Privacy Policy
Last updated: 2026-09-28
SyncYourMemory is a registered business name of National Finance Options Pty Ltd (Melbourne, Australia), which is the entity responsible for your personal information. We handle it in line with the Australian Privacy Principles (Privacy Act 1988). This policy explains what we collect, how we use it, and your choices.
1. What we collect
Account data (email, authentication metadata); the content you create (notes, links, photos you add to photo memories, and any audio you record for voice features); usage and billing metadata; and basic technical logs.
If you use voice cloning, we create a voice model from the voice you record (biometric data). If you use the 'voice identities' feature, you may also enrol voice samples of other people (e.g. family members), which are likewise treated as biometric data. If you use the voice-chat scene feature (paid plans), a background-removed face image from the photo you upload is stored in your account only and sent to Google (Gemini) to create your voice-chat scene. All voice and face data is processed only with explicit consent, stored on our servers, can be deleted anytime (voice in Settings; the face photo on the voice-chat page), and is removed when you delete your account. When a paid plan ends, any voice clone (synthesis model) created at our external voice provider is deleted. The recording it was made from is kept in your account with no time limit, so resubscribing rebuilds the same voice without recording again. We set no expiry on it because the person who comes back late is usually a family member trying to recover the voice of someone who has died. That recording is deleted when you delete the voice in Settings, and when you delete your account. You must only enrol another person's voice with that person's consent.
If someone else registered your voice, you can have it removed even though you are not a member here. How to ask for your voice to be removed.
2. How we use it
To contact you — service mail about your account, billing, security and legal notices. And, separately and only where you have consented, announcement email about new features or offers, which may include promotional content. That consent can be withdrawn at any time, free of charge, and withdrawing it does not stop service mail.
To provide the Service — storing your knowledge base, generating AI responses, transcribing and synthesising voice, processing payments, preventing abuse, and supporting you.
3. Subprocessors (who else processes your data)
- · Supabase — authentication and database hosting — data is stored in the Sydney, Australia region.
- · Google (Gemini API) — AI text, transcription, embeddings, and voice-chat scene image generation. Content you submit to AI features (including your face photo if you use the voice-chat scene) is sent to Google (US) for processing.
- · Alibaba Cloud (Qwen · DashScope) — voice synthesis and (with your consent) voice-clone creation. Answer text, and when building a clone the recording itself, is sent to Alibaba Cloud's Singapore region; a voice recording is biometric data.
- · Deepgram — speech-to-text. The audio you speak in a voice conversation is sent to Deepgram (US) and is not used to train models.
- · Stripe · PayPal — subscription and top-up payments (we do not store full card numbers). Stripe and PayPal are US companies.
- · Resend — transactional email (sign-up confirmation, receipts, billing notices). Your email address is sent to Resend (US).
- · Vercel — application hosting — served from the Sydney, Australia region (US company).
- · OpenAI — AI text and embeddings. Where this provider processes a request, content you submit to AI features is sent to OpenAI (US).
- · Upstash — rate limiting and concurrent-user counts — only counters keyed by account id and IP address, expiring within ten minutes. No memory content is sent (US company).
- · Sentry — server error diagnostics, when configured — the error message, stack trace, and which route and account it happened on are sent to Sentry (US). It is configured not to attach memory content or personal data.
- · Cloudflare — bot protection on the sign-in screen, when enabled — your browser sends your IP address and a verification token to Cloudflare (US company). No memory content is sent.
- · Google · Apple · Mozilla — web push notifications, only if you turn them on — notifications reach your device through your browser's push service (Chrome→Google, Safari→Apple, Firefox→Mozilla; all US). The payload is encrypted so only your device can open it, and we never put memory content in a notification in the first place.
4. Storage & retention
Data is retained for as long as your account exists. If you cancel a subscription, your account simply moves to the free plan — every memory stays stored, searchable, viewable, and exportable. We never delete your data for inactivity or non-payment; you can delete it yourself (Settings → permanent delete), and on request we will run the same deletion for you. Your data is primarily stored in Australia (Sydney); some processing occurs outside Australia (the US, Singapore, and the UK) via the subprocessors above. Data may be kept where the law requires it.
After death. When an account holder dies, their personal information stays stored for as long as the account exists; we do not delete it for inactivity or non-payment. The original recordings used for voice cloning (biometric data) are held in access-controlled private storage and are never deleted for the passage of time. No time limit cannot mean forever, though — what happens if the service closes is set out in section 9 of the Terms. Deleting the account deletes the recordings with it. The synthesised clone held at our external voice provider is deleted when a paid plan ends, except on an account marked as a memorial, where it is preserved and exempted from the routine expiry and cleanup. After a death, the only person who can receive any of this is a legacy contact the holder nominated in advance, and only within the powers the holder granted (downloading everything as a file, and reading in the app). Even they cannot use the cloned voice or reach payment details. Deletion is possible only where the holder explicitly granted it, and takes seven days during which it can be cancelled. If nobody was nominated in advance, no personal information is passed to anyone.
5. Transfers outside your country
If you use the service from South Korea, the following leaves the country. Each recipient's legal entity and privacy contact below were read from that company's own published privacy policy.
Supabase — Australia (Sydney)
Legal entity: Supabase Pte. Ltd. (Singapore) · privacy contact: privacy@supabase.com
- What is sent:
- email address, sign-in credentials, the text/title/tags/dates of your memories, search embeddings, settings, voice recordings, and the photos behind photo memories
- When and how:
- continuously while you use the service, over an encrypted (HTTPS) connection
- Why:
- database, authentication, and file storage
- How long:
- until you delete your account
Vercel — run from the Australia (Sydney) region · US company
Legal entity: Vercel Inc. (Delaware, USA) · privacy contact: privacy@vercel.com
- What is sent:
- connection details while a request is handled (IP address, request headers) and the request body
- When and how:
- every time you open a page or send a request
- Why:
- application hosting
- How long:
- only for the duration of the request; operational log retention follows Vercel's own policy
Google — USoptional feature
Legal entity: Google LLC (Delaware, USA)
- What is sent:
- text you submit to AI features, audio files for transcription, and — if you use the voice-chat scene — a background-removed image of your face
- When and how:
- each time you use one of those features
- Why:
- AI answers, transcription, embeddings, and voice-chat scene image generation
- How long:
- as long as processing requires; any retention beyond that follows Google's own policy
Alibaba Cloud — Singaporeoptional feature
Legal entity: Alibaba Cloud (Singapore) Private Limited (Singapore) · privacy contact: DPO_Intl@alibabacloud.com
- What is sent:
- the answer text to be spoken and, when cloning, the voice recording itself (biometric data)
- When and how:
- when you listen to a spoken answer, and when you enrol a voice
- Why:
- voice synthesis and voice-clone creation
- How long:
- the clone model is deleted when a paid plan ends or you delete your account
Deepgram — USoptional feature
Legal entity: Deepgram, Inc. (California, USA) · privacy contact: security@deepgram.com
- What is sent:
- the audio you speak in a voice conversation
- When and how:
- sent over the network during a voice conversation
- Why:
- speech-to-text
- How long:
- kept only as long as needed to process the request, and not used to train models
OpenAI — USoptional feature
Legal entity: OpenAI OpCo, LLC (California, USA)
- What is sent:
- text you submit to AI features
- When and how:
- when you use an AI feature that this provider processes
- Why:
- AI answers and embeddings
- How long:
- as long as processing requires; anything beyond follows OpenAI's own policy
Stripe — USoptional feature
Legal entity: Stripe Payments Australia Pty Ltd (A.C.N. 160 180 343, Australia)
- What is sent:
- email address, payment details (we never store the card number), and billing history
- When and how:
- when you pay or change a subscription
- Why:
- subscription payments and tax handling
- How long:
- the transaction-record period required by law
PayPal — USoptional feature
Legal entity: PayPal Australia Pty Limited (ABN 93 111 195 389, Australia)
- What is sent:
- email address, payment details, and billing history
- When and how:
- when you pay with PayPal
- Why:
- subscription payments
- How long:
- the transaction-record period required by law
Resend — US
Legal entity: Plus Five Five, Inc. (operator of Resend) · privacy contact: support@resend.com
- What is sent:
- email address, and the subject and body of the message
- When and how:
- when we send a service email, or a notice you consented to
- Why:
- email delivery
- How long:
- delivery-log retention follows Resend's own policy
Upstash — US
Legal entity: Upstash, Inc. (Delaware, USA)
- What is sent:
- counters keyed by account id and IP address (no memory content)
- When and how:
- on each request
- Why:
- rate limiting and concurrent-user counts
- How long:
- expires automatically within ten minutes
Sentry — US
Legal entity: Functional Software, Inc. (operator of Sentry, California, USA) · privacy contact: compliance@sentry.io
- What is sent:
- the error message, stack trace, the route it happened on, and the account id (no memory content)
- When and how:
- only when a server error occurs
- Why:
- diagnosing and fixing errors
- How long:
- retention follows Sentry's own policy
Cloudflare — US
Legal entity: Cloudflare, Inc. (California, USA) · privacy contact: dpo@cloudflare.com
- What is sent:
- IP address and a bot-protection verification token
- When and how:
- when you open the sign-in screen while bot protection is on
- Why:
- blocking automated sign-up and sign-in attempts
- How long:
- the token is single-use and expires as soon as it is verified
Mozilla — US (Google · Apple · Mozilla)optional feature
Legal entity: Mozilla Corporation (California, USA) · privacy contact: compliance@mozilla.com
- What is sent:
- your device's push endpoint and the encrypted notification payload (never memory content)
- When and how:
- after you turn push on, whenever a notification is sent
- Why:
- delivering the notification through your browser vendor's push service
- How long:
- discarded after delivery (a short retry window if delivery fails)
You can refuse. Anything marked “optional feature” stops being transferred the moment you stop using that feature (or switch it off in Settings), and the rest of the service keeps working. The unmarked ones are what running the service requires, so they cannot be refused on their own — refusing them means deleting the account (Settings → permanent delete). Either way you can export everything you have saved first.
6. Your rights
You can export your data and permanently delete your account and all associated data at any time from Settings → Danger zone. To request access or correction, contact us.
Communication choices: service mail — account, billing, security and legal notices — is part of the Service and keeps coming. Announcement email, which may include promotional content, goes only to people who consented; when you consent we record the time, the wording you were shown and the language it was in, and keep that record as evidence that consent was given. You can withdraw at any time and free of charge, from the link in any such email or in Settings, and withdrawing does not stop service mail. The weekly memory question is separate and can be turned off on its own.
Support access: we do not view your memory content. Only when you explicitly grant it in Settings — a read-only window (up to 48 hours, revocable anytime) — can support view it through the support screen; every such access is recorded in an audit log, and if recording fails the view itself is blocked.
7. Cookies
We use only essential first-party cookies (sign-in session, language, theme). We do not use third-party advertising or tracking cookies.
8. Security
Data is isolated per account at the database level (row-level security), and traffic is encrypted in transit. Voice audio and the photos behind photo memories are held in access-controlled storage, and any support access is written to an audit log. No system is perfectly secure, but we take reasonable steps to protect your information.
9. Contact
Questions or privacy requests: the contact page or support@syncyourmemory.com.
Telephone: +61 403 550 583 (Australian business hours). Written requests are handled faster through the contact page or email.
If you are concerned about how we handle your personal information, tell us at the address above. We will acknowledge your complaint within 5 business days and respond with our findings and any action taken within 30 days. If you are not satisfied with that response, you can complain to the Office of the Australian Information Commissioner (OAIC, oaic.gov.au).
Data breaches: if a breach occurs that is likely to result in serious harm to you, we will notify you and the OAIC as required by Australia's Notifiable Data Breaches scheme.