DirectMemoir Privacy Policy & Account Deletion
This Privacy Policy explains how DirectMemoir (also known as CineRelay) collects, uses, stores, and shares personal data when you use the app. DirectMemoir is a collaborative turn-based mobile application where friends write stories, compose soundtracks, and produce synchronized 30-second short films using AI.
1. Data We Collect
- Account data: email address, username, user ID, and authentication tokens. If you sign in with Google or Apple, we receive the profile information you authorize (e.g. name and email).
- Guest access data: if you use guest mode, we generate a random username and local device identifier. No email or password is required.
- Profile data: optional avatar image URL and credit balance (in-app currency used to generate films).
- Story and room data: story rooms you create or join, including room title, genre, BPM, musical key, turn order, scene text you write, and AI-generated lyrics.
- Media content: reference images you upload (character art / concept art), AI-generated video clips, AI-generated soundtracks, extracted video frames, and final stitched films stored in cloud storage.
- Purchase data: RevenueCat customer ID and transaction records for in-app credit purchases. We do not directly process or store payment card information — all payment processing is handled by Apple App Store, Google Play, and RevenueCat.
- Device identifiers: a locally generated device ID stored on your device to manage trial credits and prevent abuse.
- Device permissions: microphone access (for voice-assisted recording), camera access (for capturing reference photos), and photo library access (for uploading reference art and saving generated films). These are requested only when needed and can be revoked via your device settings at any time.
2. How We Use Data
- To create and manage your account and authenticate your session.
- To power the collaborative story room experience — storing your scenes, managing turn order, and enabling real-time updates between collaborators.
- To generate AI content on your behalf — sending your scene descriptions and reference images to AI services for video, music, and lyric generation.
- To process in-app purchases and maintain your credit balance for film generation.
- To enable social features — WhatsApp and iMessage invitations contain your room title, genre, and a deep link. Message content is composed locally on your device and sent through your own messaging apps; we do not access your contacts.
- To save finished films to your device photo gallery when you choose to export.
- To improve app reliability and diagnose technical issues.
3. Data Storage & Service Providers
Your data is processed and stored by the following providers:
- Supabase — authentication (Email + Password, Google, Apple, Guest), PostgreSQL database with Row Level Security for profiles, rooms, turns, and members, plus object storage for media assets. Policy: supabase.com/privacy
- Cloudflare R2 — cloud storage for generated video and audio media files. Policy: cloudflare.com/privacypolicy
- RevenueCat — in-app purchase management, receipt validation, and subscription tracking. Policy: revenuecat.com/privacy
- OpenAI / Anthropic — AI script direction, scene refinement, and lyric generation. Your scene text and prompts are sent to these services for processing. Policies: openai.com/privacy, anthropic.com/privacy
- Fal.ai (MiniMax Video) — AI video generation from your scene prompts and reference images. Policy: fal.ai/privacy
- Modal — serverless GPU compute for audio separation (Demucs) and video stitching (FFmpeg). Policy: modal.com/privacy
- DiceBear — auto-generated avatar images for guest users (no personal data is sent; only a random seed). Policy: dicebear.com/legal/privacy-policy
4. Data Sharing
We do not sell your personal data. Data is shared with the service providers listed above only as needed to operate app functionality. Your scene text and reference images are sent to AI providers solely for content generation on your behalf. Room collaborators can see shared story content (room title, scenes, generated media) within the rooms they are members of.
5. Tracking & Analytics
DirectMemoir does not use advertising SDKs, tracking
pixels, or third-party analytics services. We do not track you across
other apps or websites. The iOS Privacy Manifest declares
NSPrivacyTracking = false.
6. Your Choices & Rights
- You can edit your username and avatar from the Director Profile screen in the app.
- You can revoke microphone, camera, and photo library permissions at any time through your device's Settings app.
- You can sign out at any time, which clears your local session data.
- You can request full account deletion — see the Account Deletion section below for exact steps and what gets removed.
- If you are located in the EU/EEA, UK, California, or other jurisdictions with data privacy laws, you may have additional rights including access, rectification, erasure, and portability. Contact us using the details below.
7. Account Deletion
- How to request deletion:
- Open DirectMemoir and tap your profile icon to open the Director Profile.
- Tap "Delete Account", then confirm the deletion when prompted.
- If you cannot access the app, email fauzankamadev@gmail.com with your account email or username and request deletion.
- What is deleted:
- Your Supabase authentication record (email, password hash, OAuth tokens).
- Your profile data (username, avatar URL, credit balance, RevenueCat customer ID, device ID).
- Your room memberships and story turns (scene text, generated lyrics, video clip URLs, audio segment URLs, reference image URLs).
- Local device data (cached guest profile, device credits ledger, welcome claim flags).
- What may be retained and for how long:
- Story rooms you created may persist (with your authorship anonymized) if other members still have access. Generated media files in cloud storage may remain for up to 30 days before automatic cleanup.
- Server backups and operational logs may retain data for up to 30 days before permanent deletion.
- Purchase records held by Apple, Google, and RevenueCat are governed by their respective retention policies and cannot be deleted by us.
- Data may be retained when required for legal, security, fraud-prevention, or dispute-resolution obligations, then removed when no longer required.
8. Children's Privacy
DirectMemoir is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, please contact us so we can delete it.
9. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of the app after changes constitutes acceptance of the updated policy.
10. Contact
For privacy requests, questions, or data deletion inquiries, contact us at fauzankamadev@gmail.com.