Privacy Policy
The short version
- Your own memories live on your device and (optionally) in your own iCloud. We don't have a copy of your personal book.
- When you send a memory or a book to someone, that specific share is briefly stored on our infrastructure so the recipient can fetch it. You can withdraw it at any time.
- When you add a memory to a family book, that entry is stored on our infrastructure for as long as the book exists, so every member of the book can read it. You can remove your entries at any time.
- If you sign in with Apple to receive shares or join a family book, we keep an account record so we know which shares and books belong to you. That's it.
- App usage and diagnostics are optional and off until you make a separate choice. They never include your memory content and are never joined to your account.
- We don't sell your data. We don't train AI models on your memories.
What you provide
- Your memories — text, audio recordings, photos, tags, dates you create in the app.
- Preferences — notification choices, privacy defaults, subscription status.
- Sign in with Apple (optional) — your Apple ID stable identifier and the email or relay address Apple gives us. Used to associate received shares with your account.
Where your data lives
On your device
All memories are stored locally on your iPhone. If you never enable iCloud sync or use an optional sharing, Family Book, or Guided Session feature, your memories never leave your device.
Your iCloud (optional)
If you enable iCloud sync, your memories are stored in your personal iCloud account using Apple's CloudKit. Only you (and Apple, per their own policy) can read it. We can't.
Shares on our infrastructure (only when you share)
When you give a memory or whole book to someone — typing their email, hitting Send — the content of that share is sent to our infrastructure (a Cloudflare Worker, Cloudflare KV for metadata, Cloudflare R2 for media files). We hold it long enough for the recipient to fetch it. The default expiration is one year; you can withdraw a share before that, in which case the recipient can no longer open it. Shares are encrypted in transit (HTTPS) and at rest (Cloudflare's storage encryption).
Family books (only when you join one)
A family book is a shared book that several signed-in members write together. Entries you add to a family book — including their recordings and photos — are stored on the same infrastructure for as long as the book exists, because every member must be able to read them. Reading is restricted to approved members of that book. You can remove your own entries at any time; the book's keeper can remove any entry and can close the book. Removing an entry deletes its media from our servers. Your name, as you entered it when joining, is shown next to your entries to the other members.
Email delivery
Share notifications and confirmations are delivered through Resend. The recipient's email and the share's public URL are passed to Resend solely for delivery. Resend does not retain the body of the email beyond what's needed to send it.
AI Interviewer (optional)
If you use the optional Guided Session feature, the text of your typed or transcribed answer is sent to our AI follow-up service to produce one follow-up question. Our service forwards it to an AI provider (currently Anthropic) for the immediate response only — it is not stored or used to train models. Audio is never sent to the AI provider, and transcription happens locally. An audio file leaves your device only when you explicitly share the memory that contains it.
App usage and diagnostics (optional)
Heirloom asks separately before collecting analytics. The choice is off until you opt in, does not unlock or remove any feature, and can be changed at any time under You → Privacy. You must be at least 16 to make this choice yourself. If you are under 16, leave analytics off.
If you opt in, we collect fixed, predefined events such as completing onboarding, saving or deleting a memory, completing a recording, viewing the membership page, starting or completing a purchase, sharing, joining a family book, and whether an operation succeeded. We also collect app version and build, iOS version, device class (phone or tablet), language, coarse count or duration ranges, and limited crash, hang, disk-write, and performance count ranges supplied by Apple's MetricKit. We do not collect memory text, titles, notes, tags, search words, transcripts, prompts, recordings, photos, names, email addresses, Apple IDs, contacts, precise purchase value, share tokens, links, raw error messages, stack traces, advertising identifiers, or location.
Analytics use a random installation identifier that is kept separately from your memories and account. Apple App Attest verifies that registrations come from a genuine copy of Heirloom. Our application does not write IP addresses to the analytics database; Cloudflare processes connection information to deliver requests and rate-limit abuse under its own privacy and data-processing terms. We keep the analytics database in the European Union, use a separate Cloudflare D1 database with encryption in transit and at rest, and keep Worker observability off for this service. If we enable operational email alerts, they are delivered through Resend and contain only an incident number, metric name, threshold, and collection mode, never an analytics event or installation identifier.
Pending events stay on your phone for no more than seven days and the queue holds at most 500 events. Server event history is kept for at most 45 days, and an inactive installation credential is removed after 60 days. We retain only grouped totals for up to 13 months, and a group is saved only when it contains at least five installations. When you turn analytics off, collection stops, the local queue and identifier are removed, and Heirloom asks the server to erase the live event and installation rows linked to that installation. If the phone is offline, the deletion request remains protected on the phone and retries later. Cloudflare's always-on, encrypted D1 recovery history can retain an earlier database state for up to 30 days before it expires automatically. Heirloom does not query that recovery history for analytics and does not restore production analytics from a point before a deletion; if the analytics database is lost, we start with an empty database instead. Grouped totals already combined with at least four other installations cannot identify or be separated back to one installation, so those totals remain.
Alma Innovations Ltd. is the controller for these analytics. We process them only with your consent and only to understand product use, conversion, retention, and reliability. We do not use them for advertising, cross-app tracking, eligibility decisions, or sale. Contact support@heirloom-book.com for access, objection, or deletion questions.
Permissions we request
- Microphone — to record your voice memories.
- Photos — to attach images to memories.
- Camera — to take new photos from inside the app.
- Speech Recognition — to transcribe audio into text (Apple's on-device speech APIs).
- Notifications — optional, for gentle reminders to capture memories.
We do not request location access. We do not access your contacts.
What we don't do
- We don't sell your data.
- We don't use your memories to train AI models.
- We don't track you across other apps.
- We don't run analytics on the content of your memories.
- We don't share your memories with advertisers.
Your rights
- Access — everything you create is visible in the app. Settings → Export every entry, photo, and recording downloads a single zip file with everything inside.
- Delete — delete individual memories any time. Settings → Reset All Data wipes everything on-device. If you use iCloud sync, deleting in the app deletes from iCloud.
- Withdraw a share — Settings → Shares you've sent shows everything you've sent. Tap Withdraw to make a share no longer openable. The link in the recipient's email will show "this share was withdrawn."
- Remove family-book entries — open the entry in the family book and choose Remove from the book. The entry and its media are deleted from our servers for all members. To leave a book entirely, remove it from your Shelf and ask the keeper to remove you as a member.
- Delete your account — You → Sign out & account → Delete my account removes your server-side account record, sessions, Shelf indexes, sent shares, Family Book membership, and entries you posted, including their media. If you created a Family Book, stewardship passes to another active member when possible; an empty book is removed. You can also email support@heirloom-book.com and we'll do it for you.
- GDPR / CCPA — if you are in the EEA, UK, or California you have additional rights including portability, rectification, and objection. Export gives you portability. Contact support for the rest.
Subscription data
When you subscribe to Heirloom membership, Apple processes your payment through the App Store. We do not receive your Apple ID, email, payment details, or personal information — only a StoreKit 2 token confirming subscription status. To cancel, manage your subscription in Settings → Apple ID → Subscriptions.
Children
Heirloom is not directed at children under 13. We do not knowingly collect information from children under 13. Optional analytics are unavailable to anyone under 16, who should leave analytics off.
Changes to this policy
We'll update the "Last updated" date and — for material changes — notify you inside the app the next time you open it.
Contact
Questions, concerns, or data requests:
support@heirloom-book.com
Alma Innovations Ltd.