Privacy Policy
Effective date: February 16, 2026
Welcome to TheirStory. We are committed to protecting your privacy and handling your personal information with care and respect. This Privacy Policy explains how we collect, use, store, and protect your information when you use our memory book and oral history platform.
TheirStory enables you to create, preserve, and share personal stories and memories through recordings and written content. Because we handle sensitive personal stories and memories, we take data protection seriously and want you to understand exactly how your information is handled.
1. Information We Collect
1.1 Account Information
When you create an account, we collect:
- Email address
- Name (as you provide it)
- Password (stored securely in encrypted form)
- Profile information you choose to add
1.2 Content You Create
- Recordings: Audio and video recordings you upload or create through our platform
- Stories and text: Written stories, captions, descriptions, and other text content
- Projects: Information about memory book projects you create, including titles, descriptions, and settings
- Metadata: Dates, timestamps, and organisational information associated with your content
1.3 Information About Invitations and Sharing
- Email addresses of people you invite to contribute to projects
- Sharing preferences and access controls you set
- Collaboration activity within shared projects
1.4 Usage Information
- How you interact with our platform (features used, pages visited)
- Device information (browser type, operating system, device identifiers)
- IP address and general location information
- Log data and analytics about platform performance
2. How We Use Your Information
We use your information to:
- Provide and improve our services: Enable you to create, store, and share memory books and recordings
- Facilitate sharing: Deliver invitations and enable collaboration on projects
- Communicate with you: Send important updates, respond to your questions, and provide customer support
- Maintain security: Protect against unauthorised access, fraud, and abuse
- Analyse and improve: Understand how our platform is used to make it better
- Comply with legal obligations: Meet our legal and regulatory requirements
We process your personal stories and recordings solely to provide you with our services. We do not use your content for advertising, training AI models, or any purpose other than operating the platform for your benefit.
3. How We Share Your Information
3.1 People You Choose to Share With
When you invite someone to contribute to or view a project, we share the relevant project content with them according to the permissions you set. You control who has access to your stories and recordings.
3.2 Service Providers
We work with trusted third-party service providers who help us operate our platform:
- Cloud infrastructure: Provides our database, authentication, file storage, and backend services. Data is hosted on secure cloud servers.
- Cloud storage providers: Store your recordings and media files securely
- Email service providers: Send invitation emails and platform notifications
These providers are contractually obligated to protect your information and use it only for the purposes we specify.
3.3 Legal Requirements
We may disclose your information if required by law, legal process, or government request, or if we believe disclosure is necessary to protect our rights, property, or safety, or the rights, property, or safety of our users or the public.
3.4 Business Transfers
If TheirStory is involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify you and ensure your data continues to be protected.
We will never sell your personal information or your stories to third parties.
4. Data Storage and Security
4.1 Where Your Data is Stored
Your data is stored securely using industry-standard cloud infrastructure with robust physical and digital security measures. Your recordings and media files are stored in encrypted cloud storage.
4.2 Security Measures
We implement multiple layers of security to protect your information:
- Encryption: Data is encrypted in transit (using HTTPS/TLS) and at rest
- Access controls: Strict authentication and authorisation systems ensure only you (and people you invite) can access your content
- Regular security reviews: We review and update our security practices regularly
- Row-level security: Database-level access controls ensure users can only access data they own or have been granted permission to view
4.3 Your Responsibility
Please protect your account by:
- Using a strong, unique password
- Not sharing your login credentials
- Logging out on shared devices
- Notifying us immediately if you suspect unauthorised access
While we implement strong security measures, no system is completely secure. We work continuously to protect your information.
5. Your Rights and Choices
5.1 Access and Update
You can access, review, and update your account information and content at any time through your account settings.
5.2 Download Your Data
You can export and download your stories, recordings, and project data in standard formats.
5.3 Delete Your Data
You can delete specific recordings, stories, or projects, or you can delete your entire account. When you delete your account:
- Your profile and account information will be permanently removed
- Your projects and content will be deleted from our servers
- Invited collaborators will lose access to your projects
- Some data may be retained in backups for a limited period for security and legal compliance
5.4 Control Sharing
You control who can access your projects and can revoke access at any time.
5.5 Rights Under Privacy Laws
Depending on your location, you may have additional rights, including:
- Right to access the personal information we hold about you
- Right to rectification of inaccurate data
- Right to erasure (“right to be forgotten”)
- Right to restrict or object to processing
- Right to data portability
- Right to withdraw consent
- Right to lodge a complaint with a supervisory authority
To exercise these rights, contact us at privacy@theirstory.io.
6. Cookies and Tracking Technologies
We use cookies and similar technologies to maintain your session and remember your preferences:
- Essential cookies: Required for the platform to function (maintaining your login session, security)
- Functional cookies: Remember your preferences and settings
- Analytics: Help us understand how the platform is used (anonymised where possible)
Most browsers allow you to control cookies through settings. Note that disabling essential cookies may affect platform functionality. We do not use cookies for advertising or cross-site tracking.
7. Children's Privacy
TheirStory is intended for users 13 years of age and older. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us immediately at privacy@theirstory.io and we will delete it.
Projects may contain stories about children or from family members of various ages. The account holder is responsible for ensuring they have appropriate consent to record and share stories involving minors.
8. Data Retention
We retain your information for as long as your account is active or as needed to provide you with services. When you delete your account, most data is immediately removed from active systems. Some data may remain in encrypted backups for up to 90 days for disaster recovery purposes.
We may retain certain information longer if required by law or necessary to resolve disputes, enforce our agreements, or protect our legal rights.
9. International Data Transfers
Our platform is hosted on cloud infrastructure that may be located in various countries. By using TheirStory, you consent to the transfer of your information to countries outside your residence, which may have different data protection laws. We ensure appropriate safeguards are in place to protect your information in accordance with this Privacy Policy and applicable laws.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date at the top and notify you via email or through a prominent notice on our platform.
11. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or how we handle your information, please contact us at privacy@theirstory.io. We will respond to your inquiry within 30 days.