Skip to main content
Remem
  • Home page
  • How it works
  • Features
  • Privacy & security
  • Support

Your data and your choices

Privacy notice

Remem is local-first. This notice explains what stays on your device, what is processed when you choose online features, and what those choices mean.

Effective 19 August 2026 · Last updated 31 August 2026

On this page

  1. Scope
  2. Local data
  3. Accounts and purchases
  4. Encrypted Sync
  5. Location, addresses and sharing
  6. This website
  7. Service providers
  8. Retention and deletion
  9. Security and choices
  10. Contact

1. Scope

This notice covers the Remem mobile app, its optional online services and Remem's published public pages. It does not replace the privacy terms of your device platform, app store, sign-in provider or other services you choose to use.

This notice is issued by Remem Technologies Limited, the company that provides Remem and is responsible for the processing described here. It is registered in England and Wales under company number 17396915.

The short version Saved pins, notes and recordings are local. When foreground location is on, Remem saves an available location automatically with each new pin. Speech recognition may use your device’s Apple or Google speech service. Signed-out Home and List show bundled, immutable examples; creating a real pin requires sign-in. Every real pin belongs from creation to one exact Remem account. Free and Premium use the same local-first encrypted Sync. Signing out hides personal content and stops active Sync without silently deleting the retained account collection.

2. Data stored locally

Remem stores pin details, note text, recordings, saved locations, address labels and app settings on your device. These remain available for local and offline use, subject to the device and app continuing to hold the files.

Microphone permission is used when you record. If foreground location permission is on and a location is available, Remem saves it automatically with each new voice or typed pin. Foreground location also supports your map position and place-name lookup. Remem does not require continuous background location access for these features.

Remem keeps the saved recording on your device. Depending on device, language and availability, speech recognition may run on the device or speech audio may be processed online by Apple’s or Google’s speech service. Remem does not send the saved recording to its own server for transcription.

Local data may be lost if you delete it, clear the app’s storage, uninstall the app or lose the device. Do not assume an operating-system backup includes Remem data; Android device backup is disabled for Remem. CSV and GPX exports do not include recordings and are not a complete backup.

3. Accounts and purchases

Sign-in

Signed-out Home and List show bundled, immutable example pins. Creating or owning a real pin requires sign-in. Clerk processes the identity and session information needed to authenticate the exact Remem account. The details Clerk receives depend on the sign-in method you select.

Purchase identity

Premium plans, prices and purchase controls appear only after sign-in. Signing in automatically reconciles an eligible purchase owned by that Remem account, but does not itself charge you or grant Premium. Remem sends RevenueCat the opaque Clerk user identifier for that account; email addresses are not purchase identifiers. Checkout opens only after you deliberately select Buy, and eligible Premium access is reconciled automatically for that Remem account. RevenueCat and the relevant payment provider process product, entitlement and transaction-status information. Pins, note text and recordings are not sent for purchase linking.

Remem does not receive or store your card or bank details. The relevant payment provider handles payment. For an eligible Remem Web transaction processed in Managed Payments mode, Stripe’s Link service is shown as merchant of record and handles payment, applicable indirect tax, fraud, disputes and transaction support. If checkout ever uses standard Stripe Billing instead, Remem is the seller and the checkout terms identify that boundary before confirmation. Google Play handles Android and Apple’s App Store handles iOS.

4. Encrypted continuous Sync

On Remem Web, Android and iOS, signed-in Free and Premium use the same local-first encrypted Sync. Remem obtains that exact account’s Sync key from its authenticated service, verifies it against the encrypted cloud profile and stores it using platform-appropriate local key storage. Signing out hides personal content and stops active Sync without silently deleting the retained account collection. Account deletion and local-data removal are separate explicit actions.

Remem’s service processes the account Sync key only to provision or recover it for the authenticated account and returns it in a non-cacheable response. Supabase stores only the key wrapped with authenticated encryption under Remem’s protected, server-side key-encryption key; it does not store the plaintext account Sync key.

On an eligible platform, Sync can include pins, note text, saved precise locations, recordings, eligible photos, deletions and only five portable locale settings: language, region, date format, time format and week start. Other app and device settings are not included. A deliberate eligible-pin deletion on one connected device can remove the corresponding pin from another after the revision and conflict checks are applied.

Changes made offline remain in a durable on-device queue and are sent while Remem is open, in the foreground and connected. Remem does not promise operating-system background delivery. Compare-and-set (CAS) server revisions and deletion tombstones detect competing changes. A conflict is not silently overwritten. Android and iOS automatically preserve both versions of a conflicting pin as separate pins in the same account collection. Remem Web requires the user to choose Keep this device or Use other device.

Sync is subject to the service limits in force for the signed-in account; this notice does not promise a fixed storage quota or retention window. Premium ending preserves and synchronises every existing pin and photo and allows them to be managed. It blocks only another admission at the applicable Free boundary until the count falls below it. Sync is not a guaranteed backup, version-history or recovery service.

5. Location, address lookup and sharing

Remem tries to save your location automatically whenever you record or type a note. This works when foreground location access is on and a location is available. If either is unavailable, the note still saves without a location.

Remem first tries the phone’s native address service using coordinates rounded to 4 decimal places. If that does not return a useful result, the app can still show a local Plus Code or rounded-coordinate fallback.

For a signed-in, purchase-linked user with locally resolved Premium, Remem may ask its Vercel service for a remote place name. The app sends a Clerk bearer token and the location rounded to 4 decimal places. Four decimal places is roughly 11 metres at the equator and remains precise location data. The service verifies the account and exact live Premium entitlement before passing the rounded location to OpenCage. Audio, note text and the unrounded GPS point are not sent for that lookup.

If the account, entitlement, connection or remote service cannot be verified, remote lookup fails closed and Remem keeps the native/local fallback. Local pin saving and recording are not blocked.

Shared location links

When you choose to share a pin that has a saved location, Remem sends only its precise latitude and longitude to Remem’s location-link service to create the link. The pin identifier, title, transcript, Notes field, photos and audio are not uploaded to create that link.

If active Premium requests a sharing page without Remem branding, the signed-in app sends its current account session and the same coordinates to Remem’s Vercel service. The service verifies the exact account and derives the opaque RevenueCat app-user identifier; the app cannot choose that identifier.

The service sends the identifier—not the coordinates—to RevenueCat to confirm active Premium. It then returns a capability that expires within five minutes and is cryptographically bound to those coordinates. The session, identifier and capability are not put in the public link or stored with the shared-location record. If any check cannot be completed, Remem creates the normal branded page instead.

Remem encrypts the coordinates before storing them in Supabase. It stores hashes of the public link token and the separate revocation token, rather than either token itself. Every sent link expires 30 days after creation. If sharing is cancelled before sending, Remem may invalidate the unused link. The current app does not provide a control to stop sharing a link after it has been sent.

Once a link expires or an unused link is invalidated, it no longer returns the location. Its encrypted record is normally deleted automatically after it has been inactive for seven days. A temporary service delay may postpone deletion.

To limit automated abuse, the location-link service uses request network addresses to apply hourly and daily limits. Supabase receives a one-way keyed pseudonym, request count and time window—not the raw network address. Quota windows older than two days are normally deleted automatically; a temporary service delay may postpone deletion.

Anyone with the link can open, copy or forward the precise location. Opening it asks Remem’s service to resolve the coordinates. No maps provider is contacted until the recipient chooses one. The chosen provider then receives the precise coordinates and normal request information under its own privacy terms.

6. This website and support email

The home, How Remem works, Features, Export your pins, Encrypted Sync, Use cases and Press pages use Google Analytics (GA4) so Remem can understand how those pages are used — for example which pages are visited, approximate region, device or browser type, referrer and related usage events. The measurement tag loads automatically on those pages at the canonical tryremem.com hostname (there is no separate analytics opt-in on this site).

The tag does not run on preview or local-development hostnames. It is not placed on Accessibility, Privacy and security, Privacy, Terms, Support, Delete account, or private location-share pages such as View Location. There are no Remem advertising scripts, account forms or payment forms on the measured pages.

Google may set or read cookies or similar storage and may process request metadata (including IP address used for approximate location) under Google’s terms and privacy notice. Vercel hosts the pages and may process standard request information, such as an IP address, browser or device information, requested path and timestamps, to deliver and protect the site.

If you email support, Remem processes the email address, message and attachments you choose to send so that the request can be reviewed and answered. Do not send an access token, full recording or other information that is not needed for support.

7. Service providers

  • Clerk: exact-account authentication.
  • RevenueCat: purchase identity and Premium entitlement status.
  • Google Play or Apple’s App Store: purchase and payment processing on the relevant platform.
  • Stripe: secure hosted checkout for Remem Web through RevenueCat. For eligible transactions processed in Managed Payments mode, Stripe’s Link service is shown as merchant of record and handles payment, applicable indirect tax, fraud, disputes and transaction support. Remem does not receive card or bank details.
  • Apple or Google speech services: speech recognition provided by the device, which may process speech audio online when on-device recognition is unavailable.
  • Supabase: stores the encrypted cloud profile, encrypted pin and portable-setting envelopes, encrypted recording and photo objects, revisions, operation identifiers, deletion tombstones and limited storage, object-path, usage and timestamp metadata needed for encrypted Sync. It also stores encrypted coordinates, hashed location-link tokens and service-quota records for shared location links. Plaintext pin content is not sent to Supabase. A Account Sync keys are stored there only as server-wrapped, authenticated escrow.
  • Vercel: authorises exact-account Sync access and Premium-only cloud capabilities using Clerk and RevenueCat, coordinates account deletion, provides remote address and location-link services, and hosts these public pages.
  • Google Analytics: website usage measurement on public marketing pages (page views and related events).
  • OpenCage: remote address lookup for an eligible linked Premium account, using a 4-decimal-place rounded location.
  • Your chosen maps provider: Apple Maps, Google Maps, Waze or another maps app receives the precise coordinates only after the recipient chooses to open the location with that provider.

Each provider processes data under its own terms and privacy notice. Service providers may process data in countries other than your own, subject to their safeguards and applicable law.

8. Retention and deletion

  • Local data: remains on the device until you or the device removes it. Account deletion and local-data removal are separate explicit actions. The in-app deletion flow states its current scope and warnings before confirmation.
  • Encrypted cloud Sync data: are held for the exact signed-in account subject to the service limits and retention policy in force. This notice makes no fixed retention promise. Premium ending preserves and synchronises existing pins and photos. Account deletion removes associated cloud data. This is separate from a deliberate eligible-pin deletion that the user makes and synchronises between enabled devices.
  • Shared location links: every sent link expires 30 days after creation. If sharing is cancelled before sending, Remem may invalidate the unused link. The current app has no control to stop sharing a link after it has been sent. Once expired or invalidated, the link no longer returns the location. Its encrypted record is normally deleted automatically after it has been inactive for seven days; a temporary service delay may postpone deletion.
  • Premium location-sharing authorisation: the service verifies the exact signed-in account and Premium before issuing a short-lived capability bound to the requested coordinates. The capability and account session do not appear in the public link.
  • Account and purchase records: a completed Remem account-deletion hand-off deletes the Clerk account and the linked RevenueCat customer profile. The relevant app store keeps its own transaction and subscription records under its legal, security and operational requirements.
  • Deletion-suppression records: during an account deletion attempt, Remem keeps a one-way pseudonymous cloud-write fence with creation and expiry timestamps so stale signed-in sessions cannot recreate cloud data. A separate RevenueCat erasure retry guard retains the opaque Clerk user identifier previously used as the RevenueCat app-user identifier, together with expiry, erasure-basis and retry-attempt metadata. This identifier is needed to find and re-delete a purchase profile recreated by a stale device; it is not an email address or profile name. Both safety windows are renewed in bounded periods while deletion is incomplete, retained for 30 days after completion and then automatically deleted. Neither record contains note content, locations or recordings.
  • Website request logs and support email: are retained by the relevant hosting and email services under their policies. Remem keeps deletion-request correspondence only as long as needed to verify ownership, fulfil and document the request, keep the process secure, and meet any legitimate legal obligation. It is deleted when no longer needed for those purposes.

User-initiated account deletion

When you choose Delete account in the app, Remem first asks its deletion service to prepare a durable, account-bound cleanup job. It then asks Clerk to delete the sign-in account and attempts to reset the on-device RevenueCat purchase identity before completing the prepared cleanup. If the app closes at that point, the deletion service can independently confirm that Clerk no longer has the account and resume the deletion. It fences new cloud writes, revokes access, removes associated cloud records, verifies that the cloud data is empty and deletes the linked RevenueCat customer profile. The pseudonymous cloud-write fence and opaque-identifier RevenueCat retry guard are retained as described above to catch stale-session recreation. The app reports whether the online deletion steps complete or need a retry; do not treat an unconfirmed attempt as complete. Account deletion and local-data removal are separate explicit actions, and the in-app deletion flow states its current scope and warnings before confirmation. An external deletion request cannot erase local-only data from a device. RevenueCat customer deletion does not cancel a subscription or delete the payment provider’s transaction records. If you cannot access the app, use the dedicated Remem account-deletion request page to start a request without reinstalling Remem. Ownership must be verified before provider data is changed, and a submitted request is not described as complete until the relevant outcomes are confirmed.

9. Security and your choices

Remem uses authenticated requests and server-side entitlement checks for eligible online features. No system can guarantee absolute security. Keep your device, store account and sign-in account secure.

You can choose to:

  • view bundled examples before signing in;
  • deny or change device permissions in system settings;
  • delete individual local content in the app; or
  • start account deletion in the app; or
  • use the external deletion page to request deletion of the account and associated data without the app.

10. Changes and contact

This notice may change as Remem’s implemented features or legal obligations change. A revised notice will show a new effective date.

For privacy questions or an account-deletion concern, email support@tryremem.com. Include only the information needed to identify and investigate the request.

Remem Technologies Limited’s registered office is 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom. The company is registered in England and Wales under company number 17396915. See the full company information.

© 2026 Remem Technologies Ltd

Home How it works Features Privacy & security Terms Support Delete account Contact Company