Effective: 2026-08-27 · Version: 1.1 (memorias-legal-02)
This document is maintained in English. The English version is the legally binding version.
1. Who we are
Memorias the Service is operated by Malenko Rostyslav, registered sole proprietor (ФОП) in Ukraine, tax ID 2604802573, registered address Dniprovs'ka naberezhna 19v, Kyiv 02081, Ukraine.
Contact for privacy questions, account deletion, and data subject access requests: [email protected].
For the purposes of EU and UK GDPR we are the data controller for the personal data you provide directly to us (account, purchase, and support data) and the processor or joint controller for the memoir content you upload (see §4).
We are not required to designate a Data Protection Officer under GDPR Art. 37, but [email protected] is the single point of contact for all data protection matters.
2. What this policy covers
This policy describes:
- What personal data we collect;
- Why we collect it and what we do with it;
- Who we share it with (our sub-processors);
- How long we keep it;
- What rights you have over it and how to exercise them.
It applies to everyone who uses Memorias — website visitors, registered users, and people mentioned in other users' memoirs. If you are a person who has been written about in someone else's memoir and wants to know or change how we handle data about you, jump to §10.
3. Data we collect
Data you provide directly. Your email address and an internal account identifier. If you sign in with Google, we receive your name, email address, and profile picture. If you choose to fill in profile fields: a display name, locale, and timezone.
Payment data. Handled entirely by Paddle (see §6). We receive only a purchase reference and credit-quantity metadata; we never see your full card number, expiry, or CVC.
Content you upload. Audio recordings of your voice describing your memories.
Content you generate. Transcripts, extracted story atoms, chronologies, questions and answers, and generated book drafts — all derived from the audio you upload.
Support correspondence. Emails and messages you send us.
Technical and usage data. IP address, browser type and version, operating system, device type, timestamps of requests, and which features you used or which errors occurred. Retained for a limited period, typically under 30 days, for security and debugging.
Cookies and local storage. Strictly necessary session cookies for authentication and your language preference. We do not use advertising cookies or third-party analytics cookies that profile you across sites.
Your memoir will usually mention other people — family members, friends, colleagues, strangers. These people are data subjects in their own right. When you upload that audio we process personal data about them. See §8 of our Terms of Service (your obligations) and §10 below (their rights).
Memorias recordings often contain information classed as "special category" personal data under GDPR Art. 9 — for example health events, religious beliefs, political opinions, or information about family relationships. We process this data only because you explicitly choose to upload it and give us explicit consent to process it for the purpose of producing your memoir. This consent is the sole legal basis for this processing; you may withdraw it at any time by deleting the affected content or your account (§11).
4. Why we process your data (legal bases)
Under the GDPR and UK GDPR our processing rests on the following lawful bases:
- Creating and maintaining your account — Contract (Art. 6(1)(b));
- Transcribing and generating your memoir — Contract (Art. 6(1)(b)) and explicit consent for special category data (Art. 9(2)(a));
- Processing purchases of Memorias Credits — Contract and legal obligation (tax, accounting), payment data processed by Paddle;
- Fighting abuse, fraud, and keeping the Service secure — Legitimate interest (Art. 6(1)(f));
- Responding to your support messages — Contract and legitimate interest;
- Complying with legal obligations — Legal obligation (Art. 6(1)(c));
- Improving the Service through aggregated, non-profiling analytics — Legitimate interest.
5. How we do not use your data
We want to be specific about things we do not do, because they are common in our industry and users reasonably ask:
- We do not sell your data to anyone.
- We do not share your data with advertisers or data brokers.
- We do not use your content to train artificial intelligence models. Not our own, not third-party. Our AI providers (Anthropic, DeepSeek, OpenAI, Deepgram) contractually restrict use of customer data for training under their commercial API terms.
- We do not currently train, fine-tune, or condition AI models on user content. If we ever decide to do so — for example, to build a Ukrainian-specific memoir style model — we will notify you at least 30 days in advance by email and require your explicit opt-in before using any of your content. You will always be able to decline without losing access to the Service.
- We do not read your memoir recordings ourselves except in narrow, necessary cases — for example, you ask us for support and provide a specific recording, we must investigate a report of abuse or illegal content, or we are required by valid legal process. Internal access is logged.
6. Who we share data with (sub-processors)
To run the Service we use third-party providers. They process your data on our behalf and are bound by contracts that restrict them to the purposes we specify.
- DeepSeek (China) — Standard-tier book-generation language models. International transfer notice: DeepSeek is based in the People's Republic of China, which does not have a European Commission adequacy decision. We rely on contractual safeguards — Standard Contractual Clauses where available — and DeepSeek's commercial API terms, under which customer content is not used for training. This is the one sub-processor relationship that involves a transfer outside the EU/UK's adequacy framework; we call it out explicitly rather than bundling it with the others.
- Anthropic (US) — Premium-tier book-generation language models (Claude), and also the automatic fallback model when a Standard-tier request cannot be completed by DeepSeek. Anthropic can therefore process content from any book, not only Premium-tier ones. Commercial API terms; data not used for training; Standard Contractual Clauses for transfers outside the EEA.
- OpenAI (US) — speech-to-text fallback (used when our primary transcription provider is unavailable) and text embeddings for semantic search over your story atoms. Business API terms; data not used for training; Standard Contractual Clauses.
- Deepgram (US) — primary speech-to-text transcription. Data Processing Agreement; data not used for training; Standard Contractual Clauses.
- Amazon Web Services (AWS) — S3 object storage for audio, transcripts, generated book files, and data exports. The planned production environment will use the Frankfurt, Germany region (eu-central-1); until production launches, development storage remains in us-west-2. CloudFront is the content-delivery network for signed download URLs. AWS Customer Agreement and Data Processing Addendum.
- Hetzner Online GmbH — primary application server and database hosting, Germany (EU). Data Processing Agreement; GDPR-compliant processor located inside the EU.
- Paddle.com Market Limited — Merchant of Record for all purchases; invoicing; VAT and sales tax collection. Paddle DPA; Paddle is the controller for payment data.
- Resend — transactional email delivery (deletion confirmations, low-balance and credit-expiry warnings, audio-retention notices, processing-failure notices). Sending domain memorias.io.
We review this list whenever we add or remove a sub-processor. Material changes will be notified by email where your content is affected.
You can request copies of our international-transfer safeguards at [email protected].
7. How long we keep your data
- Account and profile data — until you close your account, then deleted per §11;
- Audio recordings — until you delete them, until account closure, or 12 months after your last book assembly if you have not purchased Family Archive (see the Terms of Service §5);
- Transcripts and generated content — same as audio, but survive audio deletion so a book can be reassembled;
- Paid transaction records and invoices — up to 7 years with your account identifier removed; Paddle separately retains invoices for 10 years under EU and US tax law;
- Support correspondence — up to 3 years after last contact;
- Application and technical logs — a limited period, typically under 30 days;
- Backups that contain deleted content — overwritten in the normal course of backup rotation.
After the retention period we permanently delete or irreversibly anonymize your data from our primary systems.
8. Where your data is stored
- Production audio, transcripts, and generated books: AWS S3, Frankfurt, Germany (eu-central-1), delivered via AWS CloudFront. Development storage remains in us-west-2 until production launches.
- Structured data (database): Hetzner Cloud, Germany.
- AI processing: happens transiently on Anthropic, DeepSeek, OpenAI, and Deepgram infrastructure (DeepSeek in China; the others in the US); your content is sent, processed, and results returned, with no training and no long-term retention beyond what each provider's terms describe.
- Authentication: our own application infrastructure on Hetzner Cloud, Germany, plus Google's infrastructure if you sign in with Google.
9. Security
We take reasonable technical and organizational measures to protect your data:
- TLS (HTTPS) in transit for all connections;
- Encryption at rest for object storage;
- Access to production systems is limited to the operator and restricted via SSH keys;
- Credentials and API keys are stored as environment variables, not in source code;
- Automated backups;
- Rate limiting and abuse detection on authentication endpoints.
No service is perfectly secure. If a breach occurs that is likely to result in a high risk to your rights, we will notify you within 72 hours of becoming aware of it — a stricter, self-imposed commitment than GDPR Art. 34 requires (which sets no fixed deadline for notifying individuals, only "without undue delay"; the 72-hour clock in GDPR Art. 33 applies to notifying the supervisory authority).
10. Your rights
If you are in the EU, EEA, UK, or any jurisdiction with comparable privacy law, you have the following rights. We honor these rights for all users globally as a matter of policy, even where local law does not require it.
- Right of access. You can request a copy of the personal data we hold about you.
- Right of rectification. You can request that we correct inaccurate data.
- Right of erasure ("right to be forgotten"). You can request that we delete your data. See §11 for how this works.
- Right to restriction. You can request that we pause processing while a dispute is resolved.
- Right to data portability. You can request a machine-readable export of the data you provided to us.
- Right to object. You can object to processing based on legitimate interest.
- Right to withdraw consent. Where we rely on consent, you can withdraw it at any time without affecting the lawfulness of processing that happened before withdrawal.
- Right to lodge a complaint. You can complain to the data protection authority in your country (for Ukraine: the Ukrainian Parliament Commissioner for Human Rights; for the EU: your national DPA; for the UK: the ICO).
How to exercise your rights. Email [email protected] with your request and the email address associated with your account. We do not yet offer a self-service export or deletion flow inside the app — every request is handled by us directly, and we respond within 30 days (extendable by a further 60 days for complex requests, in which case we will tell you). We may ask you to verify your identity before acting on a request.
If you are mentioned in someone else's memoir, you can request that we delete or restrict processing of data about you even if you are not the account holder who uploaded it. Email [email protected] with your name and any other identifying information the memoir might use, a description of the content you believe contains your data, and any context that helps us locate it. We will investigate, notify the account holder, and — where the legal balance weighs in favor of erasure — remove or redact the relevant portions. Certain limited exceptions may apply (for example, journalistic or literary expression protected under GDPR Art. 85).
11. Deletion
You can request deletion of your account or an export of your data by emailing [email protected] from your account address. We do not currently offer an automated, self-service deletion flow inside the app; every request is handled by us directly, and we complete verified deletion requests within 30 days.
When your account is deleted:
- All story atoms, transcripts, Biographical record entries, questions, sessions, and draft books are deleted from our primary database;
- Your audio recordings, transcript files, and generated book files (EPUB, PDF, DOCX) are deleted from storage;
- Any pending AI processing tasks in our queue are canceled.
Certain records are retained after deletion in anonymized form, because law requires it or because they support legitimate auditing of past transactions: transaction records are kept for up to 7 years with your account identifier set to null, for refund and chargeback investigations; paid invoices are held by Paddle (our Merchant of Record) for 10 years under EU and US tax law — Paddle is the controller for this data, contact them directly at https://www.paddle.com/legal/privacy for requests relating to those records.
Backups containing your data are overwritten in the normal course of backup rotation. We do not manually scrub backups — this is industry-standard practice.
12. Children
Memorias is not intended for users under 16. We do not knowingly collect data from anyone under 16. If you believe a child under 16 has created an account, please contact [email protected] and we will delete the account and associated data.
14. California residents (CCPA / CPRA)
If you are a California resident you have additional rights under the California Consumer Privacy Act, as amended by the CPRA:
- The right to know what personal information we have collected;
- The right to delete your personal information;
- The right to correct inaccurate personal information;
- The right to opt out of the sale or sharing of personal information — we do not sell or share personal information as those terms are defined in the CCPA;
- The right to limit the use of sensitive personal information.
To exercise these rights, email [email protected]. We will not discriminate against you for exercising them. The categories of personal information we collect are listed in §3 of this policy.
15. Changes to this policy
We may update this policy. Material changes will be announced by email to the address on your account at least 30 days before they take effect. Non-material changes (typos, clarifications, sub-processor list additions) take effect on publication and are tracked in the version history at the top of this document.
16. Contact
Privacy questions or requests: [email protected].
Operator: Malenko Rostyslav, registered sole proprietor (ФОП) in Ukraine, tax ID 2604802573, registered address Dniprovs'ka naberezhna 19v, Kyiv 02081, Ukraine.
If you are in the EU and believe your rights have been violated, you can also complain to your local data protection authority. A directory is maintained at https://edpb.europa.eu/about-edpb/about-edpb/members_en.