MomMemBack to home

Privacy Policy

This document exists in two official versions: Brazilian Portuguese (pt-BR) and US English (en-US). In case of interpretive divergence, the Portuguese version governs users in Brazil; the English version governs users in the United States.

1. Who we are

MomMem is a private digital vault for childhood memories. Our purpose is to let parents — especially first-time mothers — capture meaningful moments in their children's lives quickly (a photo plus a 15–30 second voice note), with AI handling curation, transcription, and chronological organization.

MomMem is operated by [Legal Entity Name — TBD], headquartered in São Paulo, Brazil. For any matter relating to this Policy or your data, please contact our Data Protection Officer (DPO) at dpo@mommem.com.

2. This policy, in one sentence

We collect only what the product needs to work, we never sell your data or your children's data, we encrypt everything in transit and at rest, and you can ask us to delete everything at any time.

3. Data we process

3.1. Data you provide to us

CategoryExamplesPurpose
Account identificationName, email, phone (optional), preferred languageCreate and operate the family account
Child profilesName (or nickname), date of birth, gender (optional), profile photoOrganize memories per child and surface age-relevant milestones
Memory contentPhotos, short videos, 15–30s audio clips, typed text, tagsThis is the product — it's what you're saving
Family inviteesNames and email addresses of people you invite (grandparents, godparents, co-parents)Enable limited co-curation and sharing
SupportMessages sent to support, screenshots, bug descriptionsResolve reported issues

3.2. Data generated by your use

CategoryExamples
Media metadataTimestamp, approximate geolocation (only if you opt in), format, duration
AI outputAudio transcription, generated summary, suggested tags, detected milestones
Product telemetryScreens viewed, actions taken, performance, errors — no memory content
DeviceModel, OS, language, advertising identifiers only if you consent

3.3. Data we do NOT collect

4. Children and minors

This is the most important section of this document.

MomMem is a product for parents and legal guardians, not for children. The person who creates the account, accepts the terms, and provides consent is always an adult (18+) acting in the capacity of legal guardian.

Because the content stored is by nature about children, we process it with reinforced protections under:

In practical terms:

  1. Only the legal guardian may create and administer the child's account.
  2. There is no child login. The child is not a "user" of the product.
  3. No advertising profiling of children, under any circumstances.
  4. Children's data is not used to train third-party AI models. Sub-processors (e.g., OpenAI Whisper) are contractually prohibited from retaining or training on submitted content.
  5. You can export or delete all your child's material at any time.
  6. When inviting grandparents, godparents, or co-parents, you are responsible for ensuring those individuals are authorized to view and contribute.

5. Legal bases for processing (GDPR / LGPD)

PurposeGDPR basisLGPD basis
Create and operate your accountPerformance of contract (Art. 6(1)(b))Execução de contrato (Art. 7º V)
Process your memories with AIPerformance of contractExecução de contrato
Billing and subscription managementContract + legal obligationContract + tax obligation
Transactional communications (welcome, billing, security)ContractContract
Optional marketing communicationsConsentConsentimento
Media geolocationConsentConsentimento
Children's dataParental consent (Art. 8)Parental consent + legitimate child-protection interest
Product telemetry and bug fixingLegitimate interest (Art. 6(1)(f))Legítimo interesse
Fraud and abuse preventionLegitimate interestLegítimo interesse
Compliance with court order / legal obligationLegal obligation (Art. 6(1)(c))Obrigação legal

You may withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.

6. How we process your memories with AI

When you record a moment (photo + 15–30s audio), this is the chain:

  1. Encrypted upload (TLS 1.2+) of the file to our storage (Cloudflare R2).
  2. Transcription of the audio via OpenAI Whisper API under a Zero Data Retention contract — OpenAI does not retain the audio sent and does not train on it.
  3. Structuring (tag extraction, milestone detection, sentiment) via Anthropic Claude API — also under non-retention and non-training terms.
  4. Storage of original content plus structured metadata in our database (Postgres / Supabase), with Row-Level Security: only your family sees your data.
  5. You review the suggestion. If you edit or delete, we propagate the change.

No memory of yours is viewed by MomMem humans, except if you actively open a support ticket and attach the memory.

7. Sharing and sub-processors

MomMem works with the following sub-processors. Each has been evaluated for LGPD / GDPR / COPPA compliance and is bound by a Data Processing Agreement with standard data-protection clauses.

Sub-processorRoleData location
SupabasePostgres database, authenticationUS (São Paulo region under evaluation)
Cloudflare R2Storage of photos, videos, audioMulti-region; object stored closest to user
Cloudflare (CDN/WAF)Content delivery, attack protectionGlobal edge
Fly.ioApplication serversMulti-region; São Paulo (GRU) is the default for Brazilian users
OpenAIAudio transcription (Whisper)US, under Zero Data Retention agreement
AnthropicAI memory structuring (Claude) — tag, milestone, and summary extractionUS, under non-retention and non-training agreement
Apple In-App PurchaseiOS payment processingUS (Apple)
Google Play BillingAndroid payment processingUS (Google)
PostHogProduct analytics (no memory content)US; EU self-host option under evaluation
SentryError monitoring (no memory content)US

The current list is published at mommem.com/subprocessors and we'll notify you at least 30 days before adding any new sub-processor.

We do not sell, rent, or trade your personal data with third parties for advertising or commercial purposes.

8. International data transfers

Because most of our sub-processors operate in the US, personal data is transferred internationally. The safeguards we apply:

9. Retention and deletion

Data typeRetention period
Memory content (photos, audio, video, transcriptions)While your account is active
Account after subscription cancellation12 months to allow reactivation. After that, full deletion.
Billing data7 years after end of relationship (US/IRS tax requirements)
Security logs180 days
Aggregated and anonymous telemetryRetained indefinitely for product analytics

Immediate deletion on request: if you formally request deletion before the 12 months, we process within 15 business days (LGPD) or 30 calendar days (GDPR / CCPA). Backups are purged in rotations of up to 90 days.

10. Your rights as a data subject

You have the right, at any time, to:

  1. Access the data we process about you and your family.
  2. Correct incomplete, inaccurate, or outdated data.
  3. Request deletion of your data and your children's data.
  4. Port your data in a structured format (JSON + original files).
  5. Withdraw consent for processing based on consent.
  6. Object to processing based on legitimate interest.
  7. Request human review of significant automated decisions (we do not currently use significant automated decisions in the product).
  8. Lodge a complaint with the data protection authority in your jurisdiction.

California residents (CCPA/CPRA) additionally have the right to: know what categories of personal information we collect; opt out of any sale or sharing (we do not sell or share — but the right is preserved); non-discrimination for exercising rights; limit the use of sensitive personal information.

How to exercise these rights: inside the app, under Settings → Privacy → My Data, or by email to dpo@mommem.com. We respond within 15 business days (LGPD) / 45 calendar days (CCPA).

11. Security

12. Cookies and similar technologies

The mobile app does not use cookies. It uses installation identifiers for authentication and product telemetry (only if you consent).

The mommem.com website uses:

A consent banner is active on first visit; preferences can be revised at mommem.com/cookies.

13. Changes to this policy

We update this policy whenever there is a material change in how we process your data. When that happens:

14. Contact