This policy explains personal information handled through Reminisce's mobile apps, web application, website and memory-delivery features. Contact [email protected] about privacy or your rights. Read our Terms of Service for account and plan terms.
1. Information we collect and use
- Account and sign-in information
- Identifiers, username and email from you and your chosen Apple or Google sign-in provider, including an Apple relay address where used; authentication and session records. We use these to create your account, protect access and contact you about the Service.
- Preferences and permission records
- Time zone, email frequency, plan and account status, sync preferences, and your AI and face-grouping decisions. Permission records include the choice, time and relevant disclosure/provider information so we can apply and document your choices.
- Photos and their metadata
- Photos you allow the app to synchronize or upload on the web, with available capture dates, camera/device details, orientation and embedded GPS coordinates. We use them to store and display your library, arrange photos, resolve places and create memories.
- Photo analysis and people
- Reduced images, image embeddings, scene labels, quality and safety classifications, and, when separately permitted, face crops, face-recognition templates and recurring-person groups. These help organize your library and select memory candidates. Names, relationships, visibility choices and edits you supply apply your preferences.
- Memories, shares and downloads
- Generated titles, descriptions, themes, scores, highlights and photo/event links; recipient email addresses and sharing messages you enter; keepsake projects, generated PDFs and requested data-export archives. We use these to show memories and deliver the shares, emails and downloads you request.
- Devices and operational records
- Installation identifier, platform, device name/model, operating-system version, sync settings and activity; account-linked usage, security logs, requests and error diagnostics. These support synchronization, service security, troubleshooting and operational usage/cost monitoring.
- Billing and support
- Stripe customer and subscription identifiers, account references, plan/payment status and relevant checkout information, plus information you provide to support. These let us manage paid access, recurring billing, customer requests and financial obligations. Payment entry is hosted by Stripe.
Photos, locations, names and generated descriptions can identify you and other people. Reduced images and numbered person identifiers are not anonymous.
2. AI and your AI-sharing permission
Our current AI provider is OpenAI. With your permission, it helps group selected photos into memories, write titles and stories, identify themes, score events and choose highlights. Our servers send:
- Selected photos re-encoded at up to 512 pixels on the longest edge. People and personal information can still be visible.
- Capture dates and times, GPS coordinates and place names where available. A general place label does not remove separately included precise coordinates.
- Photo scene labels and quality scores, recurring-person identifiers and names you have added.
- Relevant earlier memory titles, summaries, themes, dates, photo counts and locations, including sample coordinates, to connect related memories.
We do not deliberately include original full-resolution files, separate face-crop files, face-recognition templates, account email or device identifiers in these AI requests. Personal information can still appear inside images and memory text. Automated filtering can miss sensitive or unsuitable images.
We ask separately for AI sharing permissions, including for existing accounts. You can choose not to allow it, or withdraw permission in Settings. An active AI request may need to finish before withdrawal is confirmed. Once withdrawal succeeds, no new AI requests start, including from queued work. New AI memory generation stops; account access and existing memories remain available subject to your plan. A request already sent cannot be recalled, and withdrawal alone does not delete previously created memories or provider records.
We use OpenAI's global API with response storage disabled (store: false). This is not a guarantee of zero retention. OpenAI states that API data is not used for model training by default unless the customer opts in. Its default abuse-monitoring logs may retain content for up to 30 days, with legal and safety exceptions. Image safety review and prompt caching can involve additional retention. See OpenAI's data controls.
3. Separate, optional face grouping
Face grouping creates face crops and recognition templates on our infrastructure to group recurring people in your library. You can assign names and relationships within your account.
Face grouping requires its own explicit choice. You can decline it or withdraw it in Settings independently of AI sharing. This stops new face recognition and grouping. Existing face crops, groups, names and templates are not automatically erased by withdrawal; account deletion removes associated data through the process below.
A photo may show people who do not have a Reminisce account. Your permission does not automatically supply legal permission on their behalf. Respect their rights when uploading, naming or sharing them. People pictured can contact our privacy address about their information.
4. Providers, sharing and processing locations
- Scaleway: hosting and email
- Hosting, databases, photo and derived-file storage, operational observability and transactional email delivery. Infrastructure configuration uses Paris, France. Email delivery includes recipient addresses and message content.
- OpenAI: AI memories
- The reduced photos and associated information described above. Processing through the global API may occur outside the European Economic Area (EEA).
- Sentry: error diagnostics
- Configured mobile/backend crash and error reports, which can contain request, device or other diagnostic context. The iOS integration disables screenshots and default personal-information collection and removes the user object; these measures do not guarantee that every diagnostic field is free of personal information.
- Stripe: web subscriptions
- Account email and internal account reference, subscription identifiers, and billing/payment information supplied during checkout. Stripe hosts payment entry and returns billing records used to manage your plan.
- Apple or Google: your chosen sign-in
- Authentication requests and account-linkage information needed to sign you in with the provider you select.
- Cloudflare, Google Fonts, Wikimedia Commons and Unsplash: website
- Cloudflare serves the marketing site. External fonts and demonstration images send ordinary request information, including IP address, to their respective providers when loaded.
- Recipients you choose and their email providers
- Shared memories, photos, your accompanying message and relevant sender information. Authorized recipients may see your selected “Me” avatar. Recipients and their mail providers can be outside the EEA, and can save their own copies.
Photos containing faces and deliberately shared avatars are different from separate recognition templates. Sharing photos or requesting AI processing can transmit images of people beyond our hosting infrastructure. Account deletion cannot remove copies already saved by recipients.
Provider locations, contractual protections, retention and international-transfer arrangements must be confirmed before this draft becomes effective. We do not infer a data-processing agreement or transfer safeguard merely from a provider offering one.
5. Your choices
- Photo access and sync: use iOS Photos permissions to choose the photos the app may access, including limited access, and app sync controls to manage future uploads. Revoking access or stopping sync does not erase already uploaded copies or independently withdraw AI permission.
- AI sharing: use the privacy controls in Settings to review the provider disclosure, allow, decline or withdraw permission. Declining keeps new AI memory generation off.
- Face grouping: use its separate Settings choice to stop new recognition and grouping. This does not automatically withdraw AI sharing.
- Emails and notifications: adjust memory email settings for delivery cadence. Current iOS sync reminders are local notifications; manage notification permission in iOS Settings.
- Shares: revoke supported future access using share controls. Emails and copies already received cannot be retrieved.
- Downloads and deletion: request a data export in the web app and account deletion in iOS or web Settings.
6. Purposes and legal grounds
Account access, photo storage and requested delivery features support the service contract. Optional AI sharing and face grouping have separate consent choices. Security and operational diagnostics support protecting and maintaining the Service; required financial records support legal obligations.
7. Retention and account deletion
Account content is kept to provide the Service while your account remains active, subject to your deletion choices. Request account deletion in iOS Settings or web account Settings. It revokes access and starts removal of account records, photos and derived data, keepsakes and export archives, and cancellation of associated web subscriptions. Download anything you wish to keep first.
Data-export downloads expire seven days after completion and are scheduled for cleanup. Deleting an account is separate from stopping sync, withdrawing processing permission or canceling a subscription.
Legal or security obligations may require specified billing records and backups and operational logs to be retained after account deletion, rotated out where applicable over time.
8. Your rights and security
Depending on applicable law, you can request access, correction, deletion, restriction or portability, object to processing on applicable grounds and withdraw consent. Withdrawal does not affect the lawfulness of earlier processing. Contact [email protected]. You may also complain to a relevant data-protection authority.
We use secure transport and access controls to protect information. No system can guarantee absolute security. Review photos and generated memories before sharing them.
9. Website and policy updates
The marketing website uses Umami, a privacy-focused analytics service that sets no cookies and does not track you across websites. We add no advertising cookies. External fonts, images and hosting still involve the requests described above. The authenticated web app uses sign-in/session mechanisms needed to provide account access, and includes no third-party analytics. Your digest emails contain a small image and links that let us count how many digests are opened and clicked, so we can tell whether the stories we send are worth reading. Emails we send on your behalf to people without an account contain no such measurement.
We will identify material changes and update the policy date. Where a provider, purpose or disclosure change requires new permission, we will ask before starting that processing. Prior permission records remain historical records of the choice you actually made.