Legal & trust
Privacy statement
This page is maintained by The Memory Box to answer common privacy questions about The Memory Box. It describes the data we collect, how we use it, and the choices you have. It is not an independent certification, audit report, or legal contract.
What The Memory Box is
The Memory Box is a public archive of first-person memories. Most contributions are shared openly so others can read, listen, and learn from them. You can share a memory without creating an account, or create a free account to keep all your memories in one place and edit them later.
What we collect
- Story content: the text, video, audio, photos, scanned journal pages, newspaper clippings, documents and other files you upload, along with any captions you add to them.
- Details about the memory: the date of the experience (exact or approximate), where you were at the time (city, state or country), your current state or country, how you experienced it, your age or life stage at the time, any content notes, and the tags you choose from the question's tagging layers.
- How you're credited: your choice of full name, first name only, initials, or fully anonymous, and your permission to publish the memory, which we record with the story.
- Optional perspectives about you: if you choose to fill them in, your birth decade, ethnicity, nationality, current religion, gender, the country you were raised in and your current country. These are always optional, always self-described, never inferred, and never used as a public filter — they are used only in aggregate.
- Account information: if you create an account, we store your email address and any display name you provide. You can sign up with email or Google OAuth.
- Guest contact email: if you share a memory without an account, we store the email address you give us privately, separately from the story. It is never shown with the memory.
- Community and sharing activity: the communities you host or join, the questions you create, invitations and share links you send, collections you follow, and likes and comments you leave.
- Payment information: if you subscribe, our payment provider handles your card details — we never see or store them. We keep a record of your plan, its status and its renewal date.
- Usage data: basic technical information needed to run the site, such as your browser type, IP address, and which pages you visit. We do not use this to build an advertising profile.
Sensitive details about identity
Nationality, religion and ethnicity are three separate, optional fields you describe in your own words. We never guess them from your name, story or location. By default they are used only to understand the range of perspectives in the archive as a whole — they are not shown as a public filter and are not attached to your story for readers to browse. You can change or clear them at any time from your profile.
Tags and who can see them
The tags and location details you add to a memory are visible to you when signed in, and to moderators. They help us map where memories come from — a map pin shows only the state or country, never a precise address.
Review and moderation
Memories shared without an account wait for approval before they appear, and hosts can turn review on for their own community wall. Submissions sent in an unusual rush, or repeating an existing memory word for word, are also held. Moderators can read a held memory and the contact email attached to it in order to approve, edit or remove it.
Private communities
Community walls are private. Only the host and the members who join can read the memories shared there. If a community question matches a public one, you can choose to add your memory to the public archive as well — that only happens when you ask for it.
Translation
When a reader asks to translate a memory, the story text is sent to a translation service to produce that translation. The original text is always kept and readers can switch back to it.
Emails we send
We use your email address for account emails — confirming your address, signing in, resetting a password, invitations you send or receive, and receipts for a subscription. We don't sell your email address or use it for advertising.
Guest submissions
You can share a memory without signing in. We ask guests for an email address, which is never made public and never shown with the memory — we use it only for take-down requests and research-permission follow-up. Guest stories are stored in the archive and become public once approved by moderation. Because a guest submission isn't tied to an account, it cannot be edited or deleted from the site unless you create an account and claim it. We make that clear at the time you submit.
How we use your memories
- Display them on the site as part of the public archive.
- Show them on your personal memory wall if you have an account.
- Generate a transcript when you record a video, so readers can read what was said.
- Run automated language checks to flag content that may breach community standards.
- Use them for anonymized research only if you explicitly opt in with the research-consent checkbox on the submission or edit form. That consent is off by default and stored with the story.
What's public and what stays private
This is the part most people care about, so here it is plainly. Stories in the public archive are readable by anyone. Stories on a community wall are readable only by that community's host and members.
Shown publicly with your story
- The story text, and any photos, video, audio or files you attached, with captions.
- How you chose to be credited — and only that: your full name, your first name only, your initials, or nothing at all if you chose fully anonymous.
- The date of the experience, and the state or country you were in at the time.
- A content note, if you added one.
- A transcript of a video, when you or a moderator make it visible.
Never shown publicly
- Your real name, if you chose initials or fully anonymous. Always.
- Your contact email — your account email or the email you gave as a guest. Always.
- Your nationality, religion or ethnicity (see the section below).
- Your birth decade, gender, the country you were raised in, or your current country.
- Your street address or any precise location — map pins show only a state or country.
- The tags on your story, which are visible to you when signed in and to moderators.
- Your plan, payment records, and site usage data.
Nationality, religion, and ethnicity
These are three separate fields, and all three are governed by the same commitments, which we state here so they are documented and not just a design choice:
- Optional. You can leave any or all of them blank and share memories normally.
- Self-described. You write them in your own words. We never infer them from your name, story, location, or anything else.
- Aggregate-only by default. They are used to understand the range of perspectives across the archive as a whole, not displayed beside your story.
- Never a public filter. No reader can browse or search the archive by nationality, religion, or ethnicity.
- Reversible. You can change or clear them at any time from your profile.
A note worth saying out loud: in a small community, a combination of details can make someone recognizable even without a name. If your memory is sensitive, consider a lower level of credit and fewer identifying details.
Video and transcripts
Videos are capped at five minutes and compressed in your browser before upload. The site administrator decides whether uploaded videos are transcribed. Transcripts are stored alongside the video and shown to readers when the author or admin chooses to make them visible.
Cookies and analytics
We use a small cookie or localStorage entry to keep you signed in. We do not use third-party advertising cookies. We may use basic analytics to understand which pages are popular, but we do not sell or share that data with advertisers.
How long we keep data
- Memories: kept for as long as the archive exists, because the value of a memory grows over decades — unless you ask us to remove it.
- Account data: kept while your account is open. If you close it, we delete your profile and perspectives within 30 days.
- Guest contact emails: kept while the memory is in the archive, only for moderation and takedown requests.
- Payment records: kept as long as tax and accounting rules require, usually seven years.
- Usage data: kept in a short rolling window, normally under 12 months.
- Backups: deleted content can persist in backups for up to 30 days before those copies are overwritten.
Corrections, removal, and takedown
You can edit or delete any memory you shared while signed in, and update your display name, perspectives and research-consent choices at any time. For anything else — including a memory shared as a guest — email us and tell us which memory it is.
- We acknowledge every request within 5 business days.
- We complete corrections and removals within 30 days, and usually much sooner.
- We remove a memory that names or identifies you, or a member of your family, on request.
- A contributor's next of kin or estate representative can request a correction, removal, or a copy of that person's memories. We may ask for proof of the relationship first.
- You can ask us for a copy of everything we hold about you, in a file you can keep.
Age and children's privacy
You must be at least 13 years old to share a memory or create an account. We do not knowingly collect information from children under 13; if we learn that we have, we delete it. A contributor between 13 and 18 should have a parent or guardian's permission before sharing.
Writing about your own childhood is welcome. Writing about a child who is a minor today is different: don't include their full name, school, address, or photographs that identify them without a parent or guardian's consent. A parent or guardian can ask us to remove a memory that identifies their child, and we will.
If you're in Europe or the UK
Under the GDPR and UK GDPR you have the right to access your data, correct it, delete it, restrict or object to how we use it, withdraw a consent you gave, and receive a portable copy. We rely on your consent for publishing a memory and for the optional perspectives and research use, and on our legitimate interest in running and archiving the site for the rest. Email us to exercise any of these rights — free of charge, answered within 30 days. You also have the right to complain to your local data protection authority. Our data is hosted with providers who use standard contractual clauses for international transfers.
If you're in California
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. You have the right to know what we collect, to request a copy or deletion, and to correct inaccuracies, and we will never treat you differently for asking. The categories we collect are listed at the top of this page.
Security
We use industry-standard protections for data in transit and at rest, including managed authentication and access controls. No system is perfectly secure, and we encourage you not to share passwords or sensitive personal information in your stories.
Who processes data with us
The Memory Box runs on managed cloud infrastructure and uses third-party services for authentication, database hosting, media storage, and AI transcription. We choose providers that offer reasonable security and privacy safeguards, but we cannot guarantee their practices. A list of subprocessors is available on request.
Changes to this statement
We may update this page as the archive grows. The latest version will always be here, and we will note significant changes when we make them.
Contact us
Questions, corrections, or deletion requests? Email hello@thememorybox.org.
Shared responsibility: The Memory Box provides the platform and these controls, but each contributor decides what personal details to include in a story. Please be thoughtful about what you share about yourself and others.