LiveMemoriesAI
Privacy Policy
Version 2.1 · Last updated 17 August 2026
This policy explains, in clear and complete language, how LiveMemoriesAI handles information when a family creates and shares a virtual memorial, and which data the service processes for account, paid-plan and measurement features. We comply with Regulation (EU) 2016/679 (GDPR), Organic Law 3/2018 (LOPDGDD), Regulation (EU) 2024/1689 (AI Act) and Law 34/2002 (LSSI). We have designed the service for a sensitive setting: grief, family history and private conversations.
Service provider
Sergio Fernández · Avenida Gran Vía de Vicálvaro, Madrid, 28052, Spain
Privacy & rights contact
contact@livememoriesai.com
Jurisdiction
Spain and European Union
Last updated
17 August 2026
Text legally reviewed on 17 August 2026 (pending external counsel sign-off).
1. Data controller and contact details
The data controller for the personal data processed through LiveMemoriesAI is:
For any matter relating to personal data protection you can write to the address above. We have not formally appointed a Data Protection Officer (DPO) at this time because, based on our internal assessment, the circumstances of article 37.1 GDPR that would require it do not apply: the main processing is the provision of a service requested by the user and the profiling is instrumental to that provision. This assessment is reviewed periodically; if it changes, a DPO will be appointed and this section updated.
LiveMemoriesAI relies on external legal advice in data protection, at least every six months, to review compliance and update the measures when needed.
- Identity of the controller: Sergio Fernández
- Address: Avenida Gran Vía de Vicálvaro, Madrid, 28052, Spain
- Privacy and rights email: contact@livememoriesai.com
- Website: https://www.livememoriesai.com
2. Categories of data subjects and data processed
We process data on the following categories of data subjects, each with its own regime:
We do not process special-category data (art. 9 GDPR) as a purpose of the service. When the materials incidentally contain them, the minimisation measures described in §7 of the Terms apply.
- Custodians (account holders): email, optional name, authentication metadata, preferences, memorial parameters, and billing data when they take a paid plan.
- Collaborators (co-custodians): email, granted permissions and activity metadata within the shared replica.
- Deceased persons who give rise to the replica: texts, photographs, audio, video and other materials contributed by the family. These data fall outside the scope of the GDPR (Recital 27) but are protected by the LOPDGDD (arts. 3 and 96) and by LO 1/1982.
- Invited interlocutors: Telegram identifier, conversation metadata, fragments of their messages needed for private memory and for operating the service.
- Living third parties that appear incidentally in the materials (relatives, friends, neighbours, professionals, etc.): names, voices, faces and mentions, anonymised by default in derived text.
- Website visitors: IP address processed by the network servers for security and fraud prevention, and browsing data only if you accept the measurement category (§12 and §19).
- People exercising rights: contact data and content of Opposition channel requests.
- Platform staff: the minimum data needed for technical and security administration.
3. Data of deceased persons
Data of deceased persons are outside the scope of the GDPR (Recital 27), but Spanish law grants them specific protection:
The channel set up for these requests is the Opposition channel, available at /opposition. The platform processes the precautionary suspension and, where appropriate, the removal without undue delay, except for records strictly necessary to evidence the request and the decision taken.
- Article 3 of the LOPDGDD recognises the people connected to the deceased by family or personal ties, their heirs and the people designated or authorised by them the faculty to exercise GDPR rights over the deceased’s data.
- Article 96 of the LOPDGDD requires the deletion, without delay, of the data of a deceased person when requested by a legitimised person, unless the deceased had expressly forbidden it or the law limits it.
- LO 1/1982 protects honour, privacy and personal image, and these protections extend post mortem under article 4.
4. Data of invited interlocutors
The invited interlocutor chats with the replica from their Telegram account. To provide the service we process:
The interlocutor may request access, rectification or deletion of their data and may order the deletion of their account from the memorial by sending /borrarme to the bot or writing to contact@livememoriesai.com.
We do not process interlocutor data for advertising or for commercial profiling.
- Telegram identifier (not the phone number: Telegram does not expose it to bots by default).
- Messages sent and received during the conversation, stored to maintain the interlocutor’s memory and allow them to continue the conversation.
- Technical metadata (date, time, length) required for operation.
- Notification and channel preferences if the user configures them.
5. Data of living third parties appearing in the materials
Materials uploaded by the family may incidentally contain data of living people. By design, the service:
- Masks the names of third parties in derived text with stable per-document labels.
- Replaces the faces of unidentified third parties with a generic crop or omits them from messages to interlocutors who should not receive them.
- Restricts access to the raw texts to the custodian and to internal extraction, anonymisation and maintenance processes.
- Allows any affected third party to exercise rights through the Opposition channel without creating an account.
6. Purposes and legal bases of processing
We process the data for the following purposes and legal bases:
We do not use memorial conversations, materials or memories to build advertising profiles, to train external AI models, to sell data or to build engagement rankings. Analytics, when you accept it, serves only service improvement and is described in §19. Any other use requires your express and specific consent.
- Performance of the requested service (art. 6.1.b GDPR): authentication, account management, memorial operation, export and deletion.
- Performance of the subscription contract (art. 6.1.b GDPR): plan management, billing, failed payments and service communications.
- Specific consent (art. 6.1.a GDPR): voice cloning, proactivity reception, website analytics (§19), marketing personalisation if ever enabled, and optional automated decisions that produce legal or similarly significant effects.
- Legitimate interest (art. 6.1.f GDPR), balanced against the rights of the data subjects: security, abuse and payment fraud prevention, multi-tenant isolation, append-only audit, retention of consent proofs and aggregated service improvement.
- Legal obligation (art. 6.1.c GDPR): retention of consent records, invoices and tax documents, responses to authority requests.
- Vital interests (art. 6.1.d GDPR): detection of and response to risk signals (suicidal ideation, self-harm) and hand-off to professional resources.
7. Automated decisions and profiling (art. 22 GDPR)
The service uses artificial intelligence systems to:
Under art. 22 GDPR, automated decisions that produce legal effects on you or significantly affect you generally require human intervention, the ability to contest the decision or your explicit consent. Here, no automated decision of the service produces legal effects on the user outside the strictly contractual scope. Memory, photo and style proposals are always subject to custodian approval (HITL), and conversational responses do not replace professional advice.
- Generate the in-character responses of the replica. The automated decision here is text production and does not produce significant legal effects for the user.
- Suggest memory and photo classifications, style proposals, questionnaire questions and material summaries. These proposals are always subject to human review (HITL) by the custodian before being incorporated into the profile.
- Detect risk signals and classify the level (1 to 3). At level 3 the system interrupts the character and hands off to professional resources without a real-time human in the loop.
8. Processors and provider categories
To provide the service, LiveMemoriesAI uses the following categories of processors, all under a Data Processing Agreement (DPA) that complies with art. 28 GDPR:
The current named list of providers with their regions and transfer mechanisms is published and maintained in the technical documentation of the service. Any material change is notified to registered users at least 15 days in advance, per §16 of the Terms.
- Authentication and database infrastructure (Supabase / Postgres + GoTrue + Storage + pgvector). Processing region: European Union.
- Website hosting and edge functions (Cloudflare Workers, OpenNext). Global CDN distribution; primary data are processed in the EU.
- Natural language processing, vision and embeddings (MiniMax and OpenRouter as a gateway to third-party models). Some models may be invoked from regions outside the EEA, with the safeguards of §9.
- Voice synthesis and cloning (MiniMax Speech). Voice samples and generated audio may be processed outside the EEA under the contractual safeguards of §9.
- Conversational messaging (Telegram Bot API). The Telegram exchange happens from European regions; the Telegram platform itself processes messages under its own terms and policies.
- Payments and billing (Stripe). PCI-DSS certified provider; card data are handled in tokenised form and LiveMemoriesAI does not store them (see §20).
- Web measurement (Google Analytics 4), only when you accept the analytics category (see §12 and §19).
- Transactional email (email provider). For magic links, critical notifications, invoices and export links.
9. International transfers
When a provider processes data outside the European Economic Area (EEA), LiveMemoriesAI uses one of the mechanisms allowed by Chapter V GDPR:
In particular, voice synthesis (MiniMax), processing by some large models and the delivery of certain transactional emails may rely on services outside the EEA. In all these cases the contractual agreement includes the SCCs and, when the provider participates in the EU-US DPF, it is considered covered by adequacy decision.
When a paid plan is contracted, Stripe may process billing data outside the EEA (for example, in the United States) under the SCCs and, where applicable, the EU-US DPF. Card data never reach LiveMemoriesAI’s servers.
Google Analytics 4 processes measurement data on Google’s servers, in the United States and the European Union, under Google’s standard contractual clauses and, where applicable, the EU-US DPF. It is only enabled with your consent (§19) and is configured without personalised advertising and without Google Signals.
The category, country and specific mechanism of each transfer are documented and updated when providers or regions change.
- Adequacy decision of the European Commission (for example, for providers that participate in the EU-US Data Privacy Framework, DPF).
- Standard Contractual Clauses (SCC) adopted by the European Commission, with the corresponding impact assessment and, where applicable, supplementary technical and organisational measures.
- Binding Corporate Rules (BCR), when the provider has them approved by the competent supervisory authority.
- Explicit and specific consent, only in the cases foreseen by art. 49 GDPR.
10. Retention periods
Retention periods are defined per category:
- Custodian account: while the account is active. After cancellation, identifying data are deleted from the operational environment within 72 hours.
- Materials and replicas: while the account and replica are active, or while the replica is archived. Deletion is executed within 72 hours of a valid request, except for the technical rotation windows of backups, which may extend up to 30 days.
- Consent records (append-only): for the limitation period of the derived actions (indicatively 6 years), on the legal basis of legitimate interest for legal defence.
- Access audit and security events: for the minimum time needed to evidence compliance, no more than 5 years.
- Conversations of invited interlocutors: while the replica is active or until the interlocutor requests deletion. After /borrarme, data are deleted from the operational environment within 72 hours, subject to the technical windows of §18 of the Terms.
- Billing and payment data: for the duration of the contractual relationship and afterwards for the period required by applicable tax and corporate law (in Spain, indicatively 4 years for tax purposes and up to 6 years for the limitation of commercial obligations).
- Analytics data (Google Analytics): events are kept in Google Analytics for a maximum of 26 months from collection; user-level identifiers are kept for a maximum of 2 months and are never combined with your account identity.
- Technical logs and error records: kept between 30 and 180 days depending on their operational purpose, and pseudonymised wherever possible.
- Opposition and rights requests: for the time necessary to manage the request, document it and defend the decision; indicatively, 6 years.
- Support messages: for the time needed to resolve the query and, afterwards, up to 2 years for service quality purposes.
11. Technical and organisational security measures
We apply technical and organisational measures appropriate to the risk, under art. 32 GDPR:
- Encryption in transit (TLS 1.2 or higher) between every component.
- Encryption at rest of backups and of files in object storage.
- Verified multi-tenant isolation with automated tests in continuous integration.
- Append-only audit of consents, administrative accesses and security events.
- Role-based access control with least privilege for staff.
- Encrypted backups with automatic rotation; restoration tested periodically.
- Secrets managed in a dedicated service, never in the code or the web bundle.
- Monitoring of health, errors and operational metrics; alerts on anomalies.
- Internal training policy on data protection and confidentiality.
12. Cookies and similar technologies (LSSI)
We use browser cookies and local storage in three categories, in line with art. 22.2 of Law 34/2002 (LSSI) and AEPD guidance:
The cookie banner lets you accept all, reject the optional categories or customise your choice per category. Your choice is stored in the lm_consent cookie for 12 months and you can change it at any time by reopening the preferences panel or clearing your browser cookies.
Necessary cookies are exempt from the prior-consent requirement; the optional categories do not load until you accept. Before your choice, no optional cookie is set.
To configure cookies in your browser, please consult its help section. Blocking strictly necessary cookies may prevent the service from working.
- Necessary (always on): session and authentication (Supabase Auth), language preference (lm_locale), interface theme and the cookie preference itself (lm_consent). Without them the service cannot work.
- Measurement and analytics (only with your consent): Google Analytics 4, to understand how the website is used in aggregate and to improve the service. No personalised advertising or cross-site tracking is used.
- Personalisation and marketing (only with your consent): not used today. If this category is enabled in the future, it will only load with your explicit consent.
13. Artificial intelligence: which models we use and which data go in
The service uses several types of artificial intelligence systems, each with a different data flow:
Materials uploaded by the family and the conversations are not used to train external AI models. The platform uses the models as processors and applies the safeguards of §8 and §9.
When a model is invoked from regions outside the EEA, the mechanisms of §9 apply and calls are anonymised and pseudonymised where possible (avoiding unnecessary identifiers of the custodian or interlocutors in the prompt sent to the AI).
Generated audio carries machine-readable marking under art. 50.2 of the AI Act; the synthetic nature of the voice is additionally communicated audibly and in text.
- Conversational model (text): generates the replica’s in-character responses. Inputs are the replica-specific system prompt (profile, memory, configuration), the recent conversation history and the memory fragments retrieved by hybrid search filtered by replica_id and by the inter-interlocutor privacy rules.
- Vision model (VLM): classifies and describes photographs from the family archive. Inputs are the images sent for cataloguing and labelling; they are not used to identify living people outside the memorial.
- Embeddings: convert texts and images into vectors for semantic search within the replica. The vectors do not contain the original text and cannot reconstruct it.
- Voice synthesis: generates the replica’s audio from the text to be synthesised and the authorised clone. See safeguards in §11 of the Terms.
- Local audio transcription: converting audio to text runs on LiveMemoriesAI’s own infrastructure; intimate audio is not sent to external providers for this task.
- Risk-signal classifier: analyses incoming messages to detect signs of acute grief, dependency or ideation and to trigger the hand-off protocol. It operates on the message text and keeps no additional profiles.
14. Your rights and how to exercise them
You may exercise the rights recognised by the GDPR and the LOPDGDD:
To exercise them, write to contact@livememoriesai.com, use the controls in your account (settings, export, deletion) or use the Opposition channel (/opposition) if you do not have an account. Telegram interlocutors can use the /identidad and /borrarme commands. We will respond within a maximum of one month (art. 12.3 GDPR), extendable to two months when the request is complex, with prior notice.
We may ask for proportionate identity or relationship verification to avoid disclosing information to the wrong person. This verification is strictly the minimum necessary and is documented.
- Access: know what data we process and obtain a copy in a structured, commonly used format.
- Rectification: correct inaccurate or incomplete data.
- Erasure: request deletion of your data when no longer necessary or when you withdraw consent.
- Restriction: request that we limit processing in certain circumstances (for example, while accuracy is being verified).
- Objection: object to processing based on legitimate interest on grounds relating to your particular situation.
- Portability: receive the data you have provided in a structured, commonly used and machine-readable format, and transmit them to another controller.
- Withdrawal of consent: withdraw any previously given consent at any time (including the analytics or marketing category), without affecting the lawfulness of prior processing.
15. Security breaches and notification
In the event of a security breach affecting personal data:
- We will notify the competent supervisory authority within a maximum of 72 hours of becoming aware, unless the breach is unlikely to entail a risk to the rights and freedoms of individuals.
- If the breach entails a high risk to your rights and freedoms, we will communicate it to you without undue delay.
- The communication will include the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences and the measures taken or proposed.
- We will document every breach with its impact assessment and the measures taken, under art. 33.5 GDPR.
16. Complaints to the supervisory authority
If you believe the processing of your personal data infringes the law, you may lodge a complaint with the competent supervisory authority. In Spain:
If you reside in another EEA country, you may complain to the supervisory authority of your country of habitual residence. In cross-border consumer disputes the European Commission ODR platform can facilitate out-of-court resolution (https://ec.europa.eu/consumers/odr).
Before complaining to an authority, we invite you to write to us so we can try to resolve the issue. Most incidents are resolved without administrative intervention.
- Agencia Española de Protección de Datos (AEPD).
- C/ Jorge Juan, 6 · 28001 Madrid · Spain.
- Website: https://www.aepd.es · Electronic office: https://sedeagpd.gob.es
17. Changes to this policy
When we update this policy for a legal, technical or operational change:
- We will publish the new “Last updated” date at the top of the document.
- If the change is material, we will notify you at least 15 days in advance by email or by a prominent in-product notice.
- Where appropriate, we will ask you to accept the document again (renewed consent) to keep using the service.
18. Minors
Processing of minors’ data follows specific rules:
- Minors aged 14 to 17 only act as invited interlocutors under the supervision of an adult custodian; they cannot open accounts or act as custodians.
- We do not knowingly collect data of minors under 14. If we detect that a minor under 14 has interacted with the service, their data are deleted.
- When the deceased person was a minor, their materials and replica are processed with additional access and anonymisation restrictions (see §21 of the Terms).
- The legal basis for data of minors aged 14 to 17 as interlocutors is the consent given by the minor, collected through the adult who invites and supervises them.
19. Analytics and measurement (Google Analytics)
When you accept the measurement category in the cookie banner, we enable Google Analytics 4 to understand, in aggregate, how the website is used and to improve the service.
Google Ireland Limited acts as a processor for these data. You can withdraw your consent at any time from the cookie preferences panel.
- Prior consent: Google Analytics does not load until you accept the category. If you do not accept, no browsing data are sent to Google.
- IP anonymisation: collection is configured so the full IP address is not stored.
- No advertising: advertising features, remarketing and Google Signals are disabled, and data are not shared with Google advertising products.
- No identity cross-referencing: measurement events are not linked to your account, your replicas or the content of your memorials.
- Retention: events are kept for a maximum of 26 months; user-level identifiers for a maximum of 2 months (see §10).
- Rejection without penalty: rejecting measurement does not change how the service works or your plans.
20. Payments and tax data (Stripe)
Paid plans are managed through Stripe, which acts as a data processor for payment data. The flow is as follows:
- Card details are entered in Stripe’s secure elements; they never pass through LiveMemoriesAI’s servers.
- LiveMemoriesAI receives a customer and subscription identifier (tokens) from Stripe, along with payment status, without access to the card number (PAN).
- Billing data (name, email, tax address, amounts, VAT) are kept according to the tax and corporate periods of §10.
- Stripe may process data in the United States and the European Union under the SCCs and, where applicable, the EU-US DPF (see §9).
- To prevent fraud, Stripe may assess the transaction risk; this assessment is not used to make decisions about you beyond the specific payment.
- You can request a copy of your invoices, correction of your billing data and deletion of the payment account from the panel or by writing to contact@livememoriesai.com.
21. Administration panel and staff access
LiveMemoriesAI operates an internal administration panel to run the platform. Access follows strict rules:
- Roles and least privilege: each staff member only accesses what their function requires (support, operations, security).
- Administrative accesses are recorded in the system audit trail.
- The panel does not display the content of replica messages or materials; it shows statuses, operational metrics and errors.
- Exceptionally, on a well-founded suspicion of abuse or due to a legal request, specific content may be accessed through a motivated, recorded protocol.
- Staff sign confidentiality commitments and receive data protection training.
22. Errors, telemetry and support
To keep the service quality high we process a minimum amount of technical data:
- Browser errors: when the website fails, your browser may send us an anonymous report with the error type and the page, without conversation content or personal data.
- Operational telemetry: performance metrics, queue usage and per-replica AI consumption, without message content.
- Support: when you write to us, we process your email, subject and query for the periods indicated in §10.
- Logs never include message content or personal data; only metadata are recorded.
23. Impact assessment, records of processing and audits
LiveMemoriesAI maintains the following documentary compliance safeguards:
- Records of processing activities (art. 30 GDPR): an updated inventory of processing operations, purposes, legal bases, periods and processors.
- Data Protection Impact Assessment (art. 35 GDPR): carried out and reviewed periodically, covering at least the risks of emotional vulnerability of users, the processing of third-party materials, voice cloning and minors’ data.
- Audits: continuous internal review and external data protection advice at least every six months.
- Automated isolation and security tests: executed as a merge gate in continuous integration.
- Provider documentation: signed DPAs archived with every processor, and a register of international transfers with their mechanism.
24. Disclaimer on large-scale processing
LiveMemoriesAI processes sensitive materials (conversations, photographs, audio, data of deceased persons) and applies reinforced measures to minimise risk. Nevertheless:
- The volume and heterogeneity of family materials make it impossible to guarantee perfect anonymisation of every living third party. We therefore recommend reviewing uploaded photographs and conversations and using the anonymisation tools available in the materials panel.
- No AI system is error-free. If you detect an anonymisation issue, please report it to contact@livememoriesai.com so it can be corrected and, where appropriate, removed.
- Affected persons have the right to object and request the removal of data concerning them (§5 of the Terms and §3 of this policy).
- Audio already delivered to another person’s device is outside the technical control of the service: we cannot recover or delete it from the platform. That is why we ask for caution when activating cloned voice.
Text legally reviewed on 17 August 2026 (pending external counsel sign-off).
17 August 2026
