Privacy Policy

Last updated: September 2026

This Privacy Policy explains how Memorist (“Memorist,” “we,” “our,” or “us”) collects, uses, stores, and protects your information. By using the Memorist app (“App”), you agree to the practices described in this Privacy Policy.

Memorist is a private journaling and reflection tool. Your entries, prompts, photos, and relationship notes are personal and private by default. They are never shared publicly. If you choose to use Shared Entries, you can show a specific entry to people you have connected with; nothing is shared with another person unless you choose it (see Section 3.2).

Memorist is free to use. You can get started in Guest Mode without creating an account, or create a free account for the full core experience. An optional Subscription is available to unlock advanced features (see Section 1.4 for the current list). This Privacy Policy applies equally to all users regardless of tier. Where data practices differ, we note them explicitly below.

1. Information We Collect

We collect the minimum information necessary to operate the App, protect your data, and improve functionality.

1.1 Account Information

Sign in with Apple: To create a Memorist account, you sign in with your Apple ID using Sign in with Apple. This is the only method for creating new accounts.

When you sign in with Apple, we receive:

How authentication works: Your Apple ID token is passed to Firebase Authentication (provided by Google), which serves as our backend identity and session management layer. Firebase Auth validates your Apple ID token, creates and manages your user identity, and issues your session. The data flow is: Apple (identity provider) → Firebase Auth (identity and session management) → Firestore (user profile storage).

We store the Apple-provided email address in your user profile for account identification purposes only. We do not use it for marketing, advertising, or communications. If you chose “Hide My Email,” the stored address is a private relay address controlled by Apple (e.g., abc123@privaterelay.appleid.com).

Unified identity: Because Memorist uses Sign in with Apple for authentication and Apple’s iCloud Keychain for encryption key storage, your sign-in identity and your encryption key identity are unified under the same Apple ID. This eliminates the need for separate identity systems and simplifies your security posture. See Section 5 for details on encryption.

Legacy phone authentication: Before March 2026, Memorist used phone number verification (SMS one-time password) for account creation. If you created your account using phone verification before March 2026, your phone number may still be associated with your account. You can still sign in with your phone number, but you must link an Apple ID before you can continue using the App. New accounts require Sign in with Apple, and new phone numbers are not accepted. If the Apple ID you link is already attached to a different Memorist account, linking removes that other account so the Apple ID can be attached to your original account.

Guest Mode: You may begin using Memorist without creating an account. In Guest Mode, we do not collect an Apple ID, email address, or any personally identifiable information. Your session is anonymous, identified only by a randomly generated, app-specific identifier (not a hardware or advertising identifier). Guest Mode includes up to 30 items created in total (including event entries, daily journal entries, and photos); deleting an item does not reset this count. To continue beyond this point, you will need to create a free account by signing in with your Apple ID. When you do, your existing Guest Mode data is automatically preserved and linked to your new account.

Age verification: When you create an account, you confirm that you are 13 years or older. Apple requires users to be at least 13 years old to have an Apple ID in most regions, which aligns with Memorist’s age requirement and provides an additional verification layer. We do not collect government-issued identification or perform independent age verification beyond Apple’s own policies and user attestation at account creation.

1.2 User-Generated Content

The personal content you create in the App (“Content”) includes:

Importing from Contacts: If you grant the App access to your Contacts and choose people to import, we save the names, nickname, birthday, anniversary, relationship label, one mobile number, and photo of each person you select as a People tag. Other contact details (such as email addresses and other phone numbers) are shown during review but not saved. Imported names, dates, and numbers are end-to-end encrypted; a person’s photo and relationship type are not (see Section 5).

We may introduce additional content types in the future. Any new type is subject to the same end-to-end encryption and privacy protections described in this Policy. If a new type involves materially different data practices, we will update this Policy and notify you as described in Section 16.

Some content you log — for example, body check-ins — may relate to your health. You decide what to record, and because the content of what you write is end-to-end encrypted (see Section 5), Memorist cannot read it and does not use it for any purpose beyond the storage and sync features described in this Policy.

You retain ownership of your content.

We process this information solely to:

Important: What you write is protected by end-to-end encryption (E2EE). Section 5 lists exactly what is encrypted, the limited metadata that is not, and the opt-in features that create readable copies.

AI-derived content: When you turn on Memorist’s optional AI features, the App also creates content derived from your entries — Reflections and Memory Beliefs. These are described in Section 1.5, and how they are processed is described in Section 11.

1.3 Device & Technical Data

Automatically collected in limited form to improve reliability:

The App never requests access to your device’s location. We do not collect precise location unless you voluntarily enter it as part of an entry or tag (for example, by saving a Place tag’s location, which is end-to-end encrypted).

Crash reporting: We use Firebase Crashlytics (provided by Google) to detect and fix app crashes. Crash reports do not contain your journal content. Crash reporting runs in all release builds and is not controlled by the analytics setting.

Analytics metadata: When analytics is enabled (you can disable it in Settings), we collect usage information such as which screens you visit and which features you use. When you are signed in (including in Guest Mode), these events are linked to your account identifier. We do not collect the text of your entries, events, or AI-generated content. See Section 10 for details about analytics and your control over it.

What we cannot see: What you write is protected by end-to-end encryption. See Section 5 for a complete breakdown of what is encrypted versus what metadata we can read.

1.4 Subscription and Payment Data

Memorist subscriptions are managed via Apple’s App Store.

We do not receive or store:

We receive your subscription status (active, expired, plan tier) to activate features.

Service tiers:

Subscription details:

1.5 AI-Derived Content: Reflections and Memory Beliefs

When you turn on Memorist’s optional AI features (see Section 11), the App creates two kinds of AI-derived content from what you’ve written:

These are inferences, not things you wrote directly, and you stay in control of them. For any belief you can Keep, Remove, Edit it into your own words, Freeze it so it can’t be rewritten or fade, or Hide it. Anything you keep, correct, or freeze cannot be silently overwritten by the model.

Sensitivity and automatic hiding. Every belief carries a sensitivity rating. Because beliefs are drawn from a personal journal, some touch sensitive subjects such as health or therapy; beliefs like these are rated as private and hidden automatically the moment they are formed, before you’ve even reviewed them.

Where hidden beliefs can and cannot go. A hidden belief is never synced to our servers, never included in cloud backup or export, never added to Spotlight, never copied for connected apps under External Access, and never used to write Ask Me questions. These exclusions are enforced automatically by the App rather than left to the AI’s judgment. To keep your Memory accurate, however, the AI model you have selected reads all of your beliefs — including hidden ones — when it updates, combines, or reorganizes them. Depending on your model, that happens on your device, on Apple’s Private Cloud Compute, or, if you have connected your own Anthropic or OpenAI account, with that provider (see Section 11). A belief that was synced before you hid it may keep its earlier encrypted copy on our servers, which we cannot read.

How this content is stored. Reflections and belief text — along with the entries they draw on — are protected by the same end-to-end encryption as the rest of your Content (see Section 5). Your non-hidden beliefs, the links between them, a belief’s history, and your weekly reflections are synced to our servers as encrypted ciphertext so they can be restored on a new device; we can read only their identifiers, timestamps, format version, the week a reflection covers, and which AI engine produced it. When you remove a belief, we keep an encrypted one-way fingerprint of it so it isn’t learned again. We cannot read your reflections or your beliefs — with exceptions you control: if you turn on External Access (Section 11), Memorist places a readable copy of your shareable, non-private beliefs on its servers so a connected app can be served; and if you allow Spotlight (Section 11), a readable copy of your non-hidden beliefs is kept in your iPhone’s on-device search index.

How it changes over time. Beliefs are not permanent. A belief’s prominence fades over time if nothing in your entries keeps reinforcing it, and a belief can be superseded by a newer, sharper one. You can freeze a belief to stop this.

For how this content is generated — including when processing happens on your device, on Apple’s Private Cloud Compute, or (only if you explicitly enable it) via a third-party AI provider — see Section 11.

2. How We Use Your Information

We use your data only to provide you with a secure and meaningful journaling experience.

Specifically, we use it to:

We do not:

Subscription features and data implications: Certain advanced features are available only with an active subscription. The current list is shown in the in-app subscription screen and in the App Store listing. Subscription-only features that have distinct data implications are described below.

Push notifications: When you enable push notifications, we collect a device token (via Firebase Cloud Messaging and Apple Push Notification service) and your notification preferences. If you disable notifications, we stop delivering them and may delete the associated device token and preferences. Push notifications are available to all users. Notifications sent from our servers use generic wording (for example, “You have a private notification”) and never contain your content.

Notifications created on your device: Some notifications are created by the App on your own device rather than sent from our servers — for example, your weekly reflection and the Ask Me reminder. These can show the full text of your weekly reflection or the Ask Me question, and may appear on your Lock Screen depending on your iPhone’s notification settings.

Notification records: The App keeps an in-app notification inbox, stored on our servers. Each record holds its type, timestamps, read state, links to the item it refers to, and simple counts or date ranges (for example, “Weekly reflection” and the week it covers). Notifications about Shared Entries also include the other person’s display name and, for reactions, the reaction. These records are readable to us and are kept until you delete your account.

The Stats feature is available only to subscribers. Stats do not introduce any new data collection. Stats processing happens entirely on your device, using your existing encrypted content and queryable metadata (see Section 5). No Stats data is sent to our servers.

Analytics in Guest Mode: Guest Mode users are subject to the same analytics controls as account holders, and their analytics are linked to their anonymous Guest Mode identifier. Analytics may be enabled or disabled in Settings. See Section 10 for full details, including what the setting does and does not stop.

3. Sharing Your Data

We do not sell, trade, or position your personal data for marketing purposes.

We may share limited information:

3.1 Service Providers

To deliver App functionality securely, we work with the following service providers:

Firebase (Google LLC)

Google Cloud (Google LLC)

Apple Inc.

How authentication works: Apple acts as the identity provider via Sign in with Apple. When you sign in, Apple provides an authentication token to Firebase Auth (Google), which validates the token, creates and manages your user identity, and issues your session. Firebase Auth serves as an intermediary identity and session management layer — it does not independently verify your identity. Your user profile (including your Apple-provided email address) is then stored in Firestore.

Important: These providers are bound by confidentiality agreements and can only process data on our behalf. What you write is stored as encrypted ciphertext; Section 5 lists the metadata and opt-in copies that are not.

Optional AI connections you control: Two separate, opt-in features can move data outside Memorist. They are independent of each other, and both are off by default:

See Section 11 for details on both.

3.2 People You Choose to Share With (Shared Entries)

Shared Entries lets you show a specific entry to someone you have connected with. It requires a free account (it is not available in Guest Mode) and is not a subscription feature. Nothing is shared unless you choose to share it. There is no public posting, feed, followers, or directory.

Connecting. You connect with someone by sending them an invite link or code yourself (for example, through Messages). An invite can be used once and expires after 7 days. The invite web page shows no information about you; after the other person opens the invite in the App, they see your display name and profile photo before accepting. Invite links you send through other apps are handled under those apps’ terms.

What a recipient sees. The people you share an entry with can read it in their App, including its photos, moods, people, tags, location, any place attached to it (including a saved address and map location), and, if the entry answers an Ask Me question, that question. They see edits you make while it is shared, and they can find it in their own search. Sharing a repeating entry shares every occurrence of it, past and future, until you stop sharing it.

How it stays encrypted. When you share an entry, your device encrypts a copy of that entry’s key (and its photos’ keys) for each recipient. Recipients can read that entry; Memorist still cannot read its contents. Your encryption keys are never sent to our servers in a form we can read, and sharing one entry gives no access to any other entry.

What we can read. To deliver shares and notifications, we store the following in readable form:

Your profile photo is stored without encryption and can be viewed by anyone who has its link.

Notifications to other people. When you share an entry, accept an invite, or react, the other person receives an in-app notification that shows your display name, the day of the entry, and any reaction — never the entry’s contents. The push notification that reaches their device says only that they have a private notification.

Your controls. You can stop sharing an entry, mute a connection, or remove a connection at any time. Stopping a share removes the entry from the recipient’s App without notifying them. Removing a connection ends sharing in both directions and deletes reactions. Stopping a share cannot undo what the recipient has already seen, noted, or captured (for example, with a screenshot), and a notification they already received may remain in their inbox.

Kept out of Memory. Entries other people share with you are never used to build your Memory or by any AI feature.

3.3 Legal Compliance

We may disclose information if required by law, court order, or governmental request, but only to the extent legally necessary.

4. Data Storage and Security

We take reasonable technical and organizational steps to protect your information.

End-to-end encryption is a core design principle of Memorist, not an optional feature.

Examples may include:

End-to-end encryption (E2EE): What you write is encrypted on your device before syncing to our servers, and we cannot read it. Some metadata, and readable copies created by opt-in features you control, are exceptions; Section 5 lists them in full.

No method of digital storage or transmission is 100% secure. You use the App at your own risk.

5. End-to-End Encryption

Your journals, events, and entry photos are encrypted so only you — and anyone you choose to share a specific entry with — can read them. Not even Memorist.

Memorist uses industry-standard end-to-end encryption (E2EE) to protect your content. What you write is encrypted on your device before it leaves your hands, and only you hold the encryption keys. This section also lists, in full, the metadata we can read and the opt-in features that create readable copies.

Unified identity: With Sign in with Apple, your authentication identity and your encryption key storage are now unified under the same Apple ID. Your sign-in is handled by Apple, and your encryption keys are stored in Apple’s iCloud Keychain — both tied to the same Apple ID. This eliminates the previous separation between your sign-in identity and your encryption key identity, simplifying your security posture and reducing the risk of identity mismatch.

What makes E2EE different

Most apps say “encrypted” but mean they encrypt your data on their servers — where they still hold the keys and can technically read your content.

With E2EE:

What is encrypted

Fully encrypted (unreadable to us):

These are stored in encrypted envelopes (labeled enc in our database). Without your encryption key, they are meaningless bytes.

AI-derived content (Reflections and Memory Beliefs): Your weekly reflections, non-hidden beliefs, the links between beliefs, and belief history are synced to our servers as encrypted ciphertext so they can be restored on a new device. Hidden beliefs are not synced. We cannot read any of this content. See Sections 1.5 and 11.

What is NOT encrypted (queryable metadata)

Even with E2EE, we store some metadata in queryable form to enable core app functionality. This metadata does not contain what you write, but it does reveal patterns about your usage.

Account information:

Log metadata (for timeline sorting and scheduling):

Event metadata (for timeline sorting and recurrence):

Entry metadata (for daily journal sorting):

Photo metadata:

Tag metadata:

People tag photos: A photo you add to a People tag, including one imported from Contacts, is stored in Firebase Storage without end-to-end encryption.

Important: On records created since July 2026, tag names are encrypted and we store only UUID references that link tags to content. An attacker with access to our database could see “Event A uses Tag B” but not what Tag B’s name is. Exceptions: tag names are still stored readably on body check-ins, wine entries, and Calm entries created with the older editors; on some records created before July 2026; and, rarely, when a tag cannot be matched to its identifier. Person details on tags created before July 2026 may remain readable until the tag is next edited, when they are encrypted.

Calm metadata (for activity-stream pattern detection):

Important: Calm session details — durations, technique selections, and notes — are fully encrypted. The activities discriminator only indicates that an entry contains a meditation or breathwork session; it does not reveal how long the session was, what technique was used, or anything you wrote about it.

AI-derived content metadata: For synced beliefs and weekly reflections, their identifiers, timestamps, format version, the week a reflection covers, and which AI engine produced it.

Notification records and sharing records: See Section 2 (notification records) and Section 3.2 (Shared Entries).

Can metadata be used to reconstruct your content?

No. The queryable metadata we store (timestamps, recurrence patterns, tag UUIDs) cannot be used to reconstruct your journal entries, event descriptions, or other writing. Here’s why:

Without your encryption key (stored in your iCloud Keychain), all content remains permanently unreadable ciphertext.

What we explicitly do NOT store:

Why this metadata is necessary:

This is the trade-off of a functional E2EE journaling app: we need minimal metadata to provide features like timeline sorting and recurring events, but we never have access to what you actually write.

Important exception: Calendar Feed (optional export)

The Calendar Feed is available only with an active subscription. It is visible in Settings for all users but enabled only for subscribers. If you are a subscriber and enable the Calendar Feed (Settings → Calendar Feed), you are explicitly choosing to create a plaintext export of your Events for use with third-party calendar apps like Apple Calendar or Google Calendar. This feature does not change how your data is encrypted — it creates an additional plaintext copy specifically for calendar app compatibility.

Why plaintext? Third-party calendar apps cannot decrypt E2EE content. So when you enable this feature, you’re trading E2EE protection for calendar app compatibility.

How it works: While the Calendar Feed is on, your device writes a readable copy of each included event’s title, description, location, times, and repeat rule to our servers, and we serve it at a private web address (a link containing a secret code). Anyone who has that link can read the feed, so treat it like a password. The feed covers events from 90 days in the past to 12 months ahead. You can turn the feed off, or revoke its link, at any time.

What gets exported:

Important exception: External Access (Connected Apps)

The optional External Access feature (described in Section 11) lets a connected outside app read what Memorist has learned about you (your Memory Beliefs). To make this work, enabling it writes a readable, consent-filtered copy of your shareable beliefs to Memorist’s own servers (Firebase), which our systems read to serve the connected app.

This is a deliberate exception to end-to-end encryption, in the same spirit as the Calendar Feed above. While the feature is on, Memorist stores and can read that shareable subset of your beliefs in plaintext. Key points:

Important exception: Siri, Spotlight & Shortcuts (on your iPhone)

Memorist can make your journal and Memory available to Siri, Spotlight, and Shortcuts on your iPhone. You control each of these with its own switch in Settings → On your iPhone, and you can turn any of them on or off at any time. The defaults are:

This is an exception to end-to-end encryption on your device. Items added to Spotlight are a readable copy kept in Apple’s on-device search index, outside Memorist’s encryption and outside App Lock. They can appear in iPhone search and on your Lock Screen. Siri reads content only when you ask and keeps no copy in Memorist; how Siri itself processes your request is governed by Apple’s terms. This data is not sent to Memorist’s servers.

Turning a Spotlight switch off removes its items from the index, and the Memory items are also removed if your subscription ends. If you hide a belief, it is removed from Spotlight the next time your Memory updates; to remove it immediately, turn Spotlight → Memory of You off and on again.

How your encryption works

Your encryption key is generated automatically on your device when you first create content. This key is stored in your iCloud Keychain — Apple’s secure, encrypted key storage system.

Benefits:

Important to know:

Your Responsibility: Backups and Key Management

Because we cannot access your encrypted content, we do not store backups of your readable data on our servers. It is your responsibility to back up your content. If you lose access to your encryption keys or devices, your content cannot be recovered by Memorist.

This is the trade-off of true end-to-end encryption: your privacy is absolute, but so is your responsibility to protect your data.

How to protect your data:

1. Enable iCloud Backup (Recommended)

2. Use Multiple Devices

What happens if you lose access to iCloud Keychain:

Best practices:

Your Responsibility: Device Security

Because your encryption keys are stored on your device (via iCloud Keychain), the security of your Memorist content depends entirely on the security of your devices.

Since our servers cannot decrypt your content or help with recovery, you must protect your devices and keys. A compromised device means compromised journal content.

Essential security practices:

1. Use a strong device passcode

2. Enable biometric security

3. Enable device encryption

4. Keep your device physically secure

5. Never share your device passcode

6. Keep iOS updated

What happens if your device is compromised:

What Memorist cannot do:

Remember: Your privacy is absolute, but so is your responsibility. The same encryption that protects you from us also protects your content from recovery if you lose access to your devices or keys.

Guest Mode (Getting Started Without Creating an Account)

Even if you start using Memorist in Guest Mode (without creating an account), your data is still protected by E2EE. Your encryption key is tied to your anonymous session. End-to-end encryption applies equally to Guest Mode, Free, and Subscription users — it is a core design principle, not a paid feature.

What Guest Mode includes: Guest Mode provides core journaling features with up to 30 items created in total (including event entries, daily journal entries, and photos; deleting an item does not reset this count) and 1 photo per event entry. Shared Entries is not available in Guest Mode. Certain advanced features are visible in Settings but available only with an active subscription (the current list is shown in the in-app subscription screen). You may also see a banner encouraging account creation for long-term data safety.

Creating an account from Guest Mode: When you create a free account by signing in with your Apple ID, your Guest Mode data and encryption key are automatically preserved and linked to your new account. No data is lost in this transition.

Data Export and E2EE

Memorist provides a data export feature for backup purposes (Settings → Export for backup). This feature is available only with an active subscription; it is visible in Settings for all users but enabled only for subscribers. Important: The export feature does not change how your data is encrypted. It decrypts your content on your device and produces a plaintext backup file. The export process maintains our E2EE security model:

Important: Exported files are not encrypted. This is intentional—the export is designed so you can access your data even if you lose access to Memorist or your encryption keys. Treat exported files like you would treat your physical journal.

Technical Details

For transparency and security researchers:

6. Support Limitations Due to E2EE

Because of our end-to-end encryption architecture, there are important limitations on what Memorist support can help you with.

What We CANNOT Do

We cannot recover your data if you lose access to your encryption keys.

This is not a policy choice — it is a technical reality of end-to-end encryption. Your encryption keys are stored exclusively on your devices via iCloud Keychain. We do not have copies of your keys, and we cannot decrypt your content without them.

Specific scenarios where we cannot help:

× Lost Apple ID or iCloud Keychain access

× Forgotten device passcode

× Account recovery after key loss

× Data access from lost or stolen devices

× Decryption of your content

What We CAN Help With

✓ Technical issues and bugs

✓ Account and billing

✓ General guidance

✓ Privacy and security questions

Why This Limitation Exists

This is the fundamental trade-off of true end-to-end encryption:

You get absolute privacy → We cannot read your content, even if we wanted to.

You accept absolute responsibility → We cannot recover your content if you lose access to your keys.

Most journaling apps offer account recovery because they hold your encryption keys (or don’t encrypt at all). Memorist is different: you hold the only keys, which means you are the only one who can unlock your content.

Before You Contact Support

If you’re experiencing issues accessing your content, please check:

  1. Are you signed into iCloud? (Settings → [Your Name])
  2. Is iCloud Keychain enabled? (Settings → [Your Name] → iCloud → Keychain)
  3. Are you using the same Apple ID that you used when you created your content?
  4. Do you have iCloud Backup enabled? (Settings → [Your Name] → iCloud → iCloud Backup)
  5. Are you signed in on other devices? Try accessing Memorist on another device signed into the same iCloud account.

If none of these steps work and you’ve lost access to your iCloud Keychain, we cannot recover your data. This is by design.

7. Your Content

Your journal entries, images, tags, and reflections are private by default.

You may:

Export formats available:

1. Journal export (.zip)

Download your journal as JSON files via Settings → Export for backup. The export is available to subscribers and requires Face ID, Touch ID, or your device passcode.

Export options:

What’s included: The export covers your journal. What it contains depends on whether your account has been updated to Logs:

What’s NOT included:

Important security notes:

Rationale: The export focuses on your journal. Settings and preferences are device-specific and easily reconfigurable. See Section 5 for details on how export maintains E2EE. If you are not a subscriber, or you need a copy of data the export does not include, contact us at hello@memorist.me.

2. iCalendar (ICS) feed

Optional calendar feed for event entries only (plaintext, opt-in only). Daily journal entries are never included. See Section 5 for details about this plaintext export option.

Backups: Because of end-to-end encryption, we cannot back up your readable content on our servers. You are responsible for backing up your data using the export feature or other backup strategies. See Section 5 (“Your Responsibility: Backups and Key Management”) for recommended backup strategies.

Deleting a single item: When you delete an entry, Log, or photo, it is removed from the App right away and permanently deleted from our servers after 30 days. Deleted tags are hidden but kept until you delete your account.

If you delete your account, associated data may become permanently unrecoverable.

Account deletion: When you delete your account, your data is permanently removed immediately with no grace period or recovery option. This includes:

What may remain: Some records that contain none of your writing in readable form are not currently removed: technical markers that a shared entry could not be opened; the record of which apps you had connected under External Access; other people’s mute settings and in-app notifications that name you; copies of metadata and encrypted content previously sent to our data warehouse (Section 10); and a marker in your iCloud Keychain that you have used Memorist before, which lets the App welcome you back.

Important: Because encryption keys are stored in iCloud Keychain with sync enabled, keys may remain accessible on your other Apple devices after account deletion. Apple provides no API for us to force-delete keys from all devices. However, these keys become useless after account deletion since there is no encrypted data to decrypt.

We cannot restore your account or data after deletion.

8. Children’s Privacy

Memorist is for users 13 years and older.

We do not knowingly collect information from users under age 13.

If you believe a minor under 13 has created an account, please contact us at: hello@memorist.me

9. Third-Party Services

Memorist integrates with Apple’s systems for:

Your use of Apple services is governed by Apple’s own policies.

We are not responsible for:

10. Analytics (Minimal & Respectful)

We use Firebase Analytics (Google Analytics 4) to:

We do not collect the text of your journal entries, or anything the AI writes, for analytics.

What analytics contains: Events describe what you do in the App — for example, which screens you open, that you created an entry or photo on a given date, how many moods you logged, which AI engine produced a reflection and whether it succeeded, and your subscription status. When you are signed in (including in Guest Mode), events are linked to your account identifier, and Firebase also assigns a per-install identifier.

Data warehouse: We keep analytics events, and a copy of the metadata we can already read about your Logs, entries, and events (dates, tag identifiers, timestamps, and similar fields listed in Section 5) together with their encrypted contents, in Google BigQuery in the United States. The warehouse contains nothing we could not already read on our servers. These copies are not currently removed when you delete your account.

Your control: You can turn off analytics in Settings (“Anonymous analytics”). It is on by default. Turning it off stops the App’s own analytics events. Firebase may still record basic automatic events, such as app opens, session length, and in-app purchases. Crash reporting is separate and is not affected by this setting.

Our website: memorist.me uses Google Analytics and Google Ads measurement tags to understand visits and measure App Store downloads from our ads. Website analytics are reported into the same Google Analytics account as the App.

11. AI and Feature Processing

Memorist offers optional AI features that generate the Reflections and Memory Beliefs described in Section 1.5. These features require an active subscription and an available AI model.

On iPhones running iOS 27 or later, Apple Intelligence is selected as your model by default whenever no other model is chosen, whether or not you subscribe. The AI features that generate Reflections, Memory Beliefs, and personalized questions still run only with an active subscription, so the on-device and Apple Private Cloud Compute features (tiers 1 and 2 below) become available as part of your subscription. On earlier versions of iOS, or where no model is available, the features stay off until a model is in place. Because tiers 1 and 2 rely on Apple Intelligence, they are available only if Apple Intelligence is enabled on your device, which you can turn off in your device’s Settings. The third-party provider path (tier 3 below) is never selected automatically — it stays off until you deliberately turn it on. If you remove your third-party key, Memorist switches back to Apple Intelligence on iOS 27 or later (or turns the AI features off on earlier versions) — never to another outside provider.

Where this processing happens depends on which model is in use. There are three tiers, listed from the most private to the least:

1. On your device. By default, and wherever the device is capable of it, AI processing happens entirely on your device using Apple Intelligence and Apple’s on-device machine learning. Apple Intelligence itself requires a supported device running iOS 27 or later. Separately, we use Core ML on-device to classify whether a tag is a Person, Place, or Thing, and, if you use voice entry, your speech is transcribed on your device — these two work on earlier versions of iOS as well. In all of these cases, your content never leaves the device.

2. Apple Private Cloud Compute (for heavier tasks — iOS 27 and later only). Some requests need more computing power than the device can provide on its own. In those cases, Apple Intelligence may send the necessary content to Apple’s Private Cloud Compute (PCC). This path relies on Apple Intelligence, so it is available only on devices running iOS 27 or later. Until you update to iOS 27, Apple Private Cloud Compute is not used at all — it is not active on earlier versions of iOS. When it is available, according to Apple, content sent to PCC is used only to fulfill your request and is not retained afterward, is not accessible to Apple, is not used to train Apple’s models, and runs on software that is publicly verifiable by independent security researchers. Content sent to PCC is not sent to any third party. It is intended to be the default path when on-device processing isn’t sufficient, once Apple enables it on the device.

3. A third-party AI provider, only if you explicitly enable it. If you choose to, you can connect your own account with a third-party AI provider (currently Anthropic’s Claude or OpenAI) by providing your own API key. This is not on by default — you must take deliberate steps to enable it, and we disclose what it does at the point you turn it on. When enabled, the content needed to generate a reflection or belief — relevant entries and, when your Memory is updated, your existing beliefs, hidden ones included (see Section 1.5) — is sent directly from your device to that provider, authenticated with your own key — it does not pass through Memorist’s servers. It is processed under your account and under that provider’s terms. Your use of your own key is governed by your agreement with that provider, which you should review, including how they handle the data you send. You can turn this off at any time by removing the key or disabling the feature. Because this path sends content to an outside company, it is a deliberate exception to the on-device and Apple-only protections above — comparable to the Calendar Feed trade-off described in Section 5.

When Memorist generates your reflections and beliefs, its own servers never see your readable content. These AI requests go from your device to the model — on-device, to Apple PCC, or (with your key) directly to the third-party provider — not through Memorist. The results are stored under end-to-end encryption or on your device, as described in Section 1.5. The one server-side exception is the External Access feature described next: if you turn it on, Memorist places a readable, consent-filtered copy of your shareable beliefs on its own servers so a connected app can be served.

How AI output is checked. Reflections are screened to keep them observational and on topic; when a draft doesn’t pass, you may simply receive no reflection that day. Entries a model consistently refuses to process may be skipped. AI output can still be incomplete or wrong.

We do not use your writing, reflections, or beliefs to train our own models, and we do not sell them. For the on-device and Apple PCC tiers, no third party receives your content. For the third-party tier, your content is handled by the provider you chose, under your own account and their terms.

External memory access

Separately from the AI-model tiers above, you can connect an outside app or AI agent and grant it read access to your memory — that is, let another tool use what Memorist has learned about you (your Memory Beliefs) — and, only if you allow it, let it suggest new memories. This is an independent, opt-in feature. It does not require you to connect a third-party AI provider or supply an API key — you can use it with no AI model of your own selected. It is off by default until you deliberately enable it and authorize a connected app.

How the connection works. Connecting an app is an authorization you grant (an OAuth-style connection you approve and can revoke) — the app does not receive your Memorist password or any API key. Once authorized, the app reads your shareable beliefs from a copy Memorist hosts on its own servers (see “Where this data lives” below). This is different from the third-party-provider path in tier 3: nothing is sent from your device to Claude or OpenAI, and no API key of yours is involved.

Where this data lives — an exception to our encryption. To answer a connected app, enabling External Access writes a readable (non-encrypted), consent-filtered copy of your shareable beliefs to Memorist’s own servers (Firebase), which our systems then read to serve that app. This means that while External Access is on, Memorist does store and can read that shareable subset of your beliefs. It is a deliberate exception to the end-to-end encryption that otherwise keeps your beliefs unreadable to us — the same kind of trade-off as the Calendar Feed (Section 5) and the third-party-provider path above. Beliefs rated “private” (hidden) are never included. When you turn External Access off, this copy is deleted; revoking an individual connected app immediately blocks that app’s access.

Because this feature can expose inferences about you to a system outside Memorist, we treat it as a distinct, opt-in choice, and we record each change you make to a connected app’s access (see below).

Records we keep about external access

So that you can see — and check — what a connected app has actually done, Memorist keeps two records on its own servers while External Access is in use. These records are readable to us (they are not end-to-end encrypted), and you can view them in the App under Access history.

One honest limit. When a connected app states a purpose for a read, that purpose is declared by the app itself. We record it so you can inspect it, but it is not something Memorist can independently verify. The controls Memorist does enforce are the sensitivity level and the topic categories you grant (boundaries, as described above, are shared regardless of topic).

Siri, Spotlight & Shortcuts

Memorist can let Siri answer from your journal and Memory, and can add your non-hidden beliefs and, if you turn it on, your journal entries to your iPhone’s on-device search index. Each of these has its own switch in Settings → On your iPhone, and you can turn any of them on or off at any time. Section 5 (“Important exception: Siri, Spotlight & Shortcuts”) explains the defaults, what is included, and how the Spotlight copy sits outside Memorist’s encryption and App Lock.

12. Data Retention

We retain your information as long as:

Guest Mode data retention: Guest Mode data is associated with your anonymous session and persists as long as the session remains active. If you do not create an account, your data may be subject to removal after an extended period of inactivity. We encourage Guest Mode users to create a free account to ensure long-term data preservation.

Account-based data retention (Free and Subscription): Your data is retained for as long as your account exists, regardless of subscription status. If your subscription lapses or you choose to unsubscribe, your data remains intact and accessible — only subscription-specific features (shown in the in-app subscription screen) are disabled. Unsubscribing never results in data loss.

External Access records (Section 11): the Access history and Permission history we keep for connected apps are automatically deleted 90 days after they are created. You can also clear them yourself at any time in the App. Separately, the readable copy of your shareable beliefs that External Access creates is deleted when you turn the feature off. Memories suggested by connected apps are kept until you delete your account.

Other retention periods: Deleted entries, Logs, and photos are permanently removed 30 days after you delete them. Notification records are kept until you delete your account. Used and expired Shared Entries invites are kept until the person who sent them deletes their account. Data warehouse copies (Section 10) are not currently removed.

When deleting your account, associated data will be removed immediately. There is no grace period or backup retention after account deletion. This is a permanent, hard delete with no recovery option, subject to the limited records described in Section 7 (“What may remain”).

What gets deleted:

What happens to iCloud Keychain: Your encryption key in iCloud Keychain may persist on other devices after account deletion. Apple provides no API for us to force-delete keys from all devices. However, these keys become useless since there is no encrypted data to decrypt.

13. International Use

Data may be stored or processed in different regions to ensure reliability.

By using Memorist, you consent to transfer and processing of your information outside your country, as necessary to provide the service.

Firebase data location: Your data may be stored in Google Cloud Platform regions, primarily in the United States, including our BigQuery data warehouse. What you write is stored as encrypted ciphertext; Section 5 lists the metadata and opt-in copies that are readable.

Cross-border data transfers: Where required by law (including GDPR), we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate protection for international data transfers. These are legally binding commitments between data processors to protect personal data transferred outside the EU/EEA.

Important: Because your content is protected by end-to-end encryption, even if your encrypted data is transferred internationally, it remains unreadable without your encryption keys (which are stored exclusively in your iCloud Keychain).

14. Your Rights

Depending on your jurisdiction, you may have certain rights, including:

Important limitation: Due to end-to-end encryption, if you lose access to your encryption keys (via iCloud Keychain), we cannot recover your content for you. This is by design to ensure true privacy.

We will honor your rights where required by law and will do our best to support reasonable requests.

Control over AI-derived content: For the Memory Beliefs described in Section 1.5, you have direct in-app controls — you can Keep, Edit, Freeze, Hide, or Remove any belief. A removed belief is remembered as removed so it is not suggested again, and a hidden belief is excluded from sync, export, Spotlight, and connected apps (see Section 1.5).

For GDPR (EU) users:

For CCPA/CPRA (California) users:

15. App Store Data Safety Disclosures

Our app store listings reflect our E2EE architecture and minimal data collection practices.

When you view Memorist in the Apple App Store or Google Play Store, you’ll see “Data Safety” or “App Privacy” labels. These disclosures are consistent with this Privacy Policy and reflect our commitment to privacy.

What we report in app stores:

Data Collected:

User Content:

Data Linked to You:

Data Not Linked to You:

Key statement for app stores:

“Memorist uses end-to-end encryption. Your journal entries, events, entry photos, and personal notes are encrypted on your device before syncing. We cannot read what you write. Limited metadata (such as dates, timestamps, and settings) is stored to enable core functionality like timeline sorting, reminders, and multi-device sync.”

Important clarification:

Even though we store your encrypted data on our servers (Firebase):

Exceptions to note (see Sections 3.2, 5, and 11):

For the official breakdown of what data Memorist collects and how it is linked to you, please refer to our App Privacy labels in the App Store.

Verification:

You can verify our data collection practices by:

  1. Reviewing this Privacy Policy
  2. Checking our App Store / Google Play listing
  3. Examining our open-source security architecture documentation (if made available)
  4. Contacting us with specific questions at hello@memorist.me

If you notice any discrepancy between our app store disclosures and this Privacy Policy, please contact us immediately.

16. Changes to This Policy

We may update this Privacy Policy from time to time.

If we make material changes, we will notify you within the App or by other reasonable means.

Continued use of the App after updates indicates acceptance of the revised Policy.

17. Contact Us

If you have questions about this Privacy Policy or your data, contact us:

Email: hello@memorist.me

Website: https://memorist.me

This Privacy Policy is effective as of September 2026 and applies to all users of the Memorist app.