Legal

Privacy Policy and Data Practices

Memoria Operating Systems, LLC · memoriaos.com · app.memoriaos.com
Effective Date: July 01, 2026 · Questions: privacy@memoriaos.com

This document is the single authoritative source for how Memoria Operating Systems, LLC collects, uses, stores, retains, and deletes data across its marketing website, SMS communications, and software platform. Part One is the Privacy Policy governing collection and use. Part Two is the Data Retention and Deletion Schedule governing how long data is kept and what happens when it is deleted.

Part One

Privacy Policy

This Privacy Policy explains how Memoria Operating Systems, LLC ("Company," "we," "us," or "our") collects, uses, discloses, and protects information in connection with the MemoriaOS platform ("Platform") at app.memoriaos.com, our marketing website at memoriaos.com, and SMS communications initiated through either (collectively, "Services"). By using the Services or opting in to SMS communications, you agree to the practices described here.

1. Who this policy applies to

This policy applies to four groups:

  • Funeral Home Customers — businesses and individuals who subscribe to the Platform;
  • Authorized Users — employees, contractors, and staff of Customers who use the Platform;
  • Website Visitors and SMS Opt-Ins — individuals who visit memoriaos.com or opt in to receive SMS messages from MemoriaOS; and
  • Family Members — individuals who access the family portal, memorial pages, or receive SMS communications from a funeral home through the Platform.

This policy does not apply to third-party websites or services linked from our Services.

2. Information we collect

2.1 From Funeral Home Customers and Authorized Users

When a funeral home subscribes or its staff access the Platform, we collect:

  • Account information: business name, contact name, email address, phone number, business address, and billing information (processed by Stripe — we do not store payment card numbers);
  • Profile information: names, titles, license numbers, and contact details of Authorized Users;
  • Usage data: login times, features accessed, actions performed, and other activity logs; and
  • Communications: records of SMS and email messages sent through the Platform's communications features.

2.2 Customer Data — Case and Decedent Information

As part of providing the Platform, we process case records and decedent information. This may include:

  • Decedent identifying information: full name, date of birth, date of death, Social Security Number (if entered by staff), and place of birth;
  • Family and next-of-kin information: names, addresses, phone numbers, and email addresses;
  • Service and arrangement details: selected services, merchandise, service dates, and locations;
  • Financial information: itemized service costs, payments, insurance information, and balances;
  • Uploaded documents: including death certificates, which may contain health information; and
  • Photographs and images: submitted for AI-assisted processing or uploaded to case files or memorial pages.

Note: Death certificates and related information may constitute Protected Health Information (PHI) under HIPAA. Where applicable, our handling of PHI is governed by our Business Associate Agreement (Exhibit D of the Platform Services Agreement).

2.3 From Website Visitors and SMS Opt-Ins

When individuals visit memoriaos.com or submit a contact or inquiry form, we collect:

  • Contact information: name, business name, email address, and phone number as provided;
  • Inquiry details: the nature of the inquiry, interest in the Platform, and any message submitted; and
  • SMS consent records: when you check the SMS opt-in checkbox, we record your consent, the date and time consent was given, the phone number provided, and the form on which consent was obtained.

We retain SMS consent records as required by the TCPA and CTIA best practices. These records are maintained separately from general contact records and are used solely to document compliance with applicable consent requirements.

2.4 From Family Members

Families who access the family portal or receive SMS from a funeral home through the Platform may have the following information processed:

  • Decedent information: biographical details and personal preferences for services;
  • Contact information: names, email addresses, and phone numbers; and
  • SMS interaction records: if a funeral home sends SMS to a family member through the Platform, we process and log the message content, delivery status, and any opt-out responses.

Family members who receive SMS from a funeral home through the Platform may opt out at any time by replying STOP. Opt-out records are maintained to ensure no further messages are sent.

2.5 Automatically collected information

When you access our Services, we automatically collect:

  • Device and browser information: IP address, browser type, operating system, and device identifiers; and
  • Log data: pages visited, time spent, referring URLs, and clickstream data.

3. How we use information

3.1 To provide the Platform

We use information to create and manage accounts; provide Platform features; process family portal interactions; generate AI-assisted content; enable SMS and email communications; process subscription billing; and archive case records.

3.2 To send SMS communications

We use phone numbers and contact information to send SMS messages in two contexts:

  • MemoriaOS outbound SMS — we use phone numbers provided through website opt-in forms to respond to inquiries, provide product information, and send onboarding communications to new customers. We only send SMS to individuals who have expressly opted in.
  • Platform SMS on behalf of funeral homes — we process phone numbers provided by funeral home customers to deliver SMS messages to families on the funeral home's behalf. The funeral home is the sender of record and is responsible for ensuring all recipients have consented.

We do not use family member phone numbers obtained through the Platform for MemoriaOS's own marketing communications. Phone numbers obtained through funeral home customer relationships are used only to deliver messages on behalf of that funeral home.

3.3 To improve the Platform

We may use aggregated, de-identified usage data to analyze Platform use, fix bugs, and develop new features. We do not use individually identifiable Customer Data or decedent information to train AI models without explicit consent.

3.4 To communicate with you

We use contact information to send account notifications, invoices, and receipts; respond to support requests; and send product updates with the ability to opt out at any time.

3.5 For safety and legal compliance

We may use information to detect fraud and security incidents; enforce our Terms; maintain TCPA and CTIA compliance records; and comply with applicable laws and legal process.

4. Service providers; what we never do with your information

4.1 Service providers who process data on our behalf

The following service providers process information solely to help us deliver our Services, under confidentiality obligations, and strictly on our instructions. They do not independently use, disclose, or sell your information for their own purposes:

  • Supabase, Inc. — database hosting and file storage;
  • Amazon Web Services (AWS) — long-term data archiving;
  • Vercel, Inc. — application hosting;
  • Twilio Inc. — SMS and voice message delivery;
  • Resend, Inc. — transactional email delivery;
  • Anthropic, PBC — AI processing for AI Features; and
  • Stripe, Inc. — subscription billing and payment processing.

4.2 Legal requirements

We may disclose information when required by law, court order, or governmental authority, including in connection with TCPA enforcement investigations or regulatory audits.

4.3 Business transfers

In the event of a merger, acquisition, or sale of assets, data may be transferred to the acquiring entity subject to the same privacy commitments.

4.4 What we never do

We do not sell, rent, trade, share, or otherwise transfer personal information, phone numbers, or SMS opt-in and consent data to any third party for their own use, marketing, or any other independent purpose. This includes SMS opt-in data collected through memoriaos.com. We do not use decedent or family information for advertising, and we do not share Customer Data with other funeral home customers. The service providers listed in 4.1 process data only as necessary to deliver our Services on our behalf and are contractually prohibited from using it for their own purposes.

5. SMS opt-out and your choices

5.1 Opting out of MemoriaOS SMS

To stop receiving SMS messages from MemoriaOS: reply STOP to any message you receive from us. You will receive one confirmation message and no further messages will be sent. You may re-opt-in at any time by replying START or contacting support@memoriaos.com. You may also opt out of marketing email by clicking the unsubscribe link in any email or contacting privacy@memoriaos.com.

5.2 Opting out of funeral home SMS

To stop receiving SMS from a funeral home using the Platform: reply STOP to any message from that funeral home. Opt-outs are processed immediately and recorded in the Platform. Contact the funeral home directly for questions about their communications.

5.3 Access and correction

Customers and Authorized Users may access and update account information through Platform settings. Family members wishing to access or correct submitted information should contact the funeral home. Website visitors may request access to their contact record by emailing privacy@memoriaos.com.

5.4 Data portability and deletion

Customers may request a data export at any time during the subscription or within thirty (30) days of termination. Submit requests to privacy@memoriaos.com. Retention and deletion practices are detailed in Part Two of this document.

6. Data security

We implement appropriate technical and organizational security measures including encryption in transit and at rest; access controls limiting database and Platform access to authorized personnel; secure private file storage with signed URL access controls; regular automated backups; and incident response procedures. No security system is impenetrable. In the event of a confirmed security incident, we will notify affected parties as required by law and as described in our Platform Services Agreement.

7. Cookies and tracking

We currently use only technically necessary cookies and localStorage for authentication and user preferences. We do not use third-party advertising or analytics cookies at this time. For full details, see our Platform and Website Policies document.

8. Children's privacy

The Services are not directed to children under thirteen (13). We do not knowingly collect information from children under thirteen, including phone numbers for SMS communications. Contact privacy@memoriaos.com if you believe we have inadvertently done so.

9. HIPAA

Funeral home Customers who are Covered Entities or Business Associates under HIPAA should note that our handling of PHI is governed by the Business Associate Agreement in Exhibit D of the Platform Services Agreement. This Privacy Policy does not constitute a HIPAA Notice of Privacy Practices.

10. Changes to this policy

We may update this Privacy Policy from time to time. We will notify Customers of material changes by email or by posting a prominent notice on the Platform. SMS opt-in users will be notified of material changes by SMS or email before the changes take effect. Your continued use of the Services after the effective date constitutes acceptance.

11. Contact

Privacy questions, opt-out requests, and data access requests: privacy@memoriaos.com
Memoria Operating Systems, LLC · 116 Agnes Road Southwest · Knoxville, Tennessee 37919

Part Two

Data Retention and Deletion Schedule

This Part Two describes exactly how long Memoria Operating Systems, LLC retains each category of data, where it is stored during that period, and how it is deleted. It supplements and is consistent with the collection and use practices in Part One.

1. Data categories

The Platform and Services process and store:

  • Case Data — decedent information, family contacts, arrangement details, and case records;
  • Financial Data — itemized statements, payment records, insurance information, and transaction logs;
  • Uploaded Documents — PDFs, death certificates, signed authorizations, and other uploaded files;
  • Platform Communications Logs — SMS and email records sent through the Platform by funeral home customers to families;
  • Audit Logs — records of user actions including case edits, signing events, and financial entries;
  • Account and User Data — subscription information, Authorized User profiles, and account configuration;
  • SMS Consent Records — opt-in consent records for MemoriaOS's own website SMS program, including consent date, time, phone number, and source form;
  • Website Contact Records — name, email, phone, and inquiry details submitted through memoriaos.com forms; and
  • System and Security Logs — technical logs for security monitoring and debugging.

2. Retention during active subscription

All Platform data categories are retained in full and remain accessible during an active subscription. There is no automatic deletion of Platform data during an active subscription regardless of subscription length.

Storage tiering: files and documents not accessed within twelve (12) months are automatically migrated to AWS S3 Glacier Instant Retrieval archive storage. This migration is transparent — archived files are retrieved immediately upon access with no perceptible delay.

3. Retention after subscription termination

3.1 Days 1–30: Full access window

Customer Data remains fully accessible for thirty (30) days following termination. Company sends a reminder email at termination and again at day 25.

3.2 Days 31–365: Archive period

After thirty (30) days, account access is suspended and Customer Data moves to secure archive storage. Customer may still request a data export by contacting privacy@memoriaos.com — fulfilled within ten (10) business days at no charge.

3.3 After day 365: Permanent deletion

After twelve (12) months, Customer Data is permanently and securely deleted from all Company systems. Deletion is irreversible. Company sends a final email notification at least thirty (30) days before scheduled deletion.

Note: If you require data beyond twelve months for regulatory or business continuity purposes, export your data before the archive period ends.

4. Retention schedule by data type

Data categoryRetention periodNotes
Case DataActive + 12 monthsExported on request during archive period
Financial DataActive + 12 monthsMay be retained longer if required by law
Uploaded DocumentsActive + 12 monthsAuto-tiered to Glacier after 12 months inactivity
Platform Communications LogsActive + 12 monthsSMS and email logs for funeral home customer use
Audit LogsActive + 24 monthsRetained longer for security and legal compliance
Account and User DataActive + 30 daysDeleted after export window closes
SMS Consent Records5 years from consent dateTCPA compliance requirement; retained regardless of subscription status
SMS Opt-Out Records5 years from opt-out dateTCPA compliance; ensures no further messages are sent
Website Contact Records24 months from submissionDeleted unless converted to active customer account
System and Security Logs90 days rollingPurged automatically; not included in data exports
Anonymized Statistical DataIndefinitelyCannot identify any individual or customer

Note: SMS Consent Records and Opt-Out Records are retained for five (5) years regardless of subscription status. This retention period is required for TCPA compliance and cannot be reduced by customer request.

5. Data export

Customers may request a data export at any time during an active subscription or within thirty (30) days of termination through the Platform's built-in export tools. For assistance or for exports during the archive period, contact privacy@memoriaos.com. Exports are provided in CSV format for structured data and PDF for documents, at no charge.

6. Deletion procedures

When Customer Data is deleted, Company uses industry-standard secure deletion procedures ensuring data cannot be recovered. Deletion covers: primary database records in Supabase; uploaded files in primary and archive storage (S3); and copies in backup systems within the next scheduled backup cycle. Written confirmation of deletion is available upon written request submitted within sixty (60) days of the scheduled deletion date.

Note: SMS Consent and Opt-Out Records are excluded from early deletion requests due to TCPA retention requirements.

7. Backup retention

Automated backups for disaster recovery are retained on a thirty (30) day rolling basis. Backup data is excluded from individual export requests but is subject to the same deletion practices once the underlying Customer Data is scheduled for deletion.

8. Changes to this part

Company may update this Data Retention and Deletion Schedule upon sixty (60) days' written notice to Customers. Material changes will be communicated by email to the account's primary contact.

Data retention, export, and deletion requests: privacy@memoriaos.com · Memoria Operating Systems, LLC · 116 Agnes Road Southwest, Knoxville, Tennessee 37919