Privacy Policy
Your memories are personal. We treat them that way. This policy explains what data we collect, how we use it, and who has access.
Last updated: 1 March 2026
What we collect
When you use Remeo, we collect:
- Account information — your email address and display name, used for authentication and to identify your account.
- Memory content — the text, titles, tags, and dates you provide when creating memories. This is the core of what Remeo stores for you.
- Photos and media — images you attach to memories, stored securely and only accessible to you (and anyone you explicitly share with).
- Usage analytics — anonymous, aggregated data about how you interact with the app (page views, feature usage). This helps us improve Remeo without identifying you personally.
Third-party services
We use a small number of trusted services to run Remeo. Each has a specific role:
- Supabase — database, authentication, and file storage. Your memories and account data live here, protected by row-level security.
- Stripe — payment processing. We never see or store your full card details. Stripe handles all payment data securely.
- OpenAI (via Vercel AI SDK) — AI processing for generating titles, tags, and semantic search. Memory content is sent to OpenAI for processing but is not used to train their models.
- PostHog — product analytics and session replay. Helps us understand how people use Remeo so we can improve the experience. Uses first-party cookies only.
- Sentry — error monitoring. When something goes wrong, Sentry captures technical error details so we can fix issues quickly.
- Resend — transactional email. Used for account-related emails like password resets.
- Vercel — hosting and infrastructure. Serves the Remeo application.
How AI is used
When you save a memory, the content is processed by AI to generate a title and suggest relevant tags. This makes your memories easier to find and organise without any manual effort.
Your memories are never used to train AI models. The AI processes your content to enhance your experience — nothing more.
Data storage and security
Your data is stored in Supabase with row-level security (RLS) enabled on every table. This means your memories are isolated at the database level — no other user can access your data, and even our own queries respect these boundaries.
All data is transmitted over HTTPS. Passwords are hashed and never stored in plain text.
Sharing
Your memories are private by default. Nothing is shared unless you take explicit action:
- Public link sharing — you can generate a link that allows anyone with the URL to view a specific memory.
- People sharing (Premium) — you can share a memory with specific Remeo users by email.
We never share, sell, or provide your data to advertisers, data brokers, or any third parties beyond the service providers listed above.
Cookies
Remeo uses a minimal number of cookies:
- Authentication cookies — managed by Supabase to keep you signed in.
- Analytics cookies — first-party cookies set by PostHog to understand usage patterns. No third-party tracking.
Data retention and deletion
You can delete individual memories at any time. Deleted memories are permanently removed from our database.
If you delete your account, all associated data — memories, photos, tags, and account information — is permanently removed. This action cannot be undone.
Children
Remeo is not directed at children under 13. We do not knowingly collect information from children under 13. If you believe a child has provided us with personal data, please contact us and we will remove it.
Changes to this policy
We may update this privacy policy from time to time. If we make significant changes, we will notify you via email or an in-app notice.
Contact
If you have questions about this privacy policy or how your data is handled, email us at privacy@remeo.io.