Privacy Policy
Last updated: 26 August 2026
Welcome to Cherishly (“we”, “our”, or “us”). We are committed to protecting your privacy and keeping your family's memories secure. This Privacy Policy explains how we collect, use and protect information when you use the Cherishly mobile application (“the App”), and applies whether you use Cherishly on iOS or Android.
1. Two ways to use Cherishly — local-only or cloud-synced
Cherishly is built local-first. How your data is handled depends on how you use the App:
- Guest Mode (free, no account required): Your profiles, photos, voice recordings, notes and reminders are stored entirely on your device. Nothing is uploaded to our servers or any third party. We do not receive, see or store any of this content. If you delete the App or lose your device without a backup, this data cannot be recovered by us, because we never had it.
- Family Sharing (paid tiers): If you choose to upgrade and create or join a Family Circle, the profiles, photos, voice recordings and notes you choose to share are synced to our secure cloud infrastructure (Google Firebase) so that invited family members can view them. Only content you actively share into a Family Circle is uploaded — content you keep outside a Circle remains local to your device.
You can use Cherishly entirely in Guest Mode indefinitely. Account creation and cloud sync only happen when you choose to unlock family sharing.
2. Information we collect
a. Account information (Family Sharing tier only)
When you sign in with Apple or Google to create or join a Family Circle, we collect your basic profile information (name and email address) to create and authenticate your account. If you use “Sign in with Apple” with the private relay email option, we only receive the relay address Apple provides.
b. User-generated content (Family Sharing tier only)
When you share a profile into a Family Circle, we store the photos, voice recordings and text (names, relationships, key dates, notes) associated with that profile, so it can be synced across your invited family members' devices.
c. Family Circle data
When you invite someone to a Family Circle, we collect the email address you provide for the invitation, and, once they join, their basic account information (name, email, profile photo if provided). This allows us to manage membership and permissions within your Circle.
d. Purchase information
If you purchase a paid tier, payment is processed securely by Apple or Google. We use RevenueCat to manage and validate purchases across your devices. We share a pseudonymous app user ID and purchase/transaction data with RevenueCat for this purpose only — RevenueCat does not receive your photos, voice recordings, notes or any content you store in Cherishly. We do not store your credit card or payment details.
Lifetime & non-consumable purchase notice: “Lifetime” purchases refer to the operational lifetime of the Cherishly application, not a guarantee of perpetual, unconditional service. Purchases can be restored on a new device or after reinstalling the app via the in-app “Restore Purchases” function. In the event of unforeseen circumstances requiring the developer to terminate the service, the developer will make reasonable efforts to provide advance notice and, where technically feasible, offer alternative means of data access — such as exporting your profiles, photos, voice recordings and notes to an archive or ZIP file for local safekeeping. The app already provides data export functionality, which users are encouraged to use regularly. Data portability via export is subject to the absence of technical corruption or unrecoverable glitches at the time of export.
e. Notification data
For local reminders (Guest Mode and paid tiers), reminder scheduling happens entirely on your device. For the paid collaboration tier, we use a device push token (issued by Apple/Google) to deliver remote reminders about shared Family Circle content. This token is only used to send notifications and is deleted when you delete your account or disable notifications.
3. How we protect your data
- Strict data isolation: For Family Sharing, we use Firebase Security Rules so that memories, photos and voice recordings are locked to your specific user ID and your invited Family Circle. No other users can access or view your private data.
- Encryption: Data synced to our servers is encrypted in transit and at rest using industry-standard Google Cloud (Firebase) infrastructure.
- On-device data: Guest Mode content is protected by your device's own operating system security (for example, iOS/Android sandboxing); we recommend enabling a device passcode or biometric lock for additional protection.
4. Third-party service providers
We work with the following providers, each of which processes data only as needed to provide their specific function:
| Provider | Purpose | Data involved |
|---|---|---|
| Firebase Authentication (Google) | Account sign-in | Name, email |
| Firebase Firestore / Cloud Storage (Google) | Cloud sync of shared Family Circle content | Photos, voice recordings, profile text (Family Sharing tier only) |
| Firebase Cloud Functions (Google) | Account/data deletion, sync processing | As needed to execute the function requested |
| Apple / Google Push Notification Services | Delivering reminders | Device push token |
| RevenueCat | Purchase validation across devices | Anonymised user ID, purchase/transaction data |
| Apple / Google Sign-In | Authentication | Name, email (or relay email) |
We do not sell your personal information, and we do not use your content for advertising or share it with data brokers.
5. Data retention
- Guest Mode: Data lives only on your device and is retained until you delete it or delete the App.
- Family Sharing tier: We retain your synced data for as long as your account is active. If your account is inactive for an extended period, we may notify you before any retention-policy action is taken.
- Upon account deletion (see Section 7), all associated cloud data is permanently removed, typically within 30 days, except where retention is required by law (for example, financial records related to purchases).
6. International data transfers
Our cloud infrastructure (Google Firebase) may process and store data outside your country of residence, including in the United States. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses for transfers of personal data from the EEA, UK or Switzerland.
7. Data deletion & your rights
You have full control over your data. You can delete your account at any time from the settings menu inside the App. When you trigger account deletion, our automated Cloud Functions permanently remove your user profile, uploaded photos, voice recordings and associated database entries from our servers. This process is irreversible.
If you are located in the EEA, UK, or another jurisdiction with similar protections, you also have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request a copy of your data in a portable format
- Object to or restrict certain processing
- Lodge a complaint with your local data protection authority
To exercise any of these rights, contact us at the email below.
8. California privacy rights (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect, request its deletion, and correct inaccuracies. We do not sell or share your personal information for cross-context behavioural advertising. We do not discriminate against you for exercising any privacy right. To make a request, contact us at the email below.
9. Sensitive information you choose to share
Cherishly lets you create memorial profiles for other people, who are often not App users themselves. When you add a profile, photo, voice recording or note about another person:
- You are responsible for having the appropriate right or permission to upload and share that content, including photos or recordings that may depict or reference other living individuals.
- Optional religious calendar features: If you enable Hijri/Islamic date calculations, this is used only to calculate reminder dates and is not used to infer or share your religious affiliation with any third party.
- Voice recordings stored in Cherishly are used only for playback within the App. We do not perform voice recognition, voiceprint matching or biometric identification on any audio you upload.
- We ask that you avoid including sensitive health details (for example, cause of death, medical history) about the people you remember, beyond what you are comfortable sharing with invited Family Circle members.
10. Children's privacy
Cherishly is not directed at children under the age of 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children under this age without verifiable parental consent. If we become aware that we have inadvertently collected such information, we will delete it promptly.
11. Data security incidents
In the event of a data breach affecting your personal information, we will notify affected users and relevant authorities as required by applicable law.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the “Last updated” date above.
13. Contact us
If you have questions about this Privacy Policy or need assistance with your data, please contact us through the support section of the App or email us directly at support@cherishlyapp.com.