Last updated: September 2026
This Privacy Policy explains how Memorist (“Memorist,” “we,” “our,” or “us”) collects, uses, stores, and protects your information. By using the Memorist app (“App”), you agree to the practices described in this Privacy Policy.
Memorist is a private journaling and reflection tool. Your entries, prompts, photos, and relationship notes are personal and private by default. They are never shared publicly. If you choose to use Shared Entries, you can show a specific entry to people you have connected with; nothing is shared with another person unless you choose it (see Section 3.2).
Memorist is free to use. You can get started in Guest Mode without creating an account, or create a free account for the full core experience. An optional Subscription is available to unlock advanced features (see Section 1.4 for the current list). This Privacy Policy applies equally to all users regardless of tier. Where data practices differ, we note them explicitly below.
1. Information We Collect
We collect the minimum information necessary to operate the App, protect your data, and improve functionality.
1.1 Account Information
Sign in with Apple: To create a Memorist account, you sign in with your Apple ID using Sign in with Apple. This is the only method for creating new accounts.
When you sign in with Apple, we receive:
- An Apple ID user identifier token (used to authenticate your identity),
- An email address provided by Apple (either your real email or an Apple Private Relay address if you chose “Hide My Email”).
How authentication works: Your Apple ID token is passed to Firebase Authentication (provided by Google), which serves as our backend identity and session management layer. Firebase Auth validates your Apple ID token, creates and manages your user identity, and issues your session. The data flow is: Apple (identity provider) → Firebase Auth (identity and session management) → Firestore (user profile storage).
We store the Apple-provided email address in your user profile for account identification purposes only. We do not use it for marketing, advertising, or communications. If you chose “Hide My Email,” the stored address is a private relay address controlled by Apple (e.g., abc123@privaterelay.appleid.com).
Unified identity: Because Memorist uses Sign in with Apple for authentication and Apple’s iCloud Keychain for encryption key storage, your sign-in identity and your encryption key identity are unified under the same Apple ID. This eliminates the need for separate identity systems and simplifies your security posture. See Section 5 for details on encryption.
Legacy phone authentication: Before March 2026, Memorist used phone number verification (SMS one-time password) for account creation. If you created your account using phone verification before March 2026, your phone number may still be associated with your account. You can still sign in with your phone number, but you must link an Apple ID before you can continue using the App. New accounts require Sign in with Apple, and new phone numbers are not accepted. If the Apple ID you link is already attached to a different Memorist account, linking removes that other account so the Apple ID can be attached to your original account.
Guest Mode: You may begin using Memorist without creating an account. In Guest Mode, we do not collect an Apple ID, email address, or any personally identifiable information. Your session is anonymous, identified only by a randomly generated, app-specific identifier (not a hardware or advertising identifier). Guest Mode includes up to 30 items created in total (including event entries, daily journal entries, and photos); deleting an item does not reset this count. To continue beyond this point, you will need to create a free account by signing in with your Apple ID. When you do, your existing Guest Mode data is automatically preserved and linked to your new account.
Age verification: When you create an account, you confirm that you are 13 years or older. Apple requires users to be at least 13 years old to have an Apple ID in most regions, which aligns with Memorist’s age requirement and provides an additional verification layer. We do not collect government-issued identification or perform independent age verification beyond Apple’s own policies and user attestation at account creation.
1.2 User-Generated Content
The personal content you create in the App (“Content”) includes:
- Logs (a single unified entry that may hold text, photos, moods, tags, people, a location, a schedule, and body, wine, or Calm details; Logs are replacing the separate entry types below as accounts are updated),
- Event entries (moments associated with a specific date and time),
- Daily journal entries (reflections associated with a day, including moods, highlights, challenges, gratitude, and daily intentions),
- Body check-ins (weight and measurements you log over time),
- Wine entries (tastings and bottles you log over time),
- Calm entries (meditation and breathwork sessions you log over time, including session duration, optional technique, and any notes you add),
- Photos attached to event entries (up to 1 photo per event entry in Guest Mode and Free tier; up to 10 photos per event entry with an active subscription),
- written reflections and notes on any of the above,
- relationship Tempo™ settings,
- tags for People, Places, or Things, including details you add to a tag (for a person: names, birthday, anniversary, relationship, mobile number, and photo; for a place: its saved location),
- metadata associated with the above (dates, timestamps).
Importing from Contacts: If you grant the App access to your Contacts and choose people to import, we save the names, nickname, birthday, anniversary, relationship label, one mobile number, and photo of each person you select as a People tag. Other contact details (such as email addresses and other phone numbers) are shown during review but not saved. Imported names, dates, and numbers are end-to-end encrypted; a person’s photo and relationship type are not (see Section 5).
We may introduce additional content types in the future. Any new type is subject to the same end-to-end encryption and privacy protections described in this Policy. If a new type involves materially different data practices, we will update this Policy and notify you as described in Section 16.
Some content you log — for example, body check-ins — may relate to your health. You decide what to record, and because the content of what you write is end-to-end encrypted (see Section 5), Memorist cannot read it and does not use it for any purpose beyond the storage and sync features described in this Policy.
You retain ownership of your content.
We process this information solely to:
- operate core app features,
- sync data across devices,
- provide reminders or internal insights (e.g., relationship cadence),
- support backups.
Important: What you write is protected by end-to-end encryption (E2EE). Section 5 lists exactly what is encrypted, the limited metadata that is not, and the opt-in features that create readable copies.
AI-derived content: When you turn on Memorist’s optional AI features, the App also creates content derived from your entries — Reflections and Memory Beliefs. These are described in Section 1.5, and how they are processed is described in Section 11.
1.3 Device & Technical Data
Automatically collected in limited form to improve reliability:
- device model and OS version,
- app version,
- diagnostics and crash logs,
- performance metrics.
The App never requests access to your device’s location. We do not collect precise location unless you voluntarily enter it as part of an entry or tag (for example, by saving a Place tag’s location, which is end-to-end encrypted).
Crash reporting: We use Firebase Crashlytics (provided by Google) to detect and fix app crashes. Crash reports do not contain your journal content. Crash reporting runs in all release builds and is not controlled by the analytics setting.
Analytics metadata: When analytics is enabled (you can disable it in Settings), we collect usage information such as which screens you visit and which features you use. When you are signed in (including in Guest Mode), these events are linked to your account identifier. We do not collect the text of your entries, events, or AI-generated content. See Section 10 for details about analytics and your control over it.
What we cannot see: What you write is protected by end-to-end encryption. See Section 5 for a complete breakdown of what is encrypted versus what metadata we can read.
1.4 Subscription and Payment Data
Memorist subscriptions are managed via Apple’s App Store.
We do not receive or store:
- full billing information,
- payment card numbers,
- Apple ID passwords or account credentials (we receive only authentication tokens and an email address via Sign in with Apple; see Section 1.1).
We receive your subscription status (active, expired, plan tier) to activate features.
Service tiers:
- Guest Mode: No account or payment required. Core features with limits described in Section 1.1.
- Free tier: Account required (Sign in with Apple). No payment required. Unlimited entries with core features, including Shared Entries (Section 3.2), which requires an account but not a subscription.
- Subscription: Optional. Unlocks advanced features (currently including additional photos per entry, optional AI-generated Reflections and a personal Memory (see Section 11), calendar export, data export for backup, usage stats, photo panorama, and additional entry templates such as body check-ins, wine entries, and Calm entries). Unlimited entries are available to all account holders, including the free tier, and are not a subscription feature. Features available under the subscription may change over time; the current feature set is shown in the App Store listing and in the in-app subscription screen.
Subscription details:
- Subscription pricing is displayed in the App Store and may vary by region
- A free trial period may be available for new subscribers, as shown in the App Store at the time of purchase
- Billing and trial management are handled entirely by Apple through your Apple ID
- Cancel anytime via App Store settings
1.5 AI-Derived Content: Reflections and Memory Beliefs
When you turn on Memorist’s optional AI features (see Section 11), the App creates two kinds of AI-derived content from what you’ve written:
- Reflections — short, AI-written observations drawn from your entries. These include a weekly reflection (a synthesis of your past week) and, when enabled, as-it-happens reflections that surface when something in your writing seems worth noticing. Reflections are prose you read; they are observational, not advice.
- Memory Beliefs — a durable, structured model of you, inferred from your entries. Each belief is sorted into a type (for example: identity, fact, goal, preference, relationship, boundary, project, or context). Beliefs are how the App remembers what matters to you over time.
These are inferences, not things you wrote directly, and you stay in control of them. For any belief you can Keep, Remove, Edit it into your own words, Freeze it so it can’t be rewritten or fade, or Hide it. Anything you keep, correct, or freeze cannot be silently overwritten by the model.
Sensitivity and automatic hiding. Every belief carries a sensitivity rating. Because beliefs are drawn from a personal journal, some touch sensitive subjects such as health or therapy; beliefs like these are rated as private and hidden automatically the moment they are formed, before you’ve even reviewed them.
Where hidden beliefs can and cannot go. A hidden belief is never synced to our servers, never included in cloud backup or export, never added to Spotlight, never copied for connected apps under External Access, and never used to write Ask Me questions. These exclusions are enforced automatically by the App rather than left to the AI’s judgment. To keep your Memory accurate, however, the AI model you have selected reads all of your beliefs — including hidden ones — when it updates, combines, or reorganizes them. Depending on your model, that happens on your device, on Apple’s Private Cloud Compute, or, if you have connected your own Anthropic or OpenAI account, with that provider (see Section 11). A belief that was synced before you hid it may keep its earlier encrypted copy on our servers, which we cannot read.
How this content is stored. Reflections and belief text — along with the entries they draw on — are protected by the same end-to-end encryption as the rest of your Content (see Section 5). Your non-hidden beliefs, the links between them, a belief’s history, and your weekly reflections are synced to our servers as encrypted ciphertext so they can be restored on a new device; we can read only their identifiers, timestamps, format version, the week a reflection covers, and which AI engine produced it. When you remove a belief, we keep an encrypted one-way fingerprint of it so it isn’t learned again. We cannot read your reflections or your beliefs — with exceptions you control: if you turn on External Access (Section 11), Memorist places a readable copy of your shareable, non-private beliefs on its servers so a connected app can be served; and if you allow Spotlight (Section 11), a readable copy of your non-hidden beliefs is kept in your iPhone’s on-device search index.
How it changes over time. Beliefs are not permanent. A belief’s prominence fades over time if nothing in your entries keeps reinforcing it, and a belief can be superseded by a newer, sharper one. You can freeze a belief to stop this.
For how this content is generated — including when processing happens on your device, on Apple’s Private Cloud Compute, or (only if you explicitly enable it) via a third-party AI provider — see Section 11.
2. How We Use Your Information
We use your data only to provide you with a secure and meaningful journaling experience.
Specifically, we use it to:
- Create and manage your account (or anonymous session in Guest Mode)
- Sync and store your personal entries and media
- Provide relationship Tempo reminders
- Support app stability and performance
- Communicate with you about updates or system notices
- Maintain account security
- Detect fraud or suspicious activity
- Apply tier-based feature availability (e.g., entry limits in Guest Mode, photo limits per tier)
We do not:
- Sell your data
- Use your entries to train public AI models
- Share journal content with advertisers
- Publish anything you write
- Display your content publicly
Subscription features and data implications: Certain advanced features are available only with an active subscription. The current list is shown in the in-app subscription screen and in the App Store listing. Subscription-only features that have distinct data implications are described below.
Push notifications: When you enable push notifications, we collect a device token (via Firebase Cloud Messaging and Apple Push Notification service) and your notification preferences. If you disable notifications, we stop delivering them and may delete the associated device token and preferences. Push notifications are available to all users. Notifications sent from our servers use generic wording (for example, “You have a private notification”) and never contain your content.
Notifications created on your device: Some notifications are created by the App on your own device rather than sent from our servers — for example, your weekly reflection and the Ask Me reminder. These can show the full text of your weekly reflection or the Ask Me question, and may appear on your Lock Screen depending on your iPhone’s notification settings.
Notification records: The App keeps an in-app notification inbox, stored on our servers. Each record holds its type, timestamps, read state, links to the item it refers to, and simple counts or date ranges (for example, “Weekly reflection” and the week it covers). Notifications about Shared Entries also include the other person’s display name and, for reactions, the reaction. These records are readable to us and are kept until you delete your account.
The Stats feature is available only to subscribers. Stats do not introduce any new data collection. Stats processing happens entirely on your device, using your existing encrypted content and queryable metadata (see Section 5). No Stats data is sent to our servers.
Analytics in Guest Mode: Guest Mode users are subject to the same analytics controls as account holders, and their analytics are linked to their anonymous Guest Mode identifier. Analytics may be enabled or disabled in Settings. See Section 10 for full details, including what the setting does and does not stop.
3. Sharing Your Data
We do not sell, trade, or position your personal data for marketing purposes.
We may share limited information:
3.1 Service Providers
To deliver App functionality securely, we work with the following service providers:
Firebase (Google LLC)
- Authentication (validates Sign in with Apple tokens, manages user identity and sessions; phone number verification for legacy accounts created before March 2026)
- Cloud storage (Firestore database)
- File storage (Firebase Storage for encrypted entry photos, and for People tag and profile photos, which are not end-to-end encrypted)
- Analytics (Firebase Analytics / Google Analytics 4; optional, can be disabled in Settings)
- Crash reporting (Firebase Crashlytics)
- Cloud messaging (push notifications via Firebase Cloud Messaging)
- App security (Firebase App Check with Apple DeviceCheck)
- Backend functions (Firebase Cloud Functions and scheduled jobs)
- Web hosting (Firebase Hosting, which serves the Shared Entries invite page, the Calendar Feed, and the External Access connection service)
Google Cloud (Google LLC)
- Data warehouse (Google BigQuery, United States), which holds a copy of the metadata we can already read about your entries — alongside their encrypted contents, which we cannot read — and of analytics events, used to understand how the App is used (see Section 10)
Apple Inc.
- Sign in with Apple (identity provider and authentication)
- Subscription management (StoreKit 2)
- Payment processing (App Store)
- Push notification delivery (Apple Push Notification service)
- Encryption key synchronization (iCloud Keychain)
- Device attestation (DeviceCheck)
- Place search (Apple Maps): when you search for a place to save on a Place tag, the text you type is sent to Apple
- Apple Intelligence and Private Cloud Compute (optional AI processing; see Section 11)
- Siri, Spotlight, and Shortcuts (on-device system features you control; see Section 11)
How authentication works: Apple acts as the identity provider via Sign in with Apple. When you sign in, Apple provides an authentication token to Firebase Auth (Google), which validates the token, creates and manages your user identity, and issues your session. Firebase Auth serves as an intermediary identity and session management layer — it does not independently verify your identity. Your user profile (including your Apple-provided email address) is then stored in Firestore.
Important: These providers are bound by confidentiality agreements and can only process data on our behalf. What you write is stored as encrypted ciphertext; Section 5 lists the metadata and opt-in copies that are not.
Optional AI connections you control: Two separate, opt-in features can move data outside Memorist. They are independent of each other, and both are off by default:
- Third-party AI model: if you connect Anthropic’s Claude or OpenAI with your own API key, the content needed to generate a reflection or belief is sent from your device directly to that provider, under your own account and their terms.
- External Access (Connected Apps): if you authorize an outside app to read your memory, it reads a consent-filtered copy of your shareable beliefs that Memorist hosts on its own servers. This does not require a third-party AI provider or an API key, and your entries are never shared this way.
See Section 11 for details on both.
3.2 People You Choose to Share With (Shared Entries)
Shared Entries lets you show a specific entry to someone you have connected with. It requires a free account (it is not available in Guest Mode) and is not a subscription feature. Nothing is shared unless you choose to share it. There is no public posting, feed, followers, or directory.
Connecting. You connect with someone by sending them an invite link or code yourself (for example, through Messages). An invite can be used once and expires after 7 days. The invite web page shows no information about you; after the other person opens the invite in the App, they see your display name and profile photo before accepting. Invite links you send through other apps are handled under those apps’ terms.
What a recipient sees. The people you share an entry with can read it in their App, including its photos, moods, people, tags, location, any place attached to it (including a saved address and map location), and, if the entry answers an Ask Me question, that question. They see edits you make while it is shared, and they can find it in their own search. Sharing a repeating entry shares every occurrence of it, past and future, until you stop sharing it.
How it stays encrypted. When you share an entry, your device encrypts a copy of that entry’s key (and its photos’ keys) for each recipient. Recipients can read that entry; Memorist still cannot read its contents. Your encryption keys are never sent to our servers in a form we can read, and sharing one entry gives no access to any other entry.
What we can read. To deliver shares and notifications, we store the following in readable form:
- who you are connected with, and each connection’s display name, profile photo, and public sharing key;
- which entries are shared with whom, the entry’s date and scheduling details, and when it was shared;
- invites (a random code, your display name and photo, and when it was created, expires, and was used);
- reactions (yes or no) and their totals;
- people you have muted; and
- technical delivery records, such as a marker that a shared entry could not be opened.
Your profile photo is stored without encryption and can be viewed by anyone who has its link.
Notifications to other people. When you share an entry, accept an invite, or react, the other person receives an in-app notification that shows your display name, the day of the entry, and any reaction — never the entry’s contents. The push notification that reaches their device says only that they have a private notification.
Your controls. You can stop sharing an entry, mute a connection, or remove a connection at any time. Stopping a share removes the entry from the recipient’s App without notifying them. Removing a connection ends sharing in both directions and deletes reactions. Stopping a share cannot undo what the recipient has already seen, noted, or captured (for example, with a screenshot), and a notification they already received may remain in their inbox.
Kept out of Memory. Entries other people share with you are never used to build your Memory or by any AI feature.
3.3 Legal Compliance
We may disclose information if required by law, court order, or governmental request, but only to the extent legally necessary.
4. Data Storage and Security
We take reasonable technical and organizational steps to protect your information.
End-to-end encryption is a core design principle of Memorist, not an optional feature.
Examples may include:
- encryption in transit (TLS/HTTPS),
- encryption in storage (AES-GCM),
- access controls,
- secure backups.
End-to-end encryption (E2EE): What you write is encrypted on your device before syncing to our servers, and we cannot read it. Some metadata, and readable copies created by opt-in features you control, are exceptions; Section 5 lists them in full.
No method of digital storage or transmission is 100% secure. You use the App at your own risk.
5. End-to-End Encryption
Your journals, events, and entry photos are encrypted so only you — and anyone you choose to share a specific entry with — can read them. Not even Memorist.
Memorist uses industry-standard end-to-end encryption (E2EE) to protect your content. What you write is encrypted on your device before it leaves your hands, and only you hold the encryption keys. This section also lists, in full, the metadata we can read and the opt-in features that create readable copies.
Unified identity: With Sign in with Apple, your authentication identity and your encryption key storage are now unified under the same Apple ID. Your sign-in is handled by Apple, and your encryption keys are stored in Apple’s iCloud Keychain — both tied to the same Apple ID. This eliminates the previous separation between your sign-in identity and your encryption key identity, simplifying your security posture and reducing the risk of identity mismatch.
What makes E2EE different
Most apps say “encrypted” but mean they encrypt your data on their servers — where they still hold the keys and can technically read your content.
With E2EE:
- We never have access to your encryption keys or the readable content of your data
- What we store on our servers is encrypted ciphertext — meaningless bytes without your personal encryption key
- No one else can access your content — not our staff, not hackers, not governments (unless they have your device and passcode)
What is encrypted
Fully encrypted (unreadable to us):
- Logs: Text, moods, body, wine, and Calm details, location, people, tag names, attached places, whether the Log is marked private, and any Ask Me question it answers
- Daily journal entries: Full text including moods, highlights, challenges, gratitude, and daily intentions
- Event descriptions and notes: What you write about each event
- Body check-ins: Weight, measurements, and any notes you log
- Wine entries: Tasting notes, bottle details, and any other fields you record
- Calm entries: Meditation and breathwork session details, including session durations, technique selections, and any notes you record
- Location names: Where events take place
- People’s names: Names mentioned in events
- Tag names: Names of your People, Place, and Thing tags (see the exceptions for older records below)
- Person details on tags: Full name, nickname, aliases, birthday, anniversary, date first met, date of passing, mobile number, and linked Shared Entries connection (on tags created or edited since July 2026; see below)
- Place locations: The address and map location saved on a Place tag
- Entry photos: Encrypted before upload to Firebase Storage (ciphertext stored)
- Redaction flags: Whether an entry is marked private or as not having happened (see the exception for older events below)
These are stored in encrypted envelopes (labeled enc in our database). Without your encryption key, they are meaningless bytes.
AI-derived content (Reflections and Memory Beliefs): Your weekly reflections, non-hidden beliefs, the links between beliefs, and belief history are synced to our servers as encrypted ciphertext so they can be restored on a new device. Hidden beliefs are not synced. We cannot read any of this content. See Sections 1.5 and 11.
What is NOT encrypted (queryable metadata)
Even with E2EE, we store some metadata in queryable form to enable core app functionality. This metadata does not contain what you write, but it does reveal patterns about your usage.
Account information:
- Your Apple ID identifier and Apple-provided email address (authentication) — for users who sign in with Apple
- Your phone number (authentication) — for legacy users who created accounts before March 2026
- Apple migration status (whether your Apple ID has been linked to your account)
- Account creation date
- Last sign-in date
- Account update status (whether, and how far, your account has been converted to Logs)
Log metadata (for timeline sorting and scheduling):
- Date, scheduled time, all-day flag, duration, and timezone
- Creation and update timestamps, and format version
- Recurrence pattern, series identifiers, and skipped-date markers (for repeating Logs)
- How the Log was created (for example, from an import), when not created manually
- Tag associations via UUID
- Photo metadata (see below)
- Soft-delete markers
Event metadata (for timeline sorting and recurrence):
- Event date and time (timestamp)
- All-day flag
- Duration
- Timezone
- Creation and update timestamps
- Recurrence pattern (daily, weekly, monthly, yearly)
- Series and exception markers (for recurring events)
- Soft-delete markers
- On some events created before Logs, whether the event is marked private or as not having happened
Entry metadata (for daily journal sorting):
- Entry date
- Creation and update timestamps
- Soft-delete markers
Photo metadata:
- Photo URLs (ciphertext stored in Firebase Storage)
- Thumbnail URLs
- Encrypted blob headers (needed for decryption)
Tag metadata:
- Tag type classification (Person, Place, or Thing)
- Usage statistics (count, creation, update, and deletion dates)
- Tag associations via UUID (which events/entries use which tags)
- Your Tempo™ setting for a tag (for example, “every month”), and the date and source of your most recent interaction with it, so reminders can be scheduled
- For People tags: the relationship type (for example, friend or family), and whether the person is marked as having passed away (used to stop reminders)
People tag photos: A photo you add to a People tag, including one imported from Contacts, is stored in Firebase Storage without end-to-end encryption.
Important: On records created since July 2026, tag names are encrypted and we store only UUID references that link tags to content. An attacker with access to our database could see “Event A uses Tag B” but not what Tag B’s name is. Exceptions: tag names are still stored readably on body check-ins, wine entries, and Calm entries created with the older editors; on some records created before July 2026; and, rarely, when a tag cannot be matched to its identifier. Person details on tags created before July 2026 may remain readable until the tag is next edited, when they are encrypted.
Calm metadata (for activity-stream pattern detection):
- Entry date
- Creation and update timestamps
- Soft-delete markers
- An
activitiesdiscriminator (a small label of eithermeditationorbreathwork, or both, indicating which activity types the entry contains) — used to route the encrypted record into the correct stream for pattern detection without decrypting the contents
Important: Calm session details — durations, technique selections, and notes — are fully encrypted. The activities discriminator only indicates that an entry contains a meditation or breathwork session; it does not reveal how long the session was, what technique was used, or anything you wrote about it.
AI-derived content metadata: For synced beliefs and weekly reflections, their identifiers, timestamps, format version, the week a reflection covers, and which AI engine produced it.
Notification records and sharing records: See Section 2 (notification records) and Section 3.2 (Shared Entries).
Can metadata be used to reconstruct your content?
No. The queryable metadata we store (timestamps, recurrence patterns, tag UUIDs) cannot be used to reconstruct your journal entries, event descriptions, or other writing. Here’s why:
- Timestamps tell us when you created something, not what it says
- Recurrence patterns tell us an event repeats, not what the event is about
- Tag UUIDs are random identifiers that link to encrypted tag names—without the encryption key, they’re meaningless
Without your encryption key (stored in your iCloud Keychain), all content remains permanently unreadable ciphertext.
What we explicitly do NOT store:
- Journal entry content (fully encrypted)
- Event descriptions and notes (fully encrypted)
- Location names and saved place locations (fully encrypted)
- People’s names in events (fully encrypted)
- Tag names (encrypted, except on the older records described above)
- Your writing in readable form, except in the opt-in copies described below
Why this metadata is necessary:
- Timeline sorting requires timestamps
- Recurrence projection requires pattern information
- Multi-device sync requires update timestamps
- Tag library requires usage statistics
This is the trade-off of a functional E2EE journaling app: we need minimal metadata to provide features like timeline sorting and recurring events, but we never have access to what you actually write.
Important exception: Calendar Feed (optional export)
The Calendar Feed is available only with an active subscription. It is visible in Settings for all users but enabled only for subscribers. If you are a subscriber and enable the Calendar Feed (Settings → Calendar Feed), you are explicitly choosing to create a plaintext export of your Events for use with third-party calendar apps like Apple Calendar or Google Calendar. This feature does not change how your data is encrypted — it creates an additional plaintext copy specifically for calendar app compatibility.
Why plaintext? Third-party calendar apps cannot decrypt E2EE content. So when you enable this feature, you’re trading E2EE protection for calendar app compatibility.
How it works: While the Calendar Feed is on, your device writes a readable copy of each included event’s title, description, location, times, and repeat rule to our servers, and we serve it at a private web address (a link containing a secret code). Anyone who has that link can read the feed, so treat it like a password. The feed covers events from 90 days in the past to 12 months ahead. You can turn the feed off, or revoke its link, at any time.
What gets exported:
- Scheduled event entries only — daily journal entries are NEVER included
- Tags are NEVER exported
- The Calendar Feed is disabled by default — you must opt in
Important exception: External Access (Connected Apps)
The optional External Access feature (described in Section 11) lets a connected outside app read what Memorist has learned about you (your Memory Beliefs). To make this work, enabling it writes a readable, consent-filtered copy of your shareable beliefs to Memorist’s own servers (Firebase), which our systems read to serve the connected app.
This is a deliberate exception to end-to-end encryption, in the same spirit as the Calendar Feed above. While the feature is on, Memorist stores and can read that shareable subset of your beliefs in plaintext. Key points:
- Only shareable beliefs are copied — beliefs rated “private” (hidden), including those hidden automatically because they touch sensitive areas like health or therapy, are never included.
- Your entries are never copied — only the belief statements permitted by your sensitivity settings.
- Off by default — you must deliberately enable External Access and connect an app.
- Deleted when you turn the feature off — turning External Access off deletes this server-side copy (your device completes the deletion the next time it is online, if it was offline). Revoking an individual connected app immediately blocks that app’s access; turning the feature off entirely (which also revokes all connected apps) is what deletes the copy.
- Suggestions from connected apps — if you allow a connected app to suggest memories, its suggestions are also stored readably on our servers (see Section 11).
Important exception: Siri, Spotlight & Shortcuts (on your iPhone)
Memorist can make your journal and Memory available to Siri, Spotlight, and Shortcuts on your iPhone. You control each of these with its own switch in Settings → On your iPhone, and you can turn any of them on or off at any time. The defaults are:
- Siri → Journal entries (on by default): Siri can read your entries when you ask it.
- Siri → Memory of You (on by default; subscribers): Siri can answer from your non-hidden beliefs and the boundaries you have set when you ask it.
- Spotlight & Shortcuts → Journal entries (off by default; the App asks you to confirm before turning it on): the text of your entries (up to 2,000 characters each), a title from the first line, and keywords are added to your iPhone’s search index. Entries marked private or as not having happened are not included.
- Spotlight & Shortcuts → Memory of You (on by default; subscribers): your non-hidden beliefs are added to your iPhone’s search index.
This is an exception to end-to-end encryption on your device. Items added to Spotlight are a readable copy kept in Apple’s on-device search index, outside Memorist’s encryption and outside App Lock. They can appear in iPhone search and on your Lock Screen. Siri reads content only when you ask and keeps no copy in Memorist; how Siri itself processes your request is governed by Apple’s terms. This data is not sent to Memorist’s servers.
Turning a Spotlight switch off removes its items from the index, and the Memory items are also removed if your subscription ends. If you hide a belief, it is removed from Spotlight the next time your Memory updates; to remove it immediately, turn Spotlight → Memory of You off and on again.
How your encryption works
Your encryption key is generated automatically on your device when you first create content. This key is stored in your iCloud Keychain — Apple’s secure, encrypted key storage system.
Benefits:
- Your encryption key syncs seamlessly to your other Apple devices (iPhone, iPad, Mac)
- You can access your encrypted content on any device signed into your iCloud account
- Your key is protected by your device passcode and biometrics (Face ID/Touch ID)
Important to know:
- Memorist uses iCloud Keychain to sync your encryption key across your devices
- If you sign out of iCloud, disable iCloud Keychain, or lose access to your Apple ID, your encrypted content cannot be decrypted
- We cannot recover your data for you — this is by design to ensure true privacy
- If you need to access your data on a new device, make sure you’re signed into the same iCloud account
- App uninstall: Uninstalling Memorist does not delete your encryption keys from iCloud Keychain. Keys persist and will be available if you reinstall the app on any device signed into the same iCloud account
Your Responsibility: Backups and Key Management
Because we cannot access your encrypted content, we do not store backups of your readable data on our servers. It is your responsibility to back up your content. If you lose access to your encryption keys or devices, your content cannot be recovered by Memorist.
This is the trade-off of true end-to-end encryption: your privacy is absolute, but so is your responsibility to protect your data.
How to protect your data:
1. Enable iCloud Backup (Recommended)
- Go to iPhone Settings → [Your Name] → iCloud → iCloud Backup
- Turn on iCloud Backup
- This backs up your local database, app settings, and encryption keys
- If you lose your device, you can restore from iCloud backup and regain access to your content
2. Use Multiple Devices
- Sign into Memorist on multiple Apple devices (iPhone, iPad, Mac)
- Your encryption keys sync automatically via iCloud Keychain
- If one device is lost, you can still access your content from another device
- This provides redundancy in case one device fails
What happens if you lose access to iCloud Keychain:
- You will not be able to decrypt your content
- We cannot provide you with your encryption keys
- Your encrypted data on our servers becomes permanently inaccessible
- There is no password reset or account recovery for encryption keys
Best practices:
- Keep your Apple ID credentials secure and memorable
- Enable two-factor authentication on your Apple ID
- Ensure at least one trusted device remains signed into your iCloud account
- Use multiple Apple devices to ensure redundancy
Your Responsibility: Device Security
Because your encryption keys are stored on your device (via iCloud Keychain), the security of your Memorist content depends entirely on the security of your devices.
Since our servers cannot decrypt your content or help with recovery, you must protect your devices and keys. A compromised device means compromised journal content.
Essential security practices:
1. Use a strong device passcode
- Use a 6-digit or alphanumeric passcode (not a simple 4-digit code)
- Never use easily guessable codes (birthdays, “123456,” etc.)
- Your device passcode protects access to iCloud Keychain (and therefore your encryption keys)
2. Enable biometric security
- Use Face ID or Touch ID for quick, secure device access
- This prevents shoulder surfing and unauthorized access
3. Enable device encryption
- iOS devices have encryption enabled by default when you set a passcode
- This ensures your local database is encrypted at rest
4. Keep your device physically secure
- Don’t leave devices unlocked and unattended
- Enable “Find My iPhone” to remotely wipe a lost or stolen device
- If a device is stolen while unlocked, an attacker may access your Memorist content
5. Never share your device passcode
- Anyone with your device passcode can access iCloud Keychain
- This means they can access your Memorist encryption keys and decrypt your content
6. Keep iOS updated
- Install iOS security updates promptly
- Security patches protect against known vulnerabilities
What happens if your device is compromised:
- If someone gains access to your unlocked device or learns your passcode, they can access your Memorist content
- If your device is stolen while unlocked, immediately use “Find My iPhone” to remotely lock or erase it
- If you believe your Apple ID has been compromised, change your password immediately and review which devices have access to your iCloud account
What Memorist cannot do:
- We cannot remotely lock or wipe your devices
- We cannot revoke access to encryption keys stored on compromised devices
- We cannot decrypt your content even if you forget your device passcode (only you can access your content via your device)
Remember: Your privacy is absolute, but so is your responsibility. The same encryption that protects you from us also protects your content from recovery if you lose access to your devices or keys.
Guest Mode (Getting Started Without Creating an Account)
Even if you start using Memorist in Guest Mode (without creating an account), your data is still protected by E2EE. Your encryption key is tied to your anonymous session. End-to-end encryption applies equally to Guest Mode, Free, and Subscription users — it is a core design principle, not a paid feature.
What Guest Mode includes: Guest Mode provides core journaling features with up to 30 items created in total (including event entries, daily journal entries, and photos; deleting an item does not reset this count) and 1 photo per event entry. Shared Entries is not available in Guest Mode. Certain advanced features are visible in Settings but available only with an active subscription (the current list is shown in the in-app subscription screen). You may also see a banner encouraging account creation for long-term data safety.
Creating an account from Guest Mode: When you create a free account by signing in with your Apple ID, your Guest Mode data and encryption key are automatically preserved and linked to your new account. No data is lost in this transition.
Data Export and E2EE
Memorist provides a data export feature for backup purposes (Settings → Export for backup). This feature is available only with an active subscription; it is visible in Settings for all users but enabled only for subscribers. Important: The export feature does not change how your data is encrypted. It decrypts your content on your device and produces a plaintext backup file. The export process maintains our E2EE security model:
- On-device decryption: All decryption happens locally on your device using your encryption keys from iCloud Keychain
- Server never sees plaintext: Your encrypted data is downloaded from our servers and decrypted only on your device
- Exported file contains plaintext: The .zip file you download contains your journal data in readable JSON format (and optionally full-resolution photos). Your Memory (beliefs) and reflections are not included; see Section 7
- Your responsibility: Once exported, you are responsible for securing the .zip file. Store it in a secure location (e.g., encrypted backup drive) and do not share it.
Important: Exported files are not encrypted. This is intentional—the export is designed so you can access your data even if you lose access to Memorist or your encryption keys. Treat exported files like you would treat your physical journal.
Technical Details
For transparency and security researchers:
- Encryption algorithm: AES-GCM (256-bit keys)
- Key management: Per-user Key Encryption Key (KEK) with per-item Data Encryption Keys (DEKs) using envelope encryption
- Key storage: Apple iCloud Keychain with
kSecAttrSynchronizable=true - Authentication: Authenticated encryption with Additional Data (AAD) binding to prevent tampering
6. Support Limitations Due to E2EE
Because of our end-to-end encryption architecture, there are important limitations on what Memorist support can help you with.
What We CANNOT Do
We cannot recover your data if you lose access to your encryption keys.
This is not a policy choice — it is a technical reality of end-to-end encryption. Your encryption keys are stored exclusively on your devices via iCloud Keychain. We do not have copies of your keys, and we cannot decrypt your content without them.
Specific scenarios where we cannot help:
× Lost Apple ID or iCloud Keychain access
- If you forget your Apple ID password and cannot recover your account
- If you disable iCloud Keychain and lose your local encryption keys
- If you sign out of iCloud and delete the app before backing up
× Forgotten device passcode
- We cannot bypass your device passcode to access encryption keys
- We cannot reset or recover your encryption keys
× Account recovery after key loss
- We cannot restore your encrypted content without your encryption keys
- Memorist holds no key that can unlock your content: there is no company master key, backdoor, key escrow, or recovery mechanism
- Your content becomes permanently unrecoverable
× Data access from lost or stolen devices
- We cannot remotely lock or wipe your devices
- We cannot revoke encryption keys from compromised devices
- We cannot see what devices have access to your content
× Decryption of your content
- We cannot read your journal entries, events, or notes
- We cannot provide you with unencrypted copies of your data
- We cannot decrypt your content even with legal orders or warrants
What We CAN Help With
✓ Technical issues and bugs
- App crashes or performance problems
- Sync issues (if your devices can communicate with our servers)
- Feature requests and feedback
✓ Account and billing
- Subscription management and cancellations
- Payment issues with Apple App Store
- Account deletion requests
✓ General guidance
- How to enable iCloud Backup
- How to use multiple devices for redundancy
- Understanding how encryption works
- Explaining the Calendar Feed feature
✓ Privacy and security questions
- Understanding what data we collect
- How E2EE protects your content
- Data deletion and GDPR rights
Why This Limitation Exists
This is the fundamental trade-off of true end-to-end encryption:
You get absolute privacy → We cannot read your content, even if we wanted to.
You accept absolute responsibility → We cannot recover your content if you lose access to your keys.
Most journaling apps offer account recovery because they hold your encryption keys (or don’t encrypt at all). Memorist is different: you hold the only keys, which means you are the only one who can unlock your content.
Before You Contact Support
If you’re experiencing issues accessing your content, please check:
- Are you signed into iCloud? (Settings → [Your Name])
- Is iCloud Keychain enabled? (Settings → [Your Name] → iCloud → Keychain)
- Are you using the same Apple ID that you used when you created your content?
- Do you have iCloud Backup enabled? (Settings → [Your Name] → iCloud → iCloud Backup)
- Are you signed in on other devices? Try accessing Memorist on another device signed into the same iCloud account.
If none of these steps work and you’ve lost access to your iCloud Keychain, we cannot recover your data. This is by design.
7. Your Content
Your journal entries, images, tags, and reflections are private by default.
You may:
- edit,
- export,
- or permanently delete your content at any time, subject to system limitations.
Export formats available:
1. Journal export (.zip)
Download your journal as JSON files via Settings → Export for backup. The export is available to subscribers and requires Face ID, Touch ID, or your device passcode.
Export options:
- All data (text only): Your journal and tags, without photos, in JSON format (fast export)
- All data + Photos: The same, plus your entry photos (may take time)
What’s included: The export covers your journal. What it contains depends on whether your account has been updated to Logs:
- Logs (updated accounts): the text, moods, body, wine, and Calm details, tags, and timestamps of each Log
- Older entry types (accounts not yet updated): daily journal entries, event entries, body check-ins, wine entries, and Calm entries
- Tags: Each tag’s name, type, Tempo setting, relationship type, birthday, and dates
- Photos (optional): Full-resolution images and thumbnails
- Entries you marked private are included, with that marker
What’s NOT included:
- Your Memory (beliefs, including hidden and removed beliefs) and your reflections
- Saved place locations, and person details other than those listed above (such as full name, anniversary, aliases, and mobile number)
- For Logs: the location, people, schedule, and repeat details of each Log
- Deleted items and notifications
- App settings and preferences (notifications, theme, display preferences)
- Account and subscription data (managed by Apple)
- Integration settings (Calendar Feed configuration)
- App metadata (feature flags, onboarding state)
Important security notes:
- Decryption happens on your device to maintain E2EE security
- Exported .zip file contains plaintext (unencrypted) data
- You are responsible for securing the exported file
- Store exported files in a secure location (e.g., encrypted backup drive)
- Do not share exported files—they contain your unencrypted journal content
Rationale: The export focuses on your journal. Settings and preferences are device-specific and easily reconfigurable. See Section 5 for details on how export maintains E2EE. If you are not a subscriber, or you need a copy of data the export does not include, contact us at hello@memorist.me.
2. iCalendar (ICS) feed
Optional calendar feed for event entries only (plaintext, opt-in only). Daily journal entries are never included. See Section 5 for details about this plaintext export option.
Backups: Because of end-to-end encryption, we cannot back up your readable content on our servers. You are responsible for backing up your data using the export feature or other backup strategies. See Section 5 (“Your Responsibility: Backups and Key Management”) for recommended backup strategies.
Deleting a single item: When you delete an entry, Log, or photo, it is removed from the App right away and permanently deleted from our servers after 30 days. Deleted tags are hidden but kept until you delete your account.
If you delete your account, associated data may become permanently unrecoverable.
Account deletion: When you delete your account, your data is permanently removed immediately with no grace period or recovery option. This includes:
- All encrypted content on our servers, including entries, Logs, tags, beliefs, reflections, and photos
- Your notification records, External Access copy and records, and Calendar Feed
- Your Shared Entries connections, shares you sent and received, reactions, sharing keys, and unused invites
- Your authentication records
- All device tokens and settings
- Encryption keys on the current device (keys may persist in iCloud Keychain on other devices)
What may remain: Some records that contain none of your writing in readable form are not currently removed: technical markers that a shared entry could not be opened; the record of which apps you had connected under External Access; other people’s mute settings and in-app notifications that name you; copies of metadata and encrypted content previously sent to our data warehouse (Section 10); and a marker in your iCloud Keychain that you have used Memorist before, which lets the App welcome you back.
Important: Because encryption keys are stored in iCloud Keychain with sync enabled, keys may remain accessible on your other Apple devices after account deletion. Apple provides no API for us to force-delete keys from all devices. However, these keys become useless after account deletion since there is no encrypted data to decrypt.
We cannot restore your account or data after deletion.
8. Children’s Privacy
Memorist is for users 13 years and older.
We do not knowingly collect information from users under age 13.
If you believe a minor under 13 has created an account, please contact us at: hello@memorist.me
9. Third-Party Services
Memorist integrates with Apple’s systems for:
- authentication,
- subscription management,
- billing.
Your use of Apple services is governed by Apple’s own policies.
We are not responsible for:
- Apple App Store billing terms,
- Apple’s identity systems,
- Apple’s retention of transactional data.
10. Analytics (Minimal & Respectful)
We use Firebase Analytics (Google Analytics 4) to:
- understand feature usage patterns,
- detect errors,
- improve design and stability.
We do not collect the text of your journal entries, or anything the AI writes, for analytics.
What analytics contains: Events describe what you do in the App — for example, which screens you open, that you created an entry or photo on a given date, how many moods you logged, which AI engine produced a reflection and whether it succeeded, and your subscription status. When you are signed in (including in Guest Mode), events are linked to your account identifier, and Firebase also assigns a per-install identifier.
Data warehouse: We keep analytics events, and a copy of the metadata we can already read about your Logs, entries, and events (dates, tag identifiers, timestamps, and similar fields listed in Section 5) together with their encrypted contents, in Google BigQuery in the United States. The warehouse contains nothing we could not already read on our servers. These copies are not currently removed when you delete your account.
Your control: You can turn off analytics in Settings (“Anonymous analytics”). It is on by default. Turning it off stops the App’s own analytics events. Firebase may still record basic automatic events, such as app opens, session length, and in-app purchases. Crash reporting is separate and is not affected by this setting.
Our website: memorist.me uses Google Analytics and Google Ads measurement tags to understand visits and measure App Store downloads from our ads. Website analytics are reported into the same Google Analytics account as the App.
11. AI and Feature Processing
Memorist offers optional AI features that generate the Reflections and Memory Beliefs described in Section 1.5. These features require an active subscription and an available AI model.
On iPhones running iOS 27 or later, Apple Intelligence is selected as your model by default whenever no other model is chosen, whether or not you subscribe. The AI features that generate Reflections, Memory Beliefs, and personalized questions still run only with an active subscription, so the on-device and Apple Private Cloud Compute features (tiers 1 and 2 below) become available as part of your subscription. On earlier versions of iOS, or where no model is available, the features stay off until a model is in place. Because tiers 1 and 2 rely on Apple Intelligence, they are available only if Apple Intelligence is enabled on your device, which you can turn off in your device’s Settings. The third-party provider path (tier 3 below) is never selected automatically — it stays off until you deliberately turn it on. If you remove your third-party key, Memorist switches back to Apple Intelligence on iOS 27 or later (or turns the AI features off on earlier versions) — never to another outside provider.
Where this processing happens depends on which model is in use. There are three tiers, listed from the most private to the least:
1. On your device. By default, and wherever the device is capable of it, AI processing happens entirely on your device using Apple Intelligence and Apple’s on-device machine learning. Apple Intelligence itself requires a supported device running iOS 27 or later. Separately, we use Core ML on-device to classify whether a tag is a Person, Place, or Thing, and, if you use voice entry, your speech is transcribed on your device — these two work on earlier versions of iOS as well. In all of these cases, your content never leaves the device.
2. Apple Private Cloud Compute (for heavier tasks — iOS 27 and later only). Some requests need more computing power than the device can provide on its own. In those cases, Apple Intelligence may send the necessary content to Apple’s Private Cloud Compute (PCC). This path relies on Apple Intelligence, so it is available only on devices running iOS 27 or later. Until you update to iOS 27, Apple Private Cloud Compute is not used at all — it is not active on earlier versions of iOS. When it is available, according to Apple, content sent to PCC is used only to fulfill your request and is not retained afterward, is not accessible to Apple, is not used to train Apple’s models, and runs on software that is publicly verifiable by independent security researchers. Content sent to PCC is not sent to any third party. It is intended to be the default path when on-device processing isn’t sufficient, once Apple enables it on the device.
3. A third-party AI provider, only if you explicitly enable it. If you choose to, you can connect your own account with a third-party AI provider (currently Anthropic’s Claude or OpenAI) by providing your own API key. This is not on by default — you must take deliberate steps to enable it, and we disclose what it does at the point you turn it on. When enabled, the content needed to generate a reflection or belief — relevant entries and, when your Memory is updated, your existing beliefs, hidden ones included (see Section 1.5) — is sent directly from your device to that provider, authenticated with your own key — it does not pass through Memorist’s servers. It is processed under your account and under that provider’s terms. Your use of your own key is governed by your agreement with that provider, which you should review, including how they handle the data you send. You can turn this off at any time by removing the key or disabling the feature. Because this path sends content to an outside company, it is a deliberate exception to the on-device and Apple-only protections above — comparable to the Calendar Feed trade-off described in Section 5.
When Memorist generates your reflections and beliefs, its own servers never see your readable content. These AI requests go from your device to the model — on-device, to Apple PCC, or (with your key) directly to the third-party provider — not through Memorist. The results are stored under end-to-end encryption or on your device, as described in Section 1.5. The one server-side exception is the External Access feature described next: if you turn it on, Memorist places a readable, consent-filtered copy of your shareable beliefs on its own servers so a connected app can be served.
How AI output is checked. Reflections are screened to keep them observational and on topic; when a draft doesn’t pass, you may simply receive no reflection that day. Entries a model consistently refuses to process may be skipped. AI output can still be incomplete or wrong.
We do not use your writing, reflections, or beliefs to train our own models, and we do not sell them. For the on-device and Apple PCC tiers, no third party receives your content. For the third-party tier, your content is handled by the provider you chose, under your own account and their terms.
External memory access
Separately from the AI-model tiers above, you can connect an outside app or AI agent and grant it read access to your memory — that is, let another tool use what Memorist has learned about you (your Memory Beliefs) — and, only if you allow it, let it suggest new memories. This is an independent, opt-in feature. It does not require you to connect a third-party AI provider or supply an API key — you can use it with no AI model of your own selected. It is off by default until you deliberately enable it and authorize a connected app.
How the connection works. Connecting an app is an authorization you grant (an OAuth-style connection you approve and can revoke) — the app does not receive your Memorist password or any API key. Once authorized, the app reads your shareable beliefs from a copy Memorist hosts on its own servers (see “Where this data lives” below). This is different from the third-party-provider path in tier 3: nothing is sent from your device to Claude or OpenAI, and no API key of yours is involved.
- What can be read: each belief carries a four-level sensitivity rating — from shareable anywhere, to work-appropriate, to personal, to private. Only beliefs below the top (“private”) level can be read by an external agent, according to that rating. Your entries themselves are never exposed this way.
- Boundaries and tensions: boundaries you have set (things an app should not assume about you) are shared with every connected app within its sensitivity level, whatever topics you granted, so that it can respect them. “Tensions” (pairs of your beliefs that pull against each other) are shared by default, only when both beliefs are shareable; you can switch this off for each app.
- What is never shared: beliefs rated “private” are treated as hidden and are never shared with a connected app. This includes beliefs you hide yourself and beliefs the App classified as private automatically because they touch sensitive areas like health or therapy. This exclusion is enforced automatically by the App at a single checkpoint — it is not left to the AI’s judgment. Hidden beliefs are also excluded from data export and from cloud backup (see Section 1.5 for the one place they are processed).
- Suggested memories: if you tick the option when connecting an app (it is off by default), that app may suggest memories for you — up to 50 waiting at a time. It can never suggest a boundary. Each suggestion, with the note and purpose the app gives, is stored readably on our servers until you delete your account. Suggestions never become part of your Memory on their own.
- Your control: you enable external access deliberately and can revoke it at any time. When you hide or unhide a belief by hand, that choice sticks — the model won’t quietly reverse it.
Where this data lives — an exception to our encryption. To answer a connected app, enabling External Access writes a readable (non-encrypted), consent-filtered copy of your shareable beliefs to Memorist’s own servers (Firebase), which our systems then read to serve that app. This means that while External Access is on, Memorist does store and can read that shareable subset of your beliefs. It is a deliberate exception to the end-to-end encryption that otherwise keeps your beliefs unreadable to us — the same kind of trade-off as the Calendar Feed (Section 5) and the third-party-provider path above. Beliefs rated “private” (hidden) are never included. When you turn External Access off, this copy is deleted; revoking an individual connected app immediately blocks that app’s access.
Because this feature can expose inferences about you to a system outside Memorist, we treat it as a distinct, opt-in choice, and we record each change you make to a connected app’s access (see below).
Records we keep about external access
So that you can see — and check — what a connected app has actually done, Memorist keeps two records on its own servers while External Access is in use. These records are readable to us (they are not end-to-end encrypted), and you can view them in the App under Access history.
- Access history (what was read). Each time a connected app reads your memory, we record which app it was, the search term the app used and the purpose it declared (each stored only up to a short length), how many beliefs were returned, the sensitivity level in force, which topic categories were shared, and whether the request was slowed down or refused. No belief text and no journal content is stored in this record. Note, however, that the app’s own search term is text we retain, and a search term can itself be revealing.
- Permission history (what you changed). We separately record each change to an app’s access — connecting it, revoking it, narrowing which topics it may read, changing its purpose limits, or allowing it to suggest memories — together with the resulting scope. This record contains no belief text.
- Tamper-evident, and yours to clear. A connected app can neither read, alter, nor erase these records. You can Clear them in the App at any time, and they are automatically deleted after 90 days (deletion can take up to a few days beyond that; see Section 12).
One honest limit. When a connected app states a purpose for a read, that purpose is declared by the app itself. We record it so you can inspect it, but it is not something Memorist can independently verify. The controls Memorist does enforce are the sensitivity level and the topic categories you grant (boundaries, as described above, are shared regardless of topic).
Siri, Spotlight & Shortcuts
Memorist can let Siri answer from your journal and Memory, and can add your non-hidden beliefs and, if you turn it on, your journal entries to your iPhone’s on-device search index. Each of these has its own switch in Settings → On your iPhone, and you can turn any of them on or off at any time. Section 5 (“Important exception: Siri, Spotlight & Shortcuts”) explains the defaults, what is included, and how the Spotlight copy sits outside Memorist’s encryption and App Lock.
12. Data Retention
We retain your information as long as:
- your anonymous session is active (Guest Mode),
- your account exists (Free and Subscription tiers),
- retention is required to operate the App.
Guest Mode data retention: Guest Mode data is associated with your anonymous session and persists as long as the session remains active. If you do not create an account, your data may be subject to removal after an extended period of inactivity. We encourage Guest Mode users to create a free account to ensure long-term data preservation.
Account-based data retention (Free and Subscription): Your data is retained for as long as your account exists, regardless of subscription status. If your subscription lapses or you choose to unsubscribe, your data remains intact and accessible — only subscription-specific features (shown in the in-app subscription screen) are disabled. Unsubscribing never results in data loss.
External Access records (Section 11): the Access history and Permission history we keep for connected apps are automatically deleted 90 days after they are created. You can also clear them yourself at any time in the App. Separately, the readable copy of your shareable beliefs that External Access creates is deleted when you turn the feature off. Memories suggested by connected apps are kept until you delete your account.
Other retention periods: Deleted entries, Logs, and photos are permanently removed 30 days after you delete them. Notification records are kept until you delete your account. Used and expired Shared Entries invites are kept until the person who sent them deletes their account. Data warehouse copies (Section 10) are not currently removed.
When deleting your account, associated data will be removed immediately. There is no grace period or backup retention after account deletion. This is a permanent, hard delete with no recovery option, subject to the limited records described in Section 7 (“What may remain”).
What gets deleted:
- All Firestore data stored under your account (entries, Logs, events, tags, beliefs, reflections, notifications, settings)
- Your Shared Entries connections, shares, reactions, and unused invites
- All Firebase Storage files (encrypted photos, People tag photos, and your profile photo)
- All Firebase Authentication records
- All device tokens and notification preferences
- Encryption keys on the current device
What happens to iCloud Keychain: Your encryption key in iCloud Keychain may persist on other devices after account deletion. Apple provides no API for us to force-delete keys from all devices. However, these keys become useless since there is no encrypted data to decrypt.
13. International Use
Data may be stored or processed in different regions to ensure reliability.
By using Memorist, you consent to transfer and processing of your information outside your country, as necessary to provide the service.
Firebase data location: Your data may be stored in Google Cloud Platform regions, primarily in the United States, including our BigQuery data warehouse. What you write is stored as encrypted ciphertext; Section 5 lists the metadata and opt-in copies that are readable.
Cross-border data transfers: Where required by law (including GDPR), we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate protection for international data transfers. These are legally binding commitments between data processors to protect personal data transferred outside the EU/EEA.
Important: Because your content is protected by end-to-end encryption, even if your encrypted data is transferred internationally, it remains unreadable without your encryption keys (which are stored exclusively in your iCloud Keychain).
14. Your Rights
Depending on your jurisdiction, you may have certain rights, including:
- Access to your data
- Correction of inaccurate data
- Export or portability (journal export and iCalendar/ICS feed for subscribers; anyone may request a copy of their data at hello@memorist.me)
- Deletion (“Right to be Forgotten”)
- Withdrawal of consent
- Complaint to a regulatory authority
Important limitation: Due to end-to-end encryption, if you lose access to your encryption keys (via iCloud Keychain), we cannot recover your content for you. This is by design to ensure true privacy.
We will honor your rights where required by law and will do our best to support reasonable requests.
Control over AI-derived content: For the Memory Beliefs described in Section 1.5, you have direct in-app controls — you can Keep, Edit, Freeze, Hide, or Remove any belief. A removed belief is remembered as removed so it is not suggested again, and a hidden belief is excluded from sync, export, Spotlight, and connected apps (see Section 1.5).
For GDPR (EU) users:
- Legal basis for processing: Consent and contract performance
- Data transfers: Standard Contractual Clauses (SCCs) where applicable
- Contact for privacy inquiries: hello@memorist.me
For CCPA/CPRA (California) users:
- Do Not Sell My Personal Information: We do not sell personal information
- Right to opt-out: You can disable analytics in Settings
- Categories of data collected: See Section 1
- Right to delete: Available via Settings → Delete my Account
15. App Store Data Safety Disclosures
Our app store listings reflect our E2EE architecture and minimal data collection practices.
When you view Memorist in the Apple App Store or Google Play Store, you’ll see “Data Safety” or “App Privacy” labels. These disclosures are consistent with this Privacy Policy and reflect our commitment to privacy.
What we report in app stores:
Data Collected:
- Account identifier: Apple ID (via Sign in with Apple); phone number for legacy accounts created before March 2026
- Usage data: Analytics linked to your account identifier (optional, can be turned off in Settings; see Section 10)
- Crash data: Crash reports for debugging
User Content:
- User content: Stored and synced in encrypted form (E2EE); we cannot access or read what you write
- Photos: Entry photos are encrypted; People tag photos and your Shared Entries profile photo are not
- Other user-generated content — encrypted on your device and synced only as ciphertext
Data Linked to You:
- Apple-provided email address (for account identification)
- Phone number (for legacy accounts created before March 2026)
- Analytics data (if enabled)
- Shared Entries display name, profile photo, and connections (if you use Shared Entries)
Data Not Linked to You:
- Crash logs (anonymized)
Key statement for app stores:
“Memorist uses end-to-end encryption. Your journal entries, events, entry photos, and personal notes are encrypted on your device before syncing. We cannot read what you write. Limited metadata (such as dates, timestamps, and settings) is stored to enable core functionality like timeline sorting, reminders, and multi-device sync.”
Important clarification:
Even though we store your encrypted data on our servers (Firebase):
- We cannot decrypt or read what you write
- We do not have access to your encryption keys
- Your encrypted content is meaningless ciphertext without your personal key
- The readable metadata we store (Section 5) cannot be used to reconstruct what you write
Exceptions to note (see Sections 3.2, 5, and 11):
- Siri, Spotlight & Shortcuts: depending on your switches in Settings → On your iPhone, Spotlight keeps a readable copy of your non-hidden beliefs (on by default) and journal entries (off by default) on your device, and Siri can read your journal and Memory when you ask. None of this is sent to our servers.
- Shared Entries: people you choose can read the entries you share with them; we can read who you are connected with and who received which entry, but not the entries.
- Calendar Feed: if you turn it on, a readable copy of your scheduled events is stored on our servers and served to anyone with its link.
- Third-party AI provider: if you choose the third-party provider path (Anthropic’s Claude or OpenAI, using your own key), content needed to generate a reflection or belief is sent from your device to that provider.
- External Access (Connected Apps): if you connect an outside app to your memory, Memorist stores a readable, consent-filtered copy of your shareable beliefs (never your private/hidden ones) on its own servers so the connected app can be served. This copy is deleted when you turn the feature off.
For the official breakdown of what data Memorist collects and how it is linked to you, please refer to our App Privacy labels in the App Store.
Verification:
You can verify our data collection practices by:
- Reviewing this Privacy Policy
- Checking our App Store / Google Play listing
- Examining our open-source security architecture documentation (if made available)
- Contacting us with specific questions at hello@memorist.me
If you notice any discrepancy between our app store disclosures and this Privacy Policy, please contact us immediately.
16. Changes to This Policy
We may update this Privacy Policy from time to time.
If we make material changes, we will notify you within the App or by other reasonable means.
Continued use of the App after updates indicates acceptance of the revised Policy.
17. Contact Us
If you have questions about this Privacy Policy or your data, contact us:
Email: hello@memorist.me
Website: https://memorist.me
This Privacy Policy is effective as of September 2026 and applies to all users of the Memorist app.