Legal

Privacy Policy

What we collect, what we do with it, and what we never do.

The short version. We collect the minimum we need to run the service. We never sell your data. We never train public AI models on your memoir content. You can export or delete everything any time. Your memoir content is encrypted at rest and in transit.

1. What we collect

Account data

Memoir content

Usage data

2. How we use it

3. What we never do

4. Sub-processors (who else touches your data)

VendorPurposeData shared
StripePaymentsName, email, billing address, card info
ResendEmail deliveryName, email, email content
DeepgramVoice transcriptionVoice recordings (no retention)
AnthropicAI text generationMemoir answers (no retention, no training)
CloudflareCDN + DNSIP, browser, page views
Railway / AWSApplication hostingAll data (encrypted at rest)

Full list + contracts: Data Processing Agreement.

5. Where we store it

Primary storage is in US data centers. We use geographic replicas for redundancy and latency. EU customers can request EU-only storage (Family and above).

6. How long we keep it

7. Your rights (GDPR / CCPA / PIPEDA)

Submit any request to privacy@theheirloom.ai. We respond within 30 days.

8. Security

See Security page.

9. Children

Heirloom is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us data, email privacy@theheirloom.ai and we will delete it.

10. Posthumous content

If a memoir subject passes away, their content remains under the original purchasing account's control per Consent Policy. On request from verified next of kin, we will transfer ownership or honor deletion requests consistent with the original consent.

11. Cookies & tracking

See Cookie Policy.

12. Changes

Material changes will be notified by email 30 days before taking effect.

13. Contact

Data Protection Officer · Heirloom, Inc. · privacy@theheirloom.ai