How we protect your memories
You are trusting us with the story of a life, so here is exactly where it is kept and what protects it. No overstatement — only what we actually do.
Yours alone — every account walled off
- Every memory is locked to its account at the database level. No other member's screen or request can reach yours.
- There is no public board or feed. Your memories are seen only by family you invite, and only as far as you allow. Any single memory can be kept out of family sharing.
In transit and at rest
- Everything between the app and our servers is encrypted (HTTPS/TLS).
- Stored memories are encrypted with AES-256 at the hosting level and kept in the Sydney, Australia region. Our own daily backups are separately encrypted with AES-256.
- Our database host holds SOC 2 Type 2 and ISO 27001 certifications. (These are the host's certifications, not SyncYourMemory's.)
Your memories do not train AI
- Your memories and voice are used only to answer you and to speak. Neither we nor the AI providers we use train AI models on them.
- Every outside AI service we use for answers, voice and call transcription is used only on terms that keep customer data out of training: either a paid service whose terms say it does not train on your data, or a training opt-out sent with every request.
Never lost — backups, and proof they work
- Two backups are made every day: our host's automatic backup (7 days kept) and our own, independent of the host (daily, AES-256 encrypted, 7 days kept). Voice recordings are backed up separately every week, encrypted, with two weeks kept.
- A backup is only trustworthy once it has been restored. On September 17, 2026 we restored all production data from backup into a fresh database and compared it with the original line by line: every memory, link and search record came back identical. The drill found items the backup had been missing (such as family-sharing settings); they were added at once, and an automatic check now fails if new data is ever left out of the backup.
- When you edit a memory, the earlier text is kept as a version you can restore.
Sign-in protection
- Passwords need at least 8 characters with upper- and lower-case letters, a number and a symbol.
- You can turn on two-step verification with an authenticator app (Settings → Account).
- Rapid repeated requests are limited automatically.
We don't look, either
- Our staff do not read members' memories. If fixing a problem truly needs it, you grant support access yourself in Settings (48 hours at most, revocable at any time), and every access is written to an audit log.
- Support tickets and operational alerts never contain memory content.
- Even when you report a wrong answer, we do not see the conversation unless you allow it.
Voice (biometric data)
- A voice is enrolled only with the consent of the person it belongs to. Original recordings are kept in private, access-restricted storage.
- Anyone whose voice was enrolled can ask for it to be deleted at any time. Revoking a family member's invitation also deletes the voices they enrolled.
Your data is yours — export and deletion
- Download all of your memories as a file (JSON) at any time from Settings → Data.
- Cancelling a subscription or staying away for a long time never deletes your memories.
- Deleting your account permanently erases memories, voices and settings, and we email you a confirmation. Deleted data also leaves our backups once their retention ends (about two weeks at most).
- Only heirs you name in advance can receive your memories, and only within the permissions you gave them. An heir can ask for deletion only if you allowed it, with a 7-day window to cancel.
If something goes wrong
- If a breach is likely to cause serious harm, we notify affected members and the Office of the Australian Information Commissioner (OAIC) under Australia's Notifiable Data Breaches scheme.
- Found a security issue? Tell us at support@syncyourmemory.com. Put [Security] in the subject and we will look at it first.
What we deliberately don't claim
- We don't say "perfectly secure" or "unhackable". No service is.
- We don't claim end-to-end encryption. For your twin to answer from your memories, our servers have to read them. The isolation, access rules and audit log above are how we protect them instead.
- We don't present our host's certifications as our own.
Last reviewed: September 19, 2026