Privacy Policy
This policy explains what Youmory collects, why, and who else sees it. It covers the Youmory mobile app and the website at youmory.app.
Two parts of Youmory deserve reading even if you skip the rest, because they are the parts that are not obvious from using the app: that the postcard artwork is AI-generated, and what a shared postcard link shows to someone who does not have the app, which includes your first name and a picture.
1. Who is responsible
The controller for the purposes of the GDPR is:
Ferdinand Valentin Obermeier
Helmut-Schmidt-Allee 31
81248 München
Germany
Email: support@youmory.app
Youmory is run by one person, not a company. There is no data protection officer, because the scale and nature of the processing does not require one under Art. 37 GDPR.
2. What Youmory stores about you
Your account. Youmory does not ask you to sign up to use it. The app opens an anonymous session so that your collection has somewhere to live; that session holds no name, no email address and nothing you told us. When you do sign in — with Apple or with Google — Youmory stores your email address and which of the two you used, and what you had already collected carries over. If you use Sign in with Apple and choose to hide your email, Youmory only ever sees Apple’s relay address. Signing in keeps any name you have already given the app. If you haven’t given one, Youmory may take the name your Apple or Google account provides and, with Google, its profile picture. You can change your name and change or remove your picture in Settings at any time. Both are visible to people you are friends with in the app.
Places you check in. A check-in stores the coordinates you checked in at, the name the geocoder gave the place, the place it was matched to, and the dates of your stay. This is the app’s core purpose — it is the collection.
Your location. Youmory reads your device location only while the map is open in front of you: to show you where you are, and to confirm a check-in. It is never read in the background. You can refuse the permission and still use the app by adding places manually.
Postcards you write. The message on the back, anything you draw on it, the handwriting and pen you chose, the stamp, and who you sent it to. Messages are limited to 500 characters. A message is readable by you and by the person you sent it to, and by nobody else — including on the web page described in section 4.
Friends. Who you are friends with, when the friendship started, and anyone you have blocked.
Notifications. If you turn them on, a push token from Expo’s push service, so a device can be told a postcard has arrived.
Photos. If you pick a profile picture, the app reads the one image you select. Saving artwork writes to your photos and reads nothing.
Importing past trips from your photos. If you start the photo import, and only then, Youmory reads your photo library to find pictures that carry a location: it uses the coordinates and the date of each one, groups them into trips, and offers you the places it recognised. The coordinates of a group are sent to our database to be matched to a place, the same way a live check-in is. No photo, thumbnail or file ever leaves your device, and nothing is added to your collection until you confirm it. You can refuse the permission, or grant it for selected photos only, and the rest of the app is unaffected.
Support requests. If you write to support@youmory.app, your message, your email address and anything you attach are kept in our support inbox, run by Crisp, so the request can be answered. When you write from the app’s settings, the email already contains your account identifier, the app version and your device’s operating system, which lets us find your account and your purchases without asking you for them. You can delete those lines before sending. Support conversations are deleted twelve months after the last message.
Diagnostics and usage. See section 6.
Youmory does not sell personal data, does not run advertising, and does not build marketing profiles.
3. AI-generated artwork
Every piece of postcard artwork in Youmory is generated by artificial intelligence. None of it is a photograph, and none of it was drawn by a human illustrator.
Because it is machine-generated, it can be wrong: a landmark may be misplaced, a skyline rearranged, details invented. Treat a Youmory postcard as an illustration inspired by a place, not as a record of one.
Nothing you write or draw goes into making it, and no personal data of yours is sent to the systems that produce it. Youmory does not generate images of real, identifiable people.
4. Shared postcard links
When you share a postcard by link, your first name, the name of the place, and the front of the card become visible to anyone who has that link — including people who have never installed Youmory and have never agreed to this policy.
This is the part of Youmory with the widest exposure, so it is worth setting out precisely.
What is shown. A shared link resolves to a page on this website that shows the postcard’s front image, your first name only, and the name of the place. Nothing else.
What is never shown. The message you wrote, anything you drew, the handwriting and pen you chose, your surname, your email address, your profile picture, your account identifier, and the storage location of the artwork. None of these leave the server for a link page — the database function behind it has no way to return them. The message on the back can only be read by someone who claims the card in the app, which requires an account.
Who can see it. Anyone holding the link. A link is not a password: if it is forwarded, posted in a group chat, or pasted into a public channel, everyone who sees it can open the page. Messaging apps, mail providers and corporate security scanners also fetch link previews automatically, so the page is often loaded by machines before any person opens it.
How long. A link stops working thirty days after it is created, or as soon as somebody claims the card — whichever comes first. You can also take a postcard back before then, which kills the link immediately.
Your choice. Nothing is shared by link unless you choose to share it. Sending a postcard to a friend inside the app involves no web page at all.
Legal basis. Processing here is necessary to perform the service you asked for when you tapped share (Art. 6(1)(b) GDPR). If you are the recipient of a link, the only data processed about you is the ordinary request data described in section 7.
Friend invite links are different. An invite link opens a page that shows nothing at all about the person who sent it — no name, no picture, nothing. The app names them once you have it; the web page never does, because an invite can be forwarded by anyone who receives it and the person who made it did not choose where it ended up.
These pages are marked noindex and are excluded in robots.txt, so search engines are asked not to list them. That is a request, not a guarantee, and it does not stop anybody who has the link.
5. Why Youmory is allowed to process this
| What | Legal basis (Art. 6 GDPR) |
|---|---|
| Account, check-ins, collections, postcards, friends | Performance of the contract, Art. 6(1)(b) |
| Location while the map is open | Performance of the contract, Art. 6(1)(b) — with the device permission you grant |
| Reading photo locations for the trip import | Your consent, Art. 6(1)(a) — the photo permission, refusable and revocable |
| Push notifications | Your consent, Art. 6(1)(a) — withdrawn by turning them off |
| Usage events, diagnostics and crash reports | Legitimate interests, Art. 6(1)(f) — keeping the app working and understanding how it is used, so it can be improved |
| Shared postcard link pages | Performance of the contract, Art. 6(1)(b) |
| Support requests | Performance of the contract, Art. 6(1)(b), where the request concerns your account or a purchase; otherwise legitimate interests, Art. 6(1)(f) — answering the people who write to us |
| Subscription and purchase records | Performance of the contract, Art. 6(1)(b), and Art. 6(1)(c) for tax record-keeping |
6. Diagnostics and usage
Youmory uses PostHog, hosted in the European Union, to understand how the app is used and to find out when it breaks.
Usage events. The app records when it is installed, updated, opened and closed, which screens you open, and what you do in it: for example signing in, going through the introduction, starting and finishing a check-in, importing trips from your photos, sending or sharing a postcard, and looking at the Pro offer or buying something. Each event says what happened plus a few facts about it, such as how many friends a postcard went to, which handwriting and stamp it used, or at which step something failed. Events also note whether you have Pro. PostHog is also used to try out changes on some devices and not others, so the two versions can be compared.
What events never contain. The text of your postcards, anything you draw, your name, email address or profile picture, the coordinates or names of the places you check in, and anything you type into search.
Crash and error reports. When something fails, the app sends the device model, the operating system and app version, and the stack trace.
How it is linked to you. Events are attached to your account identifier, and what you did before signing in is merged into your account once you sign in. That makes the data pseudonymous rather than anonymous. When you sign in, PostHog is also told whether you used Apple or Google and when your account was created. There is no session recording, no screen recording, no advertising identifier and no tracking across other apps. PostHog is told not to work out a location from your IP address.
The website itself carries no analytics of any kind — no cookies, no tracking pixels, no third-party scripts. This is why there is no cookie banner: there are no cookies to consent to.
7. The website
Serving a page necessarily involves your IP address, the request, and your browser’s user agent. This data is processed by the hosting provider to deliver the page and to defend against attacks, and is not used to build a profile of you.
8. Who else processes your data
| Service | What for | Where |
|---|---|---|
| Supabase | Database, authentication, artwork storage, server functions | EU |
| Cloudflare | Website hosting and delivery | Global edge |
| PostHog | Product analytics and crash reporting | EU |
| Crisp | Support inbox for emails to support@youmory.app | EU |
| RevenueCat | Managing Youmory Pro subscriptions | USA |
| Apple, Google | Sign-in, app distribution, payments, push delivery | Global |
| Expo | Push notification delivery | USA |
Each has its own privacy policy. Transfers to processors in the United States are covered by the European Commission’s Standard Contractual Clauses, and where applicable by the EU–US Data Privacy Framework.
9. How long things are kept
Your account data is kept for as long as your account exists. Deleting your account in the app removes your profile, check-ins, collections, postcards and friendships; this cannot be undone.
Shared postcard links expire after thirty days. Crash reports are kept no longer than needed to fix the problem they describe. Support conversations are deleted twelve months after the last message. Purchase records are kept for as long as tax law requires, which in Germany is up to ten years.
10. Your rights
Under the GDPR you have the right to access your data, to correct it, to have it erased, to restrict or object to its processing, and to receive it in a portable form. You can delete your account and everything in it from the app’s settings at any time, without asking anyone. If you no longer have the app, you can ask us to delete it by email.
For anything else, write to support@youmory.app.
You also have the right to complain to a supervisory authority. For Youmory that is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany.
11. Children
Youmory is not directed at children under 13, and accounts are not knowingly created for them. If you believe a child has an account, write to support@youmory.app and it will be removed.
12. Security
Data is encrypted in transit and at rest. Access to postcards, collections and friendships is enforced at the database level by row-level security, so a postcard is readable by its sender and its recipient and by no other account, regardless of what any client asks for.
13. Changes
This policy will change as Youmory does. The date at the top says when it last did. Material changes will be announced in the app before they take effect.