Last updated: March 2026
EverMemory Inc., a company incorporated in the State of Delaware, United States ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use the EverMemory service (the "Service"). By using the Service, you consent to the practices described in this policy. If you are located in the European Economic Area (EEA), United Kingdom (UK), or California, please see the additional sections below for your specific rights.
We collect the following types of information: • Account Information: Email address and password (hashed using bcrypt) when you register. • Content: Audio recordings, transcripts, photos, family connections, places, events, and biography content you create. • Payment Information: Processed securely by LemonSqueezy (a Stripe company). We do not store credit card numbers or payment card details. • Phone Number (optional): Collected during checkout for order communication purposes only. • Usage Data: Basic analytics such as feature usage frequency, session duration, and error logs to improve the Service. • Device Information: Browser type, operating system, and language preference for compatibility purposes.
For users in the European Economic Area and United Kingdom, we process your data under the following legal bases: • Contract Performance: Processing your account data, content, and payment information is necessary to provide the Service you subscribed to (GDPR Article 6(1)(b)). • Legitimate Interest: Usage analytics and error logging help us improve service quality and security. We have assessed that this processing does not override your privacy rights (GDPR Article 6(1)(f)). • Consent: Optional communications such as weekly insight digests and newsletters are sent only with your explicit consent. You may withdraw consent at any time (GDPR Article 6(1)(a)). • Legal Obligation: We may process data to comply with tax, accounting, or legal requirements (GDPR Article 6(1)(c)).
We use your information exclusively to: • Provide, maintain, and improve the Service • Transcribe your audio recordings and generate biography content • Process payments and manage subscriptions • Send you important service notifications (account security, billing, order updates) • Send optional weekly insight digests (you can opt out anytime via Settings or by clicking the unsubscribe link in any email) We do NOT use your personal content to train AI models, serve advertisements, or for any purpose other than providing the Service to you.
Your data is stored securely using industry-standard practices: • All data is encrypted at rest (AES-256) and in transit (TLS 1.3) • Database hosted on SOC 2 Type II compliant infrastructure (AWS US-East region) • Row Level Security ensures complete data isolation between users • Daily automated backups with point-in-time recovery • Access to production systems is restricted to authorized personnel only • Regular security audits and vulnerability assessments
We do not sell, rent, or trade your personal information. We share data only with the following service providers (sub-processors), each bound by data processing agreements: • LemonSqueezy / Stripe: Payment processing (PCI DSS Level 1 certified). Location: United States. • Google Gemini AI: Audio transcription and content generation. Processing is stateless with no data retention by Google. Location: United States. • Supabase (AWS): Database hosting and file storage (SOC 2 Type II). Location: United States (US-East). • Resend: Transactional email delivery (order confirmations, account notifications). Location: United States. For EU/EEA users: Data transfers to the United States are conducted under Standard Contractual Clauses (SCCs) as approved by the European Commission, or equivalent safeguards. We will notify users via email at least 30 days before adding any new sub-processor.
We retain your data for the following periods: • Account and Content Data: Retained for as long as your account is active. Upon account deletion, all personal data is permanently deleted within 30 days. • Payment Records: Transaction records are retained for 7 years to comply with tax and accounting regulations. • Usage Analytics: Anonymized and aggregated after 12 months; raw logs deleted after 90 days. • Backups: Database backups are automatically rotated and overwritten within 30 days. Deleted data will no longer exist in any backup after this period. • Webhook Event Logs: Financial event logs are retained for 24 months for audit and reconciliation purposes.
We use minimal cookies strictly necessary for the Service to function: • Authentication cookies to keep you logged in • Preference cookies to remember your language and settings We do NOT use advertising cookies, tracking pixels, or any third-party analytics that personally identify you. No cookie consent banner is required as we only use strictly necessary cookies.
You have the following rights regarding your personal data: • Access: View all your personal data through your account dashboard • Export: Download a complete copy of all your data at any time (JSON and PDF formats) • Portability: Receive your data in standard machine-readable formats • Correction: Update your account information at any time • Deletion: Delete your account and all associated data via Settings • Restriction: Request that we limit processing of your data • Objection: Object to processing based on legitimate interests • Opt-out: Unsubscribe from non-essential communications via Settings or email unsubscribe links We will respond to all rights requests within 30 days. To exercise any of these rights, use the Settings page or contact us at privacy@evermemory.ai
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA): • Right to Know: You may request details about the categories and specific pieces of personal information we collect. • Right to Delete: You may request deletion of your personal information. • Right to Opt-Out of Sale: We do not sell your personal information. We never have and never will. • Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights. To exercise these rights, contact us at privacy@evermemory.ai or use the in-app Settings page. We will verify your identity before processing your request.
The Service is not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, please contact us immediately and we will promptly delete such information.
We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification at least 30 days before they take effect. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at: Data Protection Contact: privacy@evermemory.ai General Support: support@evermemory.ai Address: EverMemory Inc., Delaware, United States For EEA/UK users: If you are not satisfied with our response, you have the right to lodge a complaint with your local Data Protection Authority.
This Privacy Policy is effective as of March 2026.