Privacy

Your privacy.

Version draft-2026-10-06b · Updated 6 October 2026. Unpublished owner-test draft; operator and contact verification and legal review remain required.

What Mindument and SurpassLife.com keep, where it lives, and who can see it, in plain words.

This is a draft, written from Mindument as it is built today. A lawyer will review it before Mindument launches, and it will change whenever what we keep changes.

The short version

  • Your original recordings stay on your phone in the current owner-test build. Cloud backup and company transcription are off; live transcription uses on-device recognition only.
  • No advertising trackers or behavioral analytics are included in this build. We do not sell your personal information or use it for targeted advertising. Sharing you choose, service providers for an enabled feature, and legally required disclosures are described below.
  • Company cloud, model-filled replies and generated-voice flows are disabled in the public configuration. Manual exports and sharing you choose can still leave your phone; Privacy shows enabled company data flows.
  • You can export your local personal archive as plain files or erase it using the app controls. Independent copies and any future company records follow the limits and retention rules below.

What the app keeps on your phone

  • About you: the name you give, the pronoun you choose, and your spoken consent: when you gave it, the consent version and time, and an original spoken-consent recording if you choose to keep one. A displayed consent script is not treated as a transcript of what you actually recorded.
  • The people you name: their name, who they are to you, and, if you add them, a contact and a birthday, so a birthday message plays on the day.
  • What you record: the audio exactly as you recorded it, never edited or re-encoded, with the question it answered, who it is for, the date and a transcript.
  • A family helper: a helper can assist with larger questions. New shared or helper-only voice recordings are off pending consent and legal review. Older family archives may contain separately labelled helper recordings; those never become the account holder's likeness.
  • The space you build: the colours, the photographs you choose and your words on the door.
  • Your corrections to the likeness: what it said, and what you would have said.

It lives in the app’s private folder on your phone. On Android, the app’s data is kept out of cloud backups, so your recordings are not copied anywhere without you knowing.

Your optional profile and privacy choices

Your Profile under More lets you add or change your name, email address, phone number, birthday, favourite things and bio. These details are optional apart from your display name and are stored with your local archive. Optional fields default to Private. Choosing Shared with your people allows that field into a recipient copy; choosing Private excludes it. This does not send an invitation or verify a contact address. Your own full export includes your private profile so you can restore it; keep that copy secure. Changing a field does not change old consent records or original memories. You can clear optional fields later. Page appearance choices are stored locally. Built-in sample material is separate from your personal originals and excluded from personal exports and likeness inputs. A sample voice is not a recording of the person using the app. Your setup color, hobby and mood answers and unfinished setup progress are also saved locally so you can resume.

Your phone’s own speech recognition

When you answer by talking, the app requests on-device recognition only. If your phone does not support it or lacks the needed language model, you can type instead or keep only the audio. The app does not start browser or network speech recognition in this build.

What will leave your phone later, and only when switched on

None of these is switched on today. Each one will be described here in full, and reviewed by our lawyer, before it is.

When hand-over is enabled, each person would receive the originals shared with everyone you chose and those addressed to them, together with the space you designed for them. Other people’s messages, door photographs and contact details, and your private portrait, would be excluded. Corrections you make to guide your likeness would remain part of its instructions. Your original archive would stay unchanged.

  • A copy kept with SurpassLife: your archive and original recordings would be stored in Amazon S3, encrypted with AWS KMS and a separate key derived for your account. Our service decrypts them only for an authorised restore, export or hand-over. Access to the service and its secret must be restricted and audited; someone with privileged access to both could technically read a copy. This keeps your archive available if you lose your phone and lets a hand-over reach your family. After the 14-day account-deletion period, the service requests removal of every stored version, subject to the final legal retention rules.
  • The hand-over: the names, email addresses and mobile numbers of the people you chose, so that when the time comes they receive one invitation by email through Amazon SES and one by text through Amazon SNS. Never a reminder. It opens only with a code sent to their email and a code sent to their phone, together. If someone reports a death, we email the account holder and wait 14 days for an objection; an uncertain warning stays with staff for review and blocks release. A confirmed non-delivery can be resent with a fresh 14-day wait.
  • Checking who receives it: before anything is released, we verify the identity of the person receiving it, because your recordings may hold private things. We keep only that the check passed, when, and who checked it.
  • Turning speech into text on our own server: one recording at a time. The audio is deleted from that server as soon as the text is made.
  • Your likeness’s replies: your recorded words and the question asked, so the likeness can phrase a reply in your manner. Never used to train anyone’s model.
  • A likeness that speaks in your voice: only with your separate, recorded consent. Every reply it speaks is marked as AI. Deleted when you delete the voice or your account.

Planned recipient accounts

Planned Android purchase recovery would query Google Play when purchasing and accounts are both enabled, including on sign-in and return to the app. The app would send purchased subscription tokens to SurpassLife for verification against the signed-in account; Google Play would use an obfuscated account identifier; pending payments would not grant access. Tokens would remain only in memory on the phone. Sign-out, account or server changes, backgrounding and local erasure would invalidate that billing session and its pending replies. Public purchasing remains off; live store testing and owner/legal review are still required.

Planned authenticated Google Pub/Sub notifications would deliver the app package, event time and purchase token when a subscription changes. The service would verify the expected sender, audience and subscription, then recheck only receipts already retained for available accounts. A notification alone would not grant membership. We would not retain the incoming notification body or identity token.

For an authenticated full subscription refund, the service would compare a one-way hash of the refunded Google order with a hash of the verified current order. Refund hashes would remain with your encrypted receipt until account purge, so a later check cannot restore that refunded payment or cancel a different paid renewal. Raw order identifiers would not be retained. Partial refunds and refund review procedures still require implementation and owner/legal review before billing activation.

Planned recovery of missed notifications would check every page of Google's available 30-day full-refund history. Response bodies and page tokens would be used only in memory. The service would retain each receipt's last successful refund-check time and require it to be less than 15 minutes old for paid access; a failed check would not extend that time. Proposed checks would run every five minutes and after restart or a newly retained receipt. Gaps beyond Google's history window would require staff review for that receipt before paid access could resume. These settings and recovery procedures require owner/legal review before activation.

Proposed Google access checks would run every five minutes for subscriptions still being checked. Paid access would require a successful verification less than 15 minutes old. A provider outage could temporarily pause paid features after that limit; original recordings and free export remain available. These settings require review before purchases are activated.

To recheck Google renewals, suspensions or refunds without another receipt submission, the service would keep the purchase token encrypted with a separate key derived for your account. This private receipt store would not appear in membership responses, recordings or recipient exports, and would be removed when your account is purged. Automatic subscription updates and review remain required before purchases are enabled.

After verifying the account and purchased subscription, the service would acknowledge a pending Google Play purchase and check its state again before granting access. Acknowledgement would not replace the account identifier. Purchases remain disabled pending store integration and review.

Planned Google Play verification: the service would send the app package name and purchase token to Google's Play Developer API to check the product, subscription state and dates. Purchases would include an obfuscated SurpassLife account identifier that must match the signed-in account. We would retain a hashed purchase reference, verified product, dates and access state, not payment-card details. Store setup, subscription updates and approval remain required before purchases are enabled.

Planned recovery: if a recipient asks support for a replacement after an invitation expires or an unlinked accepted space is lost, staff may send a new invitation to the original email and mobile number. We would record a case reference, the operator and time, invalidate the old invitation, and require fresh email and text codes and a fresh identity check. This is requested recovery, never a reminder. Linked accounts use saved-space restore. This action does not change contacts.

This company flow is off in the public app. After accepting an identity-verified hand-over, a recipient could link that invitation to their own email-code account. We would keep the linked account ID and linking time to restore only their saved space and derive access from the funded period and their own verified purchases. Their signed-in email must match the chosen recipient. The link gives no access to the creator's account or another recipient's material. Export stays available when membership lapses. Account deletion removes this link when that account is purged; the creator's archive follows its own retention rules. Payment providers are not configured, and review is required before activation.

Until a recipient links an accepted space, the device may remember its download proof and service address in Keychain or Keystore, outside the archive. The browser test preview uses localStorage, which is not secure storage. The proof is cleared after linking or local erase, and the server rejects it after expiry. Sign-in still requires the email chosen for the invitation.

Planned web membership checkout

Stripe checkout is not enabled. If enabled later, we would send Stripe a hashed account reference and the selected plan. To prevent duplicate checkout sessions and recover interrupted requests, we would keep an account-linked checkout reference, plan, request fingerprint, attempt date and state, and Stripe session ID and expiry. After a deletion request, we would use a known session ID to ask Stripe to close a payment session that is still open. Completed payments would need separate review; this would not automatically refund a payment or cancel a subscription. An unsuccessful cleanup would not extend the account deletion grace period. This record would not keep your hosted payment link, card or bank details, raw payment responses, or secret keys. It would be removed when your account is purged, subject to the final legal retention schedule. Legal review and payment verification are still required before launch.

Planned Stripe notification recovery would keep event and checkout, subscription or charge references, a routing fingerprint, delivery and retry times, processing state and linked account references when known. These small records would let background verification recover delayed or repeated billing events. Charge recovery would read payment and invoice references from Stripe to find an already retained membership. For older charges, a limited search may read unrelated payment references in memory; we would not retain them. An incomplete search would need retry or review. We would not keep raw webhook bodies, signatures, card or bank details, or provider exception messages. Account-linked records would be removed on purge; final retention and retry rules still need legal approval. This flow remains off.

For an interrupted checkout whose session ID was not saved, planned cleanup would search a limited set of Stripe sessions created since that attempt. A unique match must prove its account and plan before cleanup. Unrelated session data would be read only in memory, not retained. An incomplete, conflicting or empty search would need review or retry. This flow remains off.

An account on SurpassLife.com

You can create an account here with your email address. We send a six-digit code to that address to sign you in; there is no password. If you join the waiting list, we keep that you joined and when, and we email you once, when Mindument is ready to download. Nothing else is sent. You can leave the waiting list at any time from your account. Company news is shown in your account, not emailed.

You can also join the wishlist with just your email address, no account. We keep the address and the language you chose, send you one confirmation with a link to leave, and one email when Mindument is ready to download, with the link. Nothing else is sent, and the link in the confirmation takes you off the list at any time.

The local site does not use advertising cookies or behavioral analytics. It stores language and appearance choices in localStorage and a sign-in session in the current tab when sign-in is enabled. Local storage is not a tracking cookie, but is still browser storage. A deployed web server and enabled account service necessarily receive connection details such as network address and request information; the service uses network addresses for abuse-rate limits. Final hosting/access-log settings, retention and any additional browser storage must be disclosed and checked before public deployment. A browser or hosting provider may apply its own storage or logging outside our code.

Downloading from an invitation

When an approved Android download is available, the private invitation page may offer a link to Google Play or SurpassLife’s download page. It opens only when you choose it. The link does not contain your invitation token, and the page sends no referrer. The download service receives an ordinary browser request under its own privacy terms. Keep the invitation and return to it after installing; downloading does not accept it or release any recordings. This option is not configured for public use yet.

Who can see it

With public cloud features disabled, the app does not upload your personal recordings to SurpassLife. Someone with access to your unlocked device, an exported file or a copy you share may nevertheless see them. Enabled website-account records are distinct from local memories. A future hosted archive could be accessed by authorized services and, in limited support/security/legal circumstances, authorized personnel as disclosed; it would not be a promise of zero technical access.

Export and deletion

  • Export: from Export and restore under More, the app makes one ZIP containing plain files: the original audio, your chosen photographs, text and JSON. Save the ZIP outside the app through your phone’s share sheet. An ordinary ZIP tool opens it; you do not need Mindument to read the contents.
  • Delete: the Privacy controls erase the local archive after confirmation; they do not erase every file on your phone. Uninstalling generally removes app-private data, but device settings and platform behavior can affect this. Exported ZIPs, photos retained in your photo library, recipient copies and external backups must be deleted separately where you control them.

Children

Mindument is for adults recording themselves. The current owner-test build permits new voice recordings only of the account holder; older family archives may contain separately labelled helper recordings. It is not directed to children and does not permit under-18 account holders or creators. An adult archive can mention or contain a lawful photograph of a child; that is not a child account or permission to record the child’s voice. If we learn an enabled service has collected information directly from an ineligible child, we must restrict it and handle deletion or other steps required by law. Age and child-recipient safeguards require review before public delivery.

The likeness

Generated voice and model-filled replies are disabled in the current public configuration. Any future likeness must be labelled and designed to rely on the creator’s authorized material, decline unsupported topics and avoid impersonation or invented memories, apologies or admissions. Automated output can still be wrong; important statements should be checked against original recordings. Mindument is grief support, not counselling or therapy.

Written consent and attached memories

Final setup requires an unchecked Terms agreement. We keep the exact agreement wording, document versions and fingerprints, language, acceptance time and the profile or verified account reference. Email-code records use the existing security logs; no voice permission is inferred. Optional written notes, chosen photos and finger drawings are saved with the memory on your phone. The automatic-save preference is off until you choose Yes; it saves on Back. Provider flows remain off.

Sources, purposes and necessary disclosures

Local memories come from what you enter, record or select through your device permissions. Account and invitation data, if enabled, come from you, the creator who names a recipient, and verification or payment services expressly described here. We use them to provide the chosen function, record consent, protect accounts, respond to requests and meet legal obligations. We do not sell personal information or use sensitive memories for targeted advertising. A company does not receive an archive solely because you added a recipient or accepted general Terms.

If an online service is enabled, contracted hosting, messaging or payment providers may receive only the information needed for their disclosed role. Authorized recipients receive only the copy you choose under the applicable delivery process. We may make a limited disclosure when legally required, to respond to valid legal process, or where applicable law permits and a documented security or safety need justifies it. We assess necessity, limit the data and notify you where lawful and appropriate. A business transfer is not blanket permission to change purposes or disregard existing choices. No prospective vendor or new purpose is authorized merely by appearing in this draft.

Retention, deletion and separate copies

Your local archive remains until you erase it or the app-private storage is removed. Ordinary exported files are not promised to be encrypted, and sending them through a share sheet may send them to another app, cloud service or person you choose. We cannot retrieve an independent recipient copy or control their later actions. Withdrawal of a feature permission applies to future processing that we control; it does not automatically erase another person's lawful independent copy or invalidate earlier lawful processing.

Before any hosted feature launches, the final policy must publish verified retention periods or clear criteria for account records, security logs, consent evidence, payment records, archives and backups. The currently planned account-deletion process includes a 14-day period before purge; it is not a promise of immediate erasure from every system. A lawful, documented retention exception for a specific dispute, security investigation or required record must be limited to necessary data, access restricted, and removed when no longer justified. Any statutory biometric destruction deadline takes precedence; a general consent-record exception must not silently preserve biometric data beyond that deadline. Exact backup deletion and subscription cancellation behavior must be verified before activation.

Voiceprints, biometrics and sensitive memories

An ordinary voice recording or photograph is not automatically a biometric identifier; deriving a voiceprint, face geometry or an identifying template can trigger additional laws. This build does not enable voice cloning, face-identification or identity-provider biometric collection. General Terms acceptance and a spoken recording do not replace a required informed written or electronic biometric release. Before collecting such data, we must identify the specific purpose, data, recipients and duration, publish the applicable retention/destruction policy, obtain the required separate authorization and support lawful withdrawal and destruction. No sale or profiting from biometric information is authorized.

Memories may contain health information, relationships, beliefs or other sensitive details even though we do not provide medical care. Do not put information in an archive that you do not have authority to disclose. We do not represent that every user archive is covered by HIPAA or that these documents establish HIPAA compliance. Consumer-health, recording-consent, publicity and other applicable privacy requirements must be assessed for the actual launch markets and implemented before affected processing starts.

Security and incidents

Device isolation and any future encryption reduce risk but do not eliminate unauthorized access, loss or operational failure. Protect your device and independent exports; do not send sign-in codes, invitation tokens or full archives in an ordinary support request. If a confirmed incident affecting personal information occurs in systems we control, we must investigate, contain it and provide notices to affected people and authorities when required by applicable law. This policy does not waive legal security, notification or service-provider oversight obligations.

Your requests and location-specific rights

Local editing, export and erasure controls do not require a company account. For records held by an enabled company service, you may request access, correction, deletion or a portable copy through its verified privacy contact. Depending on applicable law, you may also have rights to restrict or object to processing, withdraw consent, use an authorized agent, appeal a refusal or complain to a regulator. We may need proportionate identity verification and may explain a lawful exception; deadlines and fees follow applicable law rather than an unrestricted discretion to deny requests. We do not retaliate for exercising applicable privacy rights. If withdrawal makes a consent-dependent feature unavailable, that consequence must be explained. Intended countries, state-law coverage, international transfers and any required lawful bases must be settled before public collection; this draft alone does not establish international compliance.

Contact and legal operator

This unpublished owner-test preview has no verified public support/privacy channel. SurpassLife is the project and brand name. Before public collection or launch, the final policy must identify the verified legal operator, mailing address and a working contact for privacy requests, consent withdrawal, security reports and rights complaints. Do not send sensitive personal information to an unverified address. These missing details are a launch blocker, not a completed contact mechanism.

Waiting list

Be the first to know.

Create an account to join the waiting list for Mindument. We will email you once, when it is ready to download on Android and iOS. In your account you can read SurpassLife’s news.

Create an account