DirectMemoir Privacy Policy & Account Deletion
This Privacy Policy explains how DirectMemoir (also known as CineRelay) collects, uses, stores, and shares personal data when you use the app. DirectMemoir is a collaborative turn-based mobile application where friends write stories, compose soundtracks, and produce synchronized 30-second short films using AI.
1. Data We Collect
- Account data: email address, username, user ID, and authentication tokens. If you sign in with Google or Apple, we receive the profile information you authorize (e.g. name and email).
- Guest access data: if you use guest mode, we generate a random username and local device identifier. No email or password is required.
- Profile data: optional avatar image URL and credit balance (in-app currency used to generate films).
- Story and room data: story rooms you create or join, including room title, genre, BPM, musical key, turn order, scene text you write, and AI-generated lyrics.
- Media content: reference images you upload (character art / concept art), AI-generated video clips, AI-generated soundtracks, extracted video frames, and final stitched films stored in cloud storage.
- Safety reports: when you report a person or content, we store your account ID, the crew and reported target, the reason and optional details you submit, and a snapshot of relevant saved profile or story information and media URLs. Administrators can add review notes and record actions taken.
- Purchase data: RevenueCat customer ID and transaction records for in-app credit purchases. We do not directly process or store payment card information — all payment processing is handled by Apple App Store, Google Play, and RevenueCat.
- Device identifiers: a locally generated device ID stored on your device to manage trial credits and prevent abuse.
- Device permissions: microphone access (for voice-assisted recording), camera access (for capturing reference photos), and photo library access (for uploading reference art and saving generated films). These are requested only when needed and can be revoked via your device settings at any time.
2. How We Use Data
- To create and manage your account and authenticate your session.
- To power the collaborative story room experience — storing your scenes, managing turn order, and enabling real-time updates between collaborators.
- To generate AI content on your behalf — sending your scene descriptions and reference images to AI services for video, music, and lyric generation.
- To check camera, gallery, avatar, and scene reference photos for potentially inappropriate content before publishing them. The photo bytes are sent to OpenAI's Moderation API for this automated check. If the check is unavailable or flags an image, the upload is refused. Automated checks can make mistakes and are not a guarantee that all objectionable content will be detected.
- To receive, review, and keep a record of user reports; enforce our safety rules; restrict crews or accounts when appropriate; and prevent blocked users from interacting through shared crews.
- To process in-app purchases and maintain your credit balance for film generation.
- To enable social features — WhatsApp and iMessage invitations contain your room title, genre, and a deep link. Message content is composed locally on your device and sent through your own messaging apps; we do not access your contacts.
- To save finished films to your device photo gallery when you choose to export.
- To improve app reliability and diagnose technical issues.
3. Data Storage & Service Providers
Your data is processed and stored by the following providers:
- Supabase — authentication (Email + Password, Google, Apple, Guest), PostgreSQL database with Row Level Security for profiles, rooms, turns, and members, plus object storage for media assets. Policy: supabase.com/privacy
- Cloudflare R2 — cloud storage for generated video and audio media files. Policy: cloudflare.com/privacypolicy
- RevenueCat — in-app purchase management, receipt validation, and subscription tracking. Policy: revenuecat.com/privacy
- OpenAI / Anthropic — AI script direction, scene refinement, and lyric generation. Your scene text and prompts are sent to these services for processing. OpenAI also processes uploaded photo bytes through its Moderation API for the safety check described above. Policies: openai.com/privacy, anthropic.com/privacy
- Fal.ai (MiniMax Video) — AI video generation from your scene prompts and reference images. Policy: fal.ai/privacy
- Modal — serverless GPU compute for video stitching (FFmpeg). Policy: modal.com/privacy
- DiceBear — auto-generated avatar images for guest users (no personal data is sent; only a random seed). Policy: dicebear.com/legal/privacy-policy
4. Data Sharing
We do not sell your personal data. Data is shared with the service providers listed above only as needed to operate app functionality. Your uploaded photos may be sent to OpenAI for the automated safety check before upload; photos and prompts may also be sent to generation providers when you request AI content. Room collaborators can see shared story content (room title, scenes, generated media) within the rooms they are members of. Reports are available only to the administrator for review and are not shown to the reported person in the app.
Report and review records are retained as needed to assess reports, maintain safety and review history, handle appeals or disputes, and meet legal or security obligations. There is currently no automatic deletion schedule for these records. They may remain after an account is deleted, and their saved evidence may contain profile or story information and media URLs. They are deleted when no longer needed.
5. Tracking & Analytics
DirectMemoir does not use advertising SDKs, tracking
pixels, or third-party analytics services. We do not track you across
other apps or websites. The iOS Privacy Manifest declares
NSPrivacyTracking = false.
6. Your Choices & Rights
- You can edit your username and avatar from the Director Profile screen in the app.
- You can revoke microphone, camera, and photo library permissions at any time through your device's Settings app.
- You can sign out at any time, which clears your local session data.
- You can request full account deletion — see the Account Deletion section below for exact steps and what gets removed.
- You can report a crew member, scene, photo, video, or crew from the relevant in-app Report option. Reports are reviewed by the administrator; we aim to review them within 24 hours. You can block a member from the crew member menu. Blocking hides shared crews for both people and prevents future joins and credit sharing between them. You can manage and undo blocks in Profile. Other crew members keep access to shared crews.
- If you are located in the EU/EEA, UK, California, or other jurisdictions with data privacy laws, you may have additional rights including access, rectification, erasure, and portability. Contact us using the details below.
7. Account Deletion
- How to request deletion:
- Open DirectMemoir and tap your profile icon to open the Director Profile.
- Tap "Delete Account", then confirm the deletion when prompted.
- If you cannot access the app, email fauzankamadev@gmail.com with your account email or username and request deletion.
- What is deleted:
- Your Supabase authentication record (email, password hash, OAuth tokens).
- Your profile data (username, avatar URL, credit balance, RevenueCat customer ID, device ID).
- Your room memberships and story turns (scene text, generated lyrics, video clip URLs, audio segment URLs, reference image URLs).
- Local device data (cached guest profile, device credits ledger, welcome claim flags).
- What may be retained and for how long:
- Story rooms you created may persist (with your authorship anonymized) if other members still have access. Generated media files in cloud storage may remain for up to 30 days before automatic cleanup.
- Server backups and operational logs may retain data for up to 30 days before permanent deletion.
- Purchase records held by Apple, Google, and RevenueCat are governed by their respective retention policies and cannot be deleted by us.
- Data may be retained when required for legal, security, fraud-prevention, or dispute-resolution obligations, then removed when no longer required.
8. Children's Privacy
DirectMemoir is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, please contact us so we can delete it.
9. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of the app after changes constitutes acceptance of the updated policy.
10. Contact
For privacy requests, questions, or data deletion inquiries, contact us at fauzankamadev@gmail.com.