This page explains the security practices behind Make Memoir in plain language. For legal details, review our Privacy Policy and Terms of Service.
Security Overview
Make Memoir is built around the idea that family stories are private by default. The recordings, transcripts, and written stories families create are personal, and our systems are designed to keep them isolated, encrypted, and portable.
Our goal is simple: make it easy for families to preserve memories without making those memories public, searchable, or available to anyone outside the family’s account.
Our Commitments
Encrypted End-to-End
All data is transmitted over TLS 1.2+. Recordings are stored encrypted at rest with AES-256. Signed, time-limited URLs mean no recording file is ever publicly accessible.
Your Content, Your Property
We do not sell, license, or share your recordings or stories. We do not use them to train AI models - ours or any third party's. Period.
Family-Private Vault
Each family has its own isolated account. Your stories and recordings are never visible to other Make Memoir accounts. Row-level security is enforced at the database layer.
Take Your Data Anytime
Download all your videos, transcripts, and story text from account settings at any time. We never hold your memories hostage. Your data is always portable.
How We Handle Recordings
- Stored in private cloud buckets - never publicly accessible
- Accessible only to you, your invited family members, and our automated AI transcription pipeline
- Each access requires a signed URL that expires after a short window
- Permanently deleted within 30 days after subscription ends
AI Transcription
- Audio is processed under a data processing agreement that prohibits using your content for AI training
- Transcripts are stored in our database and editable by you at any time
- AI-generated story text is fully editable and legally owned by your family
- We never share your transcripts or stories with third parties for any purpose
Infrastructure & Compliance
- Hosted on Vercel and Supabase - both SOC 2 Type II certified infrastructure providers
- We are working toward our own SOC 2 Type II certification
- CCPA compliant for California residents
- GDPR-compatible data practices for EU and UK residents
- Payments are handled entirely by Stripe - we never see or store card numbers
Contact Us
Have a security question? Email us at security@makememoir.com and a real person will respond.
Have a security question?
We want families to understand how their private recordings and written stories are protected.