Privacy Policy (UK GDPR)

Escendant Ltd

Effective: 2 September 2026
Last Updated: 3 September 2026


  1. Who we are

    Escendant Ltd, company number 13914686, of Office 6 Town Hall, 86 Watling Street East, Towcester, United Kingdom, NN12 6BS, is the controller for the processing described here. Contact privacy@escendant.ai.

  2. What this policy covers

    This policy covers the Escendant apps, websites and related services. They include accounts and managed accounts; Engrams, time capsules and sharing; the Curator and Escendant Chat; transcription and generated media; adult voice and likeness simulation; subscriptions, credits, exports, support, reporting and deletion.

    Engrams are Private by default. Eligible owners can share them with selected people, create an unlisted Weblink or make them Public. Under-18 accounts cannot use Weblink or Public sharing or voice and likeness simulation.

  3. Personal data we use

    CategoryExamples
    Account and profileName, email, phone number, authentication identifiers, date or year of birth, profile details, settings, role, plan and account status.
    Engrams and other contentText, photos, video, audio, documents, links, messages, dates, places, people, relationships, tags, music selections and annotations.
    AI and generated contentPrompts, Curator and Chat exchanges, transcripts, extracted information, summaries, search context, generated or edited media, avatars and voice output.
    Sharing and relationshipsConnections, groups, invitations, blocks, permissions, link tokens, previews, Public attribution and access events.
    Managed accounts and legacySubject details, relationship, manager or Trustee capability profile, invitations and acceptance, delegation and successor records, policy versions, authority evidence, death reports and supporting documents, account state, time capsules, claims and disputes.
    PurchasesProduct, plan, credits, transaction identifier, amount, currency, renewal and entitlement status. Apple processes full card details.
    Device and useIP address, device and browser type, app version, app interactions, transaction events, crash, performance, security and diagnostic data.
    Device permissionsContent you select from photos, camera, microphone, speech recognition, contacts, location, notifications, files and Apple Music.
    Support and safetySupport messages, feedback, reports, complaints, evidence, moderation decisions and communication preferences.

    We receive this information from you, people acting with authority, other users who include or share information about you, your device, Apple and authentication providers, and events generated when the Service is used. Device permissions are requested in context and can be changed in device settings.

    Information about other people

    Memories often concern relatives, friends, colleagues and other people who did not give their information directly to us. We provide this policy as public information and, where UK GDPR requires, give the person the relevant Article 14 information directly within the applicable time. An exception may apply where notice is impossible, involves disproportionate effort or would seriously impair a lawful purpose; when we rely on an exception, we document it and use appropriate safeguards.

    Users must have a fair and lawful reason for providing another person's information and take particular care before sharing sensitive or private material. We may restrict, redact or remove material or ask for consent or authority evidence.

  4. Why we use data

    PurposeLawful basis
    Create accounts and provide Engrams, search, sharing, exports, Curator, Chat, transcription and requested media features.Contract; consent where a separate optional feature requires it.
    Operate managed accounts, Trustee profiles, delegation, successor appointments, death verification, Protected Legacy, restricted preservation, time capsules and estate or legacy requests.Contract; legitimate interests in providing continuity, preserving the requested archive, preventing misuse and resolving claims; legal obligation where applicable.
    Provide adult voice and likeness simulation.Contract and specific consent; explicit consent if special-category biometric processing is involved.
    Operate Weblinks, Public Engrams, previews, attribution, moderation and removal.Contract; legitimate interests in reliable delivery, safety and protecting rights; consent where required.
    Process subscriptions, credits, entitlements, refunds, tax and accounting.Contract and legal obligation.
    Secure the Service, prevent fraud and abuse, protect children, investigate reports and enforce rules.Legitimate interests, legal obligation and, in a genuine emergency, vital interests.
    Provide support, measure use, diagnose faults and improve reliability.Contract and legitimate interests; consent or a permitted statistical exception for device storage or analytics where applicable.
    Send essential service notices and optional marketing.Contract, legal obligation or legitimate interests for service notices; consent or the lawful soft opt-in for marketing.
    Comply with lawful requests and establish, exercise or defend legal claims.Legal obligation and legitimate interests; Article 9(2)(f) where necessary for claims.

    Where we rely on legitimate interests, we assess necessity, proportionality and the effect on people. Consent can be withdrawn without affecting earlier lawful processing. We do not sell personal memories, use them for behavioural advertising, or use private memories to train general-purpose AI models without a separate explanation and explicit opt-in.

    Account, authentication and core content information is needed to enter into and perform the contract. Without it, we cannot create the account or provide the requested Service. Profile details, device permissions, Public sharing and simulation are optional; refusing them limits only the relevant feature.

  5. Sensitive, voice and likeness data

    Memories may reveal health, ethnicity, beliefs, politics, trade-union membership, genetics, sex life or sexual orientation. We use sensitive information only for the requested Service and sharing choices, with explicit consent or another documented Article 9 condition where one is required. One person's consent does not authorise sensitive processing about someone else.

    A photo or recording is not automatically special-category biometric data. That classification applies where specific technical processing is used to identify someone uniquely. Escendant's face and voice features create or operate simulations; they are not identity verification. They use a separate adult opt-in and can be disabled for future processing. See our Voice, Likeness and Biometric Data Policy.

    UK GDPR generally protects living people, not information relating only to a deceased person. Archives commonly contain mixed information about living relatives, contributors and other people, so their rights and our confidentiality, fairness and security duties continue. Deceased-person material may also involve copyright, performance, likeness, estate or reputation interests.

  6. Children and managed accounts

    People aged 13 or over may create an independent account. An authorised adult may create a managed account for a child under 13. We use date-of-birth information to apply age controls and may ask for proportionate evidence if age or authority is disputed.

    Under-18 accounts cannot create Weblinks, make Engrams Public, or use voice and likeness simulation. Managers must act in the child's interests and their access does not remove the child's own data-protection rights. Children and their representatives can contact privacy@escendant.ai in their own words.

  7. AI

    Most AI processing happens through Escendant's backend. For a requested feature, we send the permitted content and context needed for that task to one of our AI providers: Google, OpenAI or SpaceXAI. That may include text, photos, video, audio or documents. Some voice models are operated by Escendant and hosted by Scaleway in France.

    Different tasks may use different providers, and a failed request may be retried through another approved route. Not every provider receives every request. Some speech recognition, face detection, media checks and quality checks may happen on the device. The current list is in our Sub-processors list.

    Approved production routes do not permit these providers to use private memory content to train their general-purpose models. If we ever propose a separate training use, we will identify the provider and purpose and obtain an explicit opt-in first.

    AI output can be wrong and should be reviewed. We do not make solely automated decisions that have legal or similarly significant effects on you. Automated tools may assist security and moderation; material restrictions can be challenged. See our AI Transparency Statement.

  8. Who receives data

    We share only what is reasonably needed with:

    • people, groups and link recipients chosen by users, and anyone viewing a Public Engram;
    • managers, co-managers, Trustees, delegates, accepted successors and contributors within their recorded permissions;
    • Amazon Web Services for authentication, databases, APIs, media storage, security, logging and service operation in the UK region;
    • Apple for the App Store, StoreKit purchases, Apple sign-in, push delivery and device services;
    • Google for Google sign-in, Firebase app analytics, and AI processing of content you submit for a requested feature;
    • OpenAI, OpenRouter and SpaceXAI for AI processing of content you submit for a requested feature;
    • Scaleway for hosting Escendant-operated voice models;
    • support, communications, security and professional advisers; and courts, regulators, law enforcement or others where lawfully required or needed to protect rights, safety or legal claims.

    Not every AI provider receives every request. Contact privacy@escendant.ai for current information about transfer safeguards.

    Chat uses only Engrams and sources the questioner is permitted to access. A person who receives a shared Chat answer, screenshot or transcript does not thereby receive access to the underlying archive.

    Public Engrams may be indexed and copied by anyone. Weblinks are unlisted but may be forwarded or cached by recipients and preview services. Those third parties control their own copies.

    A Death Reporter receives no content merely by reporting. After verified death, a continuity-capable delegate may receive the specific access recorded in the accepted profile. A verified executor, administrator or equivalent personal representative does not receive login access automatically; we disclose or export only what is justified by the request, evidence, rights and safeguards. We may redact information about living people or third parties.

  9. International transfers

    Our core AWS service is hosted in the United Kingdom, but some providers or support teams may process data elsewhere. Where UK personal data is transferred to a country without UK adequacy regulations, we use an approved safeguard where required, such as the UK International Data Transfer Agreement or UK Addendum, and assess the transfer risk. You may request relevant safeguard information.

  10. Retention and deletion

    We keep data only for as long as reasonably needed to provide the Service, meet legal and accounting duties, protect safety and security, resolve disputes and defend claims.

    • Active account and Engram data is normally kept while the account or content remains active. Verified death does not trigger automatic deletion.
    • A Protected Legacy without an active continuity delegate may remain in restricted dormant preservation without a fixed expiry for deceased-only material. We periodically reconsider the need for mixed living-person data and may restrict, redact, export, transfer or delete where rights, confidentiality, safety, law, disproportionate cost or service closure requires it.
    • User-kept Curator and Chat questions, answers and session history are normally kept with the relevant account or item until they are deleted. Short-lived request context is kept only as needed to complete, safely retry and operate the request under the configured route.
    • An account deletion request has a 30-day grace period. We then delete or de-identify active data, subject to technical processing, legal holds and limited records we must keep.
    • Deleted data may remain in protected backups until the backup cycle completes, normally no longer than 60 days.
    • AI providers keep inputs and output only under the approved terms for the route used. Feature-specific voice or likeness source and model data is deleted when the user deletes it, disables the feature and asks for deletion, or closes the account, subject to technical and legal limits.
    • Death evidence is kept in detailed form only while verification, challenge or a live claim requires it. We then retain a minimised record of the report, evidence type, decision, actor, profile, acceptance, notices and outcome for the relevant rights, safety or claim period.
    • Transaction, consent, security, complaint, authority and legal records are kept for a period appropriate to their purpose and applicable limitation or statutory periods.

    Unpublishing, disabling a link or deletion cannot recall copies held by recipients, search engines, web archives, platforms or caches.

  11. Analytics, storage technologies and marketing

    The iOS app uses Firebase Analytics without advertising-ID support to measure screens, onboarding, feature and purchase activity. We design events not to include Engram content. We use analytics under consent or a permitted statistical-purpose exception, as applicable, and provide the required information and objection route. Email privacy@escendant.ai to object. Our Cookie and App Technologies Policy gives more detail.

    We do not use behavioural advertising. Optional email marketing includes an unsubscribe route. We may retain a minimal suppression record so that we continue to respect an opt-out.

  12. Security

    We use proportionate measures designed to protect personal data, including access controls, secure transmission, logging, provider management, backups and incident response. No online service is completely secure. Protect your credentials and use sharing controls carefully. We notify the ICO and affected people of a qualifying breach where the law requires it.

  13. Your rights and complaints

    Depending on the circumstances, you may ask for access, correction, erasure, restriction, portability or information about transfers; object to legitimate-interest processing or direct marketing; withdraw consent; and challenge a qualifying automated decision.

    Use app export or deletion controls where available or email privacy@escendant.ai. State the account email, right and data concerned. For a managed or legacy account, explain your relationship and authority. We may verify identity and authority proportionately and provide a filtered or redacted response where other people's rights apply. A personal representative does not exercise UK GDPR rights belonging to the deceased, but may have separate estate, copyright or legal grounds for a request. We normally respond to rights requests within one month, subject to lawful extensions and exceptions. A data-protection access request is not charged unless the law permits a reasonable fee.

    Email a data-protection complaint to complaints@escendant.ai. We acknowledge it within 30 days, investigate without undue delay, keep you informed where needed and explain the outcome. You may complain at any time to the Information Commissioner's Office at ico.org.uk/make-a-complaint.

  14. Changes and contact

    We update this policy when our processing or the law changes, show the updated date and give appropriate notice of material changes. We seek a new choice where required.

    Controller: Escendant Ltd, company number 13914686, Office 6 Town Hall, 86 Watling Street East, Towcester, United Kingdom, NN12 6BS
    Privacy and rights: privacy@escendant.ai
    Security: security@escendant.ai
    Complaints: complaints@escendant.ai