Tell Past Me

Effective September 1, 2026

Tell Past Me Privacy Policy

This policy explains how Hartlore LLC collects, uses, shares, and protects information when you use Tell Past Me, Show & Tell Past Me, or Show & Tell Past Me Family.

1. Who we are

Hartlore LLC, a Michigan limited liability company, operates the services described in this policy. In this policy, “we,” “us,” and “our” mean Hartlore LLC. “You” means the person using an account.

2. Information we collect

We collect only information needed to provide, secure, support, and bill for the service:

  • Account information: your email address, display name, authentication status, service selection, and account settings.
  • Memory content: text, voice recordings and transcripts, photos, image descriptions, reminders, tags, dates, people, places, objects, and other details you choose to save or ask about.
  • Family information: household membership, household-local nicknames, invitations, roles, shared memories, and activity attribution.
  • AI information: prompts, authorized memory excerpts, model responses, embeddings used for search, token counts, audio duration, and limited feedback about answer usefulness.
  • Billing information: service, billing interval, subscription status, provider customer and subscription identifiers, transaction status, recurring-billing consent evidence, and limited delivery records for confirmations and required renewal and fee-change notices. Stripe receives and processes payment-card and billing details; we do not store full payment-card numbers.
  • Technical and support information: security events, bounded error details, usage and cost measurements, data-transfer totals, support requests, and email-delivery status. We are designed not to place memory text in ordinary operational logs.

3. How we use information

We use information to authenticate accounts; save, organize, search, explain, export, and delete memories; transcribe audio; understand images; answer questions using authorized memories; provide family spaces; deliver service email; manage subscriptions; prevent abuse; troubleshoot problems; measure reliability and cost; comply with law; and protect users, Hartlore LLC, and the public.

4. AI processing

Memory content and questions may be sent to OpenAI through its business API to classify a request, transcribe audio, understand an image, create search embeddings, or generate an answer grounded in authorized memories. OpenAI states that API inputs and outputs are not used to train its models by default unless the API customer opts in. Its standard abuse-monitoring logs may retain certain API content for up to 30 days, or longer when legally required or reasonably necessary to protect its services or a third party. Different OpenAI-approved data-retention controls may apply if Hartlore LLC becomes eligible for and enables them.

AI output can be incomplete or wrong. We keep your stored memories as the source records and show citations when answering from them. Do not use the service as the sole source for medical, legal, financial, safety-critical, or emergency decisions.

5. Private and family memories

Private memories are associated with the authenticated account that created them. A family owner or administrator cannot read another member’s private memories merely because of that role. Shared family memories are available to authorized active members of that household and are attributed to the account that created them.

Names, display names, family nicknames, and names spoken or written inside a memory never decide authorization or where a memory is stored. Storage follows only the destination you explicitly select. Family nicknames must be unique within a household, but are presentation labels rather than identity credentials.

6. When we share information

We do not sell personal information. We do not use memory content for advertising, and the service does not include third-party advertising trackers. We disclose information only as needed to operate the service, at your direction, in a business transaction, to protect rights and safety, or when lawfully required.

Current service providers include Supabase for authentication, databases, and private object storage; OpenAI for AI processing; Vercel for application hosting and delivery; Resend for service email; Stripe for payments and subscription management; and Cloudflare for domain, network, and related infrastructure. Each provider processes information under its own terms and privacy commitments.

7. Retention and deletion

We retain account and memory information while your account is active and as needed to provide the service. You can delete individual memories and request account deletion from the application. Deletion removes active records and queues associated private media for durable deletion. Unattached uploads expire after one hour. Temporary export files are removed after delivery or failure, and completed private-object cleanup history is removed after seven days.

At launch, deliberate support reports and detailed AI, delivery, export, usage, and cost records are retained for up to 24 months. Application billing-event evidence, recurring-billing consent and acknowledgment evidence, required renewal and fee-change notice records, and company tax-supporting records may be kept for up to seven years. Routine provider runtime logs follow the configured provider limits and ordinarily remain available for no more than seven days. Non-secret recovery rehearsal evidence may be kept for seven years, while encrypted recovery snapshots age out after 35 days. Legal approvals and policy versions may be retained as permanent company records.

A security incident, fraud inquiry, payment dispute, litigation hold, or legal duty may require us to preserve relevant limited records longer. Provider-controlled records, including payment and service-delivery records, also follow the provider’s applicable terms and retention practices. We do not keep memory content merely to extend an operational record’s retention period.

8. Your choices and rights

You can review and edit account settings, edit or delete memories, choose Private or family storage for each save, export personal data, export shared household data when authorized, leave a household, and request account deletion. Depending on where you live, you may also have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information. We may verify your identity before completing a request.

Service emails necessary for authentication, invitations, billing, security, and account administration cannot always be disabled while the related feature is in use. Promotional email, if introduced, will include the legally required opt-out controls.

9. Security

We use access controls, row-level database authorization, private object storage, signed delivery links, encryption in transit and at rest through our providers, restricted credentials, data minimization, and operational monitoring. No online service can guarantee absolute security. Tell us promptly if you believe an account or memory has been accessed improperly.

The service is not end-to-end encrypted because authorized content must be processed by application servers and AI providers to deliver transcription, image understanding, and recall.

10. Children

The service is not intended for children under 13, and children under 13 may not create or use an account. A user may save memories that mention children, but the user is responsible for having the right to provide that information. Contact us if you believe a child under 13 created an account or provided personal information directly.

11. Processing in the United States

Hartlore LLC and its providers operate in the United States and may process information in the United States and other locations where they maintain facilities. Data-protection laws in those locations may differ from those where you live.

12. Changes to this policy

We may update this policy as the service, providers, or law changes. We will post the new version and effective date and provide additional notice when a material change requires it. A material new use of memory content will not be applied retroactively without notice and any consent required by law.

13. Contact

Questions, privacy requests, and security reports may be sent to privacy@tellpastme.com. Please do not include private memory content in an ordinary email unless it is necessary to explain the request.