MemGlow Privacy Policy

Publication Date
Effective Date

1. Scope and Important Notice

This Privacy Policy applies to the MemGlow iOS application and related services operated by Intellisant Inc. ("we," "us," or "our").

MemGlow is intended for older adults and caregivers and provides account management, linking between older adults and caregivers, personal memory recording, reminders, AI companion conversations, and photo memory features. Because these features may involve photos, speech-to-text transcripts, and other sensitive personal information, please read this Policy carefully before using the Services.

Before entering, uploading, or viewing information on behalf of an older adult, a caregiver must ensure that valid authorization has been obtained from the older adult or the older adult's guardian or legal representative. If an older adult lacks or has limited civil capacity, the older adult's guardian or legal representative must decide whether to use and assist with the use of the Services.

2. How We Collect and Use Personal Information

We follow the principles of lawfulness, fairness, necessity, good faith, and purpose limitation, and process personal information only to the extent necessary for the purposes described below.

2.1 Registration, Login, and Account Security

To create and maintain accounts, send verification codes, complete login, recover passwords, distinguish between older adult and caregiver roles, and protect account security, we may process:

If you refuse to provide information necessary for registration and login, you will be unable to create an account or use core features that depend on an account.

2.2 Linking Older Adults and Caregivers

To establish and maintain a caregiving relationship and allow caregivers to assist older adults within the scope of authorization, we may process:

Caregivers may access and maintain an older adult's information only within the scope authorized by the older adult or the older adult's guardian or legal representative.

2.3 Basic Profile and Personal Memories of Older Adults

To provide personalized memory assistance, information review, and AI companionship, we may process information voluntarily entered by a user or provided by an authorized caregiver, including:

2.4 AI Companion Chat, Memory Collection, and Voice Input

To provide text chat, speech-to-text, context-aware conversations, and memory collection, we may process:

When a user voluntarily enables voice input, the App requests microphone and speech recognition permissions. Audio is processed using the iOS system speech recognition capability.

AI output is generated automatically by a model and may be inaccurate, incomplete, or unsuitable for a particular individual. Do not enter identification numbers, bank card information, precise addresses, account passwords, or other unnecessary sensitive information unrelated to the feature in chat.

2.5 Photos and Photo Memories

When a user voluntarily selects a photo, the App requests photo access permission and may process:

Granting photo permission does not cause the App to upload the entire photo library automatically. We process only photos voluntarily selected by the user. Users may decline photo permission and continue using features that do not depend on photos.

2.6 Reminders, Activity Status, and Push Notifications

To create and display activity or daily-life reminders and synchronize completion status with older adults or caregivers, we may process:

Push notification permission is not a prerequisite for using other core features. Users can disable notifications in iOS under Settings - Notifications - MemGlow, but may then be unable to receive reminders promptly.

2.7 Local Storage

To maintain login status, save device preferences, and improve the user experience, the App may store the following in Keychain, UserDefaults, or the App cache directory on the device:

After account deletion is completed, the App clears local authentication information, business data caches, notifications, and photo caches associated with the account. Device-level preferences such as language and speech rate may be retained. Signing out does not delete business preferences stored on the device or data stored on the server.

3. Device Permissions

1. Microphone: Audio is collected only when the user actively uses voice input and is used for speech-to-text. Refusing permission does not affect text input.

2. Speech Recognition: Converts the user's speech into text. Refusing permission does not affect text chat.

3. Photos: Used only when the user actively selects and uploads a photo. Refusing permission does not affect non-photo features.

4. Notifications: Used for activity reminders, status notifications, and other necessary service messages. Refusing permission does not affect login or features that do not depend on notifications.

Users may disable the relevant permissions at any time in iOS Settings. Disabling a permission does not affect processing already completed under valid authorization before the permission was disabled, but the corresponding feature may no longer be available.

4. How We Entrust Processing, Share, Transfer, and Publicly Disclose Personal Information

4.1 Entrusted Processing and Sharing

To provide the Services, we may provide recipients listed below with information necessary to implement the relevant features:

(1) Apple

Apple's own rules and system settings apply to its processing of relevant data.

(2) Entrusted Infrastructure Service Providers

These providers support the transmission, storage, and processing of accounts, links, reminders, chats, images, and memories. Production databases, image and file object storage, backups, logs, monitoring, alerts, and security protection use Tencent Cloud resources primarily deployed in California, United States.

(3) AI and Memory Processing

Chat, memory retrieval, memory writing, and photo conversation requests from the client are sent uniformly to services we deploy on Tencent Cloud. We send chat text, speech-to-text transcripts, conversation context, stored personal memories, photos, or photo URLs to AI models after applying de-identification or data minimization. AI inputs, outputs, prompts, and error logs are retained for 7 days.

(4) Verification Code, Email, Log Monitoring, and Similar Service Providers

We use Zoho Mail to send email verification codes. To complete delivery, we provide the service with the recipient's email address and the verification email content. Verification codes and verification records are retained for 10 minutes.

4.2 Transfer

As a general rule, we do not transfer personal information. If a merger, division, restructuring, asset transfer, or similar transaction involves a transfer of personal information, we will inform users of the recipient's name and contact details as required by law and require the recipient to remain bound by this Policy. If the recipient changes the original purpose or method of processing, it must obtain consent again as required by law.

4.3 Public Disclosure

As a general rule, we do not publicly disclose personal information. If public disclosure is necessary, we will inform users of the purpose of the disclosure, the types of information involved, and the possible impact, and obtain separate consent as required by law, unless otherwise provided by law.

4.4 Circumstances Where Separate Consent Is Not Required

To the extent permitted by applicable law, we may process necessary personal information without separate consent where such processing is necessary to enter into or perform a contract to which the user is a party, fulfill legal obligations, protect the life or property of natural persons, or in other circumstances provided by law.

5. Storage Location and Retention Period of Personal Information

5.1 Storage Location

Production databases, object storage, logs, and backups are primarily stored on Tencent Cloud resources in California, United States.

5.2 Cross-Border Data Transfer

The user acknowledges and agrees that, as necessary to provide the Services, user information may be transmitted through encrypted channels to and stored on servers in the United States, including Tencent Cloud resources located in California, United States. The user has the right to lawfully withdraw the relevant consent. Withdrawal does not affect processing already carried out on the basis of valid authorization before the withdrawal. Sections 4, 5, and 7 of this Policy govern the specific transmission methods, recipients, storage locations, and user rights.

5.3 Retention Period

We retain personal information only for the shortest period necessary to achieve the purposes described in this Policy, unless otherwise required by law.

After the applicable retention period expires, we will delete or anonymize the relevant personal information.

6. How We Protect Personal Information

We take security measures appropriate to the risks of processing, including access controls, identity authentication, transmission safeguards, secure storage of sensitive information, permission separation, log auditing, backup and recovery, and security incident response, to prevent unauthorized access, disclosure, alteration, loss, or misuse.

We transmit user information through HTTPS/TLS encrypted channels, including account information, linking information, reminders, chat text, speech-to-text transcripts, photos, and memory information. When user information is transmitted to entrusted service providers, we also apply transmission safeguards appropriate to the processing risks. Internet transmission and electronic storage cannot be guaranteed to be absolutely secure. If personal information is or may be disclosed, altered, or lost, we will take remedial measures as required by law and notify the relevant authorities and affected users as legally required.

Users must properly safeguard their accounts, passwords, and verification codes and must not allow persons without authorization to access an older adult's information through their accounts.

7. How Users Can Manage Personal Information

To the extent provided by law, users may exercise the rights to be informed, make decisions, restrict or object to processing, access, copy, correct, supplement, delete, withdraw consent, delete an account, and request an explanation of this Policy.

7.1 Access and Correction

Users can access or modify certain account information, older adult profiles, memories, and reminders through the settings, profile, and collected information pages in the App. For requests that cannot be completed within the App, users may contact us using the details in Section 11 of this Policy.

7.2 Withdrawal of Permission or Consent

Users can disable microphone, speech recognition, photo, or notification permissions in iOS Settings. The App displays a Privacy Policy consent page on first use. The login and registration pages also provide links to the Privacy Policy and User Agreement and require confirmation by checkbox. Withdrawal of consent does not affect processing already carried out on the basis of valid consent before withdrawal.

To withdraw consent to cross-border data transfer, users may submit a request using the contact details in Section 11 of this Policy. After withdrawal, networked features that depend on the relevant data transfer may no longer be available, but other features that do not depend on the relevant processing will not be affected.

7.3 Deletion of Content

Users can delete certain reminders and memory information through the edit or delete controls provided by the App. To request deletion of chats, photos, or other data that cannot be deleted within the App, users may contact us using the details in Section 11 of this Policy.

7.4 Account Deletion

Users can initiate permanent account deletion under Settings - Delete Account in either the older adult or caregiver experience. Account deletion is different from signing out. Once account deletion is completed, we will delete the account and associated personal information that we are not legally required to retain and invalidate the login token.

An account deletion request is expected to be completed within 1 minute after submission and cannot be withdrawn after submission. Upon completion, the page displays a deletion success message, and the login, session, and push tokens are invalidated immediately.

If an older adult and caregiver are linked, account deletion will affect both parties' continued access to the relevant information.

7.5 Responding to Requests

To protect account security, we may require verification of the requester's identity. We will respond within the time limit required by law. If a request involves the rights of others, trade secrets, compliance with legal obligations, or other exceptions provided by law, we may be unable to fulfill it completely and will explain the reason as required by law.

8. Special Responsibilities of Older Adults, Caregivers, and Representatives

1. A caregiver must confirm that they are authorized to represent or assist an older adult in using the Services and must not enter, upload, modify, or delete the older adult's information without authorization.

2. If an older adult lacks or has limited civil capacity, a guardian or legal representative must read and agree to this Policy and manage the account, authorization, and data rights requests.

3. If multiple caregivers assist the same older adult, each caregiver must access information only within the scope of their authorization and must not copy, distribute, or use it for any other purpose without authorization.

4. If a representative exercises rights such as access, correction, deletion, or account deletion on another person's behalf, we may require proof of identity and authority and will process only the information necessary for verification.

9. Protection of Minors

The Services are not specifically designed for minors under 14 years of age. A minor under 14 may use the Services only after a parent or other guardian has read and agreed to this Policy and provided separate guardian consent as required by law.

If we discover that we have processed the personal information of a minor under 14 without valid guardian consent, we will delete it as soon as reasonably practicable or take other necessary measures in accordance with law.

10. Updates to This Policy

We may update this Policy in response to changes in features, processing activities, or legal requirements. If there is a material change to the purpose or method of processing, the types of personal information, third-party recipients, or user rights, we will provide notice through an in-app pop-up, page notice, or other prominent means and obtain consent again where required by law.

We will not reduce users' rights under this Policy and applicable law without their consent.

11. Contact Us

Personal Information Processor: Intellisant Inc.

Registered Address: Pearland, Texas, United States

Privacy, Customer Service, and Appeals Department: Customer Support

Email: contact@intellisant-ai.com

Telephone: +1 (281) 905-5260

For questions, comments, or complaints about this Policy, our processing of personal information, or rights requests, users may contact us using the details above. After receiving a request and completing necessary identity verification, we will process and respond within the time limit required by applicable law.

If a user is dissatisfied with our response, the user may also file a complaint with the competent personal information protection, cybersecurity, communications, market regulation, or other authority, or seek other remedies in accordance with law.

12. Other Provisions

Matters not covered by this Policy are governed by the MemGlow User Agreement and applicable laws and regulations. If this Privacy Policy and the User Agreement contain inconsistent provisions regarding personal information processing, the provision that better protects the user's personal information rights and complies with applicable law will prevail.