Skip to content

Your data is safe

We understand that your memories are irreplaceable. Here is exactly how we protect them — with transparency, care, and the highest standards.

Hosting & Infrastructure

Hosted on Vercel

Your Memory Palace runs on Vercel, a world-class hosting platform with a global content delivery network (CDN). Every page loads fast, and every connection is automatically secured with HTTPS.

Database in the EU

All your data is stored on Supabase PostgreSQL in Frankfurt, Germany — safely within the European Union. This means your memories are protected by strict EU data protection laws (GDPR).

We are committed to GDPR compliance

We follow the General Data Protection Regulation to the letter. Your personal data is processed lawfully and transparently, and only for the purposes you have agreed to.

Encryption

Encrypted in transit (TLS 1.2+)

Every connection between your device and our servers uses TLS 1.2 or higher, ensuring strong transport encryption. Nobody can read your data as it travels over the internet.

Encrypted at rest (AES-256)

Your database is encrypted with AES-256, the same standard used by banks and governments. Even if someone accessed the physical servers, your data would be unreadable.

Encrypted file storage

Your photos, videos, and documents are stored in Supabase Storage, which is also encrypted at rest. Files are only accessible through authenticated, time-limited links.

Secure password hashing

Your password is never stored in plain text. It is hashed using bcrypt through Supabase Auth, making it practically impossible to reverse-engineer.

Authentication & Access

Email & password login

Sign in securely with your email address and password. Your credentials are handled by Supabase Auth, a battle-tested authentication system.

Social login (Google, Apple)

Prefer to sign in with Google or Apple? We support OAuth 2.0 social login — your password is never shared with us when you use these options.

Two-factor authentication

For extra peace of mind, you can enable two-factor authentication (2FA) using a TOTP app like Google Authenticator. This adds a second layer of protection to your account.

Row Level Security

Every database table is protected by Row Level Security (RLS). This means you can only ever access your own data — this is enforced at the database level, not just in our code.

JWT session management

Your login sessions use JSON Web Tokens (JWT), which are short-lived and cryptographically signed. Sessions expire automatically, keeping your account safe even if you forget to log out.

Privacy Controls

Full data export

You can download everything — all your memories, stories, and photos — as a JSON file with a ZIP of your media. Your data always belongs to you.

Complete account deletion

If you choose to delete your account, all your data is permanently removed. Deletion cascades through every table — nothing is left behind.

Cookie consent

We ask for your permission before setting any non-essential cookies. You can change your preferences at any time through our cookie consent controls.

No tracking, no ads, no data selling

We will never sell your data, show you advertisements, or track you across the web. Your memories are private, and that is a promise.

Legacy contacts

You can designate trusted family members as legacy contacts for digital inheritance. When the time comes, your memories can be passed on to the people you choose.

Backup & Redundancy

Daily automated backups

Your data is backed up automatically every day. In the unlikely event of a problem, we can restore your palace to its most recent state.

Point-in-time recovery

Our database supports point-in-time recovery, meaning we can restore data to any moment within the retention window — not just the last backup.

Replicated storage

Files are stored with redundancy across multiple availability zones. Even if one data center has issues, your memories remain safe and accessible.

Your memories are meant to last generations.
We take that responsibility seriously.

If you have questions about how we handle your data, or if you want to exercise any of your rights under GDPR, please contact us at privacy@thememorypalace.ai. We are here to help.

Ready to start preserving?

Your memories deserve a safe, beautiful home. Get started for free — no credit card required.

Create Your Memory Palace