Memento · Rules and privacy

What happens to what you share

Four short documents in plain language: the community rules, what is public and what is not, who owns what you share, and how reporting and appeals work.

Community rules

MEMENTO keeps a finite number of memories. Every accepted memory takes one of 3,690 addresses and replaces a synthetic one, which is why a person reads every submission before it is published.

What belongs here

Something you lived through, written in your own words. Small and ordinary is welcome; that is most of what a life is made of. A memory can be text, a photograph, a recording, a short video or a scan, with a few lines about what it changed in you.

What does not

Anything you did not experience or do not have the right to share. Material generated by a model. Advertising or promotion. Harassment, hatred against people for who they are, sexual content, graphic violence, or anything that puts a person at risk. Other people's private information: addresses, phone numbers, documents, medical details. Children identified by name; if a child appears in a photograph, the person responsible for that child must agree before it is shared, and we will ask.

About other people

Most memories involve someone else. Write what you experienced rather than what you believe another person felt, ask when you can, and leave out what they would not want public. A memory is yours; the people in it are not.

Names and attribution

Each memory is shared either under your username or as an anonymous contributor. You choose that for each one. Impersonating another person, or claiming someone else's memory or media as your own, ends an account.

If a rule is broken

A moderator may ask for changes, decline a memory, hide it while it is reviewed, remove it, warn an account, restrict publishing, suspend an account, or close it. Closing an account happens only after a confirmed serious violation or a repeated pattern; it is not a first response, and every decision carries a written reason you can read and appeal.

Privacy

What is public

Only an accepted memory and its record: the text, any media, the time and place you chose to share (both can be “Not shared”), the themes, its address and accession number, and either your username or “Anonymous contributor”. Public profiles show a username, an optional display name and bio, the month you joined, and the memories you chose to share under your name.

What is never public

Your password (only a hash of it is stored, using bcrypt), your recovery code (also only a hash), your five application answers, anything you draft or submit but that is not yet accepted, reports you send or reports about you, moderation notes and decisions beyond what you are told, your sessions, and connection data.

What we keep about connections

To limit abuse we store a salted hash of the IP address for sign-ins, uploads, reports and moderation actions, and the browser's user-agent string for your own session list. We do not store raw IP addresses, we do not use analytics or advertising trackers, and we do not sell anything. There is no email address on a MEMENTO account.

Who can see what

You see everything on your own account. Moderators see applications, submissions under review, reports, and the audit log. Administrators additionally manage roles. Nothing about you is shared with another member beyond your public profile and your published memories.

How long things are kept

Accepted memories are meant to be permanent: that is the point of a finite public memory. Drafts stay until you delete them. Application answers are kept while the account exists. Moderation records and the audit log are kept as long as needed to answer an appeal and to keep the system accountable, and are the minimum needed for that. Connection hashes are kept for a short period for abuse investigation.

Your data

You can download everything held about you from your profile at any time. You can ask for your account to be deleted: your profile details and application answers are removed or anonymised, your drafts are deleted, and you can ask for your published memories to be removed individually. An address that has been used is retired rather than reused, so the finite count stays honest.

Children

MEMENTO is not for children. Accounts are for adults. A child can appear in a memory only with the permission of the person responsible for them, and we will not publish a memory that names a child.

No scoring

No model reads your application to judge you, and nothing in this system scores truthfulness, emotion, politics or character. Applications and memories are read by people. The behaviour engine derives a state from accepted memories; it is a deterministic prototype and is not connected to any model.

Content and media rights

What you keep

You keep ownership of what you write and upload. Nothing you share is sold, licensed onward, or used to train a model.

What you grant

When a memory is accepted you give MEMENTO permission to publish it and keep it published as part of the public record, at its address, with the attribution you chose. This permission is what makes a permanent public memory possible. You can ask for a memory to be removed; the record of an address having been used remains.

What you confirm when you submit

That the memory is yours to share; that any photograph, recording, video or scan is yours or that you have permission to share it; that you have considered the people shown or heard in it; and that no identifiable child appears without the permission of whoever is responsible for them.

What we do to a file

Uploads are held privately, checked by their actual decoded content rather than their name, re-encoded, stripped of camera and location metadata, and kept out of public reach until the memory is accepted. Files that can carry scripts are refused. Nothing is served in a way that lets it run in your browser.

If someone else's work appears

Tell us with the report action and name the work. Media under a confirmed rights dispute is hidden while it is reviewed.

Reporting and appeals

Reporting

Every published memory and every public profile carries a report action. Choose a reason, say what you saw, and send it. Reports are private: the person you report is never told who reported them. Repeated reports about the same thing become one case rather than a pile-on, and reporting never removes anything on its own.

For the most serious safety categories — sexual content, content involving a child, violence — the media is hidden automatically while a moderator reviews it. That is a pause, not a finding, and the contributor is told so in those words.

What a moderator can do

Dismiss the report, ask for changes, decline a memory, hide it, remove it, warn, restrict, suspend or close an account. Every action needs a written reason. Removing a memory or suspending or closing an account also needs an explicit confirmation, so it cannot happen by a stray click.

Appeals

If a decision goes against you, you are told what it was and why, and you can appeal from your profile. A different moderator reads the appeal. If it is upheld, the decision stands and you are told why. If it is overturned, the memory goes back into the review queue for a fresh decision.

Disputed authenticity

If someone says a memory is not what it claims to be, that is a review, not an automatic removal. We look at what was submitted and at the account's history, and we say what we decided.

Contact

Until a contact address is published, reporting and appeals inside the system are the way to reach the moderators. A named contact point and a data-protection contact are required before launch; see README · Launch blockers.