Privacy Policy

    Effective Date: June 13, 2026

    1. Our Commitment to Privacy

    At Memoria, we believe your memories are deeply personal. This Privacy Policy explains how we collect, use, share, and protect your information when you use our platform. We are committed to transparency, data minimisation, and giving you full control over your personal information.

    This policy complies with the Digital Personal Data Protection Act, 2023 (DPDP Act), the DPDP Rules, 2025, and the Information Technology Act, 2000.

    2. Who We Are (Data Fiduciary)

    Memoria is a product of QUANTARACORE TECHNOLOGIES LLP, founded by Krishna Santosh Varma. Registered office at Sarafa Line, Sawkarpura, Anjangaon, District Amravati, Maharashtra, India. We are the Data Fiduciary responsible for your personal data.

    Grievance Officer (IT Rules, 2021): Krishna Santosh Varma (Founder)

    Data Protection Contact (DPDP Rule 9): Krishna Santosh Varma (Founder)

    Email: hello@memorias.in

    Response Time: Within 72 hours

    3. Information We Collect

    We collect only what is necessary to provide the Service:

    • Account Information: Name, email address, phone number, and profile information you provide during registration
    • User Content: Photos, videos, captions, comments, messages, and memories you create or upload
    • AI Processing Data: When you enable AI Features, your photos and captions are transmitted to OpenAI (GPT) and/or Google (Gemini) for processing (see Section 6)
    • Biometric Data: Face geometry descriptors and face templates - ONLY if you explicitly opt in to Face Detection & Organization (see Section 7)
    • Usage Data: Feature usage, session behavior, and interaction patterns via our in-house analytics system
    • Device Information: Device type, OS version, and app version for security and compatibility purposes

    4. How We Use Your Information

    • To provide, operate, and maintain the Service
    • To enable AI Features when you choose to use them (photo captions, memory journal, companion)
    • To enable Face Detection & Organization when you explicitly opt in
    • To personalise your experience within the app
    • To communicate important updates, security alerts, and service notifications
    • To analyze usage patterns and improve product features
    • To ensure the security and integrity of the platform
    • To comply with legal obligations and respond to lawful requests

    5. What We Don't Do

    • We do not sell your personal data to anyone, ever
    • We do not show you targeted advertisements
    • We do not use your memories or content to train AI models (our AI providers also do not train on your data - see Section 6)
    • We do not share your personal content with third parties for commercial purposes
    • We do not perform cross-account facial recognition or identification
    • We do not use dark patterns to obtain consent

    6. AI Features & Third-Party AI Providers

    Memoria offers optional AI-powered features. When you enable these features, specific data is transmitted to third-party AI providers for processing:

    AI FeatureProviderData Transmitted
    AI Photo CaptionsGoogle Gemini API (Google LLC, USA)Photos, for caption generation
    AI Memory JournalOpenAI GPT API (OpenAI, L.L.C., USA)Photo metadata, captions, context for journal generation
    AI CompanionOpenAI GPT API (OpenAI, L.L.C., USA)Text prompts and conversation context
    AI Photo OrganizationMemoria (server-side processing)Photos, processed on our AWS India servers

    Key facts about AI data processing:

    • OpenAI (GPT): Does NOT use data submitted through its API to train or improve its models. Your inputs and outputs are retained for abuse monitoring (typically 30 days) only.
    • Google (Gemini): We use the paid/enterprise tier. Per Google's API Services User Data Policy, Google does NOT use your data to train its models.
    • All AI features are OPTIONAL - you control them through app settings.
    • AI provider servers are located outside India (United States). Appropriate contractual safeguards are in place.
    • Face data is NEVER sent to OpenAI or Google (see Section 7).

    Relevant third-party terms: OpenAI Terms, OpenAI Usage Policies, Gemini API Terms.

    7. Face Detection & Biometric Data

    Memoria offers an optional Face Detection & Organization feature. This feature processes Biometric Data (face geometry descriptors and face templates) to detect and group photos of the same individuals across your library.

    This feature is STRICTLY OPTIONAL and OFF by default. You must provide a separate, explicit opt-in consent to enable it - it is never bundled with general Terms acceptance or other feature consent.

    How face data is handled:

    • Face templates are created and stored on our AWS servers in India (Mumbai region)
    • Face data is linked exclusively to your account
    • Face grouping works only within your own photo library and Circles you belong to
    • Face data is NEVER transmitted to OpenAI, Google, or any third-party AI provider
    • Face data is NEVER sold, shared, or used for advertising
    • We do NOT perform cross-account facial recognition
    • We do NOT match face data against external databases

    Your control over face data:

    • You may withdraw consent at any time in app settings (as easy as giving consent)
    • Upon withdrawal: face detection stops immediately for new photos
    • Existing face templates are deleted within 30 days
    • Deleting source photos also deletes associated face templates (see Section 11)
    • Account deletion removes all face data permanently

    Under the DPDP Act, 2023, Biometric Data is classified as sensitive personal data requiring heightened protection and explicit consent. By enabling Face Detection & Organization, you provide that explicit consent.

    8. Analytics and Tracking

    We use an in-house custom analytics system to track page views, feature usage, and session behaviour to help us understand how users interact with our platform. This system does not share any personally identifiable information with third parties. No third-party advertising or behavioural tracking tools are used on this platform.

    You may opt out of analytics tracking by contacting us at hello@memorias.in.

    9. Infrastructure & Service Providers

    To operate Memoria securely and reliably, we work with the following trusted infrastructure and service providers. These providers act as data processors on our behalf and are contractually bound by Data Processing Agreements (DPAs) to protect your data. They do not use your data for their own commercial purposes.

    ProviderPurposeData Location
    Amazon Web Services (AWS)Cloud hosting, photo storage, CDN, backend infrastructureIndia (Mumbai / ap-south-1)
    Google Firebase / Google CloudAuthentication, database, push notificationsAs configured by the Service
    SupabaseWebsite database and backend infrastructureIndia region
    VercelWeb application hostingGlobal edge network
    Cloudflare R2Photo and media storageAs configured by the Service
    OpenAI, L.L.C.AI text generation (GPT API)United States
    Google LLC (Gemini API)AI photo caption generationUnited States

    Cross-Border Data Transfer: Some providers (OpenAI, Google Gemini) process data in the United States. We ensure appropriate safeguards including Standard Contractual Clauses (SCCs) and Data Processing Agreements, in compliance with DPDP Act Rule 15.

    10. Shared Content in Circles

    Circles are shared memory spaces where you can invite family and friends. Content added to a Circle is visible to all members you have invited. If a member leaves a Circle, they will no longer have access to its content. You, as the Circle creator, remain in control of who can view and contribute to your shared memories. We encourage you to only invite people you trust.

    Content shared with Circles may remain visible to Circle members even after you delete your account, as those members also have a right to their shared memories.

    11. Data Storage, Retention & Deletion

    Your data is stored on servers located in India (primarily AWS Mumbai) and processed in accordance with Indian data protection laws. We are committed to keeping your memories close to home.

    Retention:

    • Active accounts: Data retained until you delete content or close your account
    • Inactive accounts (no login for 3+ years): Data may be permanently deleted after prior notice
    • Deleted content: Removed from active storage immediately; Derived Data (AI captions, tags, face templates) deleted alongside the original file
    • Encrypted backups: Up to 90 days for disaster recovery, then permanently purged

    You may delete your account at any time from within the app. Upon deletion, your personal data and memories will be permanently and irreversibly removed from our systems within 30 days. Aggregated, anonymised usage statistics that cannot be linked back to you may be retained for analytical purposes.

    Before deleting your account, you may request an export of your data in a standard, machine-readable format. Contact us at hello@memorias.in.

    12. Data Security

    We implement industry-standard security measures to protect your data:

    • Encryption in transit (TLS) and at rest (AES-256)
    • Access controls with role-based permissions and least privilege principles
    • Multi-factor authentication for administrative access
    • Regular security audits and vulnerability assessments
    • Data Processing Agreements with all third-party providers
    • Complete audit logs retained for a minimum of 1 year

    While we implement robust safeguards, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.

    13. Data Breach Notification

    In the event of a personal data breach, we will:

    • Notify the Data Protection Board of India without delay upon becoming aware of the breach
    • Submit a detailed report to the Board within 72 hours, including root cause, scope, number of affected users, and remedial measures
    • Notify affected users without undue delay via email and/or in-app notification
    • Describe the nature of the breach, categories of data affected, likely consequences, and measures taken
    • Provide recommendations for affected users to mitigate potential adverse effects

    14. Your Rights Under the DPDP Act, 2023

    As a Data Principal under India's Digital Personal Data Protection Act, 2023, you have the following rights:

    • Right to Access: Request a summary of personal data we hold about you and how it is being processed
    • Right to Correction: Request correction of inaccurate, incomplete, or outdated personal data
    • Right to Erasure: Request deletion of your personal data when the purpose is served or consent is withdrawn
    • Right to Withdraw Consent: Withdraw consent at any time through the app settings. Withdrawal shall be as easy as giving consent
    • Right to Grievance Redressal: Raise a complaint with our Grievance Officer regarding your data processing
    • Right to Nominate: Nominate another individual to exercise your rights in the event of your death or incapacity
    • Right to Data Portability: Request export of your data in a standard, machine-readable format

    To exercise any of these rights, contact us at hello@memorias.in. We will respond within 72 hours and resolve requests within 30 days.

    Escalation: If you are not satisfied with our resolution, you have the right to file a complaint with the Data Protection Board of India established under the DPDP Act, 2023.

    15. Grievance Officer

    In accordance with the Information Technology Act, 2000, the IT Rules, 2021, and the DPDP Act, 2023:

    Name: Krishna Santosh Varma

    Designation: Founder, QUANTARACORE TECHNOLOGIES LLP

    Email: hello@memorias.in

    Postal Address: Sarafa Line, Sawkarpura, Anjangaon, District Amravati, Maharashtra, India

    Acknowledgment: Within 24 hours | Resolution: Within 72 hours

    16. Children's Privacy

    In compliance with Section 9 of the DPDP Act, 2023:

    • Memoria requires users to be at least 18 years of age to use the Service independently
    • Users aged 13 to 17 require verifiable parental consent
    • The Service is not intended for children under 13. We do not knowingly collect personal data from children under 13
    • We do not engage in tracking, behavioral monitoring, or targeted advertising directed at children
    • If you believe a child has provided us with personal information without parental consent, please contact us immediately at hello@memorias.in and we will take steps to remove such information

    17. Changes to This Policy

    We may update this Privacy Policy from time to time. When we do, we will revise the effective date at the top of this page and notify you through the app or via email for material changes, at least 14 days in advance. We encourage you to review this policy periodically.

    18. Contact Us

    If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please reach out to us at hello@memorias.in.

    Registered Office:

    Quantaracore Technologies LLP
    Sarafa Line, Sawkarpura, Anjangaon
    District Amravati, Maharashtra, India

    We aim to respond to all privacy-related queries within 72 hours. CSAM reports receive immediate action.

    Also see our Terms of Service