Privacy Policy
Last updated: 11 July 2026
This Privacy Policy explains how Memorably ("we", "us", "our") collects, uses, shares and protects personal data when you use our apps, App Clip and website (the "Service"). Memorably is a digital disposable-camera service: guests scan a QR code, take photos on their own phone, and those photos are gathered into a shared album for the event. We are based in France and offer the Service worldwide, in accordance with the EU GDPR and the French Data Protection Act.
Contents
01Who we are & how to contact us
The data controller is N1N1 Tech Company — SAS, registered with the Paris Trade and Companies Register (RCS) under SIREN 106 967 235, registered office at 47 rue Vivienne, 75002 Paris, France.
For any privacy question or to exercise your rights, contact us at privacy@getmemorably.com.
02Data we collect
- Photos & media you or other guests take or upload, and their technical metadata (e.g. capture time).
- Event content set by the host (event name, cover photo, styles and settings).
- Account & contact data (name or display name, email, login credentials) — mainly for hosts.
- Sign-in data — if you sign in with Apple or Google, we receive basic profile information from them (such as your name and email) to create and secure your account.
- Guest participation data — a display name you enter and a guest token / device identifier that keeps you connected to the event and links your photos to it (guests can usually join without a full account).
- Device permissions — we access your camera only when you use the capture feature, and your photo library only when you choose a photo to upload. Neither is accessed in the background.
- Payment data — in-app purchases are handled by Apple or Google and validated through RevenueCat; we receive limited billing details (plan, amount, date), not your full card number.
- Technical & usage data collected automatically — device type, OS, app version, language, IP address, approximate location and log data needed to run and secure the Service.
App Clip. The iOS App Clip uses only the minimal data needed to let a guest join an event and upload photos with the host's permission — no account and no download required.
Sensitive data. We do not intentionally collect special-category data (such as data revealing health, religious or political beliefs, or sexual orientation). Because photos can incidentally reveal such information, you must not upload content revealing another person's sensitive data without a lawful basis, and you remain responsible for any content you upload.
03Why we use your data (legal bases)
- Provide the Service — capturing, storing, developing and revealing photos and sharing albums. Basis: contract.
- Run accounts & support, respond to requests. Basis: contract / legitimate interest.
- Keep the Service safe & reliable — prevent fraud and abuse, debug, improve performance. Basis: legitimate interest.
- Comply with the law and enforce our terms. Basis: legal obligation / legitimate interest.
- Marketing — newsletters and offers with your consent (new users), or on a legitimate-interest basis for existing customers; every email has an unsubscribe link. Basis: consent / legitimate interest.
We do not sell your personal data, and we do not use your photos for facial recognition or to train such systems.
04Your photos and the people in them
Photos often contain images of identifiable people and are therefore their personal data. Because you control what you capture and upload, you are responsible for ensuring that:
- you have the right to take and upload each photo, and any consent required from the people in it — especially before uploading images of children;
- you do not upload content that is unlawful, infringing, defamatory or that violates another person's privacy or image rights;
- if you are a host, you inform your guests that photos are collected and shared through Memorably and for what event.
How photos are shared: photos are linked to the event you joined and may be visible to the host and other guests of that event, according to the host's settings (for example, when the album unlocks). Albums are private to the event by default and are not published publicly by us; however, anyone holding an active link or QR code for an event may access it — treat those like a key. We do not share your photos with advertisers.
If you close your account, photos you contributed to another person's event may remain in that album so the event stays complete, but your name and attribution are anonymised.
If you believe a photo of you was shared without permission, contact privacy@getmemorably.com. Where a host collected the photo for their event, we may direct your request to that host as the responsible party.
05Who we share data with
We share data with trusted providers who process it on our behalf, under contracts requiring them to protect it and use it only for us:
- Supabase — our backend provider for database, photo storage and authentication. Your account data and uploaded photos are hosted in the European Union (Ireland) on infrastructure operated through Supabase.
- Apple & Google — app and App Clip distribution and notifications.
- Hosting providers — for our website and APIs.
- Payment & purchases — Apple and Google process in-app purchases and RevenueCat validates and manages them (only if you buy a paid plan).
- Analytics & error-monitoring — such as PostHog (product analytics) and Sentry (error monitoring), to understand aggregate usage and diagnose problems, where enabled.
A current list of our sub-processors is available on request at privacy@getmemorably.com.
We may also disclose data where required by law, to enforce our terms, or to protect the rights, safety and property of Memorably, our users or the public, and as part of a merger, acquisition or asset sale.
International transfers. Your account data and photos are stored in the European Union (Ireland). Some of our other providers (for example, Apple, Google, RevenueCat, PostHog or Sentry) may process limited data outside the European Economic Area; when they do, we rely on appropriate safeguards recognised by the GDPR — in particular the EU Standard Contractual Clauses and, where relevant, adequacy decisions.
06How long we keep your data
We keep personal data only as long as necessary for the purposes above, then delete or anonymise it:
| Data category | Legal basis | Retention period |
|---|---|---|
| Photos & event content | Contract | While the event/album is active; deleted within 30 days of a deletion request and purged from backups within 90 days. |
| Account data | Contract / legitimate interest | While the account is active; deleted within 30 days of account closure, and in any case after up to 3 years of inactivity, then deleted or anonymised. |
| Billing & transaction records | Legal obligation | 10 years (French accounting and tax law). |
| Marketing / consent data | Consent / legitimate interest | Until you withdraw consent, at most 3 years after your last contact (CNIL guidance). |
| Connection & security logs | Legitimate interest / legal obligation | Up to 12 months. |
| Cookies & similar | Consent (non-essential) | Consent up to 6 months; cookies up to 13 months; audience data up to 25 months. |
Some data may be kept longer in archived form where required to comply with the law or to establish, exercise or defend legal claims.
07Security
We apply appropriate technical and organisational measures, including encryption in transit (HTTPS/TLS), encryption at rest through our cloud providers, role-based access controls and monitoring. However, no method of transmission or storage is completely secure and we cannot guarantee absolute security. You are responsible for keeping your login credentials and any event links or QR codes confidential. If a personal data breach is likely to create a risk to your rights, we will notify the competent authority and, where required, affected users, as required by the GDPR.
08Your rights
Subject to applicable law, you have the right to access, rectify, erase, restrict or object to the processing of your data (including direct marketing), to data portability, to withdraw consent at any time, and to give directives on the fate of your data after your death.
You can also delete your account and manage your notification preferences directly in the app settings. To exercise your other rights, email privacy@getmemorably.com. We may need to verify your identity and will respond within the legal timeframe (generally one month). You also have the right to lodge a complaint with the French supervisory authority, the CNIL (www.cnil.fr), or your local data protection authority.
09Cookies
We use cookies and similar technologies that are strictly necessary to run the Service (for example, to keep you signed in) — these do not require consent. Any non-essential cookies (such as audience measurement) are only placed with your consent, requested through a banner; you can change your choice at any time. In line with CNIL guidance, cookies are not kept for more than 13 months.
10Children
The Service is not intended for children under the age of 15 (the age of digital consent in France), and we do not knowingly collect their data without appropriate authorisation. Hosts and guests must not upload photos of children without the consent of a parent or legal guardian. If you believe a child's data has been provided to us improperly, contact us and we will delete it.
11Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you. Your continued use of the Service after an update means you accept the revised policy.
← Back to Memorably