Privacy Policy
1. Introduction
This policy explains how Remea, LLC ("Remea," "we," "us," or "our") collects, uses, discloses, and protects information through the Remea Ecosystem (the "Service"). It applies to our website, mobile applications, and all related features, including the Generational Tree, Secure Vault, Ecosystem Feed, and Hardware Enclave.
Data Controller: For purposes of the EU General Data Protection Regulation ("GDPR"), Remea, LLC, located at Johns Creek, Georgia, USA, is the data controller responsible for your personal information collected through the Service.
2. Information We Collect
- Identity Data: Name, email, password, and generational relationships you create within the Ecosystem.
- Device & Analytics Data: We collect technical system information about the devices you use and information about how you use the Service, including approximate or precise location where a Spatial Memory Anchor feature is used.
- Financial Data: Processed entirely by Stripe (we do not store or process full credit card numbers).
- Vault Data: Photos, encrypted documents, biometric authentication markers used solely for on-device Hardware Enclave access, and memories uploaded to your timeline and Secure Vault.
- Children's Data: See Section 4 below for a complete, separate description of what is collected about minors and how.
3. Data Retention and Sharing
We keep personal information for as long as reasonably necessary to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements, as further described in Section 9 below.
- Sub-Processors: We share information, under strict contractual restrictions, with the following categories of service providers: secure backend hosting and database infrastructure (Supabase, Inc. — privacy policy), payment facilitation (Stripe, Inc. — privacy policy), and AI model processing used to power memory prompts and ecosystem features.
- No Sale of Data: We do not sell any personal information, as defined under laws such as the California Consumer Privacy Act (CCPA).
- International Data Transfers: Our service providers may process personal data in the United States and other countries outside the European Economic Area ("EEA"), United Kingdom, or Switzerland. Where this occurs, we rely on appropriate safeguards recognized under GDPR, including Standard Contractual Clauses approved by the European Commission, to ensure your data receives an equivalent level of protection.
4. Children's Privacy (COPPA)
United States · COPPARemea is designed for use by adults who may, at their discretion, create and manage records on behalf of a minor dependent (a "Dependent Vault"). Remea does not permit children under 13 to independently register their own account, and we do not knowingly collect personal information directly from a child under 13 through self-service registration.
4.1 How Children's Data Is Actually Collected
Where a Dependent Vault exists, all information about the minor is entered exclusively by the adult account holder acting as the Vault Custodian. The Custodian's creation of a Dependent Vault, and acceptance of these Terms and this Privacy Policy at the time of account registration, constitutes the verifiable parental consent required under COPPA for any subsequent collection of the minor's information through that Custodian's account. We record the date of this consent and the identity of the consenting Custodian in our systems.
4.2 What Information We Collect About Children
Depending on how a Custodian chooses to use the Service, the following categories of information may be collected about a minor:
- Identity information: first and last name, date of birth, and family relationship to the Custodian and other Ecosystem members.
- Media: photographs, videos, or documents the Custodian uploads to the minor's record within the Vault or Generational Tree.
- Written content: memories, dispatches, or messages the Custodian authors and attributes to the minor's record.
- Device/location data: only if the Custodian uses a Spatial Memory Anchor feature in connection with a dispatch addressed to the minor's future account.
We do not knowingly collect biometric data, precise geolocation, or persistent identifiers directly from a child under 13's own device, because minors do not independently operate authenticated sessions on the Service.
4.3 Disclosure of Children's Data to Third Parties
Information collected about a minor through a Dependent Vault is disclosed only to the same categories of infrastructure sub-processors identified in Section 3 (secure hosting and, where applicable, AI processing used to generate memory prompts), and only as strictly necessary to operate the Service. We do not disclose children's personal information to advertisers, and the Service does not display third-party advertising.
4.4 Parental Rights and Controls
- Review and Edit: The Custodian may review, edit, or correct any information held about their dependent at any time through the dashboard.
- Deletion: The Custodian may request deletion of a minor's entire Dependent Vault record at any time by contacting support@remeaeco.com or using the in-app deletion tool described in Section 9.
- Refusal of Further Collection: A Custodian may refuse to permit further collection or use of a minor's information while maintaining the underlying Remea account by discontinuing use of Dependent Vault features.
- Verification: Because Dependent Vaults are created and controlled exclusively by an already-authenticated adult account holder, the Custodian's account login itself serves as our reasonable verification mechanism under COPPA.
5. Your Privacy Rights (GDPR)
European Union / UK · GDPRIf you are located in the EEA, the UK, or Switzerland, you have the following rights regarding your personal data, in addition to the deletion rights described in Section 9:
- Right of Access: You may request a copy of the personal data we hold about you.
- Right to Rectification: You may request correction of inaccurate or incomplete personal data.
- Right to Erasure: You may request deletion of your personal data, subject to the limitations described in Section 9.
- Right to Restrict Processing: You may request that we limit how we use your data under certain circumstances.
- Right to Data Portability: You may request your data in a structured, commonly used, machine-readable format.
- Right to Object: You may object to our processing of your data where we rely on legitimate interest as a legal basis.
- Right to Lodge a Complaint: You have the right to lodge a complaint with your national Data Protection Authority (the supervisory authority in your country of residence, work, or the location of the alleged infringement) if you believe our processing of your data violates GDPR.
To exercise any of these rights, contact us at support@remeaeco.com. We will respond within one month as required by GDPR Article 12.
5.1 Legal Basis for Processing
We process your personal data under the following legal bases, as applicable:
- Contractual Necessity: Processing required to provide the Service you have signed up for, such as account authentication and Vault storage.
- Consent: Processing based on your affirmative consent, such as a Custodian's creation of a Dependent Vault, or your enabling of optional device features (camera, biometrics, location).
- Legitimate Interest: Processing necessary for fraud prevention, Service security, and product improvement, balanced against your privacy interests.
- Legal Obligation: Processing necessary to comply with applicable tax, accounting, or legal requirements.
6. Cookies and Tracking Technologies
The Service uses essential cookies and local storage required for authentication and session persistence. Where we use any non-essential analytics or tracking technology, we will provide a clear consent mechanism before such technology is activated for users located in the EEA, UK, or Switzerland, in accordance with applicable ePrivacy requirements. You may control cookie preferences through your browser settings at any time.
7. Post-Mortem Data Handling
As a digital legacy platform, the preservation of your data after death is a core function of the Service.
- Memorialization: Upon verified passing, accounts are transitioned to "Memorial Vaults." Data within these vaults is preserved securely as part of the ecosystem's Generational Tree.
- Access: Access to a Memorial Vault is strictly limited to the legally designated Custodian or verified heirs in accordance with our Terms of Service and applicable legacy laws.
8. Security
We utilize industry-standard 256-bit encryption through our backend infrastructure (Supabase) to secure Vault assets, and hardware-backed device encryption for Hardware Enclave records. However, no digital transmission or storage system is completely secure, and we cannot guarantee absolute security.
9. Data Retention and Your Right to Deletion
Default Retention Periods: Absent a deletion request, we retain account and Vault data for as long as your account remains active, plus an additional period of up to 90 days following account closure to allow for recovery of accidentally deleted accounts. Financial transaction records are retained for 7 years to comply with applicable tax and accounting laws. Device and analytics logs are retained for up to 24 months.
You have the right to request the complete deletion of your Remea account and all associated personal data, media, and Vault assets at any time. Due to the nature of our "Digital Legacy" and shared ecosystem, data deletion operates as follows:
How to Request Deletion:
- In-App: You may initiate an account deletion request by navigating to Settings > Account Settings > Delete Account within the Remea application.
- Web: You may submit a deletion request by contacting our Support Center at support@remeaeco.com with the subject line "Account Deletion Request."
Upon receiving a verified request, Remea, LLC will permanently delete your account, generational tree nodes, and encrypted vault storage from our active databases within 30 days, barring any data we are legally required to retain for compliance, tax, or legal defense purposes. Please note that data stored in immutable ledger formats or Entangled Data (information you have shared, contributed, or co-created that is now part of another user's experience, e.g., a photo uploaded to a shared family tree) may be anonymized rather than destroyed, ensuring your personal identity is entirely decoupled from the historical record without breaking the ecosystem for remaining family members.
10. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last Updated" date at the top of this page reflects the most recent revision. Material changes affecting EEA, UK, or Swiss users, or changes to how we handle children's data, will be accompanied by a more prominent notice, such as an in-app banner or email notification, prior to taking effect.
Data & Privacy Inquiries
Remea, LLC — Data Controller
Johns Creek, Georgia, USA
Email: support@remeaeco.com