Privacy & analytics
This app records limited product telemetry so administrators can understand whether the product is useful, which features are being used, and what should appear in shared activity surfaces like What's New.
What is collected
- Session starts and the current in-app path.
- Book opens, page views, and activity-feed opens.
- Authoritative write actions such as comments, suggestions, audio uploads, page uploads, and book creation.
- Basic context needed to scope the event correctly: user id, family id, book id, page id, role at the time, and timestamp.
What is not stored in analytics events
- Comment bodies.
- Suggestion text.
- Chat messages.
- Transcript text or audio content.
Why it is collected
- To understand active users, active families, and feature adoption.
- To improve the product and prioritize future work.
- To power curated activity surfaces such as family-visible updates and admin activity.
- To investigate product-level usage patterns without reading user-created content.
Retention
- Raw analytics events: 90 days.
- Analytics session rows: 180 days.
- Activity feed items: retained while product-useful or until the source object is deleted or hidden.
Who can see it
- Raw product analytics are restricted to superadmins.
- Family-visible activity is limited to the active family.
- Admin activity is limited to admins in the active family.
Third-party processors
Product analytics and activity feed data are stored first-party by this application and its database. Separate AI or transcription processors may be enabled for a family by administrators, but those processors are not the source of the product analytics shown here.
AI features and face grouping
The family owner controls two different kinds of setting, and they are not the same thing.
AI features — archive understanding and assistant, audio transcription and AI photo restoration, video understanding, and semantic search — are optional capabilities. Turning one on lets Remembrance Scan operate that feature using the service named beside it. It is a product setting, not an approval of a vendor, and it can be turned off at any time. Turning a feature off stops future processing; it does not undo work that has already been done.
Face grouping is different. It detects faces in your photos and videos and groups the ones that look like the same person, so you can name someone once and find every photo of them. Because that involves biometric information, it is off unless the family owner turns it on, and turning it on requires reading and consenting to a specific disclosure. The face analysis is performed by Amazon Web Services (AWS Rekognition), in a collection belonging solely to your archive. Face data is never sold, never used for marketing, never used to train AI models, and never compared against another family's archive or any outside face database.
The owner can turn face grouping off at any time. Doing so stops face processing immediately and deletes the archive's face data within 30 days: the AWS face collection, the stored face crops, the faces that were detected automatically, and the groupings built from them.
Your own work is kept. The people you have named stay, and so do any face boxes you drew by hand and the names you attached to them — those are notes on your photos, not face measurements. They are kept as a plain box and a name, with everything the face analysis inferred removed.
If your face appears in an archive here and you are not an account holder, you can ask for your face data to be deleted. Contact the administrator of the archive you appear in, or the product operator, and identify which archive it is so the right data can be found and removed.
Your options
If you need help with access, correction, deletion, or other privacy questions, contact the organization or administrator that invited you to the book, or contact the product operator for support.