Privacy Policy
At 2WIMC, we understand that you're entrusting us with your most precious family memories. This privacy policy explains exactly how we protect and handle your personal information and recordings.
1. Information We Collect
Personal Information
When you create an account or use our services, we collect:
- Name and email address
- Payment information (processed securely by Stripe)
- Account preferences and settings
- Communication preferences
Recording Data
The core of our service involves collecting and storing:
- Audio recordings you create
- Metadata about recordings (title, date, duration)
- Story prompts and responses
- Photos you choose to upload
- Family member email addresses for sharing
Technical Information
To provide and improve our service, we automatically collect:
- Device information and browser type
- IP address and general location
- Usage patterns and feature interactions
- Error logs and performance data
2. How We Use Your Information
Primary Purposes
- Service Delivery: Store, process, and deliver your recordings to family members
- Account Management: Maintain your account and billing information
- Customer Support: Respond to your questions and technical issues
- Security: Protect against unauthorized access and fraud
Secondary Purposes
- Service Improvement: Analyze usage patterns to enhance features
- Communication: Send important updates about your account or service
- Legal Compliance: Meet legal obligations and protect our rights
3. Information Sharing and Disclosure
Limited Sharing
We only share your information in these specific circumstances:
- Family Members: Only with people you explicitly authorize to access recordings
- Service Providers: Trusted partners who help us operate (hosting, payment processing, customer support)
- Legal Requirements: When required by law, court order, or to protect rights and safety
- Business Transfer: In the unlikely event of a merger or acquisition (with strict data protection requirements)
Service Providers
We work with carefully vetted partners who must meet our strict security standards:
- Google Firebase: Secure cloud storage and authentication
- Stripe: Payment processing (they never see your recordings)
- Netlify: Website hosting and delivery
4. Data Security
Protection Measures
- Encryption: All data is encrypted in transit and at rest
- Access Controls: Strict authentication and authorization systems
- Regular Audits: Ongoing security assessments and monitoring
- Secure Infrastructure: Enterprise-grade cloud security
Your Responsibilities
- Use strong, unique passwords
- Keep your account credentials confidential
- Log out from shared devices
- Report suspicious activity immediately
5. Your Rights and Choices
Access and Control
You have the right to:
- Access: View all personal information we have about you
- Correct: Update or fix incorrect information
- Delete: Request deletion of your account and all associated data
- Download: Export your recordings and data
- Restrict: Limit how we process your information
Family Member Access
- You control exactly which recordings each family member can access
- You can revoke access at any time
- Family members cannot share recordings with others without your permission
6. Data Retention
Account Data
- Active Accounts: We retain your data as long as your account is active
- Inactive Accounts: Data is deleted after 2 years of inactivity (with advance notice)
- Deleted Accounts: All data is permanently deleted within 30 days
Recordings
- Recordings are kept according to your plan terms
- You can download and delete recordings at any time
- We maintain secure backups for 90 days after deletion for recovery purposes
7. International Transfers
Your data may be processed in countries other than your own. We ensure appropriate safeguards are in place, including:
- Standard contractual clauses approved by regulatory authorities
- Adequacy decisions for certain countries
- Certification under recognized privacy frameworks
8. Children's Privacy
Our service is designed for adults creating recordings for their families. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child, please contact us immediately.
9. Changes to This Policy
We may update this privacy policy from time to time. When we do:
- We'll notify you by email and through our service
- We'll give you 30 days to review changes before they take effect
- Material changes will require your explicit consent
- You can always view the current version on our website
10. Contact Us
Questions about this privacy policy? We're here to help.
Email: privacy@2wimc.com
Phone: (555) 2WIMC-01
Mail:
2WIMC Privacy Officer
[Your Business Address]
[City, State ZIP Code]
Response Time: We respond to privacy inquiries within 48 hours.
11. State-Specific Rights
California Residents (CCPA)
If you're a California resident, you have additional rights including:
- Right to know what personal information we collect and how it's used
- Right to delete personal information
- Right to opt-out of the sale of personal information (we don't sell your information)
- Right to non-discrimination for exercising your privacy rights
European Residents (GDPR)
If you're in the European Union, you have rights under GDPR including:
- Right to access, rectify, and erase your personal data
- Right to restrict or object to processing
- Right to data portability
- Right to lodge a complaint with supervisory authorities