memory4.me
Login Sign up
memory4.me

Privacy Policy

Last updated: June 2026

Memory4Me is a personal memory log run by AkiCreative. This policy describes what we collect, how it's used, and how it's stored. The short version: we collect the minimum we need to run the service for you, we don't sell anything, and your memories are yours.

What we collect

What we do with it

What we don't do

Where it's stored, how it's protected

Memory4Me is hosted in the United States. Photos are stored in S3-compatible object storage. Database backups are encrypted at rest.

The free-text body of each memory (the raw text you wrote, the AI summary, and the free-form structured blob) is encrypted at rest with AES-256 using a key that lives only on our application server. Someone who steals just the database cannot read your memories. AI-extracted structured fields (category, location, people, tags, ratings) stay plaintext so that the dashboard, filters, and search keep working. These are the labels, not the content.

This protects against database-level breaches and backup leaks. It does not protect against a full server compromise (where the attacker has the application key) or against Google Gemini seeing the text we send for parsing. If you wouldn't tell it to a stranger, don't put it in Memory4Me.

Sign-in

We default to magic-link sign-in: you enter your email, we send a one-time link valid for 15 minutes that signs you in on click. The link is a server-signed URL; tampering with it returns a 403. Sends are rate-limited to 3 per email per 5 minutes. We never reveal whether an email is registered; unknown addresses get the same "check your inbox" message.

You can also set a password and sign in with that instead. Passwords are stored as bcrypt hashes, never in plaintext.

Your data

Export everything you've saved as a CSV from Settings → Profile → Your data. One row per memory, encrypted entries decrypted for you, photos listed as URLs you can download separately. No request needed, no waiting.

Delete individual memories from the web dashboard or via the bot. To delete your entire account and everything in it, email hello@memory4.me from the address on your account. We'll remove your row and all associated memories, people, and assets. The Stripe customer record gets a deletion request too.

Cookies and analytics

We use first-party session cookies for login (required) and CSRF protection (required).

The public landing page only (memory4.me/) loads Google Analytics (GA4) to help us understand how visitors find the site. Google Analytics sets its own cookies and may collect your IP address, browser, device, and referrer. It runs on the marketing page exclusively: once you sign in, the dashboard and the rest of the app load no analytics or tracking scripts. Read Google's privacy policy for what they do with that data, or block the script with any standard ad/tracker blocker if you prefer.

Changes

If we materially change this policy, we'll email registered users. Trivial wording fixes won't trigger an email.

Contact

Questions? hello@memory4.me