Last updated July 31, 2026
DigiXVault (“the Service”) is operated by DigitalX Commons LLC (“we,” “us”). This policy explains what we collect, why, and what happens to it - including the AI voice-cloning feature and the automatic legacy release mechanism, both of which are unusual enough to deserve extra clarity.
Storyteller mode is off by default. Turning it on requires your own explicit consent, applies only to your own voice, and can be revoked at any time - revoking deletes the underlying voice model within 24 hours. The voice model itself never leaves the vault - it’s excluded from vault exports (see below) and never sent anywhere beyond the narration provider used to generate each clip. Every AI-narrated clip is labeled as such, audibly and visibly, so no one mistakes it for a real recording. If your state or country recognizes a separate right around biometric or voiceprint data, this consent is intended to satisfy it, but you should not rely on this policy alone to determine your legal rights - see a lawyer if that matters to you.
We use the following subprocessors to run the Service. Each only receives what it needs to do its job:
If you turn on legacy release for your vault and choose a person (and optionally a backup), the Service monitors activity on the vault - signing in, recording a memory, or clicking a check-in link all count. By default, after 12 months of no activity we email a check-in request; 30 days later, a second warning (and a text, if you’ve added a phone number); 30 days after that, your chosen person is notified that access may transfer to them, and you get a final 30-day window to check in and stop it. If that window passes, access under our Terms of Service is granted to them, and both of you are notified by email. Every step is recorded in an audit log we retain as a record of what happened and when. This is an intentional, disclosed feature of the Service - not a bug or a breach - but it means an extended absence can result in someone else gaining access to everything in that vault. A mistaken transfer can be reversed by our support team after identity verification. Turn this setting off in Settings if that’s not what you want.
When you request a password reset, a sign-in link, or your recovery contact asks support for help getting you back in, we log the email address, timestamp, and (for a recovery contact request) which member made the request, and we email the account holder every time one of these is initiated - so a recovery attempt is never silent. This log is also used to limit how many recovery attempts can be made for the same email in a short period, to prevent abuse. If support assists with a recovery, we additionally record which admin handled it, what identity evidence was checked, and - for a vault whose owner is deceased or unreachable - a second, different admin’s approval before any access changes. This log is kept as a permanent record of what happened and when, the same as the legacy-release audit log described below; any documentation submitted for a legal-request recovery (see Terms of Service) is stored securely and used only to evaluate that request.
You can request a full export of a vault’s recordings, notes, and photos at any time from Settings. We package the export and email a download link to the person who requested it; the link expires after 7 days. The export excludes the underlying storyteller voice model (see above) - it contains only the memories in the vault, not the biometric voice data used to generate narrations.
You can generate a print-ready PDF from a vault at any time from Settings, choosing exactly which memories to include. Voice memories included in a book are transcribed by OpenAI (see above) so an excerpt can appear on the page; the transcript is saved so the same recording is never re-transcribed for a later book. If you turn on the optional AI foreword, Anthropic receives only the book’s title, dedication, contributor names, date range, and memory count - never the memories’ actual content - to write a short opening page. Each voice memory in a book gets a QR code linking to a private page with just that recording’s title, author, and an audio player - the page requires no login, but its address is an unguessable token, not something a stranger could find by browsing. We keep a count of how many times each link has been opened, visible to your vault in Settings. The vault owner or a steward can revoke a book’s links at any time, after which its QR codes stop resolving.
If you order a printed copy of a Memory Book, we send the finished PDF, along with the shipping name, address, and phone number you provide, to Lulu Press, Inc. (“Lulu”), a print-on-demand company, solely to print and ship your order. Payment is processed by Stripe, the same as every other purchase in DigiXVault. We keep a record of the order - address, price paid, and shipping status - to help if something goes wrong and to meet our own tax and support obligations.
You can delete your account at any time in Settings. This permanently removes your login and profile. Memories you personally recorded remain in any shared family vault - so your family doesn’t lose the stories - but are no longer attributed to your name. If you own a shared vault with other active members, you’ll need to transfer ownership before you can delete your account, so a vault is never left without an owner.
A full account (email and password) requires being 13 or older, confirmed by an asserted date of birth at signup - we block account creation below that age with no exception.
Questions about this policy or your data can be sent through the feedback form in Settings, or to the account holder who invited you to your family vault.
This is a plain-language policy, not a substitute for legal advice. See Terms of Service and the FAQ for plainer-language answers to common questions.