Your memories are your own. Period.
We built yeerbook on the belief that your most personal reflections shouldn't be accessible to anyone but you. Not even us.
Last Updated: July 14, 2026
Security Architecture
Hybrid End-to-End Encryption
Traditional services trade privacy for convenience. True encrypted services trade convenience for privacy. yeerbook uses a hybrid model that gives you both: total cryptographic privacy by default, with "just-in-time" permissions for AI features and printing.
User-Held Keys
Your master keys are derived from your password or your unique Recovery Phrase on your device. We never see your password, and we never store your master keys.
Ephemeral Grants
When you want our AI to process your month, your app provides Just-in-Time Access using a temporary, short-lived key. It is deleted the moment the task is done.
Signer Privacy
All signer contributions—including text notes, voice notes, and signatures and handwriting/drawings—are end-to-end encrypted. Signatures are always visible to the creator and other signers. Notes are also shared with other signers on group memories; on regular memories, notes are visible only to the creator.
How we compare
| Feature | Legacy Cloud Apps | yeerbook hybrid | Standard E2EE |
|---|---|---|---|
| Who holds the keys? | You & The Company | Only You | Only You |
| Can the server read it? | Yes (permanently) | Only ephemerally (Briefly, when you request) | No (never) |
| AI Features & Processing | Supported | Supported | Impossible |
| If database is leaked? | Your data is exposed | Your data is safe | Your data is safe |
Privacy Policy
Data Collection & Minimization
How We Use Your Data
Retention & Deletion
AI Training & Data Usage
Third-Party Sub-processors
We use a small number of trusted partners: Supabase for database and storage, Google AI (Gemini) for voice note transcription, and Stripe for payments. Photo clustering is based on timestamp metadata only and never involves sending photo content to a third party. We use enterprise-grade APIs which explicitly state that data sent via the API is not used to train their foundation models.
To fulfill your print order, your finalized book pages are briefly decrypted to generate the print file, which is then sent securely to our print fulfillment partner. They process your files solely to produce and ship your book, and are contractually prohibited from using your content for any other purpose. Print files are stored temporarily for up to 14 days from shipping to accommodate reprints or support requests for damaged shipments, after which they are permanently deleted.