Privacy Policy — MYWIE

Last update: April 2026 — Zero-Knowledge architecture integration

Mentions légales — Éditeur du site

  • Société : MBMemory
  • Siège social : 220 avenue Carnot, 17000 La Rochelle, France
  • SIRET : 107 568 867 00017
  • Directeur de la publication : Représentant légal de MBMemory
  • Contact : contact@mywie.fr
  • DPO : dpo@mywie.fr
  • Hébergement : OVHcloud — hébergement web en France (Union européenne)

Encryption at rest & content protection

Your sensitive content is encrypted with AES-256 before storage.

MYWIE encrypts sensitive content at rest — Vault of Silences, scheduled messages, private journal — with AES-256-GCM. The decryption key is derived from your password (PBKDF2, 210,000 iterations) and your 12-word recovery phrase. Without these elements, stored data remains unreadable.

  • AES-256-GCM encryption at rest: journal, vault and posthumous messages are encrypted before storage in a database hosted in France.
  • Password-derived key (PBKDF2): on login, your password derives the master key in session. Keep your recovery phrase safe.
  • No commercial exploitation of your content: At MYWIE, your personal content is neither sold, rented, nor used for profiling. Access to your data is strictly limited to the technical operations essential to the proper functioning of the service.
  • Triple recovery net: password, 12-word recovery phrase, and trusted person with a 30-day legal delay.
  • Verifiability through cryptographic proofs: hosting and emails OVHcloud (France), payments Stancer (France), local Llama 3 narrative AI (Ollama) and local Whisper transcription only if you activate these features — details in section 5 below.

If you simultaneously lose your password, recovery phrase AND trusted person, encrypted content may become permanently unrecoverable. That is the counterpart of stronger user-key protection.

1. Who are we?

MBMEMORY (publisher of the MYWIE application), a simplified joint-stock company with a capital of [amount] euros, registered with the RCS of [city] under number [SIRET], with its registered office at [full address], is responsible for processing personal data collected via the application and website mywie.com, mywie.fr and their associated extensions.

Data protection contact: dpo@mywie.fr

2. Our fundamental commitment — What MYWIE never does

Before describing what we do with your data, we want to clearly state what we do not do — and will never do.

MYWIE never sells your personal data. No data about you, whether it concerns your identity, your content, your usage habits or your family information, is ever sold, traded or monetized to any third party, regardless of the consideration.

MYWIE never rents your personal data. Your data is never made temporarily available to a third party for commercial, marketing or advertising purposes.

MYWIE does not analyze your personal data for commercial purposes. We do not perform any analysis, profiling or exploitation of your personal content, memories or family information for purposes other than the strict operation of the service you subscribed to.

MYWIE does not display any targeted advertising. The MYWIE application and website are entirely free of personalized or behavioral advertising. You will never see any advertising message based on your data, your profile or your browsing behavior.

Why these commitments? MYWIE's business model relies exclusively on user subscriptions and institutional partnerships with heritage professionals. Your data is not our product. It is what we protect.

3. Data collected and purposes

3.1 Identification and account data

Last name, first name, email address, encrypted password, date of birth, profile photo.

Legal basis: performance of contract (Article 6.1.b GDPR).

3.2 Personal content data

Life stories, digital diary, photographs, videos, audio recordings, personal documents, family tree, family member information, important geolocated places, scheduled scheduled messages (Vault of Silences), recipes, family traditions, and all content voluntarily deposited by the user.

Legal basis: explicit consent (Article 6.1.a and Article 9.2.a GDPR). This content may include sensitive data within the meaning of Article 9 of the GDPR. Their processing is based exclusively on your explicit, freely given, specific and documented consent. They are never analyzed for purposes other than the operation of the service.

3.3 Post-mortem directive data

Directives for the preservation, erasure or communication of your data after your death, in accordance with Article 63 of Law No. 2016-1321 of October 7, 2016 and Article 85 of the French Data Protection Act. Designation of a digital trusted third party.

Legal basis: explicit consent and legitimate interest in organizing your digital succession.

3.4 Technical and browsing data

IP address, connection data, access logs, browser type, session data.

Legal basis: legitimate interest (service security, fraud prevention). This technical data is never cross-referenced with your personal content or used to profile you.

3.5 Payment data

Processed exclusively by our PCI-DSS certified provider. MYWIE does not store any complete banking data on its servers.

Legal basis: performance of contract.

4. Post-mortem data — Specific regime

MYWIE processes data intended to outlive their author. This processing is governed by a specific legal regime.

In accordance with Article 63 of the Law for a Digital Republic (2016), you can define general or specific directives regarding the fate of your data after your death. These directives are stored in your MYWIE space and can be modified or revoked at any time during your lifetime.

In the absence of specific directives, your heirs may, upon proof of their status, access the data necessary for settling the estate as well as data resembling family memories, in accordance with Article 85 of the French Data Protection Act.

The scheduled messages of the Vault of Silences are triggered according to the conditions you have defined. MYWIE carries out a death verification before any dispatch, by proportionate and dignified means.

Your digital assets documented in MYWIE constitute elements of estate inventory in accordance with the Ordinance of March 8, 2024 integrating digital assets into the Civil Code.

5. Recipients of your data

Your personal data is never sold, rented or transferred to third parties. It may be communicated in the following cases only:

Your designated trusted persons: only the data and content you have explicitly authorized them to share, according to the settings you have defined.

Your legal heirs: only after verification of your death and upon proof of their status as beneficiary, within the limits set by Article 85 of the French Data Protection Act and your post-mortem directives.

Notaries and appointed professionals: only with your explicit prior authorization, in the context of a succession or authentic deed, and within the limits you have defined.

Our technical subcontractors: host and sending of transactional emails (OVHcloud, France/EU), payment provider (Stancer) and local narrative AI Llama 3 (Ollama) when these options are activated. These subcontractors are bound by contracts complying with article 28 of RGPD (see the detailed register below).

Competent authorities: only upon judicial requisition or legal obligation.

Sub-processors registry (Article 28 GDPR)

In accordance with Article 28 GDPR, MYWIE maintains an up-to-date list of sub-processors with access to personal data for service delivery. Each sub-processor is bound by a Data Processing Agreement (DPA) imposing equivalent obligations of confidentiality, security and European location.

Sub-processor Processing purpose Location Guarantees
Llama 3 (Ollama) AI processing for narrative features (Narrative AI, FAQ, story generation) — sovereign language models. Serveur MYWIE (France 🇫🇷) Art. 28 GDPR DPA · zero training on your data · EU hosting · no transfer outside the EU.
OVHcloud Web and database hosting (MySQL), application execution, storage of encrypted files, sending transactional emails (SMTP OVH). France 🇫🇷 / UE 🇪🇺 Art. 28 GDPR DPA · France/EU · TLS in transit and application-level encryption for sensitive content.
Stancer Payment and subscription processing. France 🇫🇷 Payment institution · GDPR Art. 28 DPA · PCI-DSS · France/EU · hosted page outside MYWIE servers.

Any change to this list is communicated to users in advance and published on this page (Article 28.2 GDPR).

Never: advertisers, marketing networks, data brokers, commercial behavioral analysis platforms, or any third party for advertising or commercial profiling purposes.

6. Hosting and data transfers

All your data is hosted exclusively in France and Europe, on servers located within the European Union. No data transfers to third countries outside the European Union are made. MYWIE does not use any provider located outside the EU for processing your personal data.

7. Security of your data

MYWIE implements the following technical and organizational measures:

  • End-to-end encryption of all stored and in-transit data (AES-256 standard).
  • Data access restricted to the strict minimum necessary — no MYWIE employee can access your personal content without your explicit authorization.
  • Secure authentication with password hashing.
  • Access logging and abnormal behavior detection.
  • Encrypted daily backups on separate servers.
  • Regular security audit by an independent provider.

In the event of a data breach likely to result in a high risk to your rights and freedoms, you will be notified as soon as possible in accordance with Article 34 of the GDPR, and the CNIL will be informed within 72 hours in accordance with Article 33.

8. Retention period

Data Duration
Active account data For the duration of the subscription + 3 years after termination
Personal content data According to your post-mortem directives. After death: 10 years max without directives
Payment data 10 years (legal accounting obligations)
Technical log data 12 months maximum
Vault of Silences Until triggered or deleted, no time limit while the account is active

9. Your rights

In accordance with Articles 15 to 22 of the GDPR and the French Data Protection Act, you have the following rights, exercisable at any time via dpo@mywie.fr:

Right of access

Obtain confirmation that your data is being processed and receive a complete copy.

Right of rectification

Correct any inaccurate data concerning you.

Right to erasure

Request the deletion of your data. Deleting your account results in the irreversible deletion of all your content within 30 days. A prior export will be systematically offered.

Right to portability

Receive your data in a structured, commonly used and machine-readable format (JSON / PDF depending on the nature of the data).

Right to restriction of processing

Request the freezing of the processing of your data in the cases provided for by Article 18 of the GDPR.

Right to object

Object to any processing based on legitimate interest.

Right to define your post-mortem directives

Define, modify or revoke at any time your instructions regarding the fate of your data after your death, in accordance with Article 63 of the Law for a Digital Republic.

Right to withdraw your consent

Withdraw your consent at any time for processing based on it, without affecting the lawfulness of processing carried out before this withdrawal.

Response time: 1 month maximum, extendable to 3 months for complex requests.

10. Cookies and trackers

In accordance with CNIL guidelines, only cookies strictly necessary for the operation of the application are placed without your prior consent: session, authentication and security cookies.

MYWIE does not use any advertising cookies, behavioral trackers or retargeting tools. The only analytical tools used, if your consent is obtained, serve exclusively to improve the application's features and are never shared with advertising networks.

11. Minors

MYWIE is not intended for persons under 16 years of age. If you are a parent or guardian and notice that a minor under your responsibility has created an account, contact us at dpo@mywie.fr.

12. Complaints

If you believe that the processing of your data constitutes a violation of the GDPR, you can file a complaint with the CNIL:

CNIL — 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07

www.cnil.fr — Phone: 01 53 73 22 22

13. Changes

Any substantial changes will be notified to you by email at least 30 days before they take effect.

14. Contact

MBMemory — 220 avenue Carnot, 17000 La Rochelle, France

SIRET : 107 568 867 00017

Email : dpo@mywie.fr

Site : mywie.fr