Plain English, as promised.
Memlane is a private record of your own life. This page says exactly what we collect, what happens to it, which companies touch it, how long we keep it, and what we will never do — without a single “heretofore.” Where the honest answer is uncomfortable, it is here anyway. If anything is unclear, write to privacy@memlane.ai and a human will answer.
The short version
- Your data has one reader: you. No ads, no selling or renting data, no “anonymized insights”, and no other user can see into your record. (One narrow exception, which needs both people to opt in, is described below — we would rather name it than claim “never”.)
- Photos are analyzed on our servers, then the originals are deleted. We keep what the photo means, not the photo.
- Face recognition happens on our servers, and what it produces is kept indefinitely. That includes faces of people who are not Memlane users. It is the most sensitive thing we do and it has its own section below.
- AI providers get text drawn from your record — they are named below — never your photo library. Small face crops do go to OpenAI for artwork, including once a year automatically; the AI section says exactly when.
- Every signal is optional, asked for in the app at the moment it’s actually needed, and can be turned off.
- Delete means delete — a 30-day change-of-heart window, then your record is removed. Backups take a few weeks longer to age out, and we say exactly how long below.
What Memlane collects
Memlane composes your record from signals your iPhone already holds. Each one is opt-in, requested inside the app when a feature needs it — never as a wall of permissions on day one. Turning one off stops new data; what was already collected stays until you delete it.
| Signal | What Memlane keeps |
|---|---|
| Photos & video | The files themselves, briefly, while we analyse them — then only what we derived: when and where each was taken, the camera and its settings, what the scene shows, any text visible in the picture, and the faces in it (see below). The originals stay in your photo library. |
| Location | Precise, continuous background location. Memlane records individual GPS fixes — coordinates, altitude, speed, heading and accuracy — throughout the day, and works out the places you visited and how long you stayed. Fixes older than 30 days are thinned to roughly one a minute; the visits themselves are kept indefinitely. |
| Motion | What your phone’s sensors say you were doing — walking, running, cycling, driving, stationary — and floors climbed. |
| Calendar | Event titles, notes, locations, times, your RSVP, and the attendee list, including other people’s names and email addresses as your calendar supplies them. |
| Health | What you allow from HealthKit: steps, distance, energy, exercise, resting heart rate and HRV, VO₂ max, respiratory rate, blood oxygen, body mass and composition, sleep broken down by stage, workouts (including their GPS route), and mindfulness sessions — down to minute-by-minute heart rate. Memlane never writes to Health, and health data is never used for advertising and never sold. |
| Contacts | Phone numbers and email addresses are hashed on your iPhone and only the hashes are sent — we never receive them in readable form. The contact’s name as stored on your phone is sent, so “Maya” can be Maya. If you enable it, contact photos are sent, turned into a face signature, and then discarded. Memlane never messages your contacts. |
| Calls | If you enable it: that a call happened, with whom, and when. Never audio, never content. |
| Music | If you enable it: track titles, artists and timestamps from Apple Music. Never audio, never your account. |
| Journal | Anything you write in Memlane, kept verbatim. |
| Chat with Memlane | Your questions and Memlane’s answers, kept so conversations have continuity — plus a short set of facts Memlane concluded about you from them. |
| Account & device | Your phone number or email, sign-in identity, device push tokens, subscription status, and in-app usage events for diagnostics. |
What happens to your photos
This is the part most services blur, so here it is precisely:
When you import photos, Memlane uploads them to our own infrastructure — this does not happen on your phone — where our vision pipeline reads each one: detecting faces, recognizing the scene, extracting any visible text. Then the original is deleted from our servers. What persists is the derived record: face crops and face signatures, scene tags, extracted text, and the time and place. Your photo library itself lives where it always did — on your iPhone and in your own iCloud.
Memlane keeps the memory, not the picture.
Faces, and why this section is longer
Face recognition is the most sensitive thing Memlane does, so we will not summarise it into comfort.
It runs on our servers, not on your phone. For every face detected in your photos, Memlane creates and keeps permanently:
- a face signature — a list of 512 numbers computed from the face, which is what lets Memlane tell one person from another. Under European law this is biometric data; and
- a face crop — a small 150×150 image of just that face, so you can review and name who Memlane found.
This includes people who are not Memlane users. Anyone appearing in your photographs — friends, family, strangers in the background — gets a signature and a crop, because there is no way to recognise the people you care about without first processing every face in the frame. Those people have no Memlane account and we have no way to ask them. You should know that, because it was you, not us, who chose to photograph them.
Face signatures and crops are not deleted on a schedule. They live until you reset your face data (Settings → Faces), delete the person, or delete your account — at which point both the database rows and the stored crops are erased.
Our written retention and destruction schedule for face data
Illinois law requires anyone holding biometric identifiers to publish one, so here it is, and it is the schedule we actually run:
- What starts collection. Sharing your photo and video library with Memlane. Recognising the same person across your photographs is one of the things Memlane does with the library you share, and it begins when you grant that access — there is no separate switch to turn it on. We only ever process photos and videos you have chosen to share with us; we never reach anything you have not.
- How to stop it, and erase what exists. Reset your face data at any time in Settings → Faces. That erases the signatures and the crops themselves, not just the names attached to them. You can also revoke Memlane's photo access in iOS Settings, which stops any further collection. Everything else about a photo (place, date, what is in it) keeps working either way.
- Retention period. We keep face signatures and crops for as long as you keep the account, because recognising the same person across twenty years of photographs is the purpose you enabled them for. They are not kept for any other purpose.
- Destruction triggers. Whichever comes first: you reset face data in Settings → Faces; or you delete your account. In each case both the database rows and the stored crop files are erased — not unlinked, erased.
- Timing. Immediately on the reset. On account deletion, at the end of the 30-day recovery window, along with everything else.
- Backups. Encrypted database backups can still contain face signatures for up to 90 days after deletion, because a backup you can selectively edit is not a backup. They are destroyed as those backups age out.
- We never sell, lease, trade or profit from face data, and we do not disclose it except as described in the AI section below.
Face crops are also sent to OpenAI to generate cover art and trip posters. Trip posters happen when you tap; cover art can be triggered by you and is also regenerated automatically once a year, for every eligible person in your record — including those who are not Memlane users. The AI section below has the detail.
Which companies see your data
Memlane runs on other people’s infrastructure, as everything does. These are all of them. Each processes your data only to provide its part of the service.
| Company | What it receives |
|---|---|
| OpenAI (primary), Google and xAI (fallbacks) | Text drawn from your record — “dinner with Maya at a ramen bar, third visit this month” — so Memlane can write captions, answers and essays. This includes health figures when you ask a health question. Never your photo library. They act as processors and do not use your data to train their models. |
| Anthropic | Only if you connect your own Claude subscription. Those requests then run under your account with Anthropic, under your agreement with them. |
| Cloudflare (R2 storage) | Your uploaded photos and videos while they are being processed, the permanent face crops, generated artwork, and our encrypted database backups. |
| Modal | Runs the vision pipeline: reads your uploaded photos, detects faces, computes face signatures, tags scenes, extracts text. It has direct access to the Memlane database for this purpose. |
| Apple | Maps (your coordinates, to turn them into place names), push notifications (the device token and the notification text), Sign in with Apple, and App Store subscription verification. |
| Google Places and HERE | Your coordinates, to identify which venue you were at. |
| Open-Meteo | Coordinates and dates, to find the weather on a past day. |
| Twilio | Your phone number, to send sign-in codes. |
| Resend | Your email address and the message, to send sign-in links and the weekly email. |
| Sentry | Error and performance reports. We strip personal data — emails, phone numbers, coordinates, credentials and query contents — before anything is sent. Your account’s internal id and the location in our code are kept so we can fix the bug. |
| Our hosting provider | The server Memlane runs on: the database, the application, and your avatar and export files. |
What reaches AI providers
Almost all of it is text drawn from your record — never your photo library, and never another user’s data.
Images do go to OpenAI in three cases, and in one of them it happens without you doing anything. What is sent is never an original photograph from your library — it is the small face crops Memlane already made, or an image you chose:
- When you attach an image to a chat message, that image goes to the model answering you.
- When you tap to create a trip poster, a collage built from the face crops of the people on that trip is sent to generate the artwork.
- Cover art for the people in your record is made from a collage of 25 of that person’s face crops. You can trigger it yourself — and once a year, on 31 December, Memlane also regenerates every eligible person’s cover art automatically. That yearly pass is not something you start, and it includes people who are not Memlane users.
We would rather write this down than describe the whole thing as something you always choose.
If you connect your own ChatGPT or Claude subscription, these requests run under your own account with that provider, governed by your agreement with them.
Other people’s data, and the one shared path
Your record contains other people: faces in your photographs, names from your contacts, attendees on your calendar. It is scoped to your account at every layer, and no other user can read it.
There is exactly one place where a computation crosses between two accounts, and it requires both people to have turned it on and to be connected to each other. When that is true, Memlane may compare a face in one person’s photos against the other’s in order to suggest a name. What crosses is a single similarity number — never a face signature, never a crop, never a name or a photograph. Either person turning it off, or disconnecting, ends it and removes what it produced.
We describe this in detail rather than writing “no cross-user access, ever”, which is the sentence this page used to carry and which stopped being exactly true.
What we never do
- No advertising, and no data ever sold, rented, or shared for marketing.
- No training of general-purpose AI models on your data.
- No reading your data out of curiosity — access to production data is restricted to operating and debugging the service.
- No dark-pattern retention: leaving Memlane is one screen, not a phone call.
How long things are kept
Your memories are kept until you delete them — that is the product. A few things expire on their own:
- Uploaded photos and videos: deleted as soon as they are processed, with an automatic 7-day sweep as a backstop.
- Face signatures and crops: kept indefinitely, until you reset or delete (see above).
- Location fixes: thinned to about one a minute after 30 days. The visits are kept indefinitely.
- Notifications: removed 90 days after you read them, or 365 days if unread.
- Shared links: deleted 7 days after the expiry you chose. Encrypted photos behind a share are removed after 72 hours.
- Data exports: the download expires after 7 days.
- Undo history for face edits: 30 days.
- Operational and diagnostic logs: error and AI-cost logs 90 days; notification and app-usage analytics 180 days; interaction records 365 days.
Backups. We take an encrypted backup of the database every day. Daily backups are kept for 30 days and weekly snapshots for about 12 weeks, with copies stored off the main server. So after you delete your account your data is gone from the live service immediately, but persists in backups for at least those windows before ageing out. Backups are only ever used to restore the service after a failure — never to look someone up.
Where your data lives, and how it is protected
Your record is stored on servers Memlane operates, with photo analysis running on infrastructure we control — not on third-party photo services. Everything is encrypted in transit between your phone, our servers, and every company named above.
Being straight with you about the rest: the database itself is not separately encrypted at rest beyond the protections our hosting and storage providers apply at the disk and object level. Connected accounts’ access tokens are individually encrypted, database backups are encrypted, and photos behind a shared link are encrypted such that we cannot read them. Access to production is restricted to operating the service.
Your rights and how to use them
Depending on where you live you may have the right to access, correct, delete, export or restrict your data, to object to processing, and to complain to a data-protection authority. You can exercise the main ones yourself, immediately, without asking us:
- See and correct it: the whole app is your record — rename places, fix people, hide anything.
- Export it: Settings → Your Data → Export. You get a ZIP of everything Memlane holds, with a manifest listing exactly what is and is not included, and why.
- Delete it: Settings → Your Data → Delete Account. You have 30 days to change your mind. After that it is permanent: the database record, the face signatures and the stored crops are all erased, subject to the backup windows above.
- Turn any signal off at any time in iOS Settings or in the app; Memlane keeps working with whatever you leave on.
- Ask us anything at privacy@memlane.ai, including for data the export does not cover. We answer within 30 days.
Memlane is not for children. You must be at least 13 to hold an account — see the Terms of Service.
Changes
As Memlane grows this policy will be updated and re-dated here, and material changes will be called out in the app — never slipped in quietly. We record which version of this policy your account was created under, so that “what was I shown?” has a real answer. This is version 2026-08-30.
Found a security problem? memlane.ai/security.