Privacy Policy

Last updated: August 26, 2026

1. Overview

MemoUS ("we," "us") helps parents and caregivers track child development. This Privacy Policy explains what information we collect, how we use it, and your choices — including account deletion. By using MemoUS you also agree to our Terms of Service.

2. Information We Collect

Account information: Email address, display name, authentication identifiers (from email/password, Apple, Google, or Facebook sign-in), and account role (parent or co-parent).

Child profile data: Names, birth dates, and developmental observations you enter — activity logs, wellbeing logs, milestones, memories (text and metadata), and AI-generated profiles and insights.

Usage data: Feature usage counters and app diagnostics needed to operate the service.

Photos: Photos you add are stored in Google Firebase Cloud Storage linked to your account, with local device cache for offline viewing. We do not sell or use your photos for advertising.

Voice notes. Optional Time Capsule voice recordings you add are stored in Google Firebase Cloud Storage linked to your account so they can be played back later (for example on a birthday card). They are not used for advertising.

What we do not collect from children: Children do not create accounts. We do not knowingly collect personal information directly from children under 13. All child-related data is entered by an adult account holder.

3. How We Use Your Information

We do not sell your personal information.

4. AI Processing

When you save memos, observation text and optional voice audio may be processed on our servers by Google Gemini to generate insights and transcriptions. Child first name and age context may be included in prompts. We do not send your account email to Gemini. See Google Gemini Terms.

Voice input. Live voice dictation uses your device's built-in speech recognition where available. Depending on your device settings, this may run on-device or fall back to Apple's or Google's platform speech service to convert speech to text. Separately, if you use the AI transcription option when saving a memo, the recorded audio is sent to Google Gemini as described above. Optional Time Capsule voice notes are stored as audio in Cloud Storage (see above) and are not sent to Gemini unless you also use AI transcription on a memo. Using voice input is always optional.

5. Third-Party Services

MemoUS uses Google Firebase (Authentication, Firestore, Cloud Storage for photos and app data, Cloud Functions) and Google Gemini. Data is processed on Google Cloud infrastructure (including Asia-Pacific regions).

Social sign-in providers (Apple, Google, Facebook) process authentication according to their own privacy policies.

No advertising or product analytics. MemoUS does not use third-party product-analytics or advertising SDKs, does not track you across other apps or websites, and shows no ads. We do not sell or share your personal information with data brokers.

Crash and error reporting. To keep MemoUS stable and diagnose problems, we use Sentry (Functional Software, Inc.) to collect crash and error diagnostics — device model, operating system, and technical error details, associated only with your account identifier. We do not send your photos, notes, or your child's information in these reports. See the Sentry Privacy Policy.

Email delivery. Transactional emails such as password reset and email verification are delivered through Resend (resend.com). Only your email address and the message content are shared for delivery.

6. Purchases & Subscriptions

MemoUS Premium is offered as an in-app subscription through the Apple App Store or Google Play Store. Apple and Google process your payment directly — we never see or store your card details.

We use RevenueCat to manage subscription entitlements. RevenueCat receives a random subscriber identifier tied to your Firebase account (not your email or name), along with purchase and subscription events — product purchased, price, purchase and renewal dates, and subscription status. This lets the app unlock Premium features and lets our servers verify your subscription. See the RevenueCat Privacy Policy.

We do not sell subscription or purchase data, and Premium status does not change how your child's memos, photos, or profile data are used or protected.

7. Co-parent & Family Viewer Sharing

You can invite another parent or caregiver to a child as a co-parent or a family viewer. Both use the same invite flow and per-child access controls; the difference is the permission preset you choose.

You control what an invitee can do, and you can change or revoke their access at any time. Access is scoped per child: inviting someone to one child does not give them access to your other children. Sharing a child's data is always your choice and under your control.

8. Children's Privacy (COPPA)

MemoUS complies with COPPA and applicable children's privacy laws. Parents and caregivers are responsible for the data they enter about children in their care. You may delete child-related data by permanently deleting an archived child on the Home screen (see Section 9), through account deletion (see Section 10), on the web at memous.app/delete-data, or by contacting us.

9. Data Retention

We retain your data while your account is active.

Archive child (Home screen): Hides a child profile from your active list. All memos, photos, Traces, and related records remain stored in your account — archive is a soft hide, not permanent deletion. You can restore an archived child at any time from the Archived Children section on Home.

Permanently delete a child (Home screen): If you are the child's primary parent, you may permanently erase one archived child from the Archived Children section on Home. This immediately and irreversibly deletes that child's profile and all of their server-side data (memos, photos, growth profiles, and related records). There is no 30-day grace period for per-child deletion — it is separate from account deletion below.

When you schedule account deletion, your data is retained during a 30-day grace period so you can cancel. After that period, we permanently delete server-side data as described in Section 10.

10. Account Deletion & Your Rights

You may request permanent deletion of your account and associated data from Profile → Account & preferencesDelete account in the app, or on the web at memous.app/delete-account. This is separate from archiving or permanently deleting an individual child on the Home screen (see Section 9).

Delete account (Profile → Account & preferences): Permanently removes your account and associated data, subject to a 30-day grace period. When you schedule account deletion:

Primary parent: After the grace period, we permanently delete your account and household data from our servers, including child profiles, activity logs, wellbeing logs, memories, milestones, AI profiles, and related records stored in Firebase.

Co-parent only: After the grace period, your account is permanently deleted and your access to the household is removed. The primary parent's household, child profiles, and shared child records are preserved.

Access and data export: You can download a copy of your data at any time from Profile → Account & preferencesExport my data. The export includes your account and child records — memos, memories, wellbeing logs, milestones, life stories, and AI profiles — as a readable report or a JSON file. Photos are provided as secure download links rather than embedded image data.

Limited security retention: When your account is deleted we remove your account, your content, and account operational data (including AI usage counters and diagnostic records). A small number of short-lived anti-abuse records — for example password-reset and email-verification rate-limit counters — may persist briefly and expire automatically. These contain no memos, photos, or child information.

Local photo cache on your device is not removed by server-side account deletion — remove from your device separately if needed.

11. Security

We use industry-standard security through Firebase and Google Cloud, including encrypted transport and access controls. Firestore security rules restrict data access by authenticated user and role. No method of transmission or storage is 100% secure.

Biometric unlock (optional). If you turn on Face ID / Touch ID unlock, MemoUS stores your password on your device using the platform secure keystore (iOS Keychain / Android Keystore) so you can sign back in with biometrics. If the secure keystore is unavailable on your device, the app falls back to its standard on-device app storage, which is protected by your device's operating system but is not additionally encrypted by MemoUS and is less protected. Your password is never stored on our servers in a readable form, and biometric unlock can be turned off at any time.

12. International Users

Data may be processed in regions where Google Cloud operates, including the United States and Asia-Pacific. By using MemoUS you consent to this processing.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes through the app or by email. The "Last updated" date at the top reflects the latest revision.

14. Contact Us

Privacy questions or concerns: privacy@memous.app. We aim to respond within 48 hours.