Beta

Privacy Policy

Last Updated: January 23, 2026

About This Policy

Heritage Whisper LLC ("we," "us," or "our") operates HeritageWhisper.com, a mobile application that helps families preserve and share life stories through AI-powered voice interviews. This Privacy Policy explains how we collect, use, store, and share your personal information.

By using HeritageWhisper, you agree to this Privacy Policy. If you disagree with any part of this policy, do not use our service.

Questions? Contact us at privacy@heritagewhisper.com

Quick Summary

  • What we collect: Name, email, birth year, voice recordings, photos, and story content you provide.
  • How we use it: To transcribe your stories, generate AI insights, create timelines, and enable family sharing.
  • Who we share with: OpenAI & AssemblyAI (transcription/AI), Stripe (payments), Supabase (storage), Resend (emails), Google Analytics (public website only). We never sell your data.
  • Your rights: You own your recordings. You can download your entire archive as a self-contained website, edit, or delete everything at any time.
  • AI processing: Your stories are processed by AI but never used to train AI models.

Want a simpler version? Check out our one-page summary with the most important points.

📄 View Privacy at a Glance

Your Security & Control

We protect your stories with:

  • Bank-level 256-bit encryption for all data in transit and at rest
  • Private by default - you choose who sees each story
  • Automatic removal of location data from all recordings
  • Download your entire archive as a self-contained website you can view offline forever
  • Complete deletion rights - no questions asked

We promise:

  • Never sell or share your data
  • No third-party advertising or cross-site tracking (Google Analytics only on public website, not inside your account)
  • Your family's stories stay in your family

Table of Contents

  1. What Information We Collect
  2. How We Use Your Information
  3. Who We Share Your Information With
  4. AI Processing and Voice Recordings
  5. Pearl AI Interviewer
  6. Content Ownership and Your Rights
  7. Family Sharing and Collaboration
  8. Data Security
  9. Data Retention and Deletion
  10. What Happens to Your Account
  11. Children's Privacy
  12. Cookies and Tracking
  13. California Privacy Rights
  14. International Users
  15. Changes to This Policy
  16. Contact Us
  17. How to Exercise Your Rights

1. What Information We Collect

Information You Provide Directly

Account Information:

  • Name
  • Email address
  • Password (encrypted)
  • Birth year (for timeline generation)
  • Profile photo (optional)

Biometric Login Data (if using Touch ID/Face ID):

  • Device type (phone, computer, security key)
  • Authentication method (fingerprint, face recognition, PIN)
  • Important: We only store verification tokens, NOT your actual fingerprint or face data

Story Content:

  • Voice recordings
  • Photos you upload
  • Story titles and descriptions
  • Emotion tags and metadata
  • Any text you write or edit

Memory Box Items:

  • Photos of heirlooms, documents, and keepsakes
  • Recipes and places you want to remember
  • Categories and year information

Payment Information:

  • Billing address
  • Payment card details (processed and stored by Stripe, not by us)

Social Login Data:

  • If you sign in with Google: name, email, profile photo

Collaborative Account Information:

  • Names and emails of family members you invite as collaborators
  • Permission levels assigned to each collaborator
  • Stories, photos, and recordings uploaded by collaborators
  • Activity logs showing who added/edited what content

Information Collected Automatically

Usage Data:

  • Pages visited and features used
  • Date/time stamps of activity
  • Device type, browser, operating system
  • IP address (used for security, fraud prevention, and approximate location - city/state level only)

Technical Data:

  • Session information
  • Error reports and crash logs
  • Performance metrics

Information We Do NOT Collect

  • Social Security Numbers
  • Driver's license numbers
  • Precise GPS location
  • Health/medical records (unless you choose to include them in your stories)
  • Financial account numbers (beyond what Stripe processes)

2. How We Use Your Information

We use your information to:

Provide Core Services:

  • Transcribe voice recordings using AI
  • Generate personalized follow-up questions
  • Create timeline and book views
  • Enable story sharing with family

Manage Your Account:

  • Create and authenticate your login
  • Process subscription payments
  • Send service-related emails (receipts, confirmations, password resets)
  • Provide customer support

Improve Our Service:

  • Analyze usage patterns to fix bugs
  • Develop new features
  • Monitor system performance and security

Legal Compliance:

  • Prevent fraud and abuse
  • Comply with legal obligations
  • Protect our rights and safety

We do NOT use your information to:

  • Train AI models (your stories remain private)
  • Sell or rent to third parties
  • Send marketing emails (unless you opt in)
  • Track you across other websites

3. Who We Share Your Information With

Service Providers We Use

OpenAI (transcription and AI analysis)

  • Purpose: Convert speech to text, generate follow-up questions, extract themes
  • Data shared: Voice recordings, story text
  • Privacy policy: https://openai.com/privacy

AssemblyAI (alternative transcription service)

Stripe (payment processing)

Supabase (authentication and storage)

Resend (transactional emails)

Google Analytics (public website only)

  • Purpose: Understand how visitors find our website so we can improve it
  • Data shared: Anonymous usage data (which pages you visit, how long you stay, what device you use)
  • Important: Only active on our public landing pages—NOT inside your personal account, stories, or timeline
  • Your control: You can disable this in your browser settings (see Section 12)
  • Privacy policy: https://policies.google.com/privacy

Infrastructure Providers

Vercel (website hosting)

  • Purpose: Provides the servers and infrastructure that run HeritageWhisper
  • Data shared: All data passes through their servers, but they do not access, use, or store your personal information
  • Privacy policy: https://vercel.com/legal/privacy-policy

When We Share Your Story Content

  • With family members you explicitly authorize through our sharing features. You control who sees what.
  • With legal authorities if required by valid legal process (subpoena, court order).
  • In a business transfer if we're acquired or merged, but only under equivalent privacy protections.

What We NEVER Do

  • Sell your personal information to anyone
  • Share your stories publicly without your permission
  • Use your content for advertising or marketing
  • Provide your data to data brokers

4. AI Processing and Voice Recordings

How AI Works in HeritageWhisper

Transcription:

  • Your voice recordings are sent to AssemblyAI or OpenAI's Whisper API for transcription
  • Audio is converted to text
  • Audio files are processed in real-time and not permanently stored by AI providers

Content Analysis:

Story text is analyzed by GPT-4 to:

  • Generate personalized follow-up questions based on what you said
  • Create suggested prompts

Personalized Prompts:

We use AI to suggest story prompts tailored to you:

  • AI analyzes your previous stories to understand your life timeline
  • Prompts are personalized based on your age and experiences
  • You can skip any prompt—there's no pressure to answer
  • Past prompts are saved so you can revisit skipped questions

Your AI Content Rights

You retain full control:

  • Edit or delete any AI-generated content
  • Regenerate questions or insights

We guarantee:

  • Your stories are NEVER used to train AI models
  • OpenAI processes data per their enterprise terms (no training on customer data)
  • AI-generated insights are suggestions only—you decide what's accurate

Data protection:

  • All API calls are encrypted
  • No audio is permanently stored by AI providers
  • Processing is real-time and ephemeral

🔒 Your Stories Stay Private

We NEVER use your stories, photos, or voice recordings to train AI models.

When we send your recordings to OpenAI or AssemblyAI for transcription, they process your audio and return the text, but they do not keep your recordings or use them for training their AI systems. Your family memories belong to you alone, and we have agreements with our AI providers to ensure this.

4a. Pearl AI Interviewer (Coming Soon)

Pearl is our AI interviewer who helps you tell your stories through conversation.

How Pearl Works:

  • You have a spoken conversation with Pearl about your memories
  • The full conversation is recorded and saved to your account
  • Pearl helps identify story moments you can save
  • You control which parts of the interview become permanent stories

What We Collect:

  • Full audio of your interview sessions
  • Transcripts of the conversation
  • Story moments detected during the interview

Your Control: You can delete any interview session or individual story at any time.

5. Content Ownership and Your Rights

You Own Your Content

  • Full ownership: You retain complete copyright and ownership of all voice recordings, stories, photos, and text you create.
  • Our limited license: You grant us permission to:
    • Store and process your content to provide our services
    • Display your content to family members you authorize
    • Create backups for data protection
  • Data portability: At any time, you can:
    • Download all your recordings (original audio files)
    • Export transcriptions as text files
    • Save photos and metadata
    • Delete individual stories or your entire account

No hidden claims: HeritageWhisper claims zero ownership rights to your content. When you delete content, we delete it (except for temporary backups, see Section 8).

Archive Downloads — Your Digital Heirloom

Most platforms give you messy technical files or hold your data hostage. We believe in Digital Sovereignty—your stories belong to you, forever.

What you get when you download:

  • A self-contained website that works in any browser—no internet required
  • Your beautiful timeline and book view, exactly as you see it in the app
  • All your audio recordings in organized folders
  • All your photos and transcriptions
  • Simply double-click to open your family's history, anytime in the future

How it works:

  • Request your archive from Settings
  • Receive a secure download link via email
  • Download link valid for 7 days
  • Archive files automatically deleted from our servers after 48 hours for your security
  • Generate a new archive anytime (limit: 1 per day)

No cloud dependency, no subscription required to view, no expiration date. Your legacy is truly yours to keep.

6. Family Sharing and Collaboration

Default Privacy

All stories are private by default. Nobody can access your content unless you explicitly grant permission.

Permission Levels

👁 Viewer (Free & Premium):

  • Can view and listen to stories you've shared
  • Can see photos in your timeline and book
  • Cannot add, edit, or delete any content
  • Cannot invite other users

✏️ Contributor (Premium):

  • Everything a Viewer can do
  • Plus: Can submit questions they'd like you to answer
  • Their questions appear in your prompts list
  • Cannot add stories, photos, or recordings themselves
  • Cannot edit or delete your content
  • Cannot change account settings or billing

Account Owner (You):

  • Full control over all content
  • Can add/remove collaborators
  • Can change permission levels
  • Can edit or delete any story
  • Controls billing and account settings

How Family Sharing Works

When you invite a family member:

  • They receive an email invitation with a secure access link
  • They can view your stories without creating an account
  • If you set them as "Contributor," they can submit questions for you to answer
  • All stories remain yours—family members cannot add or edit content

Content control and privacy:

  • You own and control all stories, photos, and recordings
  • Family members see only what you've explicitly shared
  • You can change permission levels or remove access at any time
  • If you delete your account, all shared access is immediately revoked

Managing Family Access

You can:

  • Change family members from Viewer to Contributor (or vice versa)
  • Remove any family member's access at any time
  • See when family members view your stories
  • See which family member submitted each question
  • Control email notifications for your family members

👥 What Family Members Can See

You (account owner) can see:

  • All your own stories, photos, and recordings
  • Which family members have access
  • Questions submitted by Contributors
  • When family members view your stories

Family members can see:

  • Only the stories you've shared with them
  • Your name (as the storyteller)
  • Not other family members' information
  • Not your email, password, or account details

We NEVER share with family members:

  • Your password or login credentials
  • Your payment or billing information
  • Other family members' email addresses
  • Support conversations with us

7. Data Security

How We Protect Your Information

Encryption:

  • All data encrypted when traveling over the internet (like your banking website uses)
  • Files encrypted in storage (protected even when not in use)
  • Passwords protected with industry-standard encryption

Access controls:

  • Role-based permissions
  • Multi-factor authentication available
  • Regular security audits

Infrastructure:

  • Hosted on secure cloud platforms (Vercel, Render, Supabase)
  • Automated backups
  • DDoS protection

What We Cannot Guarantee

Like all online services, we can't guarantee 100% security. While we use industry-standard protections and monitor 24/7, we cannot guarantee absolute protection against:

  • Extremely rare security breaches (we monitor constantly to prevent these)
  • Someone gaining unauthorized access to systems beyond our control
  • Security issues with your personal devices

You should:

  • Use a strong, unique password
  • Enable two-factor authentication
  • Keep your devices secure
  • Log out on shared devices

Data Breach Notification

If we discover a breach affecting your personal information, we will:

  • Notify you promptly via email
  • Explain what happened and what data was affected
  • Describe what we're doing to fix it
  • Provide guidance on protecting yourself

8. Data Retention and Deletion

How Long We Keep Your Information

We keep different types of information for different periods:

  • Stories, photos, and voice recordings: Forever, unless you delete them (we never automatically delete your memories)
  • Account information: Until you delete your account
  • Payment history: 7 years (required by tax and accounting laws)
  • Support tickets: 3 years
  • Usage logs: 2 years
  • Google Analytics data: 26 months (on public pages only)

After You Delete Your Account

Immediate deletion:

  • Your account is deactivated immediately
  • You lose access to all content

30-day grace period:

  • Backups are fully purged after 30 days
  • During this time, you can contact us to restore your account

Exception - Deceased Users:

  • Accounts of deceased users are preserved for 5 years to allow family members to claim access (see Section 10)
  • After 5 years, content is permanently deleted unless family has claimed it

Legal Retention

We may retain some information longer if required by:

  • Law enforcement requests
  • Pending litigation
  • Tax/accounting regulations (transaction records only)

What we keep:

  • Payment history: 7 years (IRS requirement)
  • Support tickets: 3 years
  • Fraud investigations: As needed

9. What Happens to Your Account

Keeping Your Stories Safe

Your stories are precious family memories. Here's how we protect them:

  • We never delete your stories automatically. Even if your subscription ends, your content stays safe.
  • Download anytime. You can download all your recordings, photos, and transcriptions at any time.
  • Share with family. Invite family members to view your stories—they'll keep access even if something happens to you. For detailed legacy planning, contact privacy@heritagewhisper.com.

Account Closure

If you decide to close your account or if we need to close an inactive account:

  • We'll send you an email notification before any closure
  • You'll have time to download everything before deletion
  • Once deleted, your stories are permanently removed and cannot be recovered

💡 Tip: Make sure your family members have access to your stories while you're alive. That way, your memories are preserved even if something happens to your account.

10. Children's Privacy

Age Restrictions

  • Under 13: We do not knowingly collect information from children under 13. If we discover we've collected such information, we will delete it immediately.
  • Ages 13-17: Minors aged 13-17 may use HeritageWhisper only with verifiable parental consent. Parents must create the account and maintain control.

If You're a Parent

If you believe your child under 13 has provided information to us, contact privacy@heritagewhisper.com immediately and we will delete it.

11. Cookies and Tracking

Cookies We Use

Essential cookies (required for service to work):

  • Session authentication (keeps you logged in)
  • Security tokens (protects your account)
  • User preferences (remembers your settings)

Analytics cookies (optional, you can disable):

Google Analytics - Only on our public landing pages (heritagewhisper.com home page). This helps us understand how people find our website.

  • Tracks which pages visitors view before signing up
  • Shows us what devices people use (phone, tablet, computer)
  • Tells us which cities/states visitors come from (not specific addresses)

Important: Google Analytics is NOT active inside your personal account. We don't track what you do with your stories, photos, or timeline.

We Do NOT Use

  • Third-party advertising cookies (Google Analytics doesn't share your data for ads)
  • Cross-site tracking (we don't follow you around the internet)
  • Social media tracking pixels (no Facebook, Twitter, etc.)
  • Behavioral targeting (we don't build profiles to sell to advertisers)

How to Control Cookies

Browser settings: Most browsers let you:

  • Block all cookies
  • Delete existing cookies
  • Get warnings before cookies are set

Impact of blocking: If you block essential cookies, you won't be able to log in or use core features.

"Do Not Track" & "Global Privacy Control" Browser Settings

Some web browsers have privacy settings called "Do Not Track" (DNT) or "Global Privacy Control" (GPC). These tell websites you don't want to be tracked or have your data shared for advertising.

We respect both settings. If your browser sends a DNT or GPC signal, we automatically disable Google Analytics on our public pages. Your stories and personal timeline are never tracked regardless of these settings.

How to enable GPC: Many modern browsers like Firefox, Brave, and DuckDuckGo have built-in GPC support in their privacy settings.

12. California Privacy Rights

Your California Rights (CCPA/CPRA)

Do Not Sell or Share My Personal Information

We do not "sell" your personal information as that term is defined under California law.

However, we use Google Analytics on our public landing pages, which may be considered "sharing" for advertising purposes under California law (even though we don't allow Google to use your data for ads).

To opt out: Enable Global Privacy Control (GPC) in your browser, or email us at privacy@heritagewhisper.com

California residents have specific rights regarding personal information:

  • Right to Know: Request details about personal information we've collected in the past 12 months
  • Right to Delete: Request deletion of your personal information
  • Right to Correct: Fix inaccuracies in your data
  • Right to Opt-Out: We don't sell or share for advertising, so nothing to opt out of
  • Right to Non-Discrimination: We won't treat you differently for exercising your rights
  • Right to Limit Sensitive Data Use: Request we only use sensitive information for essential services

What Personal Information We Collect (Last 12 Months)

We collect:

  • Identifiers: Name, email, account ID
  • Personal records: Birth year, billing address
  • Age information: Derived from birth year
  • Subscription info: Payment history, subscription status
  • Website activity: Pages visited (public landing pages only via Google Analytics)
  • General location: City/state from IP address
  • Your stories: Voice recordings, photos, story text

We do NOT collect: Professional or employment information, education records, or create inferred profiles about you.

How to Exercise California Rights

Request form: Email privacy@heritagewhisper.com with subject "California Privacy Request"

Include:

  • Your full name
  • Account email address
  • Specific request (access, delete, correct)
  • Verification info (we'll confirm your identity)
  • Response time: We'll respond within 45 days (may extend to 90 for complex requests)
  • Authorized agents: You may designate someone to make requests on your behalf (requires written authorization)

California "Shine the Light" Law

Once per year, California residents can request a list of third parties we've shared personal information with for their direct marketing. We don't share for marketing purposes, so this list will be empty.

13. International Users

HeritageWhisper is operated from the United States for US customers. All data is stored on US-based servers and governed by US privacy laws.

We do not currently offer services to residents of the European Union or United Kingdom. If you use our service from outside the US, your data will be stored in the US and US privacy laws will apply.

14. Changes to This Policy

When We Update This Policy

We may update this Privacy Policy to:

  • Reflect new features or services
  • Comply with new laws
  • Improve clarity

We will notify you of material changes by:

  • Email to your registered address
  • Prominent notice on our website
  • Update to "Last Updated" date at top of policy

Your continued use of HeritageWhisper after changes constitutes acceptance of the updated policy.

If you disagree with changes, you must stop using the service and may request account deletion.

15. Contact Us

Privacy questions or concerns:

Email: privacy@heritagewhisper.com

Mail: Heritage Whisper LLC, 522 W Riverside Ave, Suite N, Spokane, WA 99201, United States

Customer support:

Email: support@heritagewhisper.com

We respond to privacy inquiries within 5 business days.

16. How to Exercise Your Rights

You can access, correct, or delete your data at any time:

📋 Three Ways to Request Your Data:

1. Online (fastest):

  • Log into your account
  • Go to Settings → Privacy
  • Request data download, corrections, or deletion

2. Email:

Send to privacy@heritagewhisper.com with:

  • Subject: "Privacy Rights Request"
  • Your name and account email
  • What you need (access/correct/delete)

3. Mail:

Heritage Whisper LLC, 522 W Riverside Ave, Suite N, Spokane, WA 99201

Response Time

We'll respond within 30-45 days. For online requests through your account, you'll get immediate access to download your data.

No Charge

We don't charge for reasonable requests. It's your data—you should have it.

Document Version Control

Version 1.0: October 4, 2025 (Initial publication)

Version 1.1: October 30, 2025 (Simplified to focus on legal requirements)

Version 1.2: January 23, 2026 (Added AssemblyAI, Google Analytics, and Vercel disclosures; added AI training disclaimer; added GPC support and CCPA sharing opt-out; corrected family collaboration feature descriptions to match actual implementation; replaced legacy access section with account closure information; added specific data retention periods; added Memory Box, biometric login data, Pearl AI interviewer, personalized prompts, and archive export disclosures; clarified IP address usage; simplified technical language (encryption, security warnings); removed redundant sections; improved senior-friendly language throughout)

Effective Date: January 23, 2026

Heritage Whisper LLC reserves the right to update this document. Check the "Last Updated" date at the top for the most current version.

    Privacy Policy | HeritageWhisper