain visible in that Circle, attributed to you, consistent with Section 6 of the Terms of Service.

Hard-Deleted Accounts: When you permanently delete your account, we delete your User Content, and we remove your account record. This deletion is permanent. Limited retention may continue solely for legal hold compliance, fraud prevention, active dispute resolution, and aggregate analytics in de-identified form that cannot be linked back to you.

AI Conversations: Remain active in your list while you are engaged. Auto-archived after 14 days of inactivity, but still accessible to you. Permanently deleted on account hard-delete.

Operational and Audit Logs: Operational and audit logs do not contain the substance or meaning of any User Content or AI Conversation. General operational logs are retained for no longer than one year, after which they are deleted or fully anonymized. Trust and Safety access-audit records are retained for 3 years to preserve evidence of appropriate access scope, given that claims involving Minors may be subject to extended or tolled statutes of limitations.

Backups: We use reasonable measures to retain your information for the period necessary to fulfill the purposes outlined in this Policy, to make our Services available to you, or as instructed by you, unless a longer retention period is required or permitted by law.

10. Your Privacy Choices and Rights

Access, Correction, and Deletion

You can view and update much of your information directly within the Service settings (for example, profile, notifications, sharing policies, mute list, Archive). Premium tier members may export comprehensive copies of their data via the data export feature. Regardless of subscription tier, you may also request a copy of your personal information or exercise any statutory access, correction, or portability right available to you under applicable law, at no charge by emailing privacy@memily.com. The in-app data export tool is a convenience feature and does not limit your legal rights.

Sharing Controls

You control sharing your privacy configurations that you set within the mobile app. We will not share your User Content beyond what your active settings authorize.

Notification Controls

You can change which events notify you, and through which channels, under the Settings feature. Reply STOP to any SMS to opt out of SMS. Operational notifications (for example, account, billing, security) cannot be disabled.

California Residents (CCPA/CPRA)

If you are a California resident, you have rights under the California Consumer Privacy Act (as amended by the California Privacy Rights Act) to: (a) know what categories and pieces of personal information we have collected and how they have been used and disclosed; (b) delete personal information; (c) correct inaccurate personal information; (d) opt out of the sale or sharing of personal information (we do not sell or share for cross-context behavioral advertising); (e) limit use and disclosure of sensitive personal information to permitted purposes; and (f) be free from discrimination for exercising rights. Submit requests to privacy@memily.com. We may need to verify your identity before responding.

Other U.S. State Privacy Rights

Residents of states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, and others as enacted) have similar access, correction, deletion, portability, and opt-out rights. Submit requests to privacy@memily.com. As required by applicable law, if we deny a request, our response will explain how to appeal.

Authorized Agents

You may use an authorized agent to submit a request on your behalf. We will require proof of authorization and may require direct verification of your identity.

11. Minors' Privacy

Information Collected About Minors

With Guardian consent, we collect and process the following information for Minor accounts: display name, Guardian-provided birthdate, account credentials, the User Content the Minor creates, AI Conversation content, notification preferences, device and usage data, and operational logs. We do not require Minors to provide more than is reasonably necessary for the features they use, and we do not condition participation on disclosing more.

Guardian Access

A Guardian's ability to view User Content that a Minor has shared to a shared Circle does not constitute a waiver of the Minor's privacy interests for purposes