Privacy Policy

1. Identity of the Controller

[Company Name], a company registered in Switzerland, is the controller responsible for the processing of your personal data in connection with Memento AI. The controller determines the purposes and means of processing personal data collected and used through the Memento AI application.

Registered address: [Company Address]

Contact email: [Contact Email]

Where this Privacy Policy refers to "we", "us", or "our", it means [Company Name] acting as the data controller under the Swiss Federal Act on Data Protection (nDSG), which entered into force on 1 September 2023.

2. Scope

This Privacy Policy applies to all personal data processed through the Memento AI web application, regardless of how you access it (mobile browser, desktop browser, or installed as a progressive web app). It covers data stored in our cloud infrastructure (databases, file storage, and server logs) as well as data stored locally in your browser's local storage.

This policy does not apply to third-party websites or services that may be linked from our application. We encourage you to review the privacy policies of any third-party services you interact with.

By using Memento AI, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described herein, please discontinue use of the service.

3. Data We Collect

We collect and process the following categories of personal data. We only collect data that is necessary to provide the care support features of Memento AI.

3.1 Account Data

When you register and use Memento AI, we collect:

  • Email address
  • Authentication provider (Google, Apple, or email/password)
  • Display name
  • Profile picture URL (if provided via your authentication provider)

3.2 Patient Profile Data

When you create a patient care profile, you may provide:

  • First name and last name
  • Date of birth
  • Home address
  • Spouse name and children's names
  • Diagnosis status (e.g., early-stage Alzheimer's, mild cognitive impairment)
  • Additional medical notes and care-relevant information
  • Profile photo

This data includes health-related information, which is classified as particularly sensitive personal data under the nDSG (see Section 6).

3.3 Care Timeline Data

As you use the daily care timeline, we collect and store:

  • Daily observations and care notes you enter
  • AI-generated summaries of timeline entries
  • Flagged health concerns and alerts
  • Mood and behavioral assessments
  • Timestamps for all entries

3.4 Memory Photos

When you upload photos to the memory feature, we collect:

  • The uploaded image files
  • Year or date metadata you assign to photos
  • Descriptions and captions you provide
  • AI-generated photo analysis results (when you use this feature)

3.5 Voice Recordings

When you use the voice recording feature, we collect:

  • Audio recording files (stored in cloud storage)
  • Transcripts of recorded speech
  • AI-generated voice analysis results, including assessments of mood, coherence, and engagement indicators

Voice recordings may contain sensitive health information and are treated accordingly.

3.6 Care Circle Data

When you invite family members or other caregivers to collaborate, we collect:

  • Invited member email addresses
  • Access roles assigned (full access or viewer)
  • Invitation status (pending, accepted, declined)
  • Unique invite codes

3.7 Technical Data

When you access Memento AI, the following technical data may be collected automatically:

  • Browser type and version
  • Device type (mobile, tablet, desktop)
  • IP address (recorded in hosting provider logs)
  • Timestamps of access and usage

3.8 Local Storage Data

Memento AI stores certain data locally in your browser to improve your experience:

  • User preferences (language selection, AI mode settings)
  • Active patient profile selection
  • Session tokens for authentication

This data remains on your device and is not transmitted to our servers unless it forms part of a service request.

4. Purpose of Processing

We process your personal data for the following specific purposes:

  • Account data: To authenticate your identity, manage your account, and provide you with personalized access to the application.
  • Patient profile data: To create and manage care profiles for your loved ones, enabling you to organize care-relevant information in one place.
  • Care timeline, memory photos, and voice recordings: To track daily care observations over time, preserve meaningful memories, and provide AI-powered insights that may help you notice patterns in health and well-being.
  • Care Circle data: To enable collaborative care between family members and other caregivers, allowing you to share access to patient profiles with people you trust.
  • Technical data: To ensure the security and stability of our service, prevent abuse and unauthorized access, diagnose technical issues, and improve the overall quality of Memento AI.
  • Local storage data: To remember your preferences (such as language and display settings), maintain your session state so you do not need to log in repeatedly, and keep track of which patient profile you were last viewing.

We do not process your data for advertising purposes. We do not sell your personal data to third parties. We do not use your data to build marketing profiles.

5. Legal Basis

Under the Swiss Federal Act on Data Protection (nDSG), we rely on the following legal bases for processing your personal data:

5.1 Explicit Consent (Art. 6 para. 7 nDSG)

For the processing of sensitive health data, including patient profile information, care timeline entries, voice recordings, photo analysis results, and any other health-related data, we rely on your explicit consent. You provide this consent during the onboarding process when you create your first patient profile and acknowledge that health-related data will be processed. You may withdraw your consent at any time without affecting the lawfulness of processing that occurred before withdrawal.

5.2 Contract Performance

For account management, authentication, and delivering the core features of Memento AI, processing is necessary for the performance of our contract with you (the Terms of Service). Without this processing, we cannot provide the service.

5.3 Legitimate Interest

For technical data processing, including server logs, security monitoring, and abuse prevention, we rely on our legitimate interest in maintaining a secure and reliable service. We have assessed that these interests do not override your fundamental rights and freedoms, given the limited nature of the technical data involved and the security benefits for all users.

6. Sensitive Personal Data

Under the Swiss nDSG, health data is classified as "particularly sensitive personal data" (Art. 5 lit. c). Memento AI processes several categories of data that fall under this classification:

  • Diagnosis status and medical condition descriptions
  • Behavioral observations and daily care notes relating to health
  • AI-generated health assessments and flagged concerns
  • Voice analysis results (mood, coherence, engagement metrics)
  • Any health-related notes or observations entered by caregivers

We process this sensitive data only with your explicit consent, which you provide during account onboarding. The sole purpose of processing this data is to deliver the care support features of Memento AI and to help you and your family track and understand the well-being of your loved one.

You may withdraw your consent at any time by contacting us at [Contact Email] or by deleting your account through the Settings page. Upon withdrawal, we will cease processing your sensitive data, though we may retain certain data as required by law or to fulfill legitimate obligations. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

7. Data Recipients and Third-Party Processors

We share your personal data with the following service providers who act as data processors on our behalf. Each processor has access only to the data necessary to perform its function, and all are bound by data processing agreements that require them to implement appropriate technical and organizational security measures.

7.1 Supabase Inc.

Location: San Francisco, California, USA

Function: Database hosting (PostgreSQL), file storage (photos and voice recordings), and user authentication.

Data received: All data stored in the application database, including account data, patient profiles, timeline entries, Care Circle data, and all files uploaded to storage (photos and voice recordings). Supabase also processes authentication events (login, logout, password reset).

7.2 Anthropic

Location: San Francisco, California, USA

Function: AI analysis via the Claude API, including timeline summarization, voice transcript analysis, photo analysis, and conversational AI features.

Data received: Patient first name only (no surname is transmitted), user questions and messages, voice recording transcripts, and photo data when you actively use AI features. Data is sent to Anthropic only when you initiate an AI-powered action. Anthropic's own data retention and usage policies apply to data received through their API.

7.3 Vercel Inc.

Location: San Francisco, California, USA

Function: Web application hosting, content delivery, and serverless function execution.

Data received: IP addresses, request URLs, and request metadata via server logs. Vercel processes this data as part of serving the web application to your browser.

7.4 Google LLC

Location: Mountain View, California, USA

Function: Web font delivery via the Google Fonts content delivery network (CDN).

Data received: When your browser loads the application, it requests font files from Google's servers. During this process, Google may receive your IP address and standard HTTP request headers. No application data is shared with Google through this mechanism.

8. Cross-Border Data Transfers

All of our processors listed in Section 7 are based in the United States. Under the Swiss nDSG (Art. 16–17), the transfer of personal data to countries that do not have an adequate level of data protection as recognized by the Swiss Federal Council requires additional safeguards.

The United States is currently not on the list of countries with adequate data protection recognized by Switzerland. We therefore rely on the following mechanisms to legitimize these transfers:

8.1 Your Explicit Consent

By accepting this Privacy Policy and using Memento AI, you explicitly consent to the transfer of your personal data, including particularly sensitive health data, to the United States for processing by our service providers as described in Section 7. You understand that the data protection standards in the United States may differ from those in Switzerland.

8.2 Standard Contractual Clauses

We are in the process of establishing Standard Contractual Clauses (SCCs) with our processors to provide additional contractual safeguards for cross-border data transfers. SCCs are standardized contractual terms that obligate processors to protect your data in accordance with European and Swiss data protection standards, regardless of where the data is processed.

8.3 Withdrawal and Consequences

You may withdraw your consent to cross-border data transfers at any time by discontinuing use of the service and requesting deletion of your data. Please be aware that because all of our core infrastructure is hosted in the United States, withdrawing consent to cross-border transfers will make it impossible for us to continue providing the service to you.

9. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy, or as required by law. The specific retention periods are:

  • Account data: Retained for the lifetime of your account. Upon account deletion, your account data is permanently removed within 30 days.
  • Patient profile data: Retained for as long as the patient profile exists in the system. When the profile owner deletes a patient profile, all associated data (including timeline entries, photos, voice recordings, and AI analysis results) is deleted.
  • Voice recordings and photos: Retained together with the patient profile they are associated with. These files are removed when the patient profile is deleted.
  • AI analysis results: Retained alongside the timeline entries, photos, or voice recordings they relate to. When the parent entry is deleted, the analysis results are also removed.
  • Care Circle data: Invitation records are retained while the associated patient profile exists. When a Care Circle member is removed or the profile is deleted, access is revoked immediately.
  • Technical logs: Server and access logs are retained for up to 90 days and then automatically purged. These logs are used for security monitoring and troubleshooting during that period.
  • Local storage data: Data stored in your browser's local storage persists on your device until you manually clear your browser data, uninstall the application, or clear it through the app's settings.

After account or profile deletion, residual copies in encrypted backups may persist for a limited period (typically up to 30 additional days) before being overwritten through normal backup rotation.

10. Your Rights Under the nDSG

Under the Swiss Federal Act on Data Protection, you have the following rights regarding your personal data. We are committed to facilitating the exercise of these rights in a timely manner.

10.1 Right to Information (Art. 25 nDSG)

You have the right to request confirmation of whether we process personal data about you, and to receive details about what data we hold, the purposes of processing, the recipients of your data, and the retention periods. We will respond to your request within 30 days.

10.2 Right to Data Portability (Art. 28 nDSG)

You have the right to receive your personal data in a commonly used, structured, and machine-readable format. Memento AI provides a Data Export feature in the Settings page that allows you to download your data directly. You may also contact us to request a data export.

10.3 Right to Correction

You have the right to request the correction of inaccurate or incomplete personal data. You can update most of your data directly within the application (profile information, timeline entries, patient profiles). For data you cannot correct yourself, please contact us.

10.4 Right to Deletion

You have the right to request the deletion of your personal data. You can delete patient profiles and your account directly through the Settings page. You may also contact us to request deletion. We will process deletion requests within 30 days, subject to any legal retention obligations.

10.5 Right to Object

You have the right to object to the processing of your personal data where we rely on legitimate interest as the legal basis. Upon receiving your objection, we will assess whether our legitimate interests override your rights and freedoms, and inform you of the outcome.

10.6 Right to Withdraw Consent

Where processing is based on your consent (particularly for sensitive health data), you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing that took place before the withdrawal. To withdraw consent, contact us at [Contact Email] or delete your account through the Settings page.

10.7 Right to Lodge a Complaint

If you believe that our processing of your personal data violates the nDSG, you have the right to lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC):

Federal Data Protection and Information Commissioner (FDPIC)
Feldeggweg 1
CH-3003 Bern
Switzerland
Website: www.edoeb.admin.ch

To exercise any of these rights, please contact us at [Contact Email]. We may ask you to verify your identity before processing your request to protect the security of your data.

11. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. Given the sensitive nature of the health data we process, we take security particularly seriously.

Our security measures include:

  • Row-Level Security (RLS): Our database enforces row-level security policies that ensure each user can only access their own data and data that has been explicitly shared with them through the Care Circle feature. This is enforced at the database level, not just the application level.
  • Encryption in transit: All data transmitted between your browser and our servers is encrypted using HTTPS/TLS. This applies to all API calls, file uploads, and page requests.
  • Authentication security: User authentication is handled via industry-standard OAuth 2.0 protocols and secure session management. Session tokens are stored securely and expire after periods of inactivity.
  • Authenticated AI access: All AI features require active user authentication. No data is sent to AI services without a valid, authenticated session.
  • Access monitoring: We regularly monitor access patterns to detect unusual activity and potential security threats.

While we strive to protect your personal data, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security, but we are committed to promptly addressing any security incidents and notifying affected users in accordance with applicable law.

12. Cookies and Local Storage

Memento AI primarily uses browser local storage rather than traditional HTTP cookies to maintain session state and store your preferences. Local storage allows the application to remember your settings (such as language preference and active patient selection) between visits without transmitting this information to third parties.

Our authentication system may use secure, HTTP-only cookies or tokens for session management. These are strictly necessary for the application to function and cannot be disabled while using the service.

We do not use tracking cookies, analytics cookies, or advertising cookies. We do not participate in cross-site tracking or retargeting programs.

For detailed information about what data is stored locally in your browser and how to manage it, please see our Cookie & Storage Policy.

13. Automated Decision-Making

Memento AI uses artificial intelligence (powered by the Anthropic Claude API) to analyze voice recordings, photos, and care timeline entries. We want to be transparent about how these AI features work and their limitations.

Our AI features:

  • Provide advisory insights only. AI-generated analyses, summaries, and flagged concerns are informational in nature. They do not constitute medical diagnoses or binding decisions of any kind.
  • May flag potential health concerns based on patterns detected in voice recordings, behavioral observations, or timeline entries. These flags are presented for your review and consideration.
  • Do not replace professional medical judgment. Memento AI is a care companion tool, not a medical device. All AI outputs should be discussed with qualified healthcare professionals before making any care decisions.
  • Cannot serve as the sole basis for any care decision. You should always use your own judgment and consult with medical professionals when interpreting AI-generated insights.

No automated decisions with legal or similarly significant effects are made about you or the people you care for. All AI outputs are presented as suggestions and observations for human review. You are always in control of what actions to take based on the information provided.

14. Children's Data

Memento AI is designed for adult caregivers and family members managing care for their loved ones. The service is not intended for use by persons under 16 years of age, and we do not knowingly collect personal data from children.

While a patient profile may describe a person of any age (if they are receiving care), the application users who create accounts, enter data, and interact with AI features must be adults. Minors should not create accounts or use Memento AI without supervision.

If you believe that a child under 16 has provided us with personal data by creating an account, please contact us immediately at [Contact Email]. We will take prompt steps to verify the situation and, if confirmed, delete the child's personal data from our systems.

15. Changes to This Policy and Contact

We may update this Privacy Policy from time to time to reflect changes in our data processing practices, to incorporate new features, or to comply with evolving legal requirements under the nDSG or other applicable legislation.

When we make material changes to this policy, we will notify you via an in-app notification before the changes take effect. We encourage you to review this Privacy Policy periodically. The "Last Updated" date at the bottom of this page indicates the date of the most recent revision.

Your continued use of Memento AI after changes are posted constitutes your acceptance of the revised Privacy Policy. If you do not agree with any changes, you should discontinue use of the service and request deletion of your data.

Contact Information

For any questions about this Privacy Policy, to exercise your data protection rights, or to raise a concern about how your data is being handled, please contact us:

Email: [Contact Email]
Mailing address: [Company Address]

Swiss Data Protection Authority

If you are unsatisfied with our response or believe that we are processing your data unlawfully, you have the right to contact the Swiss supervisory authority:

Federal Data Protection and Information Commissioner (FDPIC)
Feldeggweg 1
CH-3003 Bern
Switzerland
Website: www.edoeb.admin.ch

Last updated: February 2026

Memento AI by [Company Name]