Privacy

Privacy Policy

Forever After is a private family archive on native iOS and Android. Access is invite-only. This policy describes the information Forever After handles for invited families and how you can request deletion.

Effective: August 1, 2026 Applies to: the Forever After apps and this public site Contact: support@inbetwiddle.com
This site does not host family archives. An invited account can access only the family workspace authorized for that account. Public pages here explain the product and your privacy choices. They do not display private family media.

Chapter one

Who this service is for

Forever After is for invited adults who create or contribute to a private family archive. You may use it for your own story, for a living loved one when the required archive consent is recorded, or for a memorial when authority and source ownership are recorded.

Clerk is used to sign in. Forever After separately checks current family membership, role, authority, consent, review state, privacy classification, and deletion state before serving private data or taking a family action. Public visitors cannot create an account from this site, upload media, or view a family archive.

On a self archive, the living subject holds full authority. Archive consent never authorizes voice cloning, avatar creation, or access to another person’s health information.

Chapter two

Information we collect

Account and access

Clerk identity claims for sign-in, plus Forever After family membership, roles, invitations, authority, consent, and access records.

Family archive

Directly uploaded JPEG, PNG, WebP, M4A, MP3, WAV, UTF-8 text, and Markdown sources, plus Story Room audio or Story Room video recordings, declared metadata, review decisions, provenance, and privacy state.

Talk and review

Questions, supported answers or refusals, validated citations, review decisions, flags, and reviewable memory candidates. A conversation never becomes family truth without human review.

Device needed to run the app

App and device type as needed for a signed-in session, microphone or camera access only when you record, and encrypted device-token registration when you allow notifications.

Original archive media is private. It is not placed on a public URL, copied into the public website, or used in public product imagery. Private delivery is reauthorized on every read and is not kept for offline browsing. Forever After does not process health data. Story Room recordings are archive sources and are not used to train voices.

Chapter three

How information is used

  • Authenticate invited participants and enforce family-scoped permissions.
  • Receive permitted private sources, verify their declared type, size, checksum, and family scope, and hold them for review.
  • Show approved archive material and return grounded Talk answers only from currently authorized, approved sources with validated citations.
  • Send task or review notifications only to a registered, authorized device when notification delivery is enabled for that task.
  • Maintain security, provenance, audit, processing, and deletion records without logging private archive content in generic operational logs.

Talk answers only from currently approved sources for the selected profile. It must cite them or refuse. Private, pending, processing, rejected, revoked, deleted, or cross-family sources are excluded from approved archive views and Talk answers.

Chapter four

Service providers

Forever After uses the following processors to operate the signed-in service. Only the information needed for an approved processing step is sent to a provider.

Clerk
Provides sign-in identity. Forever After remains responsible for family, role, consent, and review authorization.
Cloudflare
Hosts the API and storage used to operate the private archive and grounded Talk.
Apple
Provides iOS distribution and, when a participant permits it, device-level push-notification delivery. A notification is a prompt to open the authenticated app; it does not expose private archive content on this site.

Forever After rechecks authorization and approval state before a source can support a Talk answer.

Chapter five

Sharing and sale

Forever After does not sell family data and does not use it for third-party advertising. Archive media is shared only with invited family roles that currently have authority to see it, and with the processors named above as needed to operate the service.

We do not use family recordings as public marketing. Product phones on this site show a labeled fictional demo (Elena Marchetti), not a real family archive.

Chapter six

Retention and deletion

Original archive sources remain until an authorized deletion. Protected temporary capture files are excluded from backup and removed after verified upload or cancellation. Deleting an archive source removes its primary and derived content, including applicable captions, excerpts, citations, flags, links, and memory candidates. Only a content-free audit record remains.

You can delete your account in the authenticated app: open Settings, choose Account, and select Delete account. This public Account deletion page explains the same path. It does not collect an unverified deletion request.

Chapter seven

Children

Forever After is not directed at children. Accounts are for invited adults. Do not create an account for a child or upload a child’s personal information in order to register them as a user. A family may record a story that mentions a child only when the adult who uploads it is authorized to preserve that material in the family archive.

Chapter eight

Your choices and controls

  • On a self archive, you approve your own sources. For a loved-one or memorial source, authorized reviewers can approve, reject, classify, flag, or delete permitted material before it supports a broader family view or Talk.
  • Living participants can decline Story Room participation. Family recollections remain attributed to the living speaker who shared them.
  • Owners can manage family invitations and the current archive governance records without granting access beyond an invited role.
  • Any account holder can initiate full account deletion from the authenticated app. A sole family owner chooses account-and-owned-family deletion rather than transferring ownership through this service.

Chapter nine

Questions and changes

Contact support@inbetwiddle.com for access, privacy, or safety help. Do not include family media, transcripts, voice samples, upload links, passwords, tokens, or identity documents in an initial email.

Read the Terms of Service and Account deletion information with this policy. Material changes to this policy will be dated and presented to invited participants before new data handling begins.