Privacy Policy
By using our services, you agree to this Privacy Policy. We are registered with the UK Information Commissioner’s Office (ICO) and process personal data in accordance with UK GDPR and the Data Protection Act 2018.
Data Controller
Memorify Technologies Limited is the data controller under UK GDPR Article 4(7).
ICO membership ICO:00012736801
Contact: hello@memorifytech.com
Data We Collect
- Identity & Contact: name, email, username, account details.
- Technical: IP address, browser/device information, session tokens, logs.
- Usage: pages visited, actions taken, timestamps.
- User Content: photos, files, memories, uploaded material.
- Communications: support requests and feedback.
- Marketing Preferences: opt-in / opt-out records.
- Moderation Data: automated detection results, flags, review outcomes, appeals records, enforcement actions.
We do not intentionally collect special category data unless voluntarily included in user content.
How & Why We Use Your Data
We process personal data only where we have a valid lawful basis under applicable data protection law, including the UK GDPR and, where applicable, equivalent international privacy laws.
We use personal data for the following purposes:
A. Providing the Service (Contract)
To:
- create and manage user accounts;
- authenticate users and maintain account security;
- enable uploading, storage, organisation, sharing, and display of memories, photos, and related content;
- generate memory sequences, stories, timelines, and AI-assisted outputs;
- provide subscription features and account management;
- process payments and administer subscriptions.
B. Service Improvement & Platform Operations (Legitimate Interests)
We may process data where necessary for our legitimate interests, provided those interests are not overridden by users’ rights and freedoms. This includes:
- improving platform functionality and performance;
- developing and testing new features;
- troubleshooting, diagnostics, analytics, and debugging;
- detecting spam, fraud, abuse, and security incidents;
- enforcing our terms;
- maintaining platform safety and integrity;
- training moderation systems and improving content classification accuracy using appropriately minimised or aggregated data where possible.
C. AI & Automated Processing
Where users choose to upload content, we may use automated systems, including AI-assisted tools, to:
- analyse uploaded images and metadata;
- identify potential memories, themes, relationships, or events;
- generate captions, stories, summaries, recommendations, or timelines;
- improve memory sequencing and content organisation.
These systems are designed to assist users and improve service functionality. Users remain responsible for reviewing generated outputs.
D. Marketing & Communications (Consent / Soft Opt-In)
Where legally permitted, we may send:
- service-related notices;
- onboarding communications;
- feature updates;
- promotional or marketing messages.
Users may withdraw marketing consent at any time through account settings, unsubscribe links, or by contacting us.
E. Legal & Regulatory Compliance
We may process personal data where necessary to:
- comply with legal obligations;
- respond to lawful requests from regulators or law enforcement;
- establish, exercise, or defend legal claims;
- maintain legally required business and financial records.
We do not use uploaded personal photographs for advertising resale, data brokerage, or commercial sale to third parties.
Image Moderation & Automated Processing
To keep our services safe, lawful, and compliant, uploaded images may be analysed using automated systems designed to detect prohibited content.
This may include:
- Image classification tools.
- Hash matching for known harmful content.
- Risk scoring and flagging.
- Human review where necessary.
Moderation decisions are not intended to produce legal or similarly significant effects under UK GDPR Article 22. Users may contact us to request human review of significant account actions.
We Do Not Sell Your Data
Memorify will never sell, rent, or license your personal data to data brokers, ad networks, or third parties for commercial gain.
When We Share Data
We do not sell users’ personal data.
We may share personal data only where reasonably necessary to operate, secure, improve, or legally protect our services.
Data may be shared with the following categories of recipients:
Service Providers & Processors
We use carefully selected third-party service providers who process data on our behalf under written contractual agreements, including providers of:
- cloud hosting and infrastructure;
- content delivery and storage;
- payment processing;
- analytics and diagnostics;
- customer support systems;
- identity verification and fraud prevention;
- image moderation and safety tools;
- AI-assisted processing services.
These providers may only process personal data in accordance with our instructions and applicable data protection laws.
Linked or Shared Accounts
Where users intentionally use collaborative features, linked accounts, family accounts, or child-profile functionality, certain content and account information may be visible to authorised linked users in accordance with the settings selected by the account holder.
Legal & Regulatory Disclosure
We may disclose information where we reasonably believe disclosure is necessary to:
- comply with applicable law or legal process;
- respond to lawful requests by regulators, courts, or law enforcement agencies;
- investigate fraud, abuse, security incidents, or unlawful activity;
- protect the rights, safety, or property of users, Memorify, or third parties.
Corporate Transactions
If Memorify Technologies Limited is involved in a merger, acquisition, financing, restructuring, asset sale, or insolvency process, personal data may be transferred as part of that transaction, subject to applicable confidentiality and legal safeguards.
With User Consent
We may share data with third parties where users have explicitly requested or consented to such sharing.
We require third-party processors handling personal data to implement appropriate technical and organisational security measures.
International Transfers
We may process or store personal data in the United Kingdom, the European Economic Area (EEA), the United States, and other jurisdictions where our service providers or infrastructure providers operate.
Where personal data is transferred outside the UK or EEA to countries not formally recognised as providing an adequate level of data protection, we implement appropriate safeguards, including:
- UK International Data Transfer Agreements (IDTAs);
- UK-approved International Data Transfer Addenda;
- Standard Contractual Clauses approved by the UK Government or European Commission;
- supplementary technical and organisational safeguards where appropriate.
We assess international data transfers on an ongoing basis and take reasonable steps to ensure that transferred data receives protections that are substantially equivalent to those required under UK data protection law.
By using our services, users acknowledge that their data may be processed in jurisdictions with different data protection laws than their country of residence.
Where required by applicable law, additional regional privacy rights and disclosures may apply to users located outside the UK, including certain US state privacy laws.
Data Retention
- Account data: deleted within 30 days of verified deletion request.
- Technical & usage data: up to 24 months.
- Support correspondence: up to 3 years.
- Financial/legal records: 7 years.
- Moderation logs and enforcement records: up to 6 years where necessary for legal defence, safety, fraud prevention, or repeat-abuse detection.
- Marketing consent records: retained for compliance purposes.
Your Rights Under UK GDPR
You have rights to:
- Access
- Rectification
- Erasure
- Restriction
- Portability
- Object
- Human review of certain automated decisions, where applicable
Contact: hello@memorifytech.com
Marketing
- We only send marketing where consent exists or PECR soft opt-in applies.
- No pre-ticked boxes.
- Unsubscribe anytime via link, settings, or email.
- We do not sell or share your email with any 3rd party services.
Security
We use appropriate technical and organisational security measures, including:
- Encryption in transit and at rest.
- Role-based access controls.
- Least-privilege access.
- Security testing.
- Breach reporting where legally required.
Children
Our services are not directed at under-13s. We do not knowingly collect data from children without appropriate consent where required.
Child profiles may only be created and managed by a parent, guardian, or authorised adult with legal authority to provide data relating to the child.
Complaints
Contact us first: hello@memorifytech.com
You may also complain to the UK ICO: https://www.ico.org.uk
Changes to This Document
Material changes will be notified by email and/or in-app notice at least 30 days before taking effect. Continued use of our services constitutes acceptance of updated terms.
Legal Framework
- UK GDPR, Data Protection Act 2018
- Privacy and Electronic Communications Regulations 2003 (PECR)
- Applicable consumer protection laws in the UK
- ICO Registration Number 00012736801
Memorify Technologies Limited
Company No. 15706080
hello@memorifytech.com