Protect the device
Use a strong screen lock, keep the operating system and Remem updated, and do not leave an unlocked phone with someone you do not trust.
Plain-English guide
Remem stores its core pin data locally on your device. When location is on and available, Remem saves it automatically with each new pin. Signed-out Home and List show bundled, immutable examples; creating a real pin requires sign-in. Some optional actions involve outside services, so “local-first” does not mean that every possible action stays on the phone.
Where information goes
| Activity | Current behaviour | User choice or limit |
|---|---|---|
| Signed-out use | Home and List show bundled, immutable example pins. | Creating or owning a real pin requires sign-in. |
| Account sign-in | Clerk provides Remem’s account sign-in service. | Sign-in identifies the exact account that owns every real pin from creation; email is not the owner key. |
| Purchases and entitlement | The relevant app store and RevenueCat handle purchase status. Remem does not receive card or bank details. | Only applies when you choose an eligible purchase. |
| Remote place-name lookup | For eligible Premium use, a Remem service may send a Clerk bearer token and coordinates rounded to four decimal places to OpenCage. Rounded coordinates are still precise location data. | Native address lookup is attempted first; the remote lookup applies only when its conditions are met. |
| Shared location link | When you choose to share a located pin, only its precise coordinates are sent to Remem’s service to create the link. The coordinates are encrypted, and only hashes of the public and revocation tokens are stored. Every sent link expires 30 days after creation. If sharing is cancelled before sending, Remem may invalidate the unused link. The current app does not provide a control to stop sharing a link after it has been sent. | The pin identifier, transcript, Notes field, photos and audio are not uploaded to create the link. Anyone with the link can open, copy or forward the precise location. No maps provider is contacted until the recipient chooses one. An expired or invalidated record is normally deleted automatically after it has been inactive for seven days; a temporary service delay may postpone deletion. |
| Encrypted continuous sync | On Remem Web, Android and iOS, starts automatically for the signed-in Free or Premium account using that account’s Sync key handled internally by Remem. | Eligible content, deletions and five portable locale settings receive authenticated encryption on the device before upload. Offline changes queue durably and sync while Remem is open, in the foreground and connected. Android and iOS automatically preserve both versions of a conflicting pin. Remem Web requires a Keep this device or Use other device choice. |
| Exports | Your device saves or shares the file to the destination you choose. | After export, security depends on that destination and who can access it. |
| Public website analytics | Seven product and marketing pages on the canonical tryremem.com hostname load Google Analytics (GA4) automatically so Remem can measure page use. Preview and local hostnames, legal, support, accessibility, account-deletion and private location-share pages do not load the tag. | There is no separate analytics opt-in on the website. Full detail is in the privacy notice. |
Practical protection
No inflated claims
No software or mobile device can promise absolute security. Local data is affected by the security of the phone, its operating system, installed apps, account services and any place to which a file is exported.
On Remem Web, Android and iOS, Remem’s authenticated service provisions or recovers the signed-in account’s Sync key internally. Eligible content is encrypted on the device before upload, and Supabase stores only authenticated server-wrapped key escrow rather than the plaintext account Sync key. Remem makes no absolute-security, zero-knowledge or guaranteed background-delivery claim.
Full documents