Privacy Policy
Your memories are yours.
Last updated September 2026. Written in plain language on purpose.
This page is written by the people who build Reverie — it describes what the app actually does — and it is not a substitute for your own legal advice.
The short version
- No ads. No selling data. No algorithm. Reverie is paid for by the families who use it, not by advertisers. There are no advertising or tracking SDKs in the app.
- What you share is visible only to the people you invite, unless you choose to make a memorial page public through a physical tag or a link.
- Download everything, or delete everything. Both are buttons in Settings, both work today, and neither costs anything.
- We record how the app is used, and those records are tied to your account. They are not anonymous and there is no opt-out yet. The details are below — we would rather tell you than describe it as "anonymous usage data."
What we collect
- Account details — your name, email address, and password. The password is stored as a hash by our authentication provider; nobody at Reverie can read it. Optionally: a username, a short bio, a profile photo, your birthday, your phone number, your location, and the family details you choose to fill in (spouse, parents, children, siblings, grandchildren).
- What you share — photos, videos, voice memos, recorded stories, scanned letters and handwriting, written memories, comments, reactions, private journal entries, guest-book messages, pet records, and anything you put in the Legacy Vault.
- Connections — the people you invite, the people you are connected to, the memorials you create or are invited to keep, and anyone you have blocked.
- Device information — a push-notification token for each device where you turn notifications on, which platform you are on (iPhone or Android), and your time zone, so anniversary reminders arrive on your local day.
- Usage events — see What we measure below. These carry your account id.
- Memorial visits — see Visits to a memorial below.
- Purchases — if you buy a physical tag or a gift, a shipping address and the order details. Card payments are handled by Stripe; we never see your card number. If you subscribe, RevenueCat tells us whether the subscription is active — not your payment details.
- What you write to us — if you email support, we keep the email.
We do not collect your location. The app never asks for location permission, and no part of Reverie records where you are.
How we use it
To run Reverie: showing your family's feed to your family, delivering the notifications you asked for, resurfacing "on this day" memories, sending the weekly family digest, fulfilling tag orders, keeping the service reliable and free of spam, answering your emails, and understanding which features families actually use. We do not build advertising profiles, we do not sell or rent personal information, and we do not use your photos, videos, or writing to train any AI model.
Who can see what
- Private posts and journal entries — only you.
- Family posts — the people in your circle.
- Your profile — other members see your name, username, photo, and bio. People you are connected to also see your birthday. Your email, phone, location, and the family details you filled in are not shown anywhere in the app. We are in the middle of moving those fields into a table only you can read; until that work lands, they are technically still reachable through the database API by a signed-in account that goes looking for them. We would rather say so than imply otherwise.
- Memorials — the creator and the people they invite (Keepers, Archivists, Storytellers, Visitors). A memorial opened from a physical tag or a shared link is visible to anyone holding that tag or link; the creator controls whether it is public.
- Gift and event albums — the family that owns the album. See Occasions below for venue-hosted albums.
- Media files — the database checks permissions on every record it hands out. The photo and video files themselves are served from long, unguessable storage links rather than individually access-checked ones, so anyone holding such a link can open that file. Treat a copied media link like the photo itself. Moving media behind short-lived, per-person links is work in progress.
What we measure (it is not anonymous)
The app records product events so we can see what works. Each event is stored with your account id, the event name, whether you are on iPhone or Android, and a few properties. It is not anonymous, and there is no opt-out today. If that matters to you, please write to us — it is the kind of thing we will build if people ask.
- What is recorded — things like signing in, finishing onboarding, sending an invitation, creating or viewing a memorial, viewing an album, posting a memory, adding a comment, opening a family room, scanning a QR tag, opening the paywall, and completing a purchase.
- The properties — identifiers and counts, not content: the id of the memorial, album, family room, or venue involved; the amount of a purchase in cents; the code on a QR tag you scanned; whether a post had media and how many items; the privacy setting you chose.
- What is never recorded — your photos, captions, messages, names, or email addresses. Events carry ids and numbers, never the words you wrote.
- Where it goes — nowhere. These events stay in our own database. There is no third-party analytics service, no advertising SDK, and no attribution tracking in Reverie.
These events are included in your data download, so you can read exactly what is there.
Visits to a memorial
When a signed-in member opens one of your memorials in the app, we record that a visit happened: the memorial, the visiting member's account id, and the time. At most one visit per person per memorial per day. The memorial's owner can see that visits happened and when.
No location is recorded. Not a city, not a country, not coordinates. An earlier version of this policy said we recorded an approximate city; that was never true and the claim is gone. Scans of a physical tag by someone who is not signed in are not recorded at all.
Remembering someone
When someone in your circle dies, a person they were connected to can create a memorial for them and mark it as being about them. Doing so carries that person's existing family-visible posts onto the memorial, where the memorial's keepers can tend them. Their private posts are never carried.
Two things worth knowing. Only someone with an accepted connection to that person can do this — a stranger cannot. And the person's account itself is not changed, closed, or notified. If a memorial has been made about you or someone in your family and it should not have been, write to us at hello@reverielife.co and we will undo it.
The Legacy Vault
The vault holds the things you want to leave behind: letters to specific people, letters scheduled for a future date, funeral wishes (burial, songs, readings, dress, flowers, donations), recipes and traditions, and scanned documents. You can name up to three trusted people from your circle, and you can address a letter to a person by name even if they are not on Reverie — that name is stored with the letter.
Today, nothing in your vault is visible to anyone but you. The app describes a release process where your trusted people agree that the time has come and the vault opens. That process is not switched on yet: there is no way, for you or for us, to release a vault. Naming a trusted person does not give them access, and does not notify them. Until the release process ships, please treat the vault as a private place you are preparing — and tell the people who matter where your wishes are.
Occasions and guest albums
A venue can set up an Occasion — a funeral repast or a celebration — and put a card with a code on the tables. Guests add photos by scanning it, with no account and no sign-in. We store the photo, the display name the guest types, an optional short note, and an anonymous code that identifies that guest's device for the evening so we can cap how much one person uploads. No email address, no account, no location.
Until the family claims the album, it belongs to the venue's account, and the staff member who created it can see and remove the photos guests added. The moment a family member claims it with the code, the album transfers to them and the venue loses access to the photos entirely — from then on the venue sees only counts: how many occasions, how many uploads, how many contributors, how many were claimed.
Family plans
One Reverie Family subscription covers the person paying and up to 12 people in their circle. Coverage is worked out from your connections; nothing is shared between the accounts. The person paying cannot see any of the covered members' content — not their photos, not their memorials, not their albums — and is not shown a list of who is covered. Covered members are shown the first name of the person covering them, so they know who to thank.
People who are not on Reverie
Some things in Reverie mean we hold an address or a name for someone who never signed up. Here is all of it, and how to get it removed.
- Invitations — when a member invites someone by email, we keep that email address and a one-time invite code so the link works. If they never join, the invitation expires but the row stays until the person who sent it deletes their account.
- Memorial followers — a visitor to a public memorial page can leave an email address to be told when the family adds something. We keep the address, an optional name, and an unsubscribe token. Every email has a one-click unsubscribe link. Unsubscribing stops the emails; the row is kept, marked unsubscribed, so we do not accidentally re-add you.
- Waitlist and notify-me — an email address, an optional name, and which page you signed up from.
- Gift albums — when a member creates a gift album for someone, they enter that person's name and email address. The address is how the recipient gets access when they sign in; we do not currently email them.
- Guest-book messages — a visitor signing a public memorial leaves a name, typed by them, and a message. No email address, no account, no location. The memorial's owner and circle are notified that a message arrived.
- Occasion guests — as described above: a display name, an optional note, and an anonymous device code.
- Spam protection — when anyone uses a form on this website, we hold a rate-limiting record keyed to their IP address for up to 24 hours, then delete it. That is the only place an IP address is stored.
If any of this is about you and you want it gone, write to hello@reverielife.co from the address in question and we will delete it. You do not need an account to ask.
Where it lives, and who else touches it
Your data is stored with Supabase on servers in the United States. It is encrypted in transit and on disk by the hosting provider. We do not add a second layer of encryption of our own, which means we can read what is in the database — that is how support, exports, and the weekly digest work.
These are the companies involved in running Reverie, and what each one is for. We do not sell data to anyone, and none of these are advertising companies.
- Supabase — the database, file storage, and sign-in. Hosted in the United States. This is where everything lives.
- Vercel — hosts this website.
- Expo — delivers app updates and passes push notifications to Apple and Google.
- Apple and Google — distribute the app, and handle subscription payments. Apple also delivers push notifications to iPhones.
- RevenueCat — tells us whether your subscription is active.
- Stripe — takes payment for physical tags and gift orders, and receives your shipping address so the order can be fulfilled.
- Resend — sends our email: invitations, memorial updates, the weekly family digest, and your export link.
- Cloudflare — the spam check on the public forms on this website.
- Sentry — crash diagnostics. It ships inside the app but is switched off; no crash data is being sent today. If we turn it on, this page will say so before we do.
Notifications and email
Push notifications are per-category and per-device: you choose which kinds you want in Settings, and you can turn them all off there or in your phone's settings. We send one recurring email to members — a Sunday digest of what your family shared that week, birthdays coming up, and memorial anniversaries. It is on by default and turned off in Settings under Notification Preferences. Everything else we send is a reply to something you did.
Reporting and blocking
You can report a post, comment, profile, message, or guest-book entry from the menu on it, and you can block another member. A report stores who reported it, what was reported, a reason, and anything you type in the box. Reports are read by a person — there is no automated moderation in Reverie.
Blocking takes effect immediately and works in both directions: neither of you sees the other's memories, comments, or profile, any connection between you is removed, and no notification crosses a block. The person is not told. You can unblock from Settings.
Your choices
- Download my data — in Settings. We gather everything you have shared into one JSON file: your profile, memories, comments, memorials and their albums, your vault, your circle, your orders, and the usage events above. Your photos and videos are included as download links that work for 7 days. The app shows you the file when it is ready, and emails you a link too. One export per day.
- Delete my account — in Settings. See below for exactly what happens.
- Notifications — off, or per-category, in Settings or in your phone's settings.
- Being found — you can hide your profile from search in Settings, so people can only reach you by invitation.
- Correcting things — edit your profile in the app, or write to us.
Deleting your account
Deleting from Settings is immediate. There is no waiting period and no way to undo it. It removes your profile, your memories and their photos and videos, your memorials and albums, your private journal, your vault, your connections, your orders, and your notification settings — and then deletes the sign-in account itself. Your photo and video files are deleted from storage along with the records.
Three honest caveats:
- What you added to other people's memorials goes with you. Guest-book messages you signed, voice memos you recorded on someone's memorial, candles you lit, comments, and photos you added to another family's album are deleted too. An earlier version of this policy said they stayed; that was wrong. If you want to leave something behind for another family, tell them before you delete, so they can keep their own copy.
- A few records survive without your name on them. The usage events described above remain, with the account id removed; so do reports you filed, and photos you added to someone else's gift album. They can no longer be connected back to you.
- Backups. Deleted content is gone from the live service at once, but our provider's backups are kept for up to 30 days before rolling off.
How long we keep things
- Your content — for as long as your account exists. We do not expire, archive, or delete memories, and we do not delete anything because a subscription ended.
- Usage events — 12 months.
- Memorial visit records — 12 months.
- Rate-limiting records with an IP address — up to 24 hours.
- Your data export — the file and its links stop working after 7 days, and a new export replaces the old one.
- Backups — up to 30 days.
- Invitations, followers, waitlist entries, and gift recipient addresses — until the account that created them is deleted, or you ask us to remove yours.
Children
Reverie is for people 13 and older. We do not ask your age when you sign up, so this is a rule rather than a check — if you tell us an account belongs to someone younger, we will close it and delete what is in it.
Children do appear in Reverie, in two ways. They appear in family photos and stories the way they appear in any family album. And a parent can create a vault about a child — a time capsule holding the child's name, date of birth, photos, and letters written to them, to be opened at an age the parent chooses. That content belongs to the parent's account. The child has no account and no separate control over it; the parent can edit or delete all of it at any time, and it is included in the parent's data export and deleted with the parent's account.
This website
reverielife.co sets no cookies, runs no analytics, and loads no third-party scripts. Three forms send us something: the guest book and follow form on a public memorial page, and the notify-me form. They go through one spam-checked endpoint that keeps a rate-limiting record of your IP address for up to 24 hours and then deletes it.
Changes and contact
If this policy changes in a way that matters, we will tell you in the app. One address for everything — privacy questions, removal requests, or telling us something here is wrong: hello@reverielife.co. A real person reads it.