Security & privacy
You are handing us the most private thing you own.
So the burden is on us to be specific. This page is what we have built, what we refuse to do, and what happens in the situations nobody likes to plan for.
The architecture
Your vault is sealed separately from everyone else's.
Its own keys
Every account — including free ones — gets a dedicated vault with its own encryption keys, rather than a partition of a shared store. It means deletion is genuinely final: destroy the key and the contents are unrecoverable, by us included.
Encrypted in transit and at rest
Envelope encryption, with the data key itself encrypted. Isolation is enforced at the database layer, not only in application code — so a bug in a feature cannot hand one person another person's Beads.
Identity checks that scale with the stakes
Reading your own Beads is a normal login. Changing who inherits your vault, or entering it after a death, requires login plus a code to your phone plus a code to your email. The most dangerous actions are the hardest to perform.
Everything is logged
Every access to a vault is recorded, including by us. Export your data and you are alerted — even if it was you who asked. If your account is ever compromised, that alert is how you find out.
Staff access
We cannot casually read your vault.
There is an emergency path — there has to be, for lawful orders and genuine catastrophes. It requires several senior approvers acting together, it is written down as a procedure rather than improvised, and every use of it is logged permanently. No individual at MemoBeads, at any level, can open a vault alone.
Taking your data out
A button, not a support ticket.
Export lives in your account settings and works whenever you like, on every plan including the free one. You do not have to ask us, explain yourself, or wait on a queue.
You get back everything you actually put in: your photos, documents, video and voice recordings, the text you typed, your answers to prompts, and the details you set yourself. It arrives as plain folders — one per Bead — that open on any computer without our software.
The package is encrypted, delivered by a time-limited link, and can be requested about once a month. It stays available even if your account has lapsed and is heading for deletion, because losing decades of memories while technically able to save them is a failure we are not willing to design in.
What is not in the export
The parts that are our analysis rather than your content: the search index, how your Beads are ranked and related to each other, and internal labels.
It is worth saying plainly why. Those things are the product; your memories are yours. We would rather be honest about that distinction than pretend the line is somewhere else.
If MemoBeads ever shuts down
Ninety days' notice, written into the contract.
Not a line in a blog post — a term in the Terms of Service, so it binds us. If we wind down, every user is notified, the export button stays live throughout, and nobody discovers it from an error page.
We are explicit about this because the alternative has already happened to people. Companies in this category have gone under holding customers' recordings, and the customers found out when the site stopped loading. A published continuity commitment costs us nothing except the discipline of keeping it.
Commitments
Things we will not do.
We will not invent
Your vault answers from what you recorded. It does not extrapolate a personality, guess an opinion, or generate words in your voice that you never said — on any plan, and especially after you are gone.
We will not sell your data
Not to advertisers, not to data brokers, not to insurers. The business model is subscriptions; there is no second revenue line hiding behind it.
We will not train on your vault
Your Beads are used to answer your questions and your family's. They are not training material, for us or for the AI providers we work with.
We will not hoover up your phone
There is no bulk import of your photo library, no friends list, no message scraping. Personal media enters one Bead at a time, added by you.
We will not open a vault to the wrong person
Executors, appointees and family members who were not named as beneficiaries get no access to vault contents. Handling someone's affairs is not the same as being trusted with their memories.
We will not promise forever
We publish how long we keep things and what triggers deletion. An unfunded promise of permanence is the most common lie in this category.
MemoBeads is in development. This page describes the security architecture as designed and being built; independent security review and legal review of our privacy, export and posthumous-access policies are scheduled before we open to the public, and this page will be updated to reflect their outcome. If you have questions in the meantime, write to hello@memobeads.com.
Early access
The best time to start was thirty years ago.
MemoBeads is being built now. Join the waitlist and we will write to you once — when there is something real to open.