Privacy Policy
Last updated: July 16, 2026
Remi ("we", "us", "our") cares about your privacy. This policy explains the personal data we collect when you use the Remi mobile app, how that data is used, and what rights you have.
1. Data We Collect
1.1 Account Information
You can sign in to Remi with an email and password or with your Google account. A Spotify account is not required.
If you sign up with email, we collect the following:
- Email address
- Display name and username
- Your password — stored not as plain text but only as an irreversible hash (BCrypt); we cannot see your actual password either
If you choose to sign in with Google, we receive the following via the Google ID token:
- Google user ID (sub)
- Email address
- Display name
- Profile photo URL
Your Google password is never shared with us; verification is done through a short-lived token signed by Google Identity Services.
1.2 Music Listening Information
When you capture a memory, we record the following about the track playing at that moment:
- Track name, artist, album
- Album cover URL
This information is read from the notification of the music app playing on your phone (see 1.7). Notification access does not give us your music library, your play history, or the artists you follow — only the notification for the track playing at that moment is read.
If you link your Spotify account, we additionally ask for these permissions: the track playing now and its playback state, your recently played tracks, and your top tracks. Recently played is so you can pick a track from your history while capturing a memory; your top tracks are so we can show suggestions on the search screen. Both lists are fetched from Spotify at the moment you open that screen, shown to you, and never stored on our server — we keep no record of your listening history. Linking Spotify is entirely optional; if you don't link it, none of these permissions are requested.
1.3 Data You Enter
- Short note text (max 500 characters)
- Emotion tag (from 9 fixed options)
- Privacy preference (Public / Friends / Private)
- List of tagged friends
- Photos and voice notes you attach to a memory (see 1.3.1)
1.3.1 Photos and Voice Notes
You can optionally attach a photo and a short voice note to a memory. Both are entirely optional; if you don't add them, the memory is saved with just the track and your note.
Photos. The photo you pick from your gallery or take with the camera is uploaded to our server and re-encoded there: it is converted to WebP at a maximum size of 1080×1080, and in the process all embedded metadata is stripped — including the GPS location in the photo's EXIF, the camera model, and the capture time. In other words, we don't hold any record of where your photo was taken. (If you also attach a location to the memory, that is separate data and is explained in 1.4.) The photo permission is used only while you make a selection; we do not scan your gallery.
Voice notes. If you grant microphone permission, you can attach a short recording to a memory (up to 15 seconds on a free account, 30 seconds on Plus). Recording happens only when you press the record button, and only for that long — Remi never listens in the background or without your knowledge. The audio is converted to AAC, and amplitude values are extracted to draw the waveform. Audio content is not transcribed, not analyzed, and not used for advertising.
Who can see them. Photos and voice notes follow the privacy setting of the memory they're attached to: if the memory is "Private", only you (and the people you tagged in it); if "Friends", your friends; if "Public", all users. Media files are served over unguessable, time-limited (2 hours) signed links; they cannot be reached directly without a link.
Moderation. Uploaded media passes through a processing pipeline and, if it is reported for breaking the rules, can be reviewed and removed by an administrator (see Child Safety).
Deletion. When you delete a memory, the attached photos and voice notes go with it; once the 90-day undo window has passed, the files are permanently deleted from the server. If you delete your account, your media files are removed from the server entirely (see 5 and 7).
1.4 Location Data
If you grant permission, we record your precise location (latitude, longitude) at the moment a memory is captured, along with a human-readable name for that point (city/neighborhood). Location permission is entirely optional — if you don't grant it, the memory is saved without a location. You can revoke the permission at any time from Android Settings → Apps → Remi → Permissions → Location; previously saved locations remain unchanged after revoking, but new memories will be saved without a location.
1.5 Device and Notification Information
- Firebase Cloud Messaging (FCM) token — to send push notifications
- Device type and operating system version (for error diagnosis)
- App version
1.6 Crashlytics / Diagnostics
We use Firebase Crashlytics to report app crashes anonymously. These reports contain no personal data — only technical information such as the error stack trace, device model, and operating system version.
To improve the app's user experience, anonymous session analytics (screen interactions, heatmaps) are collected via Microsoft Clarity. Password and sensitive fields are automatically masked by the SDK; it contains no personally identifiable information.
1.6.1 Lyrics
You can view a track's lyrics using the "Show lyrics" button in the memory detail. Lyrics are not user data; they come from the lrclib.net open-source community and, as a fallback, from lyrics.ovh. The fact that you viewed a track is not shared with anyone. Rights holders can submit a takedown request to remithememory@gmail.com; the content is removed from the cache within 24 hours.
1.7 Notification Access (NLS)
To automatically capture the tracks that are playing, Remi uses Android's notification access (Notification Listener Service) permission. Although this permission grants the ability to read all system-wide notifications, Remi only parses notifications from the following music apps and does not read, store, or send to the server any notification belonging to any other app:
- Spotify (com.spotify.music)
- YouTube Music (com.google.android.apps.youtube.music)
- Deezer (deezer.android.app)
- Apple Music (com.apple.android.music)
- Tidal (com.aspiro.tidal)
- SoundCloud (com.soundcloud.android)
- Muud (com.ttnet.muzik)
- fizy (com.turkcell.gncplay)
- PowerAMP (com.maxmpz.audioplayer)
- Riff (com.musicmuni.riff)
Notifications from apps other than these (WhatsApp, Telegram, Gmail, banking apps, social media, calendar, etc.) are not even loaded into Remi's memory — a client-side whitelist filter ignores external packages at the first evaluation. There is also an additional defensive whitelist on the server side; even if the client filter is bypassed for any reason, the server rejects unsupported sources.
If you don't want a particular music app to be monitored by Remi, you can turn that package off from within the app via Settings → Monitored music apps. To revoke notification access entirely, you can remove Remi from Android Settings → Notification access.
Captured data: the track's name, artist, album, and (if available) duration. The content of notifications from other apps is not read: the message text of your messaging apps, your contact list, your banking notifications, your calendar events, and your emails are not collected by Remi. (Messages you send to each other within Remi are a separate matter — see 1.9 Messages.)
1.8 Listening Now
If this feature is on, when the track you're playing changes, the following information is sent to the Remi server and appears in your friends' "Listening now" list:
- Track name, artist, (if available) album cover
- Track source (Spotify / YouTube Music / Deezer / Apple Music / Tidal / SoundCloud)
- Display name, username, and profile photo URL
Your location, listening duration, the exact second you're at in the track, your playlist, library, or history are not shared. Only the "business card" of the track you say you're playing at that moment is sent.
Visibility levels (default ON + friends only):
- Friends only: Only users who are mutual friends with you can see it.
- Everyone: If you select this manually, all users on Remi can see this information on your profile.
- Off: No user can see it; your last record on the server is deleted immediately.
This data is not stored permanently on the server — it is only kept as a short-lived (a few minutes) temporary cache and is automatically deleted shortly after if you don't switch to another track. It is not written to the database.
Users you have blocked or who have blocked you — regardless of your visibility level — cannot see you (two-way block filter).
You can turn this feature off from within the app via Settings → Listening now. The moment you turn it off, your record on the server is deleted; until you turn it back on, no user can see you in the list.
1.9 Messages (Direct Messaging)
You can message one-on-one with users you are mutual friends with. The text of the message you send is stored on our server; along with the message, the sender, recipient, and time sent are kept.
Messages are not end-to-end encrypted. We're stating this plainly, because you need to know it: the message text sits in our database in readable form. Communication is encrypted with HTTPS, and under normal circumstances only you and the person you're messaging can see your messages — but technically the party operating the server can access the content. We did not design Remi for private or sensitive conversations; use an end-to-end encrypted app for that kind of conversation.
Notifications do not carry message content. The notification you receive shows only who wrote to you; the message text does not appear on your lock screen.
When you delete a message, the message is removed from both your conversation and the other party's. Due to record-keeping, abuse review, and the natural cycle of backups, it remains marked as deleted in the system for a while longer; when you delete your account, it is permanently destroyed.
When you report a message, a copy of that message is additionally stored for review. This copy remains even if the person who wrote the message deletes it — otherwise a harasser could destroy the evidence by deleting their message. Only our administrator can view the copy, and only to review the report; every viewing is logged. If the report is dismissed, the copy is deleted immediately; copies of resolved reports are retained for at most 90 days. If you delete your account, all copies of messages belonging to you are also deleted.
You can block someone you don't want to message; a user you have blocked cannot send you messages. You can turn off message notifications entirely from Settings.
2. How We Use Your Data
- To host your memories on the server as you saved them
- To show the memories you share with your friends to them (according to your privacy preference)
- To share real-time track information at the visibility level you choose for the "Listening now" feature (default: friends only; short-lived temporary storage)
- To send push notifications (friend request, common moment, time capsule)
- To improve our service and diagnose errors
- To meet legal obligations
We never sell or rent your data to third parties.
3. Services We Share With (Third Parties)
- Google — Sign in with Google (authentication). Google privacy policy.
- Google Firebase — push notifications (FCM) and crash reporting (Crashlytics). Firebase privacy policy.
- Microsoft Clarity — anonymous UX analytics (session recording, heatmaps). Microsoft privacy policy.
- Google Maps — map display (client-side only). Google privacy policy.
4. Data Security
- All communication is encrypted with HTTPS/TLS
- JWT tokens (1-hour access + 30-day refresh) are used for authentication
- If you sign in with Google, your password is never shared with us — Google handles verification
- If you sign up with email, your password is not stored as plain text: only an irreversible hash (BCrypt) is kept, and we cannot see your actual password either
- Our servers are hosted in data centers in Germany (Hetzner) — GDPR-compliant
What we do not promise: Remi does not use end-to-end encryption. Your messages, notes, and memories are stored on our server in readable form. Communication is protected with HTTPS during transit, and we technically limit access to your content, but the party operating the server can access the content. In the event of a data breach, you should assume that this content could be exposed. Do not share information that must be kept confidential through Remi.
5. Data Retention Period
Your data is retained until you delete your account. When you delete your account, all your data (memories, notes, photos and voice notes, messages, friendship information) is deleted immediately and permanently; your media files are removed from the server as well. There is no waiting period or recovery window — the operation is irreversible and we cannot restore your account. You can export your data from Settings before deleting.
The one exception — security records: We keep an audit record for security-related administrative actions such as account deletion and banning. This record holds the type of action, its time, your account's identifier, and your display name at that moment; it does not hold your memories, notes, messages, or media. It is retained indefinitely under legitimate interest, so that we can detect abuse and show that a deletion request was carried out. To request the deletion of this record, you can email remithememory@gmail.com.
When you delete your account, your conversations with the people you've messaged are also removed from their side — including the messages they sent to you.
The real-time track information you share as part of the "Listening now" feature is not stored permanently: it is only kept in a short-lived temporary cache and is automatically deleted shortly after if you don't switch to another track. It is not written to the database.
Messages: The messages you send are retained until you or the other party deletes them, or until you delete your account. The review copy of a reported message is deleted immediately if the report is dismissed; for resolved reports it is retained for at most 90 days and then automatically deleted. When you delete your account, the review copies of messages belonging to you are also deleted.
Device notification records: To be able to send notifications, we keep the notification identifier for your device. Device records unused for 270 days are automatically deleted; when you uninstall the app, the relevant record is invalidated and cleaned up.
Server access logs (IP, timestamp, request path) are kept for at most 30 days for abuse detection and service health, then automatically deleted. In the event of a request from a legal authority, these records may be retained for the relevant period for the duration required by law.
6. Your Rights (GDPR)
Under KVKK and GDPR, you have the following rights:
- Right of access: to access the data we hold about you
- Right to rectification: to correct inaccurate data
- Right to erasure: to delete your data ("right to be forgotten")
- Portability: to receive your data in a structured format
- Right to object: to object to data processing activities
You can download most of your data yourself without waiting: in the app, Settings → Export my data. The downloaded file includes your profile, your memories, your comments and likes, your friendship history, the people you've blocked, your notification preferences, and your messages (those you sent + those sent to you). Deleted messages are not included in the file. If you have a large number of messages, the file is limited to the most recent 10,000 messages and this is clearly stated in the file; you can request the rest by email.
To exercise these rights, you can email remithememory@gmail.com. We respond within 30 days.
7. Account Deletion
You can delete your account and all your data in two ways:
- From within the app: Settings → Delete Account
- Via the web: Account Deletion Page
8. Children's Privacy
Remi is not designed for users under the age of 13. If we discover that we have collected data belonging to a user under 13, we delete it immediately. If you believe data has been collected without a parent's knowledge, please contact us.
9. Changes
We may update this policy. Significant changes are announced via an in-app notification. The current version is always available on this page.
10. Contact
For privacy-related questions:
- Email: remithememory@gmail.com
- Data controller: Birkan Cemil Abacı