Skip to main content

Privacy Policy

Last updated: 10 June 2026

1. Who we are

Memora.help is operated by Customer Experience Insight Pty Ltd ("we", "us", "our"), an Australian company. For the purposes of the Privacy Act 1988 (Cth) we are the organisation that holds your personal information, and for users in the European Union or United Kingdom we act as the data controller for the personal data described in this policy.

Contact for all privacy matters: support@memora.help.

2. What this service is — and an important note about care data

Memora.help helps family members and carers support people living with dementia. This means you may record information about another person (the person you care for), including health-related information, which is sensitive information under Australian law and special category data under the GDPR. You must only add information about another person where you have their consent or other lawful authority (for example, as their authorised decision-maker). The app asks you to confirm consent before sensitive features are used.

3. What we collect

  • Account information — your name, email address, and password (stored as a secure hash; we never see your plain-text password).
  • Care records you create — profiles of the people you care for, observation notes, care plans, session notes, and reminiscence memory descriptions.
  • Photos and audio recordings — media you choose to add to a person's Memory Vault, only after media-storage consent is recorded.
  • Usage and audit records — security logs of significant actions (for example, who viewed a stored photo or recording, and when), kept to protect the people whose data is stored.

We collect this information directly from you. We do not buy data about you, and we do not use advertising trackers in the app.

4. Where your information is stored and processed

We believe you deserve plain answers about where data physically lives. Different kinds of data are stored in different places:

  • Photos and audio recordings — Sydney, Australia. Media files are kept in private, access-controlled storage located in Sydney (Australia). They are never publicly accessible and are served only to signed-in members of the person's care team. Every access is logged.
  • Written records — United States. Our database (accounts, profiles, notes, plans, session history, and memory descriptions) is hosted on secure servers located in the United States (US East). This is a current infrastructure constraint and we disclose it rather than overstate Australian residency.
  • AI processing — United States. When you use AI features, the written text needed for that feature is sent to an AI model (currently OpenAI's GPT-4o-mini, accessed via Vercel's AI Gateway) processed in the United States. Details are in section 5.

Cross-border disclosure (Australian Privacy Principle 8)

The United States storage and processing described above are cross-border disclosures of personal information for the purposes of APP 8. By creating an account and using these features after seeing this notice and the in-app consent notices, you consent to these disclosures. We choose reputable infrastructure providers with strong security practices; however, overseas recipients are subject to the laws of their own jurisdiction, and we cannot guarantee that they are subject to privacy obligations identical to the Australian Privacy Principles. We do not claim, and you should not assume, guaranteed Australian data residency for the database or AI processing.

International transfers (GDPR/UK GDPR)

For users in the EU/UK, personal data is transferred to and processed in Australia and the United States as described above. Where we rely on third-party infrastructure providers, transfers are made on the basis of safeguards offered by those providers (such as standard contractual clauses and, where applicable, the EU-US Data Privacy Framework). You can contact us for more information about the safeguards applying to a specific transfer.

5. AI features — exactly what is sent, and when

  • AI features send written text only. Photos and audio files are never sent to AI services.
  • Reminiscence prompt generation sends the written titles and descriptions of stored memories — and only where AI-processing consent has been recorded for that person. If consent is declined, the feature uses our built-in Australian prompt library instead and nothing is sent to an AI service.
  • All AI-drafted session notes are saved as drafts and must be reviewed and approved by a person before they become part of the care record.
  • We use AI services for inference only. We do not sell your information, and we do not use your information to train AI models.

6. Why we process your information (purposes and lawful bases)

We process personal information to:

  • provide the service you signed up for, including care notes, plans, guidance, and reminiscence features (GDPR basis: performance of a contract, Art. 6(1)(b));
  • operate AI-assisted features where consent has been recorded (GDPR basis: consent, Art. 6(1)(a), and for health-related information explicit consent, Art. 9(2)(a));
  • keep the service secure, including audit logging of access to sensitive media (GDPR basis: legitimate interests, Art. 6(1)(f) — protecting vulnerable people's data from misuse);
  • comply with legal obligations (GDPR basis: Art. 6(1)(c)).

Where processing is based on consent, you may withdraw consent at any time in Settings or per person in the Consent panel; withdrawal does not affect processing that occurred before withdrawal.

7. Who can see the data

  • Care records and media are visible only to the account that created them and, where an institution is configured, members of the same care institution.
  • Our infrastructure providers (database hosting, media storage, and AI gateway services) process data on our behalf as described in section 4. We do not authorise them to use your data for their own purposes.
  • We may disclose information where required by law (for example, a lawful request by an authority), or to protect the safety of a person at risk.
  • We do not sell personal information.

8. Security

We take reasonable steps to protect personal information, including: private, access-controlled media storage; authentication on every request for stored media; per-user and per-institution access scoping; password hashing; parameterised database queries; consent gating for sensitive features; and audit logging of access to photos and recordings. No internet service can guarantee absolute security, and we encourage you not to store financial details, government identifiers, passwords, or answers to security questions in care records or recordings.

9. Retention and deletion

We retain personal information while your account is active and for as long as needed to provide the service. When you delete a person's profile, their associated records and stored media are deleted, and a deletion event is recorded in our audit log. When you ask us to delete your account, we will delete or de-identify your personal information unless we are required to retain it (for example, security audit records or legal obligations). Backup copies held by our infrastructure providers are deleted in line with those providers' standard cycles.

10. Your rights

Australia (Privacy Act 1988, APPs)

  • You may request access to the personal information we hold about you (APP 12).
  • You may request correction of inaccurate, out-of-date, or incomplete information (APP 13).
  • You may withdraw consent for optional processing at any time.
  • You may request deletion of your data, subject to legal retention requirements.

EU/UK (GDPR / UK GDPR)

  • Right of access (Art. 15) and right to rectification (Art. 16).
  • Right to erasure (Art. 17) and restriction of processing (Art. 18).
  • Right to data portability (Art. 20) for data you provided to us, where processing is based on consent or contract.
  • Right to object (Art. 21) to processing based on legitimate interests.
  • Right to withdraw consent at any time (Art. 7(3)).
  • Right to lodge a complaint with your local supervisory authority.

To exercise any right, email support@memora.help. We will respond within a reasonable period (and within any timeframe required by applicable law). We may need to verify your identity before acting on a request.

11. Complaints

If you believe we have mishandled your personal information, please contact us first at support@memora.help and we will investigate and respond. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au. EU/UK users may also complain to their local data protection supervisory authority.

12. Changes to this policy

We may update this policy as the service or our infrastructure changes. We will update the "Last updated" date above and, for material changes (including any change to where data is stored or processed), we will take reasonable steps to bring the change to your attention in the app.