Politique de confidentialité

Vos conversations restent les vôtres.

Le texte intégral ci-dessous fait foi en anglais

Effective Date: June 1, 2026

Provider: Beautiful ONES Inc., 250 W El Camino Real #1112, Sunnyvale, CA 94087, USA

This Privacy Policy (“Policy”) explains how Beautiful ONES Inc. (“Hemory”, “we”, “us”) handles your Personal Information when you use the Hemory mobile applications, the Apple Watch companion, web consoles, and related services (collectively, the “Services”). We are the data controller. “Personal Information” means information relating to an identified or identifiable individual. By using the Services, you accept the practices described here. If you do not agree, do not use the Services.

If you are a California resident, please also see the California Privacy Rights (CCPA/CPRA) section. If you are in the EEA or the UK, please also see the Your Rights and Cross-Border Data Transfers sections.

1. Information We Collect

Information you provide

  • Account information: email, display name, optional avatar, birth year, and the jurisdiction in which you primarily use the Services. Payment is processed by Apple (or the relevant app store); we do not receive your full payment-card details.
  • Audio recordings that you initiate, and transcripts and derived text generated from them.
  • Voiceprints / biometric identifiers, only if you enable speaker labeling (see the Sensitive & Biometric Information section).
  • Communications information when you contact support.

Information about others

Recordings you submit may contain the personal information or voices of third parties. You are responsible for providing required notices and obtaining required consents before recording (see the Terms of Service, Recording Consent).

Information collected automatically

  • Usage information: timestamps and events (record, edit, delete, share), feature usage, and transaction records.
  • Device information: device identifiers (UUID), IP address, device model, OS, and app version.
  • Semantic vectors derived from your transcripts to power search and the memory graph.
  • Approximate location, inferred from your IP address.
  • Cookies and similar technologies on our web consoles (see the Cookies & Similar Technologies section).

Information from third parties

If you sign in through a third-party identity provider (e.g., Apple, Google), we receive basic profile information such as your name and email. We receive transaction confirmations from the app store.

2. How We Use Your Personal Information

  • To set up and administer your account, in performance of our agreement with you.
  • To provide the Services — recording, transcription, AI Q&A, search, and the memory graph — including, with your consent, transmitting content to third-party LLM providers.
  • To maintain, secure, and improve the Services and develop new features.
  • To communicate with you, including operational messages and, with your consent or where otherwise permitted, marketing communications. You can opt out of marketing emails at any time via the unsubscribe link or by contacting us, and we will give effect to your request promptly.
  • To prevent fraud, enforce our terms, defend legal claims, and comply with legal obligations.

We do NOT use your User Content (audio, transcripts) or your voiceprints/biometric identifiers to train or improve any machine-learning or AI model.

3. Aggregated & De-identified Data

We may create and use aggregated or de-identified data — data that does not identify, and cannot reasonably be used to identify, you — for purposes such as analytics, understanding usage trends, and improving and securing the Services. We maintain such data in de-identified form and do not attempt to re-identify it. For the avoidance of doubt, we do not use your User Content or your voiceprints/biometric identifiers to train or improve any machine-learning or AI model.

4. Cookies & Similar Technologies

On our web consoles we use strictly necessary cookies (for login, authentication, and security), functional cookies (to remember preferences), and limited analytics cookies to operate and improve the Services. You can block cookies through your browser settings, but some features may not function. Our mobile apps do not rely on third-party advertising cookies, and we do not use your content for advertising.

5. With Whom We Share Your Personal Information

We do not sell, and do not “share” (as defined under the CCPA/CPRA), your personal information, including sensitive personal information and biometric information. We share personal information only with:

  • Cloud infrastructure providers, including Amazon Web Services (servers located in the United States), for hosting and storage.
  • Third-party LLM providers — which may include Anthropic, OpenAI, and Microsoft Azure — to which, with your consent, content is transmitted to provide AI features. These providers act as our service providers / processors and are contractually restricted from using your content for their own purposes or for training.
  • Payment processing through Apple or the relevant app store, under their own policies.
  • Identity providers you choose to sign in with (e.g., Apple, Google).
  • Law enforcement, public authorities, or others where legally required, or to protect rights, property, or safety, consistent with applicable law.
  • Acquirers in a merger, acquisition, financing, or sale of assets, subject to this Policy.

6. How Long We Store Your Information

Raw audio is retained by default for a limited period and then permanently (hard) deleted; it is not stored long-term. Transcripts and other User Content are your asset and are retained until you delete them or delete your account. Voiceprints are retained only as long as necessary for speaker labeling and destroyed upon expiry, upon deletion of the related content, or upon account deletion. We retain account and limited records as needed to provide the Services and to comply with law. When we delete Personal Information, we take measures to render it irrecoverable.

7. Your Rights

Subject to applicable law, you may exercise the following rights regarding your Personal Information:

  • Access, correct, delete, and port your Personal Information.
  • Object to or restrict certain processing, and withdraw consent (including for voiceprints and AI processing) at any time.
  • Opt out of any sale or sharing — noting that we do not sell or share your Personal Information.

To exercise your rights, contact privacy@hemory.com. We will verify your identity and respond within the time required by law. We may decline a request where we have a valid legal basis, and will inform you if so. You will not be discriminated against for exercising your rights. If you are a California resident, see the California Privacy Rights (CCPA/CPRA) section below for additional rights and disclosures.

Legal bases (EEA/UK). Where the GDPR or UK GDPR applies, we process your Personal Information on the following legal bases: performance of our contract with you, to provide the Services; your consent (for example, for voiceprints and AI processing, which you may withdraw at any time); and our legitimate interests in securing, maintaining, and improving the Services and preventing fraud, balanced against your rights. If you are in the EEA or the UK, you also have the right to lodge a complaint with your local supervisory authority.

8. California Privacy Rights (CCPA/CPRA)

This section provides additional disclosures for California residents under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”). Terms used here have the meanings given in the CCPA/CPRA.

Categories of personal information we collect

  • Identifiers — email, display name, device identifiers, IP address.
  • Customer records — name and similar account information.
  • Commercial information — subscription and transaction records.
  • Internet or other network activity — usage and event logs.
  • Geolocation — approximate location inferred from IP address.
  • Audio and electronic information — your audio recordings, transcripts, and semantic vectors.
  • Sensitive personal information — account log-in credentials; the contents of your recordings and communications; and, only if you enable speaker labeling, biometric information (voiceprints).

Sources and purposes. We collect this information directly from you, automatically from your use of the Services, and from identity and app-store providers, and we use it for the business and commercial purposes described in this Policy (to provide, secure, and improve the Services; account management; communications; fraud prevention; and legal compliance).

No sale; no sharing. We do not, and in the preceding 12 months did not, sell or “share” (for cross-context behavioral advertising) any personal information, including sensitive personal information. We do not knowingly sell or share the personal information of consumers under 16.

Use of sensitive personal information. We use and disclose sensitive personal information only for purposes permitted under the CCPA/CPRA — namely, to provide the Services and the features you enable. Because our use is already limited to these purposes, the right to limit does not require us to change our practices; you may nonetheless contact us with any request.

Your California rights

  • Right to know and access the personal information we have collected.
  • Right to delete and right to correct your personal information.
  • Right to opt out of the sale or sharing of personal information (not applicable, as we do not sell or share).
  • Right to limit the use and disclosure of sensitive personal information.
  • Right to non-discrimination for exercising your rights.

Opt-out preference signals. Because we do not sell or share personal information, no opt-out is necessary; where applicable, we honor Global Privacy Control (GPC) and similar browser opt-out preference signals on our web consoles.

How to exercise. Submit requests to privacy@hemory.com. We will verify your identity and respond within 45 days (extendable by an additional 45 days with notice). You may use an authorized agent who provides proof of authorization. If we deny a request, you may appeal by contacting privacy@hemory.com. Under California Civil Code § 1798.83 (“Shine the Light”), we do not disclose personal information to third parties for their own direct-marketing purposes.

9. Sensitive & Biometric Information

Audio recordings, transcripts, and voiceprints may constitute sensitive personal information. Voiceprints are created only if you enable speaker labeling, only after your explicit, informed consent, and are used solely for internal speaker recognition within your own content. We do not sell, share, or disclose voiceprints to third parties except as strictly necessary to provide the feature or as required by law, and we do not use them for training. We maintain a written retention and destruction schedule for biometric identifiers.

10. Children

The Services are not directed to children, and we do not knowingly collect Personal Information from children under 13. If you believe a child has provided us Personal Information, please contact privacy@hemory.com.

11. Cross-Border Data Transfers

We are based in the United States, and the Services are operated from the United States. If you access the Services from outside the United States, you understand that your Personal Information may be transferred to, stored, and processed in the United States, where data-protection laws may differ from those of your country. Where required by applicable law, we implement appropriate safeguards to protect your Personal Information in connection with such transfers.

The Services may link to or interoperate with third-party services (such as identity providers and app stores). Information you provide directly to a third party, or that you access through a third-party service, is governed by that third party’s privacy policy, not this Policy. We are not responsible for the privacy practices of third parties, and we encourage you to review their policies.

13. Data Security

We implement physical, administrative, and technical safeguards designed to protect Personal Information, including transport encryption (HTTPS / TLS 1.2+), storage of iOS credentials in the Keychain, AES-256-GCM encryption for DPU backups, and a local-first storage design. No method of transmission or storage is completely secure, and we cannot guarantee absolute security; you transfer information at your own risk.

14. Contact & Complaints

For questions or complaints about this Policy or to exercise your rights, contact privacy@hemory.com (Attn: Privacy Officer) or write to Beautiful ONES Inc., Attn: Privacy Officer, 250 W El Camino Real #1112, Sunnyvale, CA 94087, USA. If you are in the EEA or the UK, you may also lodge a complaint with your local supervisory authority. This is without prejudice to any other rights you may have.

15. Changes

We may update this Policy from time to time. When we do, we will post the updated Policy here and indicate the latest revision date. Please check this page periodically.