Last updated 16 August 2026
Privacy
Preservation holds recordings of people's voices and the things they chose to say about their own lives. That is about as personal as data gets, so this page is written plainly and says what actually happens, including the parts that are still being built.
Who we are
Preservation is an early-stage product, small enough that the person who built it is the person who answers you. It is in active testing, which means real families are using it while features are still being added. If you would rather wait until it is finished, that is a reasonable thing to do.
Questions, requests and complaints all go to the same place: the contact page. A person reads every one of them, and it reaches us directly rather than sitting in an inbox nobody watches.
What we collect
Only what an archive needs to exist:
- Your email address, which is how you sign in. There is no password to store or leak.
- The name and details you enter about the person whose archive it is.
- Recordings, video if you turn the camera on, photographs, documents and anything typed in.
- Transcripts of the recordings, and the questions asked and skipped.
- Ordinary technical logs: which pages loaded, and errors, so failures can be fixed.
We do not collect anything for advertising, we do not buy or sell personal data, and there are no third-party advertising or tracking scripts on this site. Site analytics are Cloudflare Web Analytics, which is cookieless and does not fingerprint or profile visitors.
Who can see an archive
Archives are private by default. Nobody sees one unless the person who owns it grants access, either by inviting an email address or by sharing a family link, and any link can be cut off at any time.
On the company side: the founder can technically access archive data, because during testing someone has to be able to diagnose a failure and restore a lost recording. That access is used for support and operations, not for reading families' stories, and there is currently no other employee. As the team grows, this page will say so and access will be restricted and logged.
Where it lives, and who processes it
Data is stored on servers in the United States. If you are outside the US, using Preservation means your information is transferred there.
These outside services process parts of an archive:
- Railway, which runs the application and stores the database and media.
- Cloudflare, which serves the domain, and provides cookieless analytics and the encrypted off-site backup storage.
- OpenAI, which transcribes recordings, generates follow-up questions, and answers questions about an archive. Content sent through their API is not used to train their models.
- Resend, which delivers sign-in codes and notification emails. It sees email addresses and the contents of those messages.
- ElevenLabs, where a demonstration voice is generated. No family's recordings are sent to it.
Backups run nightly to encrypted storage and exist so that a family's recordings survive a server failure. Because backups are point-in-time, deleted material can persist in them for up to thirty days before ageing out.
Voice, likeness and AI
Recordings are never used to train public AI models, and they are never used to generate a synthetic version of anyone's voice unless that person, or their family, has explicitly turned that on. It is off by default and the original recordings always remain exactly as spoken.
When the archive answers a question, it answers from the material in that archive and shows where each answer came from. It does not claim to be the person. See the FAQ for the longer version.
Deleting things
Photographs and written entries can be deleted yourself, immediately, from the archive's add page.
Deleting individual recorded answers and deleting an entire archive are not yet self-serve. Until they are, ask through the contact page and it will be done, including from backups at the next cycle. This is a real obligation, not a courtesy: if you ask us to delete an archive, we delete it. Self-serve deletion is being built, and this paragraph will change when it ships.
You can also export everything at any time, from the archive's family page: original recordings, photographs, documents and every story as plain text, in one download that opens without Preservation.
Your rights
Wherever you live, you can ask what we hold about you, get a copy, have it corrected, or have it deleted. If you are in the UK, EU, or a US state with its own privacy law such as California, those rights are legal entitlements rather than favours, and they include the right not to have personal information sold, which we do not do.
Requests go through the contact page and are answered within thirty days, usually far sooner.
Children
Preservation is not designed for children to sign up for, and accounts are for adults. Children obviously appear in family photographs and stories, which is normal for a family archive; that material is controlled by the adult who owns the archive.
If the company changes hands
If Preservation is ever acquired or shut down, archives go with it under these same terms, and you will be told before anything changes. Nobody gets to quietly acquire your family's recordings under looser rules than the ones you agreed to. If Preservation shuts down, families will be given notice and a window to export everything.
Changes to this page
When this page changes in a way that matters, the date at the top changes and account holders are emailed. Silent rewrites of a privacy policy are a bad sign in any product, and especially in this one.
Questions about any of this? Write to us.