What we hold, and why
Privacy Policy
This policy explains what Memoroam collects, why we collect it, who else ever sees it, and the control you have over all of it. The plain-English summary comes first. The full detail follows it.
Last updated: 21 August 2026
Plain-English summary
Memoroam is a travel memory app. You log trips, plan itineraries, save photos, and collect digital stickers and stamps. Here is the short version of this policy:
- We collect what you type and upload: your account details, your passport profile, your trips, your photos, and your support messages. We do not collect anything behind your back. The only automatic technical data is what Sections 3.5, 3.8, 3.11 and 5 describe: a device snapshot attached to support requests you send, daily place-search counters, a small set of usage counts and crash reports that carry no name and no account identity, and the standard connection data (IP address) any web service's servers receive.
- We have no advertising, no cookies, no tracking across other apps or websites, and we never sell your data. We do count a few moments of use (such as how often the app is opened) and receive crash reports when something breaks; neither carries your name or account identity, nothing is stored on your device for either, and you can switch the usage counting off in Settings. Section 3.11 describes both in full.
- We never access your device's location. Every place in the app is a city you picked from a list or typed yourself.
- Photo location data (EXIF and GPS) is stripped on your phone before anything is uploaded.
- Friends you accept can see your passport by default, including your name, date of birth, gender, home city, portrait, and signature. You can hide all of it with one switch. Section 10 explains exactly what friends can and cannot see.
- Deleting your account is immediate and permanent. A few narrow exceptions are listed honestly in Section 8.
- You must be at least 16 to use Memoroam.
The rest of this policy is the long version. Nothing in the summary changes or limits it.
1. Who we are and how to contact us
Memoroam is operated by MEMOROAM LTD ("Memoroam", "we", "us"), of 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ. We are the data controller for the personal data described in this policy.
Privacy questions, requests, and complaints: support@memoroam.com.
2. Definitions used in this policy
- "The app" means the Memoroam progressive web app and the Memoroam Android and iOS apps, which are the same application. This policy also covers our public website at memoroam.com; the one disclosure specific to the website appears at the end of Section 6.4.
- "Confirmed friend" means another Memoroam user whose friend request you accepted, or who accepted yours. Itinerary shares can only be sent to confirmed friends. The only things a signed-in non-friend can ever see are your display name and account identifier, and only if they enter your friend code (Section 10.6). Content you export yourself leaves the app entirely (Section 10.5).
- "Starlight" means Memoroam's virtual currency.
- "Passport" means the digital passport feature inside your profile.
3. Data we collect
We only collect data you actively give us or that the features you use necessarily create. There is no background collection of any kind.
3.1 Account and identity
- Email address, from Google or Apple. Memoroam does not have its own username and password. You sign in with Google or with Apple, and that provider tells us your email address, your name, and (for Google) your profile picture. We never create, see, or store a password for you, because there is none to store. If you use Sign in with Apple and choose to hide your address, we receive a forwarding address from Apple instead of your real one, and that is all we ever have.
- Your sign-in stays with your provider. Changing your password, turning on two-factor authentication, and revoking Memoroam's access are all done in your Google or Apple account, not in our app. We cannot change them for you and we cannot see them.
- No account emails. Because Google and Apple confirm your address before they pass it to us, Memoroam sends no sign-up code, no verification link, and no password reset message. We do not send marketing email and have no system that could. In practice Memoroam does not email you at all.
- Date of birth (full date, required). Used to check you are at least 16, and displayed inside your own passport, including its simulated machine-readable line. Your date of birth is visible to confirmed friends by default; see Section 10.
- Gender (required). You must pick an option at signup, including "prefer not to say", which is stored as your selection. Gender is used for one thing: the sex letter printed on your passport page. It is visible to confirmed friends by default; see Section 10. It is not used for anything else: no profiling, no advertising, no recommendations.
- Home country and city. You pick these from a list. They set your home airport suggestions, your passport's place of residence line, and your home pin on the globe. This is a city name you chose, never a device location.
- Friend code. A random 6-character code generated for you so friends can find you. Anyone you give it to, and any signed-in user who enters it, can see your display name and account identifier. There is currently no way to change or disable your friend code.
Providing an email address, date of birth, and gender is required to create an account. Everything else in this policy is optional.
3.2 Profile and passport
- Passport name and display name. Shown on your passport and to friends. Some identity fields (passport name, date of birth, home country and city) can only be edited once every 30 days; see Section 11 if you need to correct an error sooner.
- Passport photo (optional). A portrait you can add to your passport. This is a photo of your face if you choose to upload one. It is stored as an image only: we run no face recognition and create no biometric data of any kind.
- Round profile icon (optional). Shown next to your name in the friends menu of accepted friends.
- Handwritten signature (optional). A drawing you make with your finger at signup, stored as an image and shown on your passport.
- Passport number. A randomly generated decorative number. It is not derived from any personal data.
3.3 Travel content
- Trips: origin and destination airports, cities, dates, seat, gate, flight number, airline, times, and layover details you enter, plus any custom statistic you choose to show on a trip poster.
- Itineraries: day plans, stops (including place names, addresses, phone numbers, websites, times, and your free-text notes), saved places, links, notes, document checklists, and day-to-city tags.
- Trip finances: budgets and itemised expenses (amount, currency, category, date, name) you enter. These are never visible to anyone but you.
- Streak quiz answers: which option you picked, whether it was correct, and when, plus your streak counters.
- Highlights and personal destination tips: collections you curate from your own memories and notes you write.
- Itinerary shares: when you send days of a trip to a confirmed friend, we store a frozen copy of those days and stops, including your free-text stop notes, together with your name as it was at the moment of sending. See Section 10.4.
3.4 Photos, and what happens to photo metadata
- Memory photos. When you save a memory we store two versions: a square cropped version and a larger uncropped version (up to 2048 pixels) used by the "view original" screen.
- Photo metadata is stripped on your device. Every image you upload (memory photos, the larger "original", your portrait, your profile icon, highlight covers) is re-encoded on your phone before upload. This removes all embedded metadata, including GPS coordinates, camera details, and the original capture date. No metadata ever reaches our servers, and no code in the app reads it.
- The "original" is not your camera file. What the app calls the original is a re-encoded copy at up to 2048 pixels. Your true camera file, and all of its metadata, never leaves your phone.
- No location is attached to photos from your device. The coordinates attached to a memory are reference coordinates for the city you tagged, or for a place you added to your itinerary, taken from our city database or our place-search provider, never from the photo and never from your device. The date on a memory is the date you picked on a calendar, never the photo's own date.
- Memory details. Alongside each photo we store the city and country you tagged, your chosen date, your free-text note, and which trip it belongs to.
- The app supports photos only. There is no video or audio upload anywhere.
3.5 Support requests
When you send a support or feedback request we collect:
- your name, email address, message, and the category you picked; and
- a technical snapshot to help us reproduce problems: your browser identifier (user agent), language, screen size, the page of the app you were on, its address, and the app version.
Our support team is notified of new requests through Discord; Section 6.5 describes that notification, which contains none of your personal data.
3.6 Friends
We store your friend connections: who sent each request, who received it, its status (pending, accepted, or declined), and when. Each connection is visible only to the two people in it. Declined requests are kept so the app can show the request's state; either person can remove a connection at any time.
3.7 Starlight and collection records
- Starlight wallet and ledger. Your Starlight balance and a full transaction history (amount, reason, resulting balance). Starlight can be bought in bundles through your app store; see Section 14.
- Collection records. The collectibles you own, a log of every pack you open, your daily free pack counters, and your unlocked covers and banners. The daily pack limit is calculated using the timezone stored in your profile.
- These records are kept for the integrity of the collection features and cannot be individually deleted; they are removed when your account is deleted.
3.8 API usage counters
To control costs on our paid place-search service, we count how many place searches your account makes per day. This is a per-day number only. See Section 8 for an honest note about how long these counters are kept.
3.9 Notifications
If you allow notifications, we store a push token for each device you allow them on (the delivery address Google's messaging service assigns your device), which platform that device runs (Android or iOS), and the device's timezone, so daily reminders can arrive at a sensible local hour. We also store your notification preference: whether you have notifications switched on or off. We do not send promotional or marketing notifications. A device's push token is deleted when you sign out on that device, when the messaging service reports the app was uninstalled from it, and when your account is deleted. Daily reminders (your packs and daily question) are scheduled by your device itself and involve no server at all. For server-sent reminders (such as a trip starting soon), we keep a short log of which reminders we already sent you, so you never receive the same one twice; entries are deleted after 60 days.
3.10 Data that mostly stays on your device
Most of the data below never reaches our servers at all. The one exception is stated where it appears:
- Settings and app state. Your theme choice, recently used airports, tutorial progress, and similar convenience state live in your device's local storage. The exception: your theme choice is also saved to your profile on our servers so it follows you between devices.
- Activity log. The in-app bell showing your recent trip edits exists only in memory and disappears when you close the app. It is never stored or transmitted.
- Image cache. Your photos are cached on your device for speed. This cache is wiped when you sign out (including when your session is ended remotely), and individual photos are evicted from it when you delete them.
3.11 Usage statistics and crash reports
Two narrow kinds of technical reporting exist, added in August 2026. Both are described here in full, and neither carries your name, email, photos, message content, or account identifier.
- Usage statistics. We count a few moments of use, like how often the app is opened and whether the upgrade screen is seen. The counts help us understand what to improve. They include no names, photos or message content, and nothing is saved on your phone. Switch this off in Settings (Data & Privacy, Usage Statistics) and the counting stops on that device. In more detail: each count is a named event (for example the app being opened, the upgrade screen being shown or dismissed, a globe theme or photo frame being changed) carrying a small fixed set of technical properties, such as whether you use the installed app or a browser, plus the basic device and browser context our analytics provider attaches to any event it receives. Automatic capture of clicks, typing, screens, and page views is switched off in code, as are session recording, heatmaps, and surveys. Because nothing analytics-related is stored on your device, the counting cannot recognise you between sessions: each session is counted afresh, and we never attach your account to any of it. Within a single session the events are pseudonymous rather than anonymous, which is one reason the off switch exists. The off switch itself is stored on your device (the one piece of storage this feature has) and it survives signing out, because it belongs to the device rather than to an account.
- Crash and error reports. When the app hits an error, a report is sent to our error-monitoring provider so we can find and fix the breakage. A report contains the technical description of the error, the app version, which surface you were using (installed app or browser), and a short trail of the technical steps that led up to it: console messages, the addresses of recent network requests (with sign-in tokens and photo-link signatures stripped out before anything is sent), and the on-screen elements recently tapped, recorded as code identifiers rather than as visible text. Reports are configured to carry no account identity: we never attach your name, email, or user ID, and the report is sent without your IP address attached. Like any server, the provider's server sees the connection's technical data when a report arrives. Crash reporting has no in-app switch, and the Usage Statistics toggle does not cover it: it covers the usage counting only. We keep crash reporting always on because it is how we find breakages, including for users who could never reach Settings to tell us about them.
Both providers are named in Section 6.1, and both store this data in the European Union (Frankfurt, Germany). We hold no copy of any of it ourselves: nothing from either feature is written to our own database, so it is retained only at those providers, under our project settings there.
4. Data we do NOT collect
Every statement below has been verified against the app's full source code. None of them is aspirational.
- No advertising and no cross-service tracking. There is no advertising SDK, no tracking pixel, no fingerprinting, no session replay, and no A/B testing anywhere in the app, and nothing follows you across other apps or websites. The analytics we do have is the narrow usage counting described in Section 3.11, with automatic capture switched off in code; crash reporting (also Section 3.11) exists to fix errors, not to profile you.
- No cookies. The app sets no cookies. Sign-in uses tokens stored in your device's local storage. Because we use no cookies and no tracking storage, we do not show a cookie banner: there is nothing to consent to. One caveat: the third-party content delivery servers listed in Section 6.4 may set their own cookies on their responses; we do not control these, and they will end when we bundle those resources into the app.
- No advertising. There are no ads and no advertising identifiers.
- No payment card data. Purchases are billed entirely by Google Play or the Apple App Store; your card details go to the store and never reach us or our systems. See Section 14.
- No precise location. The app never asks for or reads your device's location. There is no geolocation code anywhere. Locations in Memoroam are city-level entries you typed or picked.
- No photo metadata. As described in Section 3.4, EXIF and GPS data are stripped on your device before upload.
- No contacts, no calendar, no SMS, no microphone, no video. The app never accesses any of these.
- No profiling and no automated decision-making. Nothing in Memoroam makes automated decisions about you or builds a profile of you. Pack openings are random draws with published odds, not profiling.
5. Why we process your data, and our lawful bases
Under UK and EU data protection law we need a lawful basis for each purpose. Ours are:
- Creating your account, signing you in, keeping your session active: Data involved: Email address and account identifier from Google or Apple, session tokens. Lawful basis: Contract (providing the service you signed up for).
- Checking you are at least 16: Data involved: Date of birth. Lawful basis: Legitimate interests (keeping under-16s off the service and enforcing our Terms).
- Displaying your passport (name, number, date of birth, gender letter, home place, portrait, signature): Data involved: Profile and passport data. Lawful basis: Contract (the passport is the product).
- Storing and displaying your trips, itineraries, finances, memories, highlights, and tips: Data involved: Travel content and photos. Lawful basis: Contract.
- Hosting and delivering your photos through signed links: Data involved: Photos, auth tokens. Lawful basis: Contract.
- Friend requests and the friend graph: Data involved: Friend connections. Lawful basis: Contract (a feature you actively use).
- Showing your passport and collection to confirmed friends: Data involved: See Section 10. Lawful basis: Contract for the feature; the default visibility is described in Section 10.
- Sending an itinerary share you initiate: Data involved: The frozen share copy, including stop notes. Lawful basis: Contract (you tap send).
- Running the collection features (packs, collection, wallet, streaks) and enforcing the daily pack limit: Data involved: Collection records, wallet ledger, streak answers. Lawful basis: Contract, plus legitimate interests (preventing abuse and keeping the ledger accurate).
- Answering your support requests: Data involved: Support request content and device snapshot. Lawful basis: Legitimate interests (responding to a request you made).
- Limiting place-search usage: Data involved: Daily search counters. Lawful basis: Legitimate interests (cost control and abuse prevention on a paid service).
- Counting how the app is used (usage statistics): Data involved: Named usage events with basic device and browser context, never your identity (Section 3.11). Lawful basis: Legitimate interests (understanding what to improve); object at any time with the Usage Statistics switch in Settings.
- Detecting and fixing crashes and errors: Data involved: Crash and error reports as described in Section 3.11. Lawful basis: Legitimate interests (keeping the service working).
- Sending push notifications you have allowed: Data involved: Push token, device platform, device timezone, notification content, a 60-day log of reminders already sent. Lawful basis: Legitimate interests (telling you about activity in features you use); controlled by your device permission and the Notifications toggle.
- Processing purchases and subscriptions: Data involved: Purchase, subscription, and entitlement records from your app store, relayed by RevenueCat (Section 14). Lawful basis: Contract (delivering what you bought).
- Serving the app at all (hosting, backend, security): Data involved: IP address and browser identifier, processed by our hosting providers. Lawful basis: Legitimate interests (it is impossible to deliver an online service without this).
- Loading fonts, code libraries, and map tiles from third-party servers: Data involved: IP address and browser identifier sent to those servers. Lawful basis: Legitimate interests; Section 6 names each one.
Where we rely on legitimate interests you can object; see Section 11.
6. Third parties who process or receive data
We do not sell your data to anyone, and we share nothing for advertising. The parties below receive data only as described.
6.1 Core infrastructure (processors acting for us)
- Supabase Inc. (USA). Our backend: the database holding everything described in Section 3 that reaches a server (including some images stored directly in the database: your signature, highlight covers, and portraits not yet moved to photo storage), the authentication service holding your credentials, and the server functions that run features like pack opening and account deletion. Supabase's servers see your IP address and browser identifier on every request, and their short-term server logs can contain technical error details. Data location: the European Union (Frankfurt, Germany).
- Cloudflare, Inc. (USA). Hosts the app itself, stores your memory photos and portrait images in private storage, and runs the signing service that checks you (or a permitted friend) are allowed to see each photo before issuing a short-lived link. To do this, Cloudflare's service processes your sign-in token on every image request and looks up the relevant photo and friendship records. Cloudflare sees your IP address on every visit. Photo storage location: Western Europe. If you share content into Memoroam from another app, the shared text and link pass through the web address and can appear in Cloudflare's standard server logs.
- Google LLC (Firebase Cloud Messaging, USA). Delivers push notifications, if you allow them. Google's messaging service holds the push token that routes messages to your device and sees the content of each notification in transit (for example a friend's display name in "sent you a friend request"). It receives nothing else about you from us.
- PostHog Inc. (PostHog Cloud EU, Germany). Runs the usage counting described in Section 3.11, on servers in Frankfurt, Germany. It receives the named events and their technical properties and, like any server, sees your IP address when an event arrives; our PostHog project is set to discard that IP address rather than store it with events. We never send it your name, email, or account identifier, and its automatic capture, session recording, and profile features are switched off in our code. PostHog is an active participant in the EU-US Data Privacy Framework, including the UK Extension.
- Functional Software, Inc., trading as Sentry (EU region, Germany). Runs the crash and error reporting described in Section 3.11, on servers in Frankfurt, Germany. Reports arrive with tokens and photo-link signatures already removed, carry no account identity, and are sent without your IP address attached. Sentry is an active participant in the EU-US Data Privacy Framework, including the UK Extension.
- RevenueCat, Inc. (USA). Manages purchases and subscriptions (Section 14). It receives your account identifier, the product bought, which store billed it, and the store's transaction records (timestamps, renewal state, transaction identifiers). It never receives your name, email, or card details; payment itself is processed by your app store. RevenueCat processes this data for us under the EU Standard Contractual Clauses together with the UK Addendum.
6.2 Sign-in providers (only if you choose them)
- Google LLC. If you sign in with Google, Google confirms your identity and passes your name, email, and profile picture to our authentication service. We request no additional Google permissions.
- Apple Inc. If you sign in with Apple, Apple confirms your identity and passes your name and email to our authentication service via Apple's web sign-in flow.
Separately from sign-in, Google has an Android platform role for every Android install: Google verifies the app's link to our domain when you install it, and your device's Google backup may include the app's local data (see Section 13).
6.3 Maps and places
- Geoapify (place search). Powers place search when you plan an itinerary. Your search text, the relevant city, and the map area being searched are forwarded to Geoapify from our server. For place search, Geoapify never receives your identity or your IP address; those requests come from our server, not your device. Your search text is not stored by us.
- Geoapify (map tiles). Also provides the background map images in itinerary maps. When you open a map, your device requests map tiles directly from Geoapify, so Geoapify sees your IP address and the coordinates of the map area you are viewing, which can indicate your trip destinations. This happens each time you open a map.
- OpenStreetMap Foundation (Nominatim). A fallback geocoding service. During airport search and certain lookups your device may send a searched city name, trip city names, or your home city name, together with your IP address, directly to the public Nominatim service.
- Google Maps and Apple Maps. Only when you tap "open in maps" on a saved place, that place's coordinates are passed to the maps app you chose. Nothing is sent unless you tap.
6.4 Content delivery (every visitor, including before sign-in)
The app currently loads fonts and code libraries from public content delivery networks. When you open Memoroam, your device contacts these servers directly, which means each one sees your IP address, browser identifier, and the page address, including on screens shown before you sign in:
- Google Fonts (fonts).
- jsDelivr (code libraries and map data).
- cdnjs, operated by Cloudflare (code libraries).
- unpkg (the Leaflet map library).
- Cloudflare public asset storage (app artwork and banners).
These services receive no account data, only the standard technical data any web server receives. Because this happens as the app loads, there is currently no way to use Memoroam without these requests being made. We plan to bundle these resources into the app itself, which would end these disclosures; this policy will be updated when that happens.
Our public website at memoroam.com loads its fonts from Google Fonts in the same way, so visiting the website sends the same standard technical data to Google. The website itself runs no analytics, sets no cookies, and collects nothing.
6.5 Support delivery
- Discord Inc. (USA). When you send a support request, its content stays in our database. What Discord receives is only a notification that a ticket exists: the category you picked, your plan tier, the ticket reference, the time, and a link that opens the ticket in our own dashboard. Your name, email address, and message are never sent to Discord. The notification is pseudonymous rather than anonymous: we can look the ticket up from its reference, but Discord cannot identify you from it.
6.6 Services that receive no personal data
- open.er-api.com supplies currency exchange rates to our server. The request contains nothing about any user.
- Our server functions load their own code from esm.sh at startup. No user data is involved.
6.7 People and apps you choose
- OS share sheet. When you export a trip poster or a passport page image, the app renders the image on your device and hands it to the app you pick (for example a messaging app). That image can contain your photos, captions, trip details, and dates, and the file name of a passport export includes the destination country and travel month. Once shared, copies are outside Memoroam's control; see Section 10.5.
7. Where data is stored and international transfers
- Your account data and content live in our Supabase database in the European Union (Frankfurt, Germany). Your photos live in Cloudflare storage in Western Europe. Usage statistics and crash reports (Section 3.11) are also stored in Frankfurt, Germany. Cloudflare additionally processes requests at its global edge network, so some processing occurs close to wherever you are.
- Some of our providers are United States companies. Where your data is transferred outside the UK or the European Economic Area, the safeguard depends on the provider. Google, Cloudflare, PostHog, and Sentry are active participants in the EU-US Data Privacy Framework, including the UK Extension, which the UK and the EU recognise as providing adequate protection. Supabase (whose contracting entity is incorporated in Singapore, with our database held in Frankfurt) and RevenueCat rely on the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum, as incorporated in their data processing agreements. Apple acts as an independent controller for sign-in and App Store billing under its own privacy policy and uses Standard Contractual Clauses for its own transfers. Discord is not on this list because it no longer receives personal data (Section 6.5).
- The map, geocoding, and content delivery services in Section 6.3 and 6.4 receive limited technical data (IP address, map areas, place names) directly from your device; their server locations are their own.
8. How long we keep data
Our honest retention rule is simple: almost everything is kept until you delete it or delete your account, and account deletion is immediate.
- Profile, trips, itineraries, finances, memories, photos, highlights, tips, friend connections, collection records, wallet ledger, streak answers, itinerary shares: kept until you delete the item (where the app allows) or until you delete your account. We do not run scheduled purges, and we will not pretend otherwise with "as long as necessary" wording.
- Account deletion is immediate, not delayed. When you delete your account it is hard-deleted straight away, with no grace period and no recovery. There is no 30-day window.
- What survives account deletion, stated plainly:
- Support tickets are kept as anonymised records: your name, email, and message are replaced with "[deleted]" before your account is removed, and the remaining row (category, dates, our replies context) is retained.
- Purchase records are kept by your app store and by RevenueCat under their own policies after your account is deleted, because stores retain transaction records for refund, fraud, and legal purposes. Our own entitlement and Starlight ledger records are deleted with the account.
- Usage counts and crash reports already sent (Section 3.11) cannot be looked up or deleted by account identity, because they were never linked to your account; they remain at the providers as unattributed technical records.
- Daily place-search counters linked to your account identifier are not currently removed by the deletion process.
- Photo files: deletion sweeps your photo storage, but the sweep is best-effort. If a storage deletion fails there is currently no automatic retry. We state this so our deletion promise is accurate.
- Server logs at our hosting providers may transiently contain technical records for a limited period under their standard practices.
- Deleting a single trip removes the trip, its days, stops, notes, links, document checklists, and budget, and also permanently deletes the memories and photos attached to that trip. Two categories of planning data connected to it (city segment records and saved places) are not removed until you delete your account.
- Deleting a single memory is complete: the database record, both stored image files, and the cached copy on your device are all removed.
- Itinerary shares you have sent remain stored (including after being accepted or declined) until either party deletes their account. There is currently no button to withdraw a sent share.
- Streak answers, pack history, and the Starlight ledger cannot be individually deleted; they last until account deletion, for the integrity of those features.
- Submitted support requests cannot be viewed, edited, or deleted in the app; they are retained as described above.
- Your portrait and profile icon can be replaced at any time but can only be removed by deleting your account.
- Declined friend requests are retained so the request state can be shown; either person can remove the connection.
9. How we protect your data
We describe only measures that actually exist:
- All connections between your device and every service we use are encrypted in transit (HTTPS/TLS).
- Every database record is protected by row-level security: the database itself refuses to return another user's data, independent of app code.
- There are no Memoroam passwords to protect. Sign-in is handled entirely by Google or Apple, so your credentials are never sent to us, never pass through our systems, and cannot be exposed by a breach of ours.
- Photos live in private storage. They are never public. Memory photos and portrait images stored in our photo storage require a short-lived signed link, issued only after server-side verification that the requester is the owner or a permitted confirmed friend. A small number of images (your signature, highlight covers, and portraits not yet migrated to photo storage) are stored inside the database itself and are protected by the same server-side access rules rather than signed links.
- Friend access is enforced server-side on every request, not just hidden in the interface.
- Photo metadata is stripped on your device before upload (Section 3.4).
- When you delete a photo, it is also purged from your device's cache; signing out wipes the entire photo cache on that device.
We do not claim security certifications or independent audits, because none have been performed.
10. Sharing with friends, and content that leaves the app
10.1 What a confirmed friend sees by default
Friend visibility is ON by default. Unless you turn on "hide passport from friends", a confirmed friend can view:
- your name, home country and city, full date of birth, gender, account creation date, passport number, your handwritten signature image, and your portrait photo;
- your designed passport trip pages: destination country, city, airport code, trip and return dates, the cities list, and the page design you created;
- the memory photos you personally placed on a designed passport page. This access is checked on our servers each time, and only for photos you placed there.
A friend can never see, under any setting: your raw photo library, your memories gallery, your highlights, your trip finances, your notes, your document checklists, your booking details (seat, flight number, airline, origin airport), or the larger "original" versions of your photos.
10.2 The hide toggles
- Hide passport from friends: one switch that hides everything in 10.1. When it is on, friends see only your name and whether you have an avatar. The switch is all-or-nothing; there is currently no field-by-field control.
- Hide collection from friends: collection visibility is on by default. Unless you turn on this separate switch, confirmed friends can browse your collection (owned cards, showcase picks, cover art).
10.3 Avatars
Your profile icon is visible to accepted friends only. People with pending or declined requests see a monogram, not your photo.
10.4 Itinerary shares
When you send days of an itinerary to a confirmed friend:
- the recipient receives your name (as it was when you sent it) and a frozen copy of the selected days and stops, including any free-text notes you wrote on those stops;
- booking details, the trip Notes tab, finances, and document checklists are never included;
- if the recipient accepts, the copy becomes part of their own trip data and is theirs; unfriending or editing your trip later does not recall it;
- share records are removed if either of you deletes your account.
10.5 Exports leave our control
Trip posters and passport page images you export are rendered on your device and handed to the app you choose. From that moment the image, which can include your private photos, captions, trip details, and collectible artwork, is outside Memoroam's protection entirely. The signed-link system that protects photos inside the app does not apply to exported copies. Share exports thoughtfully.
10.6 Friend codes and identifiers
Anyone who has your friend code, and any signed-in user who types it in, can see your display name and account identifier. Your account identifier also appears inside the web addresses of your photos' signed links. Neither reveals anything else by itself, but treat your friend code like a handle you are happy to be found by. It cannot currently be changed.
11. Your rights and the tools we give you
If you are in the UK or the EEA you have the rights below under data protection law. We voluntarily extend the same rights to every Memoroam user, wherever you are.
- Access: ask what data we hold about you.
- Rectification: have inaccurate data corrected.
- Erasure: have your data deleted.
- Portability: receive your data in a machine-readable format.
- Restriction: ask us to pause certain processing.
- Objection: object to processing based on legitimate interests (Section 5).
- Withdraw consent: nothing we do today relies on your consent, so there is nothing to withdraw. If that ever changes, you can withdraw consent at any time by removing the content or emailing support@memoroam.com.
- No automated decisions: not applicable in practice, because we make none (Section 4).
- Complaint: see the end of this section.
In-app export (Settings, Data & Privacy, Export My Data). Builds a ZIP on your device containing your profile, trips, itineraries, memories with their cropped photos, collection, Starlight history, streak history, your daily place-search counts, and support tickets, as JSON files you can read and reuse. Be aware of its current limits: the export does not include the larger "original" photo versions (crops only), your avatar and profile icon images, or itinerary share records. For those, or for a complete formal access request, email support@memoroam.com. One category can never be produced, for you or anyone else: the usage counts and crash reports in Section 3.11 are not linked to your account, so we have no way to find which of them were yours.
In-app deletion. Go to Profile, tap the settings cog, choose Delete Account, and type DELETE to confirm. Deletion is immediate, permanent, and unrecoverable, and Section 8 lists exactly what survives. You can also request deletion without the app at https://www.memoroam.com/delete-account or by emailing support@memoroam.com from your account email address.
Corrections and the 30-day cooldown. Passport name, date of birth, and home country and city can be edited in-app once every 30 days. If you need to correct a genuine error inside that window, email support@memoroam.com and we will fix it; the cooldown never blocks your legal right to rectification.
Email requests. For any request we cannot serve in-app, email support@memoroam.com. We verify requests against your account email address and respond within one month (UK/EEA) or 45 days (California), extendable once where the law allows, with notice.
Complaints. You can complain to the UK Information Commissioner's Office: ico.org.uk, 0303 123 1113, or Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. If you are in the EEA you can complain to your local supervisory authority. You are welcome to contact us first at support@memoroam.com, but you never have to.
12. Children
Memoroam is not for children under 16. You must be at least 16 to create an account, and we ask for your date of birth at signup to check. We do not knowingly hold accounts for anyone under 16; if you believe a child under 16 has an account, email support@memoroam.com and we will delete it.
If you are 16 or 17, note that friend visibility (Section 10.1) is on by default, including your date of birth and gender; you can turn it off in one switch at any time.
13. On-device storage (and why there is no cookie banner)
The app stores data on your device only to make it work: your sign-in token, your settings, convenience state (like recent airports and which sign-in button you last used), cached copies of the app and your own photos for speed, and, if you have used it, the off switch for usage statistics. We set no cookies. The usage counting in Section 3.11 deliberately stores nothing on your device: it sets no cookie, writes nothing to local storage, and cannot recognise you between sessions. Because every piece of on-device storage is strictly necessary for something you asked for (including the off switch, which exists only to honour your objection), no consent banner is required and none is shown.
On Android, standard device backup may include the app's local data as part of your device's Google backup, under your device backup settings.
14. Purchases and payments
Purchases are billed by your app store, never by us. The app offers a paid subscription (the Collector's Pass) and Starlight bundles. Both are bought inside the installed app through Google Play or the Apple App Store, and payment is processed entirely by the store: we never see or store your card details, and no payment details of any kind ever touch our systems. In the browser version of Memoroam nothing can be bought at all.
What we receive about a purchase. To credit what you bought and keep it working, we receive purchase confirmations through RevenueCat (Section 6.1): your account identifier, the product, which store billed it, the transaction identifiers and timestamps, and the subscription's renewal state. That is the full list. Subscriptions are managed and cancelled through your app store, not through Memoroam, and deleting your Memoroam account does not cancel a store subscription; Section 8 explains what happens to purchase records.
15. Changes to this policy
When we change this policy we will publish the updated version in the app and at its public web address, and update the "Last updated" date at the top. We do not promise email notifications, because Memoroam does not send you email at all.
16. Region-specific information
16.1 UK and EEA
Sections 1, 5, 7, 8, and 11 together provide the information required by UK GDPR and EU GDPR Articles 13 and 14: our identity, purposes and lawful bases, recipients, transfers and safeguards, retention, and your rights including complaint. In addition:
- Providing your email address, date of birth, and gender is a contractual requirement to create an account; you are not obliged to provide them, but we cannot open an account without them. All other data is optional.
- We do not carry out automated decision-making or profiling within the meaning of Article 22.
- Memoroam is operated from the United Kingdom and offered in the United Kingdom, the United States, Canada, and Australia. We have not appointed an EU representative under Article 27, because the service is not offered in the EU.
16.2 California
This section supplements the rest of the policy for California residents. We extend these rights to all users, not only Californians.
Categories collected (in the statutory categories), all collected directly from you or generated by your use of the service:
- Identifiers: we collect name, email address, account identifier, friend code, IP address and browser user agent (processed by our hosting providers to serve the app).
- Customer records: we collect home country and city (city-level, typed by you).
- Protected classifications: we collect date of birth, gender.
- Commercial information: we collect trip budgets and expenses you enter; your Starlight ledger; and records of your store purchases and subscription (product, store, timestamps, renewal state), relayed by RevenueCat.
- Audio, visual: we collect photos, portrait, signature image. No audio or video.
- Geolocation: city-level only, entered by you; never precise, never from your device.
- Internet or network activity: first-party feature history (pack opens, streak answers); when you send a support request, a technical snapshot (browser identifier, language, screen size, page address, app version); and the usage counts and crash reports in Section 3.11, held without your identity. No cross-context tracking data.
- Inferences: none. We build no profiles.
- Sensitive personal information: none. Memoroam holds no login credentials: sign-in is delegated to Google or Apple, and we receive only a confirmed email address and an account identifier.
Sale and sharing. We do not sell personal information, we do not share it for cross-context behavioral advertising, and we have not done either in the preceding 12 months. Because there is nothing to opt out of, we do not provide a "Do Not Sell or Share" link. We do not sell or share the personal information of anyone, including consumers under 16. We disclose personal information only to the service providers and recipients listed in Section 6, for the purposes described there.
Sensitive personal information is used only to provide the service, so no "Limit the Use of My Sensitive Personal Information" link is required or provided.
Your California rights: to know and access (Section 11 export and email), to delete (Section 11 deletion paths, with the honest exceptions in Section 8), to correct (Section 11), and to portability (the export ZIP is machine-readable JSON). We will never discriminate against you for exercising any right. Submit requests in-app or to support@memoroam.com; we verify against your account email and respond within 45 days, extendable once by 45 days with notice. Because Memoroam operates exclusively online, email is our designated request channel.
Shine the Light: we disclose no personal information to third parties for their own direct marketing, so no request mechanism is needed.
Questions about anything in this policy: support@memoroam.com.