1. What we collect
Account data
- Name, email, password (hashed with bcrypt), locale preference.
- Billing information (handled by Stripe; we never see your card number).
Memoir content
- Answers you type, voice recordings you upload, photos, video.
- AI-generated transcripts, translations, and chapter drafts derived from your input.
- Sharing metadata (who you invited, when they accessed content).
Usage data
- Pages visited, actions taken, timestamps, IP address, browser, device.
- Referral source (how you found us).
2. How we use it
- To provide the service (auth, storage, AI processing, email delivery).
- To process payments (via Stripe).
- To send transactional emails (welcome, verification, password reset, interview reminders).
- To improve product quality (aggregate, anonymized usage metrics only).
- To prevent fraud, abuse, and violations of our Acceptable Use Policy.
3. What we never do
- We do not sell your data. Not to advertisers, not to data brokers, not to anyone.
- We do not train public AI models on your memoir content. AI processing happens per-request, under contract with providers who are prohibited from retaining or training on your content.
- We do not read your memoir content for marketing. Only automated systems and on-request human support access it.
- We do not share with family members you haven't invited.
4. Sub-processors (who else touches your data)
| Vendor | Purpose | Data shared |
|---|---|---|
| Stripe | Payments | Name, email, billing address, card info |
| Resend | Email delivery | Name, email, email content |
| Deepgram | Voice transcription | Voice recordings (no retention) |
| Anthropic | AI text generation | Memoir answers (no retention, no training) |
| Cloudflare | CDN + DNS | IP, browser, page views |
| Railway / AWS | Application hosting | All data (encrypted at rest) |
Full list + contracts: Data Processing Agreement.
5. Where we store it
Primary storage is in US data centers. We use geographic replicas for redundancy and latency. EU customers can request EU-only storage (Family and above).
6. How long we keep it
- Active accounts: indefinitely, while you're a paying customer.
- Cancelled accounts: 30-day grace period to reactivate or export, then permanent deletion.
- Billing records: 7 years (tax/legal compliance).
- Audit logs: 12 months.
7. Your rights (GDPR / CCPA / PIPEDA)
- Access — request a copy of everything we hold about you.
- Correction — fix inaccurate data.
- Deletion — "right to be forgotten."
- Portability — export in a machine-readable format.
- Objection — opt out of processing you disagree with.
- Do Not Sell / Share (CCPA) — we don't sell or share, but you can formally confirm this status.
Submit any request to privacy@theheirloom.ai. We respond within 30 days.
8. Security
- TLS 1.3 encryption in transit.
- AES-256 encryption at rest.
- bcrypt-hashed passwords with per-user salt.
- Row-level access controls (you can only see your own data).
- SOC 2 Type II audit in progress (target: Q4 2026).
See Security page.
9. Children
Heirloom is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us data, email privacy@theheirloom.ai and we will delete it.
10. Posthumous content
If a memoir subject passes away, their content remains under the original purchasing account's control per Consent Policy. On request from verified next of kin, we will transfer ownership or honor deletion requests consistent with the original consent.
11. Cookies & tracking
See Cookie Policy.
12. Changes
Material changes will be notified by email 30 days before taking effect.
13. Contact
Data Protection Officer · Heirloom, Inc. · privacy@theheirloom.ai