Privacy Policy
Last updated: June 2026
1. Data Controller
The controller responsible for the processing of personal data is:
Bullhornlab e.K.
Owner: Sebastian Werner
Marienstr. 19
90402 Nürnberg
Germany
Email: hello@remembr.app
No data protection officer has currently been appointed.
2. General Information
We take the protection of personal data seriously. We process personal data in accordance with applicable data protection laws, in particular the General Data Protection Regulation (GDPR).
This Privacy Policy applies to the remembr.app website and to the Remembr iOS app.
Remembr is an app for personal relationship memory. It helps users remember contacts, meetings, conversation context, notes, reminders, photos, voice notes, transcripts, AI-generated summaries and AI search answers.
3. Purposes and Legal Bases
We process personal data for the following purposes:
- providing the website and app
- creating and managing user accounts
- storing and synchronizing contacts, notes, facts, interactions, reminders, photos, voice recordings and transcripts
- providing AI features such as search, summaries, suggestions, transcription and structured processing of user input
- providing map and location-related features
- processing support, error and contact requests
- displaying non-personalized notices inside the app
- collecting anonymous, aggregated usage statistics to improve the app and estimate operating costs
- managing waitlist and launch updates
- managing subscriptions and premium entitlements
- ensuring security, troubleshooting, abuse prevention and service stability
- complying with legal obligations
Legal bases include:
- Art. 6(1)(b) GDPR where processing is necessary to provide the app, perform a contract or take pre-contractual steps
- Art. 6(1)(a) GDPR where consent is given, for example for waitlist updates or certain permissions
- Art. 6(1)(f) GDPR for our legitimate interests, including security, stability, support, abuse prevention, troubleshooting, improving app functionality and anonymous usage statistics
- Art. 6(1)(c) GDPR where processing is necessary to comply with legal obligations
4. Website, Hosting and Server Logs
When the website is accessed, technical data is processed to deliver and securely operate the website. This may include:
- IP address
- date and time of access
- requested page or file
- transferred data volume
- browser type and version
- operating system
- referrer URL
- access status / HTTP status code
This processing is necessary to provide the website, ensure IT security, detect abuse and maintain stability. The legal basis is Art. 6(1)(f) GDPR.
The website is hosted by Lovable Labs Incorporated, 2261 Market Street STE 86612, San Francisco, CA 94114, USA. The hosting provider processes the data listed above on our behalf as a processor (Art. 28 GDPR). This may involve a transfer of data to the USA, which takes place on the basis of the EU Standard Contractual Clauses. Further technical infrastructure providers are also engaged as processors.
5. Cookies and Similar Technologies
The website uses technically necessary cookies or similar technologies where required to operate the website and store user preferences. These may include:
- storing cookie or privacy preferences
- storing language preferences
- technically necessary functional storage
For marketing and reach measurement we use the Meta Pixel and the Meta Conversions API. These are loaded only after your explicit consent via the cookie banner. As long as no consent has been given, no such processing takes place and no related requests are sent to Meta. Details can be found in the section "Meta Pixel and Meta Conversions API". Consent can be changed or withdrawn at any time via the "Cookie settings" link in the footer.
6. Waitlist and Launch Updates
If users sign up for the waitlist or launch updates, we process the information submitted, in particular:
- email address
- optional name or first name
- time of registration
- technical proof of registration and confirmation
- language or source information where relevant
The legal basis is consent under Art. 6(1)(a) GDPR. Consent can be withdrawn at any time with effect for the future.
MailerLite may be used as a technical service provider for waitlist management and launch updates if the existing website integration uses MailerLite.
7. User Account and Authentication in the App
The Remembr iOS app uses user accounts. The following data may be processed:
- email address
- user ID
- authentication data and technical account metadata
- language settings
- registration and usage timestamps
- premium or subscription entitlement status
Authentication, database, storage, synchronization and certain backend functions are provided by Supabase. The Supabase project is hosted in the EU / Ireland.
8. Contact and Relationship Memory Data
Remembr processes data that users enter into the app or generate through app features. This may include:
- names and contact information
- phone numbers, email addresses, websites or social profiles, if entered
- company, role, birthday or memory cues
- locations, home/work locations or meeting places
- notes
- facts
- interactions and conversation history
- reminders and follow-up context
- tags
- photos, profile images or photo memories
- scanned content where the scan feature is used
- voice recordings, transcripts and structured entries generated from them
- AI-generated summaries, search answers and suggestions
Users decide which information they store in Remembr. Please only store information that you are allowed to use lawfully.
9. Photos, Scans, Voice Recordings and Transcripts
If users use photo, scan or voice features, the corresponding media and derived information may be processed.
Voice recordings may be transmitted for transcription and processing. Transcripts may then be used to propose structured contacts, notes, facts, interactions or reminders.
Photos and other media may be stored in private storage areas associated with the user account.
10. Location and Map Features
Remembr may offer location or map features, for example to connect contacts with places or display contacts on a map.
If the app requests access to the current location, this only happens with permission through iOS. Permissions can be changed at any time in iOS settings.
Where possible, contacts are displayed in a privacy-conscious, location-based way, for example city-based or based on locations entered by the user. Remembr is not designed to create precise movement profiles or live tracking of contacts.
11. AI Features and OpenAI
Remembr uses AI features to help users save, structure, search and summarize relationship memory.
For this purpose, user input, search queries, contact information, notes, facts, interactions, reminders, transcripts and similar context may be sent to AI service providers, in particular OpenAI.
OpenAI processes this data as a technical service provider to provide the AI features. According to current OpenAI API data controls, API data is not used to train models by default unless explicitly opted in. Depending on the configuration, API inputs and outputs may be temporarily retained for abuse monitoring, safety or operational purposes.
AI-generated content may be incomplete or inaccurate. Important information should be verified.
12. Anonymous Usage Statistics
Remembr may collect anonymous, aggregated usage statistics to understand which features are used, improve the app and better estimate operating costs such as AI usage.
Only general events are counted, for example whether the app was opened, a search was started, an AI search answer was received, voice input was started, a voice draft was created, text entry was started or saved, a contact was created or edited, a scan was started, a reminder was created, a photo memory was added, the paywall was shown or an in-app notice was shown or dismissed.
These usage statistics do not include user IDs, names, email addresses, contact content, notes, search texts, transcripts, photos, audio data, precise location data or device identifiers. The usage statistics stored in the application tables consist only of aggregated counters, for example by date, event category, app version, platform and language.
The anonymous usage statistics are not used for advertising and are not used to track users across apps or websites. Users can disable anonymous usage statistics in the app settings.
13. In-App Notices
Remembr may display public, non-personalized notices inside the app, for example information about new features, maintenance notices or general product information.
These notices are loaded from the backend. They are not personalized based on individual user profiles. If users dismiss a notice, this decision may be stored locally on the device so that the same notice is not shown again.
If showing or dismissing such notices is measured statistically, this is done only as an anonymous, aggregated counter as described in the section "Anonymous Usage Statistics".
14. Support Requests
If users contact us through the app or by email, we process the data required to handle the request, in particular:
- name or email address
- user ID where required
- content of the request
- app version, device model, iOS version or technical information if transmitted
- attachments or screenshots if voluntarily included
Support requests may be technically sent and processed through Resend or similar email service providers. Support email: support@remembr.app
15. Error Reports and Report a Problem
If an error occurs in the app, users may voluntarily send an error report or support request. Such a report may include an error code, affected feature area, app version, build number, iOS version, device model, language settings, a voluntary message and optional attachments or screenshots added by the user.
Error reports are sent only after user action. They are used to process support requests, analyze errors, improve app stability and fix technical issues.
Error reports do not automatically include contacts, notes, search texts, transcripts, photos, audio data, precise location data or other stored memory content unless users voluntarily include such information in a message or attachment.
16. Subscriptions and Payments
Premium features of Remembr may be offered through auto-renewable subscriptions in the Apple App Store.
Payment and subscription management are handled by Apple / App Store / StoreKit. Bullhornlab e.K. does not process full payment card details. The app receives only the information required to unlock and manage premium status.
Subscriptions can be managed and cancelled through the user's Apple ID or iOS subscription settings.
17. Local Processing on the Device
Some data may be stored locally on the device so the app works quickly and certain features remain available locally.
Depending on the feature, local data may be synchronized with the user account on the server. Deleting the app may remove local data. Server-side deletion is handled through the account deletion function inside the app.
18. Account Deletion
Users can initiate deletion of their Remembr account inside the app. This deletes the account and associated server-side user data unless legal retention obligations apply.
If an active Apple subscription exists, it may need to be managed or cancelled separately through Apple. Deleting the Remembr account does not automatically cancel an Apple subscription.
19. Recipients and Service Providers
We disclose personal data only where legally permitted and necessary for the respective purposes.
Service providers may include:
- Supabase for authentication, database, storage, synchronization and Edge Functions
- OpenAI for AI processing
- Resend for support email processing
- Apple for App Store, StoreKit, payments and subscription management
- MailerLite for website waitlist and launch updates, if used
- hosting and infrastructure providers for the website
Where required, service providers are engaged under data processing agreements or comparable data protection arrangements.
20. International Transfers
Some service providers may process personal data outside the EU/EEA or make it accessible from outside the EU/EEA. Where this occurs, transfers are made in accordance with legal requirements, in particular on the basis of appropriate safeguards such as Standard Contractual Clauses or comparable mechanisms.
21. Retention
We store personal data only for as long as necessary for the respective purposes or as required by legal retention obligations.
In general:
- account data and app content are stored while the user account exists
- when an account is deleted, server-side user data is deleted unless legal retention obligations apply
- support requests and error reports are retained as long as necessary for handling and documentation
- waitlist data is retained until withdrawal, unsubscribe or the purpose no longer applies
- server logs are retained only as long as needed for security and operations
- anonymous aggregated usage statistics may be retained for a longer period because they do not identify any user
- local device data may be removed by deleting the app or through app functions
22. Obligation to Provide Data
Providing personal data is generally voluntary. However, certain information is required for specific app functions. Without an account, app usage may be limited or unavailable. Without contact, note or reminder data, the corresponding Remembr features cannot be provided.
23. No Automated Decision-Making
We do not use automated decision-making within the meaning of Art. 22 GDPR. AI features help organize and search information but do not make legal or similarly significant decisions about users.
24. Data Subject Rights
Subject to legal requirements, users have the following rights:
- right of access
- right to rectification
- right to erasure
- right to restriction of processing
- right to data portability
- right to object to processing based on legitimate interests
- right to withdraw consent with effect for the future
- right to lodge a complaint with a supervisory authority
Requests can be sent to hello@remembr.app.
25. Meta Pixel and Meta Conversions API (Website)
On this website we use – only after your explicit consent – the Meta Pixel and the Meta Conversions API to measure the effectiveness of our advertising and to evaluate conversions (e.g. interactions with our calls to action).
- Recipient: Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
- Purpose: ad campaign measurement, reach measurement and conversion tracking.
- Legal basis: your consent under Art. 6(1)(a) GDPR. Consent is voluntary and can be withdrawn at any time with effect for the future via the "Cookie settings" link in the footer.
The Meta Pixel is only loaded in the browser after consent has been given. In addition, we send the same events server-side via the Meta Conversions API. The browser event and the server event share the same event ID (event_id) so that Meta can deduplicate matching events.
Where personal identifiers (e.g. an email address) are transmitted, they are pseudonymized before transmission to Meta using a secure hashing procedure (SHA-256). In addition, technical information such as IP address, browser identifier (user agent) and Meta cookies (_fbp, _fbc) may be processed. This also includes the click ID (fbclid) that Meta appends to the URL, which we use to attribute ad clicks.
Using Meta services may involve a transfer of data to third countries, in particular the USA. Meta bases such transfers on appropriate safeguards, in particular Standard Contractual Clauses and – where applicable – the EU-US Data Privacy Framework. There is a risk that authorities in third countries may access data.
26. Refer-a-Friend Program (Referrals)
Where a referral program is offered, users can invite other people using a personal invite code. In doing so we process:
- the personal invite code
- the mapping between the inviting account and the invited account (each via account identifiers)
- the status of the referral and of any reward
The legal basis is Art. 6(1)(b) GDPR (operating the referral program at the user's request). The actual redemption of an offer and the granting of any resulting reward are handled by Apple. Referral data is deleted when the account is deleted, unless statutory retention obligations apply.
27. Changes to this Privacy Policy
We may update this Privacy Policy if legal, technical or organizational changes occur. The current version published on the website applies.
