⚠️ DRAFT – needs legal review before publication
Generated from a Nova template. This is not legal advice and must not be published until a lawyer has checked it and marked it reviewed.
Missing facts to fill in: 2.
Memory Box – Privacy Policy
Version 0.2.0-draft · Effective from: ⟦TO FILL: data zatwierdzenia / approval date⟧
This Privacy Policy explains how personal data is processed when you use Memory Box (a private family archive of recorded memories), available for iOS devices (App Store) (the "Service"). It is written to be read: every section says what we do, why, and what you can do about it.
1. Who we are
The controller of your personal data is NOVA AI VENTURES SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, ul. Jasna 26, 00-054 Warszawa, Poland, entered in the register kept by the District Court for the Capital City of Warsaw, 12th Commercial Division of the National Court Register, KRS 0001208266, NIP 5253069869, REGON 543362820, EU VAT PL5253069869, share capital PLN 156,000.00 ("NovaAI", "we", "us").
You can reach us at privacy@novaai.ventures, or by post at the address above.
We process personal data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") and the applicable Polish law.
2. Two kinds of data, two roles
When you use the Service, two kinds of personal data are processed, and our role is different for each:
- Your account data (for example your name and e-mail address). For this data, we are the controller: we decide why and how it is processed, as described in this policy.
- Personal data inside the content you add – audio and video recordings, photos, transcripts, descriptions and information about the people close to you (in the Service called "Memories", in this policy "User Content"), including data of other people who appear in it. For this data, you decide what is recorded, why and who sees it. To the extent the GDPR applies to you, you are the controller of that data and we process it on your behalf as a processor (Article 28 GDPR), on the terms set out in the Terms of Service (https://memory-box.family/en/terms). Processing by a natural person in the course of a purely personal or household activity is outside the GDPR (Article 2(2)(c) GDPR).
3. What data we process
Account data
When you create an account and use the Service, we process: your e-mail address, your name or display name, the identifiers of your account and of the sign-in methods you use (if you sign in through another provider, we never receive your password for it), your language and other settings, and the history of your consents.
Technical and usage data
To run and secure the Service we process technical data: IP address, device and operating-system type and version, app version, time and type of requests, and error reports.
User Content
You can add audio and video recordings, photos, transcripts, descriptions and information about the people close to you. User Content may include personal data – yours and of other people, for example their names, faces or voices. You decide what you add and who can see it.
Members of your Circle
The Service lets you create or join a group (in the Service: "Circle") and invite others by e-mail or link. We process the e-mail addresses of the people you invite, their roles (Owner, Administrator, Member), the invitation status, and which content is shared with whom.
4. Why we process data and on what legal basis
| Purpose | Legal basis |
|---|---|
| Creating and running your account and providing the Service | performance of the contract (Article 6(1)(b) GDPR) |
| Answering your messages and support requests | performance of the contract (Article 6(1)(b) GDPR) or our legitimate interest in communicating with users (Article 6(1)(f) GDPR) |
| Securing the Service, preventing abuse, fixing errors | our legitimate interest in a secure and working Service (Article 6(1)(f) GDPR) |
| Handling notices about illegal content and moderation decisions | our legal obligations under Regulation (EU) 2022/2065 (Digital Services Act) (Article 6(1)(c) GDPR) |
| Recording consents and objections, and proving compliance | our legal obligations and legitimate interest (Article 6(1)(c) and (f) GDPR) |
| Establishing, pursuing or defending legal claims | our legitimate interest (Article 6(1)(f) GDPR) |
Giving your account data is voluntary, but without it we cannot create an account or provide the Service. Consents are always optional: refusing them does not limit the Service, and you can withdraw a consent at any time (Profile → Privacy and data → Consents and withdrawal) without affecting processing done before the withdrawal.
5. AI features
The Service uses artificial intelligence models to prepare interview questions before a recording and, after it, produce a transcript, chapters, suggested title, description, dates, places and people, profile facts and a cover picture. To do this, the data needed for the specific task (for example the content you are working on) is sent to the AI model provider listed in section 6, which processes it on our instructions only to produce the result.
- Your data and User Content are not used to train or improve AI models – neither ours nor the provider's.
- AI results can contain mistakes. You decide whether to use, change or reject them.
- AI does not make decisions about you that have legal or similarly significant effects.
6. Who receives your data
We do not sell personal data. We share it only with service providers who help us run the Service and who process it on our instructions (processors), under data processing agreements required by Article 28 GDPR. The current list:
| Provider | What for | Data | Where | Transfer safeguard | Agreement |
|---|---|---|---|---|---|
| WorkOS, Inc. ⟦TO FILL: row to be verified by legal (verified: false)⟧ (processor) | sign-in, user authentication and session management | e-mail address, name, account identifiers, sign-in tokens and credentials, IP address, device data | United States | standard contractual clauses (Commission Decision 2021/914) | https://workos.com/legal/data-processing-addendum; sub-processors: https://workos.com/legal/subprocessors |
| Cloudflare, Inc. ⟦TO FILL: row to be verified by legal (verified: false)⟧ (processor) | storing and serving files (user content, profile photos) | user content, media files, profile photo, account identifiers | EU (R2 bucket in the EU jurisdiction); company in the US | EU–US Data Privacy Framework and standard contractual clauses | https://www.cloudflare.com/cloudflare-customer-dpa/; sub-processors: https://www.cloudflare.com/gdpr/subprocessors/ |
| Google LLC (Gemini API, paid services) ⟦TO FILL: row to be verified by legal (verified: false)⟧ (processor) | running AI features (Gemini models via the Gemini API) | data sent to AI models, AI model outputs, user content | United States and other Google locations | EU–US Data Privacy Framework and standard contractual clauses | https://business.safety.google/processorterms/ |
| Plus Five Five, Inc. (Resend) ⟦TO FILL: row to be verified by legal (verified: false)⟧ (processor) | sending account and service e-mails (e.g. invitations, confirmations) | e-mail address, name, e-mail content, account identifiers | sent from the EU (Ireland); account data and logs in the United States | EU–US Data Privacy Framework and standard contractual clauses | https://resend.com/legal/dpa; sub-processors: https://resend.com/legal/subprocessors |
| Apple Inc. (Apple Push Notification service) ⟦TO FILL: row to be verified by legal (verified: false)⟧ (processor) | delivering push notifications to Apple devices | push notification tokens, notification content | United States | EU–US Data Privacy Framework | https://developer.apple.com/support/terms/apple-developer-program-license-agreement/ |
| Cloudflare, Inc. ⟦TO FILL: row to be verified by legal (verified: false)⟧ (processor) | hosting the product website (Cloudflare Pages) and delivering it over Cloudflare's network | IP address, device data, sign-in tokens and credentials | Cloudflare's global network; company in the US | EU–US Data Privacy Framework and standard contractual clauses | https://www.cloudflare.com/cloudflare-customer-dpa/; sub-processors: https://www.cloudflare.com/gdpr/subprocessors/ |
| Functional Software, Inc. (Sentry) ⟦TO FILL: row to be verified by legal (verified: false)⟧ (processor) | detecting and diagnosing app errors | crash and error reports, device data, account identifiers | EU (Frankfurt) for error data; Sentry account data (users, settings) in the United States | EU–US Data Privacy Framework and standard contractual clauses | https://sentry.io/legal/dpa/; sub-processors: https://sentry.io/legal/subprocessors/ |
| Hostinger International Ltd. (Hostinger) ⟦TO FILL: row to be verified by legal (verified: false)⟧ (processor) | hosting the Memory Box server and database during the pilot | account identifiers, e-mail address, name, user content, media files, IP address | EU — Germany (Frankfurt am Main); company in Cyprus | none – data stays in the EEA | https://www.hostinger.com/legal/dpa |
Some providers also decide themselves about part of the processing (for example a payment provider's own fraud-prevention and regulatory duties). For that part they are independent controllers and their own privacy policies apply:
| Provider | What for | Their terms |
|---|---|---|
| Apple Inc. (App Store Connect / TestFlight) ⟦TO FILL: row to be verified by legal (verified: false)⟧ | TestFlight beta-test invitations (the tester's e-mail address and name) | https://developer.apple.com/support/terms/apple-developer-program-license-agreement/ |
We may also disclose data to public authorities when the law requires it, and to our advisers (lawyers, auditors, accountants), who are bound by confidentiality.
Content you share is visible to the people you share it with (the members of your Circle with access to it).
7. Transfers outside the European Economic Area
Some providers listed in section 6 are based or process data outside the European Economic Area (EEA). In those cases data is transferred only with the safeguards shown in the table: an adequacy decision of the European Commission (including the EU–US Data Privacy Framework for certified US companies) or standard contractual clauses adopted by the European Commission (Decision (EU) 2021/914), together with additional technical measures such as encryption where needed. You can ask us for a copy of these safeguards at privacy@novaai.ventures.
8. How long we keep data
We keep personal data only as long as we need it for the purpose it was collected for:
| Data | How long |
|---|---|
| Account data | until the account is deleted, then 30 more days; after that the data is deleted |
| Memories and the results of their processing | until deleted by the user, the storyteller withdraws consent, or the account is deleted |
| Backups | 30 days; older copies are deleted |
| Server and security logs | 30 days |
| Consent and withdrawal records | while the account exists, then 3 more years after it is deleted |
When a period ends, the data is deleted or irreversibly anonymised. Data in backup copies is overwritten in the normal backup cycle. We may keep data longer only where the law requires it or for as long as needed to establish, pursue or defend legal claims.
9. Your rights
You have the right to:
- access your data and get a copy of it;
- rectify data that is wrong or incomplete;
- erase your data ("right to be forgotten") – you can also delete your account yourself: https://memory-box.family/en/delete-account;
- restrict processing;
- data portability – receive the data you gave us in a machine-readable format;
- object to processing based on our legitimate interest, and at any time to processing for direct marketing;
- withdraw consent at any time, without affecting processing done before the withdrawal.
To use these rights, write to privacy@novaai.ventures. We answer within one month; in complex cases we may extend this by two further months and will tell you why within the first month (Article 12(3) GDPR). We may ask you to confirm your identity.
Requests about personal data inside User Content should go first to the user who added it, because they decide about that data. If you contact us, we will pass your request on to them and help them answer it.
10. Automated decisions
We do not make decisions about you based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you (Article 22 GDPR).
11. Cookies and similar technologies
The Service uses cookies and similar technologies (for example local storage in the browser or identifiers in the app). Strictly necessary ones are used without consent; all others only with your consent. Details are in the Cookie Notice: https://memory-box.family/en/cookies.
12. How we protect data
We use technical and organisational measures appropriate to the risk, including:
- encrypted connections (HTTPS) for all data in transit
- storing Memories in cloud storage with access control
- access to personal data only for the people who need it for their work
- deleting data within the periods described in this policy
If a personal data breach is likely to result in a high risk to you, we will inform you without undue delay (Article 34 GDPR).
13. Supervisory authority
If you think we process your data unlawfully, you can lodge a complaint with the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl), or with the supervisory authority of the EU country where you live, work or where the infringement took place.
14. Children
The Service is intended for people aged at least 16. We do not knowingly create accounts for younger people; if you believe that a child has created an account, write to privacy@novaai.ventures and we will delete it. If User Content contains data of children (for example photos), the user who adds it is responsible for having a legal basis to do so.
15. Changes to this policy
We may update this policy, for example when we add a provider or a new feature. We will inform you about important changes in the Service or by e-mail before they take effect. The version and the effective date are shown at the top.
16. Contact
NOVA AI VENTURES SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, ul. Jasna 26, 00-054 Warszawa, Poland Privacy questions: privacy@novaai.ventures · Support: privacy@novaai.ventures