Privacy Policy

Last updated: June 2026

1. Introduction

This privacy policy explains how Lembray Ltd ("Lembray", "we", "us", "our") collects, uses, stores, and protects your personal data when you use our family memory preservation platform at app.lembray.com.

We only collect personal data that is necessary to provide and improve the Service. Some content uploaded to Lembray may include special category personal data, such as information relating to health, religious beliefs, ethnicity, or other sensitive information that users choose to share. We are committed to handling all personal data with the highest standards of care and legal compliance.

This policy applies to all users of app.lembray.com. It does not apply to our marketing website at lembray.com, which has its own privacy notice. This Privacy Policy forms part of our Terms of Service (available at lembray.com/terms) and should be read alongside them.

2. Data Controller

Legal entity: Lembray LtdRegistered in England and WalesCompany number: 17193414
Contact email: hello@lembray.com
Privacy contact: hello@lembray.com

For all data protection enquiries, contact us at hello@lembray.com. We aim to respond within 5 working days.

EU Representative: In accordance with Article 27 EU GDPR, our designated EU Representative is João Roso, Rua Alexandre Ferreira, 30 6DT, 1750 Lisboa, Portugal. EU data subjects and supervisory authorities may contact our EU Representative at rosojao@gmail.com on all matters relating to the processing of personal data by Lembray Ltd.

Registered office: 31 Manor Road, Manchester, M6 8QN

3. Personal Data We Collect

We collect the following categories of personal data:

3.1 Account information

Full name, email address, password (hashed - never stored in plain text), date of birth (optional), city (optional), country (optional).

3.2 Profile information

Profile photo (optional), preferred language.

3.3 Voice recordings

Audio files you record directly in the app or upload from your device. These are the core content of the Lembray service.

3.4 Transcriptions

Text transcriptions automatically generated from your voice recordings using OpenAI services.

3.5 Stories and written content

Text stories, chapter titles, storybook titles, and any written content you create within the app.

3.6 Photos and media

Cover images for storybooks and profile photos.

3.7 Payment information

Subscription tier, billing status, and payment date. We do not store card numbers or payment details - these are processed entirely by Stripe.

3.8 Device and usage data

IP address, browser type, device type, operating system, pages visited, session duration, and error logs. Collected automatically when you use the app.

3.9 Communications data

Emails and messages you send to hello@lembray.com, and records of transactional emails we send to you.

3.10 Consent records

A timestamped record that you accepted our Terms of Service and Privacy Policy at sign-up, including the version accepted and method of acceptance.

3.11 Collaboration data

Email addresses of family members you invite as collaborators, and the role you assign them.

4. How and Why We Use Your Data

For each processing activity, we set out the data used, the lawful basis under UK GDPR and EU GDPR, and how long we keep it.

Creating and managing your account Data: Account information, consent record Lawful basis: Contract (Article 6(1)(b))Retention: Duration of account + 90 days

Providing the core service (recording, transcription, storybook) Data: Voice recordings, transcriptions, stories, photos Lawful basis: Contract (Article 6(1)(b))Retention: Duration of account + 90 days

Processing payments and managing subscriptions
Data: Payment informationLawful basis: Contract (Article 6(1)(b))Retention: 7 years (UK tax law)

Sending transactional emails Data: Name, email addressLawful basis: Contract (Article 6(1)(b))Retention: Duration of account + 90 days

Maintaining platform security and diagnosing technical issues Data: Device and usage data, IP addressLawful basis: Legitimate interests (Article 6(1)(f))Retention: 90 days rolling

Responding to support enquiries Data: Communications dataLawful basis: Legitimate interests (Article 6(1)(f))Retention: 2 years from last contact

Demonstrating legal compliance Data: Consent recordsLawful basis: Legal obligation (Article 6(1)(c))Retention: 7 years

Family collaboration features Data: Collaborator email addresses Lawful basis: Legitimate Interests (Article 6(1)(f))Retention: Duration of account + 90 days

Bot protection (Cloudflare Turnstile ) Data: Device and browser signalsLawful basis: Legitimate interests (Article 6(1)(f))Retention: Not retained by us

We may retain certain data for longer where necessary to establish, exercise, or defend legal claims.

4a. Special Category Personal Data

Family memories recorded or uploaded to Lembray may contain special category personal data as defined under Article 9 UK GDPR and EU GDPR, including information relating to health, religious beliefs, ethnicity, political opinions, or other sensitive matters that users choose to share.Where User Content contains special category personal data, processing is carried out on the basis that such data has been manifestly made public by the user, or another lawful condition under Article 9 UK GDPR and EU GDPR applies, including explicit consent where required.Users are independently responsible for ensuring they have obtained any necessary permissions or consents from individuals whose special category personal data they upload to Lembray.

5. Voice Recordings and AI Processing

Voice recordings are the heart of Lembray. We handle them with particular care.

What we do with your recordings:
• Store them securely in Cloudflare R2, encrypted at rest
• Send them to OpenAI API services solely for the purpose of generating a text transcription
• Make them available for playback within your storybook

What we do not do:
We do not sell your voice recordings
• We do not use your voice recordings for advertising
• We do not use your voice recordings to identify you or create voiceprints or biometric profiles
• We do not train AI models on your voice recordings
• We do not share your voice recordings with any party other than OpenAI (for transcription) and Cloudflare (for storage), both of whom act strictly under our instructions

OpenAI data usage: Voice recordings sent to In accordance with OpenAI's API data usage policies applicable at the time of processing, data submitted via the API is not used by OpenAI to train its models.

Third-party voices: When you record or upload audio that includes the voice of another person (such as an elderly relative), you are responsible for ensuring that person has given their informed consent to be recorded and for their voice to be stored on Lembray. By uploading such a recording, you confirm that you have obtained this consent.

6. User-Generated Content

Lembray allows you to upload and store personal memories, photos, and recordings that may include information about other people - family members, friends, or others.

You are responsible for:
• Ensuring you have the right to upload any content you add to Lembray
• Obtaining consent from anyone whose voice, image, or personal information you upload
• Not uploading content that infringes the rights of others

Lembray is a private, family-facing platform. We do not publish user-generated content publicly unless you explicitly choose to make your storybook public in Settings.

Where you upload content relating to another identifiable person, you are independently responsible for ensuring that you have a lawful basis for sharing that information with Lembray.

7. App Permissions

Lembray requests the following permissions on your device:
Microphone - To record voice stories directly in the app.
Storage / Files - To upload audio files and photos from your device.
Notifications - To send reminders about recording stories. This is optional and can be turned off in Settings at any time.

You can revoke any permission at any time in your device settings. Revoking microphone access will prevent in-app recording but will not affect your existing stories.

8. Children's Privacy

You must be at least 13 years old to use Lembray, or the minimum age required to consent to digital services in your country of residence, whichever is higher. In some EU member states this age is 14, 15, or 16. We do not knowingly collect personal data from anyone below the applicable minimum age in their country. If you believe such a person has created an account, please contact us at hello@lembray.com and we will delete the account and associated data promptly.

Users aged 13–17 may use Lembray only with the knowledge and consent of a parent or legal guardian. By creating an account, a user aged 13–17 confirms that their parent or guardian has given consent. Parents or guardians who have consented on behalf of a minor accept our Privacy Policy and Terms of Service on their behalf and are responsible for the minor's use of the Service.

Note: Lembray is designed to help users preserve the stories of elderly relatives. It is common for users to create storybooks about family members of any age. The age restriction above applies to the account holder (the person signing up), not to the subjects of the stories.

9. Third-Party Service Providers

We use the following third-party service providers. Where required by applicable law, we have entered into appropriate contractual arrangements with our service providers, including data processing agreements where they act as processors on our behalf. Note that some providers, such as Stripe for payment compliance purposes, may act as independent controllers for certain processing activities. We may update this list from time to time - material changes will be reflected in this policy.

Supabase Purpose: Database and authentication (SOC2 compliant) Location: USA Transfer mechanism: Appropriate transfer safeguards
Cloudflare R2 Purpose: Voice recording and media storage Location: Global network, including USA Transfer mechanism: Appropriate transfer safeguards
Cloudflare (CDN and Turnstile) Purpose: Content delivery, DDoS protection, bot protection Location: Global network, including USA Transfer mechanism: Appropriate transfer safeguards
OpenAI Purpose: Voice transcription (Whisper) and translation (GPT-4o) Location: USA Transfer mechanism: Appropriate transfer safeguards
Stripe Purpose: Payment processing (PCI-DSS Level 1 compliant), independent controller for payment compliance- Global, including USA Transfer mechanism:  Appropriate transfer safeguards
Brevo Purpose: Transactional email delivery Location: France (EU) Transfer mechanism: Adequacy decision

We do not sell your data.

We do not share your data with advertisers.

We may update this list from time to time - material changes will be reflected in this policy.

10. International Data Transfers

Several of our service providers are based in the United States. Transfers of personal data outside the UK are carried out under one of the following safeguards:

We rely on appropriate safeguards including the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, the EU Standard Contractual Clauses, adequacy decisions, and other lawful transfer mechanisms where applicable. France (where Brevo is based) benefits from the UK's adequacy decision for EEA countries.

We have conducted transfer risk assessments for our US-based providers. You can request copies of the relevant transfer agreements by contacting hello@lembray.com.

11 Data Retention

We retain your data for the following periods:
Account data (name, email, profile): Duration of account + 90 days after closure
Voice recordings: Duration of account + 90 days after closure
Transcriptions and stories: Duration of account + 90 days after closure
Payment records: 7 years from transaction date (UK tax law requirement)
Device and usage logs: 90 days on a rolling basis
Consent records: 7 years from date of consent
Support communications: 2 years from last contact
Collaborator data: Duration of collaboration + 90 days

Following account closure, we retain data for up to 90 days to enable recovery if requested. You may request immediate deletion at any time - we will process it within 30 days, subject to legal retention requirements. We may retain certain data for longer where necessary to establish, exercise, or defend legal claims.

Accounts with no login activity and no content creation for more than 24 months may be treated as inactive. We will notify you at least 60 days before taking any action on an inactive account. Lawful basis for processing in relation to inactive account management: Legitimate interests (Article 6(1)(f)) to maintain accurate records, minimise unnecessary data retention, and ensure efficient operation of the Service.

After all applicable retention periods, data is permanently and securely deleted from our systems and from those of our processors. Deleted data may remain in secure encrypted backups for a limited period before being permanently overwritten in accordance with our backup retention schedules.

12 Security Measures

We implement the following technical and organisational measures to protect your personal data:
In transit: All data transmitted between your device and our servers is encrypted using TLS 1.3.
At rest: Data stored by us and our service providers is encrypted at rest using industry-standard encryption methods.
Voice recordings: Stored in Cloudflare R2 with private access controls. Recordings are never publicly accessible unless you explicitly share a storybook link.
Authentication: Managed by Supabase Auth (SOC2 Type II compliant). Passwords are hashed using bcrypt and never stored in plain text.
Access controls: Access to production systems and user data is restricted to authorised personnel on a least-privilege basis.
Bot protection: Sign-up, sign-in, and password reset forms are protected by Cloudflare Turnstile to prevent automated attacks.
Monitoring: We monitor our infrastructure for unusual activity and security events.

Despite these measures, no system is entirely secure. In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach, notify affected users without undue delay where required by law, and take immediate steps to contain and remediate the breach.

13 Your Rights Under UK GDPR and EU GDPR

You have the following rights in relation to your personal data. To exercise any of them, contact us at hello@lembray.com. We will respond within one calendar month.

Right of access: You have the right to receive a copy of all personal data we hold about you.
Right to rectification: You have the right to request correction of inaccurate or incomplete data. You can update most of your data directly in Settings within the app.
Right to erasure: You have the right to request deletion of your personal data. We will delete your account and all associated data within 30 days of your verified request, except where we are legally required to retain certain data.
Right to restriction of processing: You have the right to request that we suspend processing of your data in certain circumstances.
Right to data portability: ou have the right to receive your personal data in a structured, commonly used, machine-readable format (such as JSON). Legacy and Founding Member subscribers may also export their storybook as a PDF from within the app. Note that PDF exports are provided for convenience and do not replace your right to receive your data in a machine-readable format. To request a machine-readable export, contact hello@lembray.com.
Right to object: You have the right to object to processing based on legitimate interests. We will cease such processing unless we can demonstrate compelling legitimate grounds.
Right to withdraw consent: Where we rely on consent as a legal basis, you may withdraw it at any time by contacting hello@lembray.com. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Right not to be subject to automated decision-making: We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.
Right to lodge a complaint: You have the right to lodge a complaint with your relevant supervisory authority - see section 20 below.

14 Cookies and Bot Protection

Cookies
Lembray uses only essential cookies for authentication and session management. We do not use non-essential cookies or similar tracking technologies, including advertising cookies, analytics cookies, or tracking pixels. We do not use Google Analytics or Meta Pixel or any third-party analytics tools that track your behaviour across websites.

Cloudflare Turnstile
To protect our forms from automated abuse, we use Cloudflare Turnstile in invisible mode. Turnstile operates in the background without requiring you to complete a CAPTCHA or click anything. As part of this, Cloudflare may process certain device and browser signals.

For full details, please refer to the Cloudflare Privacy Policy (cloudflare.com/privacypolicy) and the Cloudflare Turnstile Privacy Addendum (cloudflare.com/en-gb/trust-hub/gdpr).

15 Automated Decision-Making

Lembray does not make any automated decisions about users that produce legal or similarly significant effects. AI transcription via OpenAI API services is used solely to convert voice to text - it does not make decisions about users.

16 Data Protection Impact Assessment

Given that Lembray processes voice recordings and sensitive family memories, we have conducted a Data Protection Impact Assessment (DPIA) in accordance with Article 35 UK GDPR. A summary is available on request by contacting hello@lembray.com.

17 Record of Processing Activities

As required by Article 30 UK GDPR, Lembray maintains an internal Record of Processing Activities (RoPA) documenting all data processing carried out by the company. This record is available to the ICO on request.

18 Changes to This Policy

We will notify you by email at least 14 days before making any material changes to this privacy policy. Non-material changes (such as correcting a typo) may be made without prior notice but will always be reflected in the version number and effective date at the top of this page.

Where required by applicable law, we will obtain your consent before implementing material changes that require a new lawful basis for processing. For other changes, your continued use of the Service after the effective date means your personal data will be processed in accordance with the updated policy.

19. Contact

For privacy enquiries, data subject requests, or any questions about this policy:
Email: hello@lembray.comWe aim to respond within 5 working days.

For complaints about how we handle your data, please see section 20 below. We would always welcome the opportunity to resolve concerns directly - please email us at hello@lembray.com before contacting a supervisory authority.

20 Supervisory Authorities

UK - Information Commissioner's Office (ICO)
If you are based in the UK and have a concern about how we handle your data, you have the right to lodge a complaint with the ICO.
Website: ico.org.ukPhone: 0303 123 1113Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

EU - Supervisory Authorities
If you are based in the European Union, you have the right to lodge a complaint with the data protection authority in your EU member state. A full list of EU supervisory authorities is available at edpb.europa.eu.


This privacy policy is written to comply with the UK General Data Protection Regulation (UK GDPR) as retained in UK law by the European Union (Withdrawal) Act 2018, the Data Protection Act 2018, and the EU General Data Protection Regulation (EU GDPR -Regulation 2016/679).

Lembray Ltd - Company No. 17193414 - Version 4.1 - Effective 24 June 2026

This is some text inside of a div block.