Last updated 2 October 2026
Privacy Policy
Memoir is a place for your memories, so we collect as little as we can and keep private content encrypted. This policy explains what Memoir keeps, why we use it, who receives it and what you can do about it. Memoir is made by Flex Code Labs Limited ("we", "us"), at Near Mawasiliano Bus Terminal, Ubungo 16102, Tanzania.
The short version
- You can use Memoir without an account. Your memories then stay on your iPhone, and in your own iCloud if you turn that on.
- With an account, your memories, photos and videos are end-to-end encrypted: locked on your devices for you and anyone you deliberately share them with. We store them, but we can't read them.
- Recognising faces, suggesting titles and helping you write happen on your device.
- We don't sell your data, show ads, or use third-party analytics or tracking.
- You decide what to share. Other people receive only the content you choose, although they can make their own copies.
- You can delete everything, or your whole account, from Settings at any time.
What stays on your device
Everything you keep lives on your iPhone or iPad first: your words, photos, videos, voice notes, people, places, chapters and events. The photos you add come only from the ones you pick. Face recognition, grouping photos into a day, and writing suggestions (using Apple Intelligence where your device supports it) run on your device, and what they learn stays there.
If you allow it, Memoir reads your location when you add where something happened, your calendar when you choose events to bring in, and the songs you've recently played in Apple Music so you can pick one. Apple Weather may use a location you choose to fetch the weather. None of that is sent to our servers unless it becomes part of a memory you keep, and then it is encrypted like the rest.
If you back up with an account
Your memories
When you sign in, your memories and their photos, videos and voice notes are encrypted on your device, then uploaded. Our servers store them encrypted, and we don't have a key that can open them. A key can move between your devices through iCloud Keychain, when you scan a code from one device with another, or through an optional recovery method. When you share something, your device gives the chosen recipients encrypted access; our server still cannot read the content.
For each thing you back up, our servers see only an identifier, its size, its type and when it changed. Not your words, photos, names, places, or the dates of your memories.
This protects your memories if our database, storage or backups were ever exposed, and it means we can't look. It assumes our servers do their job honestly: we don't yet claim it would hold against a server that had been taken over and set out to trick your app, for example by giving it a false key.
Optional recovery
You can choose to create a recovery kit: a 30-character code that can restore your key if you lose every device. You can save it to iCloud Drive as a PDF, print it, keep it in a password manager or write it down. The code locks a copy of your key that we store but can't open. We never see the code. If you save the PDF to iCloud Drive, Apple's protection for that file depends on your iCloud settings. You may also be offered other optional recovery methods, such as trusted friends; the server stores only encrypted recovery pieces and the relationships needed to deliver them.
Your account
You create an account with Sign in with Apple. We receive an identifier from Apple, and your name and email address if you choose to share them (Apple lets you hide your email behind a private relay address). If you add an email sign-in, we store the verified address and send one-time codes to it. A sign-in method opens the account but cannot decrypt existing memories without a trusted device or recovery method. We also keep:
- the devices you're signed in on: their name, model, iOS and app version, and when each was last used;
- a shortened form of the IP address each session came from, to spot sign-ins from somewhere unusual;
- the days you used Memoir (not what you did), and how much storage your account uses;
- your subscription status, if you have Memoir Pro.
For short-lived service diagnostics, our server also remembers recent request routes, response status and timing, and the account involved. It does not keep request bodies, query strings or memory identifiers in these diagnostics, and the in-memory history resets when the server restarts.
Sharing and safety
If you use sharing, we store your sharing name, @handle, identity key, friends, blocks, invitations, shared-space membership and the technical history needed to sync changes and remove access. Your name and handle are visible to people who find or interact with you. Members of a shared space can see who else belongs to it. Shared memory content stays end-to-end encrypted for its intended recipients.
While you are using a shared space, we may pass short-lived presence and editing signals to its other members, such as that you are viewing or changing an item. Signed encrypted edits and their author and time are kept so devices can agree on the result.
If you remove someone's access, their app removes the shared content when it next syncs. We cannot erase screenshots, exports or other copies they made outside Memoir.
When you block or report someone, we receive the people or item involved, your selected reason and any note you write. A report includes readable memory text or pictures only if you explicitly choose to include them for our moderators. That material is encrypted at rest with a server-held key because our authorised moderators need to read it.
Reminders
If you have more than one device or keep your memories off your iPhone to save space, reminders such as "On this day" are sent by our server through Apple's push service. Your device writes them and encrypts them before they're uploaded; the server only knows when to send each one. We keep your device's push token to deliver them.
Problems and ideas you send us
When you report a problem or suggest an idea from Settings, we receive what you write, any pictures you add, and, unless you turn it off, basic details: app version, iOS version, device model, plan and language. These are not encrypted like your memories, because you're sending them for us to read. We use them only to fix problems and improve Memoir, and we reply in the app.
Early access requests
If you request early access on our website, we keep the email address you enter so we can choose participants and invite you through Apple TestFlight. It is separate from a Memoir account and we do not use it for advertising. We keep it while the early-access programme is active, or delete it earlier if you ask us at [email protected].
Who else is involved
- Apple provides Sign in with Apple, push notifications, iCloud, including iCloud Keychain and iCloud Drive (if you use them), Apple Intelligence, Apple Music, WeatherKit, and handles all payments. Apple's own privacy policy applies to those.
- RevenueCat helps us manage subscriptions. It receives an identifier for your account and your purchases from Apple, never your memories or your name.
- Our hosting provider runs the servers that store your encrypted memories and your account details.
- Our email delivery provider sends sign-in and account emails when you use email sign-in. It receives the destination address and the message being delivered.
We disclose information when you choose to share it, to the providers needed to run the service, to protect people and the service, or where the law requires it. We require service providers to protect the information they process for us to at least the standard required by this policy and applicable law. They may process it outside your country; where the law requires safeguards or authorisation for an international transfer, we use them. Because memories are end-to-end encrypted, a legal demand to us could reach account details, sharing records, and the technical sizes and times described above, but not the encrypted memory content. A report you deliberately send for moderation is an exception.
Why we use information
We process information to provide the app and services you request, including accounts, encrypted backup, subscriptions, sharing, recovery and support. We rely on your consent for optional device permissions and for readable content you include in a report. We use limited account, security and diagnostic information for our legitimate interests in keeping the service reliable, preventing abuse and helping users. We also process information when needed to meet a legal obligation. You can withdraw a permission in iOS Settings and stop optional sharing or recovery features in the app.
We do not use your information for advertising, profiling or automated decisions that have legal or similarly significant effects on you.
How we protect information
We use end-to-end encryption for memory content and shared content, encryption for readable reports and credentials kept by the server, access controls for administrative tools, hashed session credentials, and limits designed to detect or slow abuse. No system is perfectly secure. If a breach creates a risk to you, we will notify you and the relevant authority when the law requires it.
How long we keep things
We keep your account and encrypted memories for as long as you have an account. Deleting a private memory removes it from our live servers and your devices. Deleting shared content sends a removal to recipients; their copy of Memoir removes it when it next syncs.
Deleting your account (Settings → Account → Delete Account) erases the account, encrypted memories, files, reminders, devices, sharing profile and support feedback from our live systems straight away, and ends Sign in with Apple for Memoir. It does not cancel a subscription billed by Apple. Residual encrypted copies may remain in disaster-recovery backups until those backups are routinely overwritten and are not used for any other purpose.
We keep minimal deletion and revocation markers so an old or offline device cannot bring deleted shared content back. These markers contain technical identifiers, not the memory content. A released @handle is reserved for 30 days to reduce impersonation. Safety reports may remain after account deletion with the reporting and reported account links removed, for as long as reasonably needed to investigate abuse, prevent repeat harm, resolve disputes or meet legal duties.
Your choices and rights
- See and change what Memoir may access in the iOS Settings app.
- Export everything you've kept as a backup file from Settings → Backup & Sync.
- Sign out any device, delete everything, or delete your account from Settings.
- Ask us what we hold about you, to correct it, delete it, restrict or object to its use, or provide a portable copy, by writing to [email protected].
- Withdraw consent for optional processing. This does not affect processing that already happened lawfully.
- Complain to the Personal Data Protection Commission in Tanzania or, where applicable, your local data protection authority.
Children
Memoir isn't made for children under 13, and we don't knowingly collect information from them.
Changes
If we change this policy, we'll update the date at the top. If a change matters, we'll tell you in the app before it takes effect.
Contact
Questions about privacy: [email protected].