Privacy Policy
Last updated: August 22, 2026
1. Introduction
MemoryVault ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our Service.
2. Information We Collect
We collect the following types of information:
- Personal Information: Name, email address, and payment information provided during account creation and checkout.
- User Content: Photos, captions, messages, and other content you upload to create your memory vault.
- Usage Data: Information about how you interact with the Service, including pages visited, time spent, and device information.
- Cookies and Local Storage: We use browser storage to save your preferences and draft progress locally on your device.
- Analytics and Session Recording: With your consent, we use Google Analytics and Microsoft Clarity. Clarity records how you navigate our public pages — cursor movement, clicks, and scrolling — so we can see where the site is confusing or broken. Your photos, email address, names, and captions are masked in these recordings: we see the shape of the page and what you clicked, never your content. Recording is disabled entirely on museum pages and on edit links. None of this loads until you accept analytics cookies, and you can withdraw that consent at any time.
3. How We Use Your Information
We use your information to:
- Provide and maintain the Service, including creating and hosting your memory vaults.
- Process payments and send transaction confirmations.
- Communicate with you about your account, updates, and support requests.
- Improve and optimize the Service based on usage patterns.
- Comply with legal obligations.
4. Data Storage and Security
We take reasonable measures to protect your personal information:
- Photos and content are stored securely using encrypted cloud storage.
- Payment information is processed by our secure payment provider and is never stored on our servers.
- We use HTTPS encryption for all data transmitted between your browser and our servers.
- Access to user data is restricted to authorized personnel only.
5. Data Sharing
We do not sell your personal information. We may share your data with:
- Service Providers: the companies that make the Service run. Today these are Supabase (database and photo storage), Dodo Payments (payment processing), Resend (transactional email) and Vercel (hosting). Each receives only what it needs to do its job, and none of them is allowed to use your content for its own purposes.
- Analytics Providers (only if you consent): Google (Analytics) and Microsoft (Clarity, session recording). They receive page-level usage data and, for Clarity, a recording of your navigation on public pages with your photos and personal fields masked. Nothing is sent to either until you accept analytics cookies.
- Legal Requirements: When required by law, regulation, or legal process.
- Vault Recipients: When you share your vault link, recipients can view the content you have chosen to include.
6. Your Rights
You have the right to:
- Access and receive a copy of your personal data.
- Request correction of inaccurate personal data.
- Request deletion of your personal data and vault content.
- Withdraw consent for data processing at any time.
- Object to the processing of your data for certain purposes.
To exercise any of these rights, please contact us at the email address provided below.
7. Data Retention
We keep your content only while there is a reason to:
- Museums you paid for: for as long as the museum exists. Access is for life, so we keep your photographs until you ask us to delete them or delete the museum yourself.
- Drafts you never paid for: about 72 hours. We email you one reminder with a link to finish, and then the draft and its photos are deleted automatically.
- Payment and invoicing records: kept for as long as tax and accounting law requires, independently of the museum.
If you ask us to delete your data, we remove it within 30 days, except where retention is required by law.
8. Children's Privacy
Only adults aged 18 or over may purchase or create an account. Children may not contract the Service themselves.
Some of our museum themes — such as Baby's First Year and Graduation — exist specifically to collect photographs of children. Where that happens, we process those images only in the best interests of the child and only on the specific, prominently given consent of at least one parent or legal guardian, as required by Article 14 of the Brazilian LGPD and Article 8 of the GDPR.
By uploading a photograph of a child you confirm that you are their parent or legal guardian, or that you have that person's express authorisation. Children's data is never used for advertising, profiling, AI training, or shared with third parties for marketing, and we do not require more data about a child than is strictly necessary to build the museum you purchased. Location metadata (GPS EXIF) is stripped from every photograph on upload.
A parent or legal guardian may request access, correction, or immediate deletion of a child's images and data at any time, free of charge and without giving a reason, by writing to dreamgridbr@gmail.com.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. We ensure that appropriate safeguards are in place to protect your data in accordance with this Privacy Policy.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page with a revised "Last updated" date. Your continued use of the Service after changes are posted constitutes your acceptance of the updated policy.
11. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact us at dreamgridbr@gmail.com. This is the same address for support, privacy requests and data deletion — there is no separate queue, and we answer every message ourselves.