Skip to content
Memory Jar
How it works Privacy Terms
← Back to home

Privacy Policy

Last updated: 5 July 2026

Who we are

Memory Jar is an Android app provided by Joshua David Lawson, a sole trader trading as “appy lad” (“we”, “us”, “our”), based in the United Kingdom. We are the data controller for the limited personal data described below.

You can contact us about privacy at support@memory-jar.app.

The short version

Memory Jar is local-first and built so that we cannot read your memories. Everything you create stays on your device unless you choose to turn on cloud backup or share a keepsake, and those are encrypted on your device before they leave it. We show no ads, use no third-party trackers, and never sell your data.

What stays on your device

By default, everything you put into Memory Jar (your jars, notes, photos, voice notes, and the people or occasions they are for) is stored only on your device, in a database that is fully encrypted at rest using SQLCipher. None of it is sent to us. Temporary decrypted copies of photos or audio are treated as throwaway and cleared. You can also require fingerprint or face unlock to open the app.

If you never turn on cloud backup, never share a keepsake, and never send us a problem report, we hold no personal data about you at all.

What we process if you use cloud features

These features are optional and only run when you choose to use them.

  • Cloud account. To use cloud features you create an account with an email address and password, managed for us by Amazon Cognito. We store your email address so the account works. Your password is handled by Cognito and is not visible to us.
  • Encrypted cloud backup. When you turn on cloud backup, your data is encrypted on your device before upload. We generate a random 256-bit key that encrypts your backup, and that key is itself locked with your passphrase (stretched with PBKDF2-SHA256 at 310,000 iterations) plus a one-time recovery code. The unlocked key never leaves your device. Our servers hold only encrypted data and a locked copy of the key, so we cannot read your backup. Because of this, if you lose both your passphrase and your recovery code, no one (including us) can recover your backup.
  • Shared keepsakes. When you share a sealed jar, it is encrypted with AES-256 and the decryption key is placed in the link itself, in the part after the “#”, which browsers never send to a server. The keepsake is decrypted in the recipient’s browser. Only someone with the exact link can open it, and we cannot read a keepsake you have shared.

Payments

Paid subscriptions are sold and billed through Google Play. Google handles your payment details; we never see your card information. We receive your subscription status (whether it is active and when it renews) so we can unlock paid features.

Problem reports

If you choose to send a problem report from the app, it opens your email app pre-filled with: the app version, your device model and Android version, the error that occurred (if any), and any note you write. It is sent only when you send it, and it never includes your notes, photos, voice notes, or any other memory content.

Who processes data for us

We keep our list of processors short and use them only to run the optional cloud features:

  • Amazon Web Services (AWS) for account sign-in (Cognito) and encrypted backup storage and keepsake hosting (S3, CloudFront, Lambda), in the London (eu-west-2) region.
  • Google Play for subscription billing.

We do not use third-party advertising, analytics, or tracking SDKs in the app.

What we do not do

  • No ads and no advertising identifiers.
  • No third-party analytics or behaviour tracking in the app.
  • We never sell, rent, or share your personal data for marketing.

This website

The memory-jar.app website (the pages you are reading now) uses Cloudflare Web Analytics to count visits. It is privacy-first and cookieless: it sets no cookies, stores nothing on your device, does not identify or fingerprint you, and collects no personal data. We see aggregate figures such as page views, referrers, and country. This is separate from the app, which uses no analytics at all.

Legal bases (UK GDPR)

Where we process personal data, our lawful bases are: performing our contract with you (providing the cloud features and subscription you ask for), your consent (which you give by turning a feature on and can withdraw by turning it off), and our legitimate interests (keeping the service secure and fixing problems you report).

How long we keep data

  • Local data stays on your device until you delete it or uninstall the app.
  • An encrypted cloud backup stays until you delete it or delete your account. If your subscription lapses, your existing backup remains restorable; we do not hold your memories hostage.
  • Your account email is kept while your account exists. Delete your account in the app, or ask us to, and we remove it.

Deleting your data

You can remove your data at any time:

  • On your device: delete individual jars or notes in the app, or uninstall Memory Jar to remove everything stored locally.
  • Cloud backup and account: turn off cloud backup in the app to stop backing up. To erase your cloud backup and close your account, open Settings → Account → Delete cloud account in the app, or email support@memory-jar.app from your account address. See deleting your account for step-by-step instructions. Because the backup is encrypted with a key only you hold, deleting it removes the data we hold; we were never able to read it.
  • Shared keepsakes: stop sharing a keepsake to revoke its link; hosted shares also expire automatically.

We action deletion requests within 30 days, as required by UK GDPR.

Your rights

Under UK GDPR you have the right to access, correct, delete, restrict, or port your personal data, and to object to processing or withdraw consent. To exercise any of these, email support@memory-jar.app. You also have the right to complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk. We are registered with the ICO under registration number ZC189956.

Children

Memory Jar is not directed at children under 13, and we do not knowingly collect personal data from them.

Changes to this policy

If we change this policy we will update the date above and, for significant changes, surface a notice in the app. Continuing to use Memory Jar after a change means you accept the updated policy.

Contact

Questions or requests: support@memory-jar.app, or by post: appy lad, Unit 169383, PO Box 7169, Poole, BH15 9EL, United Kingdom.

Memory Jar
FAQ Privacy Terms Contact
For parents For long distance Just for you Private

Made by appy lad. in the UK