Privacy Policy
This Privacy Policy explains how Remembr ("Remembr," "we," "our," or "us") collects,
uses, stores, and shares information when you use the Remembr mobile app, related backend
APIs, and the public website at rmbr.day (including challenge pages,
auth callback pages, and install pages) (collectively, the "Services").
1. What this policy covers
This policy covers data handled across all currently implemented product flows, including:
- Account sign-in and authentication (email magic link and Google sign-in).
- Onboarding and profile setup (name, phone, birthdays/anniversaries, holiday preferences).
- Photo-library scanning and memory gameplay features.
- Metadata ingestion and processing (for example timestamp, EXIF-derived values, and location fields when available).
- Quiz sessions, answers, scores, journaling, and statistics.
- Challenge creation/sharing flows, including shared thumbnails/photos and challenge results.
- Push notification registration and reminder/test notifications.
- Public site pages, app install redirects, and deep-link/auth callback handling.
- Operational logging, anti-abuse, and product analytics.
2. Information we collect
2.1 Account and identity data
- Supabase account identifiers (such as user ID and email).
- Google sign-in identity token exchange data and basic profile metadata when provided.
- Auth callback parameters used to complete login and route back into the app.
2.2 Profile and onboarding data
- Name.
- Phone number (optional).
- Birthday and anniversary dates (optional).
- Holiday selections/preferences.
- Onboarding completion status and related profile timestamps.
2.3 Photo and memory data
- Local photo library records processed in-app (asset identifiers, capture timestamps, dimensions, screenshot flag, and location coordinates when available).
- Photo metadata submitted to backend endpoints (for example local asset ID, URI reference, EXIF payload, camera make/model, ISO, focal length, and latitude/longitude when included).
- Derived photo context and quality indicators used for gameplay (for example screenshot, text/person indicators, and scoring metadata).
2.4 Gameplay, journal, and social interaction data
- Quiz session history (start/completion times, progress, score, duration).
- Question records (question type, prompt, user answer, correctness, score, timing, and related metadata).
- Journal entries linked to questions/photos/days.
- User tags/labels/emojis for assets.
- Challenge records (challenge ID/token, related question, photo object key, challenge result status).
- Interaction metrics (for example challenge sends/receives/answers between users).
- Aggregated statistics and streak calculations.
2.5 Location and environmental context data
- Day-level location points and dispersion metrics uploaded for timeline processing.
- Derived home/vacation timeline records.
- Reverse-geocoding lookups and formatted location labels.
- Weather snapshot lookups for memory context (historic weather by coordinates/time).
2.6 Notifications and device data
- Push notification tokens, platform, and device identifier (if provided).
- Notification event payload metadata required for routing users in-app.
2.7 Analytics and diagnostics
- Product analytics events (for example onboarding started, sign-in success/failure, startup sync states, and API errors).
- Event properties used for analysis (for example method type, status code, and duration).
- Service logs and request metadata for security, abuse prevention, and reliability.
2.8 Public website and challenge-page data
- Standard web request metadata (IP address, user agent, path, timestamp) from infrastructure providers.
- Challenge IDs and tokens passed in URL paths/query parameters.
- Install and deep-link routing requests (for example
/app,/auth-callback,/c/:id). - Static asset requests (for example challenge thumbnails and public site resources).
3. How we use information
- To create and maintain user accounts and authenticated sessions.
- To personalize memory-game content and operate quiz/challenge/journal features.
- To store and retrieve challenge images and thumbnails.
- To calculate scores, stats, streaks, and challenge results.
- To support location-based and weather-based memory context features.
- To send push notifications (including reminders, challenge notifications, and test notifications).
- To improve app performance and feature quality through analytics and diagnostics.
- To monitor misuse, enforce our terms, and protect service security.
- To operate public website routing, install flows, and deep-link handoff to the app.
4. Legal bases (where applicable)
Depending on your jurisdiction, we process personal data under one or more legal bases, including: your consent, performance of a contract (providing the Services), legitimate interests (security, product improvement, abuse prevention), and legal obligations.
5. How and where data is processed
Processing occurs in a combination of local-device storage/processing and cloud services. Some analysis happens on-device (for example local photo scanning/selection), and some data is sent to backend services for syncing, challenge delivery, and account-level features.
6. Third-party services and disclosures
We share data with service providers as needed to run the Services, including:
- Supabase for authentication and account identity flows.
- Cloudflare Cloudflare for website/edge API hosting, request handling, object storage (R2) for challenge images and thumbnails, and automated photo quality filtering via Cloudflare Workers AI.
- Expo push service for push notification delivery.
- PostHog for product analytics events.
- Google services for sign-in, geocoding, and places lookup where enabled.
- Open-Meteo for weather snapshot retrieval.
- Apple/TestFlight for install and distribution links from public pages.
We may also disclose information if required by law, to enforce rights, investigate abuse, protect users, or in connection with a merger, financing, acquisition, or asset transfer.
6.1. Photo Quality Filtering
Some photos are briefly processed through Cloudflare Workers AI for quality control to filter out receipts, photos of computer screens, blurry images, and accidental captures before quiz generation. This processing is transient — Cloudflare does not store, retain, or use your photos to train AI models or for any purpose beyond this step. No human reviews your photos. See Cloudflare's Workers AI data policy at developers.cloudflare.com/workers-ai/platform/data-usage.
7. Data retention
We retain data for as long as reasonably necessary to provide and improve the Services, maintain security logs, comply with legal obligations, and resolve disputes. Retention periods can differ by data type (for example account records, challenge content, analytics, and infrastructure logs).
8. Your choices and rights
Depending on your location, you may have rights to:
- Access personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of account-related personal data.
- Object to or restrict certain processing.
- Withdraw consent where processing relies on consent.
- Request portability of certain data where legally required.
You can also control permissions at the device level (for example photo access, notifications, and location) and disable them at any time in your OS settings.
9. Children
The Services are not directed to children under 13 (or the minimum age required by local law), and we do not knowingly collect personal data from children under that age.
10. International transfers
Your information may be processed in countries other than your own. Where required, we implement appropriate safeguards for cross-border data transfers.
11. Security
We use reasonable technical and organizational safeguards designed to protect personal information. No system is perfectly secure, and we cannot guarantee absolute security.
12. Changes to this policy
We may update this Privacy Policy periodically. The updated version will be posted here with a revised effective date.
13. Contact us
Privacy questions or rights requests: hello@remembr.day.