Privacy Policy
Last updated: February 2026
In plain English
Memory Lane is built for caregivers in a vulnerable moment. We treat your data the way we'd want our own family's data treated. We collect only what we need to make Memory Lane work for you, we don't sell it, we don't share it with advertisers, and we don't use it to train outside AI models.
You can ask us to show, export, or delete your data at any time by emailing ashlee@asvmedicalservices.com. We'll respond within 30 days.
Want the cookie-by-cookie breakdown? See our Cookie Policy.
Memory Lane is not HIPAA-covered
Memory Lane is not a HIPAA-covered entity, and what you enter here is not Protected Health Information (PHI) in the legal sense. HIPAA only applies to healthcare providers, health plans, and the "business associates" they contract with. Memory Lane is a self-service caregiver tool — we are not your loved one's clinic, hospice, or insurance company, and we are not under contract with any of them.
Your data here is protected by this Privacy Policy and the U.S. privacy laws that apply to ordinary consumer services (including CCPA-style rights in some states), but it is not protected by HIPAA. If you want a record that is legally treated as PHI, keep it in your loved one's hospital or clinic patient portal — not in Memory Lane.
Please do not enter your loved one's social security number, full insurance ID, or full credit card number into Memory Lane. We don't need them and we don't want to store them.
What we collect
- Account info — your name, email, password (stored hashed with bcrypt), the country you're caregiving from, the relationship you described at signup, and your "biggest challenge" note.
- Intake answers — relationship, living situation, FAST stage, top concerns, safety priorities, family support level, burnout score, hours per week.
- Caregiving content you create — patient profile (medications, doctors, allergies, etc.), behavior logs (incidents, triggers, what helped), appointment notes, drafted messages, Lane chat history, GUIDE screener answers, Continuity Passport data, document uploads.
- Usage signals — login timestamps, IP, user agent, which sections you visited, what you searched for, when you completed the tour, when you marked items done on your roadmap.
- Feedback — anything you submit through the Feedback page.
What we don't collect
- We do not ask for your loved one's social security number, full date of birth (we only ask for year), or insurance ID. If you choose to add those to the patient profile, they stay encrypted at rest in our database — but we recommend you leave them out.
- We do not use ad-network tracking, cross-site advertising pixels, or remarketing tags. The analytics tools we do use are listed below.
Analytics — what we use and why
To know whether Memory Lane is actually helping caregivers — and which parts to invest more in — we use a small set of privacy-respecting analytics tools. None of them are advertising trackers, and none of them are allowed to sell or share your data.
- Google Analytics 4 (GA4). Aggregated traffic and engagement (which pages get visited, how long caregivers stay, which CTAs convert). We run GA4 with IP anonymization enabled and we do not send any identifying information about you to Google. We also fire a small set of named events (e.g. Account Created, Search Memory Lane,Roadmap Completed, Care Navigator Session Booked) so we can measure how well the product is serving caregivers — never whatyou typed.
- PostHog (product analytics + occasional session replay).Helps us understand where caregivers get stuck (e.g. "people drop off on step 3 of intake"). When session replay is enabled it is masked by default — input fields are redacted so what you type is not captured. We use this to fix bugs and rough edges, not to spy.
- Microsoft Clarity (heatmaps and behavioral analytics). Shows us aggregated heatmaps and click patterns. Like PostHog, sensitive form fields are masked. Clarity is a first-party tool that does not feed advertising networks. Clarity only loads after you opt in via the cookie consent banner (or never, if you decline or have Global Privacy Control on).
- Our own backend telemetry. When a caregiver runs a search that returns no results, we log just the search phrase (no account, no IP) so we can write the article you couldn't find. We also log anonymous article views (slug only) so we know which guides are most useful.
You can change your mind at any time. The cookie consent banner you saw on your first visit can be re-opened — until then, Google Analytics 4 cookies stay denied via Google Consent Mode v2, and Microsoft Clarity does not load at all. You can also block any of these at the browser level using any standard tracker blocker (uBlock Origin, Privacy Badger, your browser's built-in tracking protection). Memory Lane will continue to work normally either way. If your browser sends a Global Privacy Control signal, we treat that as a decision to deny — no banner shown, no analytics loaded.
Cookies and similar technology
Memory Lane uses a small number of cookies and similar identifiers, grouped into three categories:
- Strictly necessary — the login token and your session ID. Without these, you can't stay signed in or have a persistent place where your caregiving notes live.
- Analytics — GA4's
_gaidentifier, PostHog'sph_client ID, and Microsoft Clarity's_clck/_clsk. These are pseudonymous; they tell us how the product is used, not who you are. GA4 and Clarity only set their cookies after you accept the cookie banner. - Preferences — your selected country and language, the "show me the tour" flag, and a few similar flags so the app remembers small choices you've already made.
For the full list — including approximate lifespans — see our Cookie Policy.
Why we collect what we collect
- To personalize Memory Lane. Your intake is what gives Lane (and your roadmap) context. Without it, you'd get generic advice.
- To make Lane remember what worked. Behavior logs with "what helped" notes feed Lane's memory so it can bring back your wins next time.
- To improve the product. We look at aggregated, anonymized usage patterns (e.g., "X% of caregivers in middle stage skip the appointment-prep tool") to decide what to build next. We do not look at individual users' data unless you explicitly write to us and ask us to.
- To keep you safe. Login IPs and user agents help us detect suspicious access.
The AI behind Lane
Lane is powered by large language models from OpenAI, Anthropic, and Google (via our Emergent integrations key — a single managed gateway, not direct API keys per provider). What each provider sees:
- The text you typed into the chat.
- A small context block built from your intake at the moment of the chat (e.g. "caregiver of a parent, middle stage, top concern: wandering").
- Optionally, prior Lane chat memory for continuity — only if you've let it build.
All three providers are contractually prohibited from training their models on Memory Lane traffic. Inputs to Lane are not shared with any other third party.
Lane is a guide, not a doctor. It can be wrong, biased, or out of date — always verify clinical, legal, or financial guidance with a qualified human professional.
Payments, scheduling, and email
- Stripe handles all Care Navigator session billing. Memory Lane never sees or stores your card details — Stripe gives us back a token and a payment status, nothing more.
- Calendly is used to schedule Care Navigator and partner intro calls. When you book, Calendly receives your name, email, and the slot you picked.
- Resend sends transactional email (welcome notes, share-link notifications, magic links). Resend sees only the recipient email and the message body. We do not run marketing campaigns from Resend; everything we send is in response to something you did.
Who can see your data
- You. Always.
- A very small founding team. Only when necessary for operations, debugging, or support — and only on the encrypted database, never copied out to other systems.
- Our infrastructure partners. The data lives on cloud infrastructure (MongoDB Atlas for storage, our hosting provider for the app). They process data on our behalf under their own enterprise security agreements but do not have any independent rights to your content.
- Specific service providers for the narrow purposes above — AI providers, Stripe, Calendly, Resend, GA4, PostHog, and (when enabled) Microsoft Clarity. The Security page lists every sub-processor and exactly what they receive.
We do not share your data with advertisers, data brokers, employers, insurers, or family members. If a court ever issued a lawful subpoena, we would notify you (where legally permitted) before responding.
How long we keep your data
For as long as your account is active. If you delete your account, we delete everything within 30 days, except where we're required to retain certain records for fraud or legal compliance (e.g., audit logs for security investigations — these never include your caregiving content). Analytics data in GA4/PostHog/Clarity is retained according to those providers' default retention windows (typically 14 months for GA4).
Your rights
You can, at any time:
- Ask us to show you everything we have about you.
- Ask us to export it in a portable format (JSON or PDF — your choice).
- Ask us to correct anything that is wrong.
- Ask us to delete your account and all associated data.
- Ask us to stop using your data for product improvement (we'll exclude your account from analytics queries).
Email ashlee@asvmedicalservices.com. We respond within 30 days. If you're in California, the EU/EEA, or the UK, you have additional statutory rights — we honor them globally even where not required.
Children
Memory Lane is for caregivers age 18+. We don't knowingly collect data from children. If you believe a child has signed up, write us and we'll delete the account.
Security
Passwords are hashed with bcrypt. Data in transit is TLS-encrypted. Data at rest in MongoDB is encrypted at the storage layer. Only a small team has database access, and access is logged.
No system is perfectly secure. If we ever experience a breach affecting your data, we will email you within 72 hours of confirming it, tell you what happened, and explain what we're doing about it.
Changes to this policy
If we materially change this policy, we'll show a notice in the app and email approved users. Continued use after the change means you accept the updated policy.
Contact
We write our privacy policy in the language we use to talk to caregivers. It is not a substitute for legal advice — but it is the truth about what we do with your data.