Privacy

Your story stays yours.

The current As Lived iPhone release keeps your archive on your device. Planned hosted features will launch only with clear consent and updated privacy terms.

Encrypted by designProtected on-device today; encrypted in transit and at rest when hosted.
No trackingNo ads, public profiles, or behavioral tracking.
Access by instructionA designated successor never receives automatic or immediate access.

Effective July 27, 2026

Privacy Policy

What the current app sends

As Lived does not transmit your photos, videos, voice recordings, captions, transcripts, faces, locations, search queries, diagnostics, or usage analytics to the developer. Clerk retains the account identifier needed for authentication. During account deletion, the app sends a fresh Apple authorization code, Apple identity token, random nonce, and Clerk session token to As Lived's deletion endpoint. Those values are used transiently to verify ownership and revoke Sign in with Apple authorization; they are not stored as archive content.

Encrypted hosted archive in development

The current release does not upload archive content to a Story of Me hosted vault. Before that service launches, the app and this policy will explain what is stored, how long it is retained, how deletion works, and any service providers involved, then ask for your choice. The hosted archive is being designed so content is encrypted while transferred and while stored on infrastructure we operate.

Server-side search and AI

Server-side search and AI must process archive content to work. When you choose one of those features, your question and the relevant memories will be decrypted inside a protected processing environment only to produce the requested result. The planned service is not zero-knowledge or end-to-end encrypted. It will not create a public profile or use memory content for advertising or behavioral tracking. Generated answers can be wrong and will link back to source memories so you can check them.

Designated successor access

Legacy Access is in development and is not available in the current release. The planned controls will let you name a designated successor, choose what they may receive, and change or revoke your instructions. Naming someone will not give them immediate access. Release will require the verification process described in your settings; access will never be inferred merely because someone is your next of kin.

What stays on your device

In the current release, the protected app container may hold memories, captions, typed notes, local speech transcripts, dates, favorites, tags, user-entered people, place labels, app-owned photo, video, and voice files, on-device visual-analysis results, recap plans and videos, settings, a rebuildable search index, thumbnails, and backup history.

Apple services and user-selected providers

Apple frameworks may use a network connection when iCloud Photos retrieves an original you explicitly request or when Apple reverse-geocodes a photo coordinate into a place label. If you choose a third-party Files provider or share destination, that provider receives only the files you select and applies its own privacy policy.

Photos, camera, microphone, and speech

These permissions are requested only for features you choose. Denying them does not prevent text-only memories. Voice transcription is configured to require supported on-device recognition and does not fall back to a developer speech service.

On-device analysis

In the current release, visual analysis, OCR, search, and supported story-generation features run on the device. The app never automatically names a person and prohibits sensitive personal-trait inferences. You can disable visual analysis.

Backups and data deletion

You start every backup and choose its Files destination. Optional encryption uses a passphrase that the app does not store and the developer cannot recover. Deleting the app can delete its private on-device archive; a separate Files backup is not deleted with the app. As Lived currently uses Clerk only for authentication and keeps no server-held personal archive.

Security and diagnostics

The app can lock its archive UI with device authentication and obscures its interface when leaving the foreground. Release logs use a closed set of technical events and exclude private content, identifiers, coordinates, filenames, and encryption material.