Legal
Privacy Policy
Effective August 3, 2026 · Last updated August 3, 2026
Forever & Ever is a private vault for your family’s memories. That only works if you trust us with them. So this page explains, in plain language, what we collect, why we collect it, who else ever touches it, and how to get it back or get rid of it. We have kept the lawyer-speak to what the law actually requires, and we have not written a single promise here that our software does not already keep.
The short version
- We do not sell your data. Not to anyone, not ever. There are no ads in Forever & Ever, no advertising SDKs, and no third-party analytics or tracking pixels — no Google Analytics, no Meta pixel, nothing of that kind.
- Your memories are private by default. Photos, videos and voice notes are served over signed links that expire; they are not published, listed or indexed anywhere public.
- Face grouping is off until you turn it on. Faces are found on your own device, and switching the feature off deletes every face record we hold for you, immediately and permanently.
- You can leave whenever you like. Export your data or delete your account yourself, from Settings → Privacy.
- Children never have their own accounts here. A parent creates every child profile and stays in control of it.
Who this covers
This policy applies to the Forever & Ever website at foreverandever.app, the Forever & Ever iOS app, and the APIs behind them — together, the Service. The Service is operated by Forever & Ever LLC (“we”, “us”).
It covers everybody who uses the Service: the adult who owns an account, and the children or loved ones that adult invites as recipients. Where a right or a choice belongs only to the account owner, we say so.
What we collect
Things you give us
- Your account. Your name, email address and password. Passwords are stored only as a bcrypt hash — we never hold the password itself. If you sign in with Google instead, we receive the name, email address and profile picture on your Google account.
- The profiles you create. For each child or loved one: the name, date of birth, relationship and avatar you enter. If you build a family tree, the members you add and how they are related.
- Your content. The photos, videos, voice notes and written notes you upload, plus the titles, descriptions, tags, dates and place names you attach to them, the albums you sort them into, the unlock moments you schedule, and who each memory is meant for.
- Recipient logins. The usernames and passwords you set for the children and loved ones you give access to.
- What you write to us. Support requests, abuse reports, and anything you attach to them.
Things created as you use the Service
- Usage records, kept in our own database. Which memories were opened and when; the searches you run — the text you typed, the filters you used, how many results came back and which one you opened; video playback measurements such as start-up time, buffering and playback errors; a log of deletions; and the time and IP address of your most recent sign-in.
- Voice note transcripts. Transcription runs on your own device or in your own browser — the audio is never sent to a transcription service. The text it produces is saved with the memory and added to your private search index.
- Technical data. Ordinary server and CDN logs from our hosting providers: IP address, browser and device type, the address requested, and the time.
- Push notification tokens, if you turn notifications on.
- Administrative audit records. When someone on our team performs an administrative action on an account, that action is written to an audit log.
Payment information
Subscriptions are handled by Stripe. Card details are entered directly with Stripe and never reach our servers. What we store is your Stripe customer and subscription identifier, the plan you are on, and its status.
What we deliberately do not collect
We do not collect your device’s GPS position. A place name on a memory is text you typed; the browser geolocation API is switched off site-wide by our own security headers. We do not use third-party analytics, advertising or session-recording tools, so there is no vendor quietly watching how you use the app.
How we use it
- To give you the Service: store your files, serve them back to you quickly, and keep your albums, timeline, search and unlock moments working.
- To group faces into people — only if you have switched that feature on. See the next section.
- To send you email that the Service requires: password resets, family invitations, confirmations, storage and account notices, and the notifications you have asked for.
- To take payment and manage your subscription.
- To keep the Service safe and working: preventing abuse and fraud, investigating problems, rate-limiting, and keeping the audit trail that lets us see who did what.
- To answer you when you contact support.
- To understand what is slow or broken — for example playback measurements that tell us a video buffered, or search records that tell us a query returned nothing useful.
- To comply with the law, and to enforce our terms.
What we never do
- We never sell, rent or trade your personal information, and we never share it for cross-context behavioural advertising.
- We do not show you ads and we do not embed advertising or analytics SDKs.
- We do not use your photos, videos, notes or face data to train artificial-intelligence models. The face and transcription models we use are fixed, pre-existing models that run on your device; nothing you upload goes back into them.
- We do not browse your memories for our own purposes. A small number of authorised people can reach production data when it is genuinely necessary — to run the Service, to answer your support request, to investigate abuse, or because the law requires it — and those actions are logged.
Face recognition & biometric data
It is off until you say otherwise.
Forever & Ever can group the photos and videos in your vault by the people who appear in them. That feature does nothing at all until the account owner reads a dedicated consent screen and explicitly turns it on. It cannot be switched on by a child or loved-one recipient, and it is never on by default. Until you grant consent, the app does not even download the models that would do the work.
Where the analysis happens
Finding faces and turning each one into a numeric signature happens on your own device. On iPhone we use Apple’s built-in Vision framework together with two small open-source models (YuNet for detection, SFace for the signature) that the app downloads to the phone. Nothing is sent anywhere new to be analysed, and no outside company ever sees your media for this: we use no third-party face recognition service — not Amazon Rekognition, not Google, not Clearview, not anyone. The only handling of the media itself happens on our own infrastructure, to make the derived copies described below.
What leaves your device and what we store
What the app sends us, for each face it finds, is a list of numbers rather than a picture:
- a face embedding — 128 numbers that describe the geometry of the face, and which we treat as biometric information;
- where the face sits inside the image, as a rectangle, and the dimensions of the image it was measured against;
- how confident the detector was, which model version produced it, and when;
- for a video, how far into the video the frame was;
- the person group it belongs to, the name you give that person, and a numeric average of that group.
We do not store pictures of faces. There is no face crop, thumbnail or cut-out on our servers — the little round face pictures you see in the app are cropped out of your own photo by your own device, at the moment the screen is drawn. The embeddings themselves are never returned by our API, never written to logs, and never shown to anyone, including us.
Grouping is the one part that happens on our servers: we compare those numeric signatures with each other to decide which faces belong to the same person, and a nightly job revisits the grouping as your library grows.
Two kinds of derived picture are made to feed that analysis, and both are copies of your own media rather than pictures of faces. For a photo, our servers generate a downscaled copy of the whole photo. For a video, our servers can pull out a short series of still frames — at most twelve, one every two and a half seconds across roughly the first half-minute — so that someone who walks into shot after the opening moment can be found too. Both are ordinary, whole pictures, they are kept in the same private storage as the original, and they are covered by the note on derived copies in Retention and deletion.
What we do with it — and what we do not
Face data is used for exactly one thing: grouping the people in your own vault so you can browse by person, and offering to match a person to someone in your family tree. It is never used to identify anyone outside your account, never combined with other accounts, never sold or shared, never used for advertising, and never used to train a model.
Turning it off, and our deletion schedule
You can withdraw your consent at any time from the app. The moment you do:
- every face record we hold for you, including every embedding, is permanently deleted from our database — a real deletion, not a hidden flag;
- every person group we built for you, including its numeric average, is permanently deleted;
- the app deletes the face models it downloaded to your device.
Face data is also destroyed automatically in two other cases: when you delete the photo or video a face came from, and when you delete your account. We keep face data only for as long as your consent is live; there is no separate archive of it and no retention period beyond that.
One thing we do keep is the consent record itself — which version of the consent text you agreed to, when you granted it and when you withdrew it. We keep that after revocation, because it is the evidence that we held your permission lawfully and honoured your withdrawal.
Children and family profiles
Forever & Ever accounts are for adults. You must be 18 or older to create one. Children do not sign up and cannot create an account.
A parent or guardian creates each child profile and decides what goes into it: the name, date of birth, relationship and avatar, the memories addressed to that child, and whether the child gets a recipient login of their own. Recipient logins are created by the account owner, with a username and password the owner sets, and they give a limited view of what the owner has shared.
We do not ask children for personal information, we do not advertise to anyone, and we do not build advertising or marketing profiles of children. The information we hold about a child is what the parent put there, plus the sign-in records for that child’s recipient login.
Face grouping can only be enabled by the account owner. Children and loved-one recipients cannot reach the consent screen at all, and cannot switch the feature on.
A parent can edit or delete a child profile, and everything inside it, at any time; deleting the parent account deletes all of it. If you believe a child has sent us personal information directly, write to privacy@foreverandever.app and we will delete it.
Retention and deletion
How long we keep things
Your memories and profiles stay until you delete them or delete your account. Usage and security records — sign-in records, audit logs, deletion logs, search and playback records — are kept while your account is open, for security and to keep the Service working, and are removed with your account. Face data is kept only while your face-grouping consent is active, as described above. Records we are legally required to keep, such as invoices, are kept for the period the law sets.
Deleting a memory
When you delete a memory we remove its record from our database and delete the file from storage, and tell the CDN to drop its cached copy. Our storage keeps non-current versions of objects as a safeguard against accidental loss, so a copy can persist in that backup form for a period after deletion; those versions are not reachable from the app or the API.
Derived copies
To show your media quickly, and to run face grouping, we generate derived copies of your files: thumbnails, video renditions, the downscaled copy of a photo used for face analysis, and the still frames taken from a video for the same purpose. We are extending our deletion routines to cover every one of those derived copies; until that work is complete, some of them can remain in our private storage after the original has been deleted. They are never publicly accessible, and you can ask us to remove them at any time by writing to privacy@foreverandever.app.
Deleting your account
You can delete your account yourself, at any time, from Settings → Privacy on the web app. It is immediate and permanent: your account, your memories, your profiles, your albums, your face and consent records and your stored files all go, with no grace period and no way for us to bring them back. Export your data first if you want to keep it.
If you have a paid subscription, cancel it before you delete your account, or write to privacy@foreverandever.app and we will take care of both — deleting the account does not by itself stop billing at Stripe. You can also ask us to delete your account by email instead of doing it yourself.
Your rights and choices
Wherever you live, you can ask us to do the following, and we will not treat you differently for asking:
- See what we hold. Ask for a copy of your personal information.
- Take it with you. Settings → Privacy has a one-click export of your profile, albums and memory records as a machine-readable file; ask us if you need it in another form.
- Correct it. Fix anything inaccurate, from your profile or by writing to us.
- Delete it. Delete individual memories, a whole profile, or your entire account.
- Withdraw consent. Turn face grouping off, which deletes the face data as described above, or turn off notification email and push.
- Object or restrict. Ask us to stop or limit a particular use of your information.
- Complain. Raise it with us first if you can, but you are entitled to complain to your data protection authority.
Write to privacy@foreverandever.app to exercise any of these. We answer within 30 days, or 45 days for requests made under California law, and we may need to confirm who you are before we act — particularly for deletion.
If you are in the EEA, UK or Switzerland
We process your information on these legal bases: to perform our contract with you (running your account, storing and serving your memories, taking payment); our legitimate interests in keeping the Service secure, preventing abuse and fixing what is broken; your consent, which we ask for separately and which you can withdraw at any time, for face grouping and for optional notifications; and legal obligation where the law requires us to keep or disclose something. You also have the right to data portability and, in some cases, to object to processing based on legitimate interests.
If you are in California
In the last twelve months we have collected the categories of personal information described in What we collect: identifiers, customer records, commercial information, internet activity, audio and visual information, and — if you turn face grouping on — biometric information, which California treats as sensitive personal information. We use sensitive personal information only to provide the feature you asked for; we do not use it to infer characteristics about you. We have not sold or shared personal information, and we do not sell or share the personal information of anyone under 16. You may exercise your rights to know, delete, correct and limit through the contact address above, and you may use an authorised agent.
If your state has a biometric privacy law
Some states, Illinois and Texas among them, require a written policy setting out how long biometric identifiers are kept and when they are destroyed. The Face recognition section above is that policy: we collect a face embedding only after you give written consent through the in-app consent screen, we use it only to group people within your own vault, we never sell, lease or otherwise profit from it, we never disclose it to anyone else, and we destroy it as soon as you withdraw consent, when you delete the underlying photo or video, or when you delete your account — whichever comes first.
Security
We would rather describe what we actually do than make promises we cannot demonstrate.
- Everything travels over HTTPS, and our servers instruct browsers never to connect any other way.
- Your media is not public. Files are served through short-lived, cryptographically signed links and cookies, so a URL cannot be passed around or guessed, and nothing in our storage is browsable.
- Passwords are stored as bcrypt hashes, never in a form we can read.
- You can turn on two-factor authentication; administrator accounts have their own, separately encrypted, two-factor secrets.
- Face embeddings are excluded from every API response by construction, and are never written to logs.
- The site sends a strict content security policy and related protective headers on every response.
- Access to production data is limited to the people who need it, and administrative actions are recorded in an audit log.
No service can promise perfect security, and we will not pretend otherwise. If we ever discover a breach affecting your personal information, we will notify you and the relevant authorities as the law requires. If you spot a vulnerability, please tell us at privacy@foreverandever.app.
Where your data lives
Forever & Ever is operated from the United States, and your information is stored and processed there: media in Amazon S3 in Ohio (us-east-2), the database in Northern Virginia (us-east-1), with delivery through a global content network that caches your media closer to you.
If you use the Service from outside the United States, you are sending your information to a country whose privacy laws differ from your own. Where a transfer mechanism is legally required, we rely on the standard contractual clauses in our providers’ data processing agreements.
Changes to this policy
We will update this page when the Service changes. The effective date at the top always tells you which version you are reading. If a change materially affects how we handle your information, we will tell you in the app or by email before it takes effect, and where the law requires fresh consent — anything to do with biometric data, for one — we will ask you again rather than assume.
Contact us
Questions, requests or complaints about privacy go to privacy@foreverandever.app. A person reads that address.
Forever & Ever LLC · foreverandever.app