Legal · Privacy
Privacy Policy
Last updated: 27 September 2026
Your memories stay yours. Privacy is the default in Human Memory Cloud: private memories remain private unless you intentionally authorise another use. This policy explains what we collect today, how it is protected, and the rules that will govern planned AI features.
Part A — Current features
1. Who we are
Human Memory Cloud is operated by DrexPoint Limited (“we”). For privacy questions, email Nwosusamson2009@gmail.com.
2. Information we collect today
- Account and authentication: email address and a securely hashed password (we never see or store your plain password), or basic Google account details (name, email) if you choose Google sign-in; sign-in timestamps.
- Profile: display name and optional settings you add.
- Memories: titles, stories and written reflections, dates, locations, categories, people you name, tags, memory type, favourite status and privacy label.
- Uploaded files: photos, videos, audio recordings and documents (up to 50 MB each), with file name, type and size.
- Technical information: standard server and security logs such as IP address, browser type and request times, used to run and protect the service.
3. Cookies and browser storage
We store a sign-in session in your browser so you stay logged in. We do not store your memories or files in the browser, we do not use advertising cookies, and we do not currently use any analytics tools.
4. How we use information
- to create and secure your account and let you sign in, including password-reset emails;
- to store, display, search and organise your memories for you;
- to keep the service secure, prevent abuse and fix problems;
- to contact you about your account or important changes.
We do not sell your data, use it for advertising, or use your memories to train AI models.
5. Storage, authentication and service providers
Your account, memories and files are stored with our managed cloud backend, which provides the database, authentication and private file storage. Google provides sign-in if you choose it. Our website is hosted on a cloud hosting platform. These providers process data on our behalf to run the service.
6. Security practices
- Database access rules ensure each signed-in user can read and change only their own profile, memories and file records.
- Files are kept in private storage with no public web address; each user’s files sit in a folder only they can access, and files open through short-lived links.
- Private vault pages are excluded from search engines.
- Automated privacy tests regularly check that signed-out visitors and other users cannot access your data.
- Connections to the site use HTTPS.
No system is perfectly secure, and we do not claim any specific certification.
7. Your privacy controls
Every memory is private by default. You can edit or delete memories and their files at any time. The PRIVATE / SHARED / PUBLIC label is stored today, but no sharing feature exists yet, so every memory is currently visible only to you. Nothing becomes public automatically.
8. Retention and deletion
We keep your data while your account is active. Deleting a memory removes the memory record and its uploaded files from active storage. You may request deletion of your whole account and data by emailing us; we will delete it within 14 days of your request. Residual copies in backups may persist for up to 30 days before being overwritten.
9. Children and other people in your memories
You must be at least 13 years old to use Human Memory Cloud. Users under 18 need permission from a parent or legal guardian.
Memories often include children, family, friends and other identifiable people, their photos, voices or writing. Please only upload what you have the right to store and respect their privacy. Uploading someone’s image, recording or writing does not give you rights over their voice, likeness or private information.
10. International processing
Our providers may process data in countries other than the one you live in. Where that happens, we rely on the safeguards offered by those providers.
11. Your rights
Depending on where you live, you may have rights to access, correct, delete or export your data, or object to certain processing. Email us to exercise them. If you ask for a copy of your data, we will provide it within 30 days.
Part B — Planned / future AI features
Planned · not yet available
12. Four separate permissions
- Memory storage — saving to your vault. Does not authorise AI.
- AI use — opt-in, only for memories you select. Does not authorise voice.
- Voice generation — separate explicit opt-in. Uploading audio never authorises it.
- Legacy access — only for people you name. Not public.
Each will be off by default, never pre-selected, and revocable independently.
13. Future AI processing
Private memories will never automatically become AI training material. Only content you specifically authorise will be used for AI-assisted legacy responses. Responses will be labelled as AI-generated from preserved, authorised materials and will never claim to be you or to know with certainty what you would say.
Before any third-party AI provider is used, this policy will be updated to state: which provider; what information is sent; why; whether and how long the provider stores it; whether it is used for model training; how to opt out; and how deletion affects AI-related data.
14. Future synthetic voice
If introduced, voice generation will require separate explicit consent explaining what the voice model is used for and who may hear it; you can disable it without deleting your audio; generated audio will be identified as AI-generated (e.g. “This response was generated using your grandfather’s preserved memories, stories, values, advice, and authorised voice.”); and nobody may create another person’s voice model without verified authorisation. Safeguards against impersonation, fraud, harassment and unauthorised commercial use will be required.
15. Future digital-legacy controls
The intended design lets you control who can access your legacy, which memories, stories and photographs may be used, whether likeness may ever be used, whether written or voice responses are allowed, when access begins (immediate, scheduled or after a defined event), trusted legacy contacts and managers, and whether permissions can be changed, revoked, memories excluded, or the legacy permanently deleted.
16. Changes and contact
We will update the date above and notify you of material changes. For privacy questions, email Nwosusamson2009@gmail.com. See also our Terms of Service.
