Privacy

Selected photos. Clear boundaries.

Last updated September 20, 2026

In plain English

Memento is operated by Ramey Ventures LLC. We turn only the photos you choose into a personal editorial recap. It is not designed to scan your full photo library, build an advertising profile, or sell your personal information. Your Memento stays private unless you deliberately create a share link.

What Memento handles

Photos you select

You choose 30–150 images through Apple’s system photo picker. On-device preparation may load those selections, remove duplicates, identify screenshots, locate text for layout, make small thumbnails and contact sheets, and strip unnecessary metadata. We do not automatically mask visible content or reject selected photos based on document text or barcodes. The app temporarily reads selected originals to prepare smaller copies. Original full-resolution files are not uploaded to our servers.

Generation evidence and your deck

We send prepared photo copies, contact sheets and crops, available dates and place labels, dimensions, and derived photo information to our servers and OpenAI to create your Memento. Derived information can include face locations, counts, and groups of recurring people within your selected roll. Face-recognition embeddings used for local grouping stay on your device; the resulting grouping information may be uploaded. For gifts, we also process the names, occasion, relationship details, and recipient selections you provide. We store the resulting recap and Keepsakes, access records, and operational information needed for recovery, duplicate prevention, and support.

Share links you create

Public-link sharing is optional. When you confirm that anyone with the link may view, save, screenshot, and reshare your Memento—and that you have the right to share it—Memento uploads the completed recap’s 9–16 flattened, metadata-sanitized 1080 × 1920 PNG cards for format validation and hosting. A public share never includes your original photos, photo-library identifiers, source metadata, private generation evidence, editable deck data, account identity, or private storage address.

The link is a high-entropy bearer link: anyone who receives or forwards it can open and save the cards without signing in. Shared pages ask search engines not to index them, but that is not an access-control guarantee. A recipient may retain a copy after you replace or stop the link.

When someone opens a shared Memento, we count the visit so its owner can see how many times it was viewed. For these measurements and abuse prevention, our service receives the visitor’s network address and records a shortened network prefix, keyed identifiers, approximate city or region, browser and device information, and viewing activity. These measurements do not use cookies. Hosting providers also process request information to deliver and secure the page.

Visits to our marketing website

Our marketing website uses Vercel Web Analytics to measure page visits, referral sources, approximate location, and browser or device categories. It uses request-derived identifiers instead of third-party cookies and provides aggregate traffic statistics. This website measurement is separate from the optional product analytics setting in the iOS app. See Vercel’s analytics privacy information.

Account, purchase, and technical data

Memento may process privacy-preserving installation or Apple continuity identifiers, StoreKit transaction records, job state, cost and latency measurements, and tightly limited product events. For public-link safety, Memento also keeps moderation decisions, reports, and a one-way publisher pseudonym that lets a visitor block links from the same publisher without revealing the publisher’s account. Reporter network context is converted server-side into a keyed one-way fingerprint for abuse prevention; raw network addresses are not stored in the report record.

Optional product analytics is off by default and can be changed in Settings. It uses random or one-way identifiers linked to app activity, along with bounded events such as creation, purchase, and sharing actions. It excludes photos, private generated copy, text extracted from photos, prompts, signed links, and raw Apple purchase payloads. Service and security records needed to operate Memento are separate from this optional setting.

How information is used

  • Prepare the selected roll and generate the requested recap and Keepsakes.
  • Validate safety, accuracy, supported layouts, and generation authorization.
  • When you choose to share, validate and host the flattened cards behind the share link you control and investigate reports about shared content.
  • Resume interrupted work, prevent duplicate bills, restore eligible paid decks, and answer support requests.
  • Protect the service from abuse and measure reliability without using private photo content for general analytics.

Retention

  • Original photos: remain in your photo library or iCloud; we do not upload the original full-resolution files.
  • Temporary generation evidence on our servers: scheduled for deletion when recovery no longer requires it, with a 24-hour retention target. Failed cleanup is retried. This target is separate from OpenAI’s retention described below.
  • Included-first recap data: may remain server-side for up to 30 days for recovery, duplicate protection, and support. Prepared private sharing images have a 30-day idle retention period. Saved local recaps remain until you delete them or remove the app; generated Keepsakes and other recovery assets follow their associated Memento’s deletion lifecycle.
  • Paid or subscription-created decks: retained for recovery until you delete the Memento or all Memento data.
  • Public-link cards: retained while the link is active. Stopping the link or deleting its Memento removes public access and schedules the hosted copies for deletion, but it cannot recall copies someone already saved or reshared.
  • Moderation, report, and security records: retained only as needed to review reports, prevent abuse, meet legal obligations, and demonstrate safe operation.
  • Optional product analytics: detailed events are scheduled to expire within 31 days.
  • Operational and purchase records: kept only as required for product operation, security, accounting, and legal obligations.

Service providers

Memento uses Apple for photo selection, app distribution, and purchases; Supabase for account, database, and storage services; Vercel for hosting and request delivery; and OpenAI for server-side editorial generation. Creating a public link does not trigger a separate OpenAI safety review. Providers process the information needed to deliver and secure their services under their applicable terms. Our service and providers may process information in the United States and other countries.

OpenAI’s API data is not used to train its models by default. Its default abuse-monitoring retention may keep submitted content for up to 30 days, with exceptions for legal requirements and protecting people or services from harm. We do not promise Zero Data Retention. See OpenAI’s data controls for details.

Your choices

If payment is required for a later generation, you can dismiss the offer and keep the protected unfinished draft. You decide whether to publish a read-only share link and can remove public access from the app at any time. You can also delete an individual Memento or request deletion of all Memento data from Settings. Apple manages App Store purchase and subscription controls. Already exported, downloaded, screenshotted, or reshared files cannot be recalled after deletion, revocation, or refund.

Contact

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, object to or restrict processing, and complain to a privacy authority. Contact us to make a request; we may need to verify your connection to the data. We do not sell personal information or use it for cross-company advertising tracking.

Ramey Ventures LLC handles privacy questions and deletion issues at support@makeamemento.com.