Legal

Privacy Policy

Effective August 3, 2026 · Last updated August 3, 2026

Forever & Ever is a private vault for your family’s memories. That only works if you trust us with them. So this page explains, in plain language, what we collect, why we collect it, who else ever touches it, and how to get it back or get rid of it. We have kept the lawyer-speak to what the law actually requires, and we have not written a single promise here that our software does not already keep.

The short version

  • We do not sell your data. Not to anyone, not ever. There are no ads in Forever & Ever, no advertising SDKs, and no third-party analytics or tracking pixels — no Google Analytics, no Meta pixel, nothing of that kind.
  • Your memories are private by default. Photos, videos and voice notes are served over signed links that expire; they are not published, listed or indexed anywhere public.
  • Face grouping is off until you turn it on. Faces are found on your own device, and switching the feature off deletes every face record we hold for you, immediately and permanently.
  • You can leave whenever you like. Export your data or delete your account yourself, from Settings → Privacy.
  • Children never have their own accounts here. A parent creates every child profile and stays in control of it.

Who this covers

This policy applies to the Forever & Ever website at foreverandever.app, the Forever & Ever iOS app, and the APIs behind them — together, the Service. The Service is operated by Forever & Ever LLC (“we”, “us”).

It covers everybody who uses the Service: the adult who owns an account, and the children or loved ones that adult invites as recipients. Where a right or a choice belongs only to the account owner, we say so.

What we collect

Things you give us

  • Your account. Your name, email address and password. Passwords are stored only as a bcrypt hash — we never hold the password itself. If you sign in with Google instead, we receive the name, email address and profile picture on your Google account.
  • The profiles you create. For each child or loved one: the name, date of birth, relationship and avatar you enter. If you build a family tree, the members you add and how they are related.
  • Your content. The photos, videos, voice notes and written notes you upload, plus the titles, descriptions, tags, dates and place names you attach to them, the albums you sort them into, the unlock moments you schedule, and who each memory is meant for.
  • Recipient logins. The usernames and passwords you set for the children and loved ones you give access to.
  • What you write to us. Support requests, abuse reports, and anything you attach to them.

Things created as you use the Service

  • Usage records, kept in our own database. Which memories were opened and when; the searches you run — the text you typed, the filters you used, how many results came back and which one you opened; video playback measurements such as start-up time, buffering and playback errors; a log of deletions; and the time and IP address of your most recent sign-in.
  • Voice note transcripts. Transcription runs on your own device or in your own browser — the audio is never sent to a transcription service. The text it produces is saved with the memory and added to your private search index.
  • Technical data. Ordinary server and CDN logs from our hosting providers: IP address, browser and device type, the address requested, and the time.
  • Push notification tokens, if you turn notifications on.
  • Administrative audit records. When someone on our team performs an administrative action on an account, that action is written to an audit log.

Payment information

Subscriptions are handled by Stripe. Card details are entered directly with Stripe and never reach our servers. What we store is your Stripe customer and subscription identifier, the plan you are on, and its status.

What we deliberately do not collect

We do not collect your device’s GPS position. A place name on a memory is text you typed; the browser geolocation API is switched off site-wide by our own security headers. We do not use third-party analytics, advertising or session-recording tools, so there is no vendor quietly watching how you use the app.

How we use it

  • To give you the Service: store your files, serve them back to you quickly, and keep your albums, timeline, search and unlock moments working.
  • To group faces into people — only if you have switched that feature on. See the next section.
  • To send you email that the Service requires: password resets, family invitations, confirmations, storage and account notices, and the notifications you have asked for.
  • To take payment and manage your subscription.
  • To keep the Service safe and working: preventing abuse and fraud, investigating problems, rate-limiting, and keeping the audit trail that lets us see who did what.
  • To answer you when you contact support.
  • To understand what is slow or broken — for example playback measurements that tell us a video buffered, or search records that tell us a query returned nothing useful.
  • To comply with the law, and to enforce our terms.

What we never do

  • We never sell, rent or trade your personal information, and we never share it for cross-context behavioural advertising.
  • We do not show you ads and we do not embed advertising or analytics SDKs.
  • We do not use your photos, videos, notes or face data to train artificial-intelligence models. The face and transcription models we use are fixed, pre-existing models that run on your device; nothing you upload goes back into them.
  • We do not browse your memories for our own purposes. A small number of authorised people can reach production data when it is genuinely necessary — to run the Service, to answer your support request, to investigate abuse, or because the law requires it — and those actions are logged.

Face recognition & biometric data

It is off until you say otherwise.

Forever & Ever can group the photos and videos in your vault by the people who appear in them. That feature does nothing at all until the account owner reads a dedicated consent screen and explicitly turns it on. It cannot be switched on by a child or loved-one recipient, and it is never on by default. Until you grant consent, the app does not even download the models that would do the work.

Where the analysis happens

Finding faces and turning each one into a numeric signature happens on your own device. On iPhone we use Apple’s built-in Vision framework together with two small open-source models (YuNet for detection, SFace for the signature) that the app downloads to the phone. Nothing is sent anywhere new to be analysed, and no outside company ever sees your media for this: we use no third-party face recognition service — not Amazon Rekognition, not Google, not Clearview, not anyone. The only handling of the media itself happens on our own infrastructure, to make the derived copies described below.

What leaves your device and what we store

What the app sends us, for each face it finds, is a list of numbers rather than a picture:

  • a face embedding — 128 numbers that describe the geometry of the face, and which we treat as biometric information;
  • where the face sits inside the image, as a rectangle, and the dimensions of the image it was measured against;
  • how confident the detector was, which model version produced it, and when;
  • for a video, how far into the video the frame was;
  • the person group it belongs to, the name you give that person, and a numeric average of that group.

We do not store pictures of faces. There is no face crop, thumbnail or cut-out on our servers — the little round face pictures you see in the app are cropped out of your own photo by your own device, at the moment the screen is drawn. The embeddings themselves are never returned by our API, never written to logs, and never shown to anyone, including us.

Grouping is the one part that happens on our servers: we compare those numeric signatures with each other to decide which faces belong to the same person, and a nightly job revisits the grouping as your library grows.

Two kinds of derived picture are made to feed that analysis, and both are copies of your own media rather than pictures of faces. For a photo, our servers generate a downscaled copy of the whole photo. For a video, our servers can pull out a short series of still frames — at most twelve, one every two and a half seconds across roughly the first half-minute — so that someone who walks into shot after the opening moment can be found too. Both are ordinary, whole pictures, they are kept in the same private storage as the original, and they are covered by the note on derived copies in Retention and deletion.

What we do with it — and what we do not

Face data is used for exactly one thing: grouping the people in your own vault so you can browse by person, and offering to match a person to someone in your family tree. It is never used to identify anyone outside your account, never combined with other accounts, never sold or shared, never used for advertising, and never used to train a model.

Turning it off, and our deletion schedule

You can withdraw your consent at any time from the app. The moment you do:

  • every face record we hold for you, including every embedding, is permanently deleted from our database — a real deletion, not a hidden flag;
  • every person group we built for you, including its numeric average, is permanently deleted;
  • the app deletes the face models it downloaded to your device.

Face data is also destroyed automatically in two other cases: when you delete the photo or video a face came from, and when you delete your account. We keep face data only for as long as your consent is live; there is no separate archive of it and no retention period beyond that.

One thing we do keep is the consent record itself — which version of the consent text you agreed to, when you granted it and when you withdrew it. We keep that after revocation, because it is the evidence that we held your permission lawfully and honoured your withdrawal.

Children and family profiles

Forever & Ever accounts are for adults. You must be 18 or older to create one. Children do not sign up and cannot create an account.

A parent or guardian creates each child profile and decides what goes into it: the name, date of birth, relationship and avatar, the memories addressed to that child, and whether the child gets a recipient login of their own. Recipient logins are created by the account owner, with a username and password the owner sets, and they give a limited view of what the owner has shared.

We do not ask children for personal information, we do not advertise to anyone, and we do not build advertising or marketing profiles of children. The information we hold about a child is what the parent put there, plus the sign-in records for that child’s recipient login.

Face grouping can only be enabled by the account owner. Children and loved-one recipients cannot reach the consent screen at all, and cannot switch the feature on.

A parent can edit or delete a child profile, and everything inside it, at any time; deleting the parent account deletes all of it. If you believe a child has sent us personal information directly, write to privacy@foreverandever.app and we will delete it.

Sharing and service providers

We do not sell your information and we do not share it for advertising. We do rely on a small set of vendors to run the Service. Each of them receives only what it needs, only to do work for us, and under contracts that require them to protect it.

Amazon Web Services

Storage, delivery, video

Stores your photos, videos, audio and their derived copies in Amazon S3 (Ohio, us-east-2) and delivers them through CloudFront using signed links that expire. Also used for video processing and for holding the keys that sign those links.

Vercel

Application hosting

Runs the website and the API. Sees all request traffic and keeps ordinary server logs, including IP addresses.

Neon

Database

Hosts the PostgreSQL database (AWS, us-east-1) that holds your account, profiles, memory records, search and usage records, and face embeddings.

Stripe

Payments

Receives your name, email address and payment details to take payment and manage your subscription. Card numbers go to Stripe directly and never reach us.

Resend

Transactional email

Delivers the email the Service sends you: password resets, invitations, confirmations and account notices. Receives your email address, your name and the contents of that message.

Klaviyo

Notification delivery

Used to deliver notification messages, including mobile push. Receives your email address, your account identifier, and the title, text and link of the notification.

Meilisearch (hosted on Railway)

Search index

Holds the index that makes your library searchable: memory titles, descriptions, tags, place names, note text and voice-note transcripts, album names, unlock moment titles, and the names, birthdays and avatars of the profiles you create.

Google

Place suggestions, optional sign-in

When you type a place name on a memory, the text you type is sent to Google Places to suggest matches. If you choose to sign in with Google, Google confirms your identity and sends us your name, email address and profile picture.

Hugging Face

Model download

When you transcribe a voice note in the browser, the speech model is downloaded from Hugging Face's CDN. Your audio is not sent there — only the request for the model file, which reveals your IP address.

Apple

App distribution, push

Distributes the iOS app and carries push notifications to your device. Apple's own privacy policy governs your App Store account.

We may also disclose information when the law compels us to — a valid subpoena, court order or similar legal process — or when we believe in good faith that disclosure is necessary to prevent serious harm. If Forever & Ever is ever acquired or merged, your information may transfer as part of that deal; we will tell you before it becomes subject to a different privacy policy.

Cookies

We use cookies to run the Service, not to follow you around the internet. Specifically:

  • a session cookie that keeps you signed in, and a separate one for administrator sessions;
  • media access cookies that let your browser load your own photos and videos from our CDN, and that expire on their own after a short time;
  • an appearance cookie remembering display choices such as dark mode;
  • short-lived flags, for example one that tells the app your session has expired.

We set no advertising, marketing or third-party tracking cookies, which is why there is no cookie banner to click past: everything we store is either necessary to deliver the Service or a setting you chose yourself.

Retention and deletion

How long we keep things

Your memories and profiles stay until you delete them or delete your account. Usage and security records — sign-in records, audit logs, deletion logs, search and playback records — are kept while your account is open, for security and to keep the Service working, and are removed with your account. Face data is kept only while your face-grouping consent is active, as described above. Records we are legally required to keep, such as invoices, are kept for the period the law sets.

Deleting a memory

When you delete a memory we remove its record from our database and delete the file from storage, and tell the CDN to drop its cached copy. Our storage keeps non-current versions of objects as a safeguard against accidental loss, so a copy can persist in that backup form for a period after deletion; those versions are not reachable from the app or the API.

Derived copies

To show your media quickly, and to run face grouping, we generate derived copies of your files: thumbnails, video renditions, the downscaled copy of a photo used for face analysis, and the still frames taken from a video for the same purpose. We are extending our deletion routines to cover every one of those derived copies; until that work is complete, some of them can remain in our private storage after the original has been deleted. They are never publicly accessible, and you can ask us to remove them at any time by writing to privacy@foreverandever.app.

Deleting your account

You can delete your account yourself, at any time, from Settings → Privacy on the web app. It is immediate and permanent: your account, your memories, your profiles, your albums, your face and consent records and your stored files all go, with no grace period and no way for us to bring them back. Export your data first if you want to keep it.

If you have a paid subscription, cancel it before you delete your account, or write to privacy@foreverandever.app and we will take care of both — deleting the account does not by itself stop billing at Stripe. You can also ask us to delete your account by email instead of doing it yourself.

Your rights and choices

Wherever you live, you can ask us to do the following, and we will not treat you differently for asking:

  • See what we hold. Ask for a copy of your personal information.
  • Take it with you. Settings → Privacy has a one-click export of your profile, albums and memory records as a machine-readable file; ask us if you need it in another form.
  • Correct it. Fix anything inaccurate, from your profile or by writing to us.
  • Delete it. Delete individual memories, a whole profile, or your entire account.
  • Withdraw consent. Turn face grouping off, which deletes the face data as described above, or turn off notification email and push.
  • Object or restrict. Ask us to stop or limit a particular use of your information.
  • Complain. Raise it with us first if you can, but you are entitled to complain to your data protection authority.

Write to privacy@foreverandever.app to exercise any of these. We answer within 30 days, or 45 days for requests made under California law, and we may need to confirm who you are before we act — particularly for deletion.

If you are in the EEA, UK or Switzerland

We process your information on these legal bases: to perform our contract with you (running your account, storing and serving your memories, taking payment); our legitimate interests in keeping the Service secure, preventing abuse and fixing what is broken; your consent, which we ask for separately and which you can withdraw at any time, for face grouping and for optional notifications; and legal obligation where the law requires us to keep or disclose something. You also have the right to data portability and, in some cases, to object to processing based on legitimate interests.

If you are in California

In the last twelve months we have collected the categories of personal information described in What we collect: identifiers, customer records, commercial information, internet activity, audio and visual information, and — if you turn face grouping on — biometric information, which California treats as sensitive personal information. We use sensitive personal information only to provide the feature you asked for; we do not use it to infer characteristics about you. We have not sold or shared personal information, and we do not sell or share the personal information of anyone under 16. You may exercise your rights to know, delete, correct and limit through the contact address above, and you may use an authorised agent.

If your state has a biometric privacy law

Some states, Illinois and Texas among them, require a written policy setting out how long biometric identifiers are kept and when they are destroyed. The Face recognition section above is that policy: we collect a face embedding only after you give written consent through the in-app consent screen, we use it only to group people within your own vault, we never sell, lease or otherwise profit from it, we never disclose it to anyone else, and we destroy it as soon as you withdraw consent, when you delete the underlying photo or video, or when you delete your account — whichever comes first.

Security

We would rather describe what we actually do than make promises we cannot demonstrate.

  • Everything travels over HTTPS, and our servers instruct browsers never to connect any other way.
  • Your media is not public. Files are served through short-lived, cryptographically signed links and cookies, so a URL cannot be passed around or guessed, and nothing in our storage is browsable.
  • Passwords are stored as bcrypt hashes, never in a form we can read.
  • You can turn on two-factor authentication; administrator accounts have their own, separately encrypted, two-factor secrets.
  • Face embeddings are excluded from every API response by construction, and are never written to logs.
  • The site sends a strict content security policy and related protective headers on every response.
  • Access to production data is limited to the people who need it, and administrative actions are recorded in an audit log.

No service can promise perfect security, and we will not pretend otherwise. If we ever discover a breach affecting your personal information, we will notify you and the relevant authorities as the law requires. If you spot a vulnerability, please tell us at privacy@foreverandever.app.

Where your data lives

Forever & Ever is operated from the United States, and your information is stored and processed there: media in Amazon S3 in Ohio (us-east-2), the database in Northern Virginia (us-east-1), with delivery through a global content network that caches your media closer to you.

If you use the Service from outside the United States, you are sending your information to a country whose privacy laws differ from your own. Where a transfer mechanism is legally required, we rely on the standard contractual clauses in our providers’ data processing agreements.

Changes to this policy

We will update this page when the Service changes. The effective date at the top always tells you which version you are reading. If a change materially affects how we handle your information, we will tell you in the app or by email before it takes effect, and where the law requires fresh consent — anything to do with biometric data, for one — we will ask you again rather than assume.

Contact us

Questions, requests or complaints about privacy go to privacy@foreverandever.app. A person reads that address.

Forever & Ever LLC · foreverandever.app