Privacy & Security
What’s protected, how — and the exceptions.
A plain-language explanation of how RYMVI protects your library. The legally binding version is the Privacy Policy; this page is written to help you decide what to turn on.
On your phone
Your memories, categories, and the photos, videos and files you save are stored on your phone. RYMVI encrypts them there with a key kept in your phone’s secure storage (the iPhone Keychain, or the Android Keystore).
App lock (optional, off by default). In Settings → Privacy → App lock you can have RYMVI ask for Face ID, Touch ID, your fingerprint or your phone’s passcode before it shows your memories — immediately or one minute after you leave the app, and always when it starts. It uses your phone’s own security: your phone checks your face, fingerprint or passcode and only tells RYMVI whether it succeeded; RYMVI has no separate PIN or password and never receives your biometrics or passcode. Anyone who can unlock your phone with its passcode, face or fingerprint can also unlock RYMVI.
RYMVI Cloud (optional)
On plans that include RYMVI Cloud storage, you can turn on Cloud Sync to keep your phones in step and restore your library on a new one. It’s off until you turn it on, and RYMVI Cloud is being introduced gradually, so it may not be available to you yet. Your cloud library is stored on Google Cloud (Firebase) in the United States.
End-to-end encryption
You can choose end-to-end encryption for your cloud library. Your content is then encrypted on your phone, with a key RYMVI doesn’t have, before it’s uploaded — so RYMVI and its providers can’t read your memories, notes, captions, summaries, photos, videos or files.
To make sync work, the server can still see some operational details: each item’s type (post, photo, video and so on), when it was created and deleted, how many items and files there are and how big they are, the order of your categories, and your account’s sign-in details. It can’t see what any of them contain.
Adding a phone: device linking
With end-to-end encryption on, a new phone needs your key before it can open your cloud library. Signing in isn’t enough on its own. You give the new phone the key in one of two ways:
- Link it from a phone you already use. The new phone shows a one-time link code. You enter it in RYMVI on your existing phone and approve. Your key travels to the new phone encrypted with a one-time key that only the two phones can work out — RYMVI’s server passes it along but can’t read it. A link code works once and expires after 15 minutes.
- Use your recovery phrase. If you don’t have another phone with you, enter your recovery phrase on the new phone.
Only approve a link for a phone you are setting up yourself, right now.
Recovery: your account vs. your encrypted library
Getting back into your account
Forgotten your password or lost your phone? Sign in again with your email (and a password reset if needed) or with Google. RYMVI support can help you regain access to your account.
Opening your encrypted library
With end-to-end encryption on, your library also needs your key: your 24-word recovery phrase, or a phone that already holds the key. Recovery always needs you signed in and one of these.
When content is processed readably
Some features can only work if the content is readable for the moment it’s processed — even when your cloud library is end-to-end encrypted. These only happen after you choose them.
AI features (after you allow them)
When RYMVI analyses a memory or answers a question, what that feature needs is sent to RYMVI’s servers and to AI providers: text, titles, notes and links, downscaled photos, and for a video either still frames and audio (processed by OpenAI) or the whole clip including audio (processed by Google Vertex AI through a United States endpoint). A video you analyse is uploaded to temporary storage and deleted once its analysis finishes.
Link previews (a separate choice)
When link previews are on, the address of a link you save is sent to RYMVI’s server, which fetches the page’s public title, description and preview image. Your phone then downloads that image from the website directly, so the website sees that request. Link previews are off until you choose to allow them.
Read AI & your data for more detail on what each AI feature sends.
Deletion and what’s kept
- Recently Deleted. A deleted memory stays in Recently Deleted on your phone for 30 days before it’s removed for good.
- Cloud deletion. Permanently deleting a memory also removes, from RYMVI Cloud, photos, videos and files no other memory uses. Two follow-up clean-up steps — retrying an interrupted file removal, and removing a deleted memory’s chat history — are currently paused, so that data stays on the servers (encrypted, if you use end-to-end encryption) until they resume or you delete your account.
- Deleting your account removes your RYMVI Cloud data and account records from RYMVI’s servers. Our storage provider can keep deleted files recoverable for up to 7 days before final removal.
- Purchase records (store transaction identifiers) are kept so a purchase can’t be credited twice.
- Backups you export stay wherever you saved them until you delete them there.
How to delete your account: Support → Delete your account.
Analytics and advertising
The contents of your memories — titles, notes, links, photos, videos, files, category names, AI conversations and precise locations — are never sent to analytics. This website uses no analytics or advertising cookies unless you allow them, and none are currently switched on. See Website data & analytics.
Reporting a security problem
If you think you’ve found a security issue in RYMVI or this website, email support@rymvi.com with “Security” in the subject. Please don’t include anyone’s personal data, passwords or recovery phrases.
