Privacy

Your memories, your control.

Last updated 10 September 2026.

This policy covers honordawn.com, every memorial published at its own address on that domain, and the email we send.

The short version

  1. You control what is public. A memorial is private until you publish it, and you decide what appears on it.
  2. AI drafts; a person approves. Nothing the AI writes about someone is published on your behalf.
  3. We do not track you. No analytics, no advertising, no third-party scripts — one cookie, to keep you signed in.
  4. Your photographs lose their GPS coordinates the moment they arrive.
  5. Delete means delete — and you can take everything with you first.

Who we are

HonorDawn is made by Tunabear Inc., 11711 Hillcrest Rd., Dallas, TX 75230-3109, USA. We decide what happens to the information described here, and we are the people to write to about any of it.

What we collect

Your account. Your name, your email address, and a password we store only as a one-way hash — we cannot read it, and if you forget it we can only help you set a new one.

The memorial you make. Everything you write or upload: names, dates, places, the life story, service details, photographs, links. That is the product, and there is no version of it that holds less.

People you invite. When you invite someone to contribute, we store the email address you gave us, the invitation itself, and whatever they choose to share.

People who leave a tribute. The name, message and relationship they type — and their email address only if they ask to be reminded of an anniversary, which they can stop from any reminder we send.

Payment. Stripe collects the card on its own page. We never see a card number. We keep what was charged, when, and Stripe’s reference for it.

Server logs. The server keeps operational logs so we can find faults. They are not in the database, not linked to your account, and used for nothing else. Cloudflare, which sits in front of the site, keeps its own connection records.

What we never do

This is the short list, and every line of it is a decision we can show you in our own source code rather than a promise about intentions.

  • No analytics. Not Google Analytics, not a privacy-friendly alternative, not a self-hosted one. There is no analytics code on this site at all.
  • No advertising and no tracking pixels — including in our email, which contains no images whatsoever.
  • We have never sold or shared personal information, and we never will. We do not profile you and we run no targeted advertising. Because none of that happens, there is no “Do Not Sell” link for us to give you, and a Do Not Track signal changes nothing about our behaviour — there is nothing to switch off.
  • No third-party fonts or scripts. Every font is served from our own server, so loading a page tells nobody else that you visited it.
  • One cookie. It keeps you signed in for 30 days, and it is the only thing we store on your device. There is no consent banner because there is nothing to consent to.
  • No facial recognition. We never analyse the faces in your photographs — no matching, no grouping by person, nothing that turns a face into data.
  • No precise location. The only geolocation that would ever reach us arrives inside a photograph, and we destroy it on arrival.

Who else touches it

Running this product means a handful of other companies handle some of it. Here is all of them, what reaches them, and why. We update this list when it changes.

WhoWhat reaches themWhy
AnthropicWhat you ask the assistant, the memorial content it needs to answer, and a photograph when you ask for a captionDrafting and captioning
ResendThe address, subject and body of each message we sendDelivering our email
StripeYour payment details, which you enter on Stripe’s own pageTaking the one-time payment
CloudflareTraffic to the site passes through their networkDNS and secure connections
Our hosting providerEverything, at rest — the database and the photograph files live on one server we rentHosting
Groq or OpenAIOnly if voice notes are switched on for you: the audio you recordTurning speech into text

The AI, specifically

What leaves our server. What you ask the assistant, along with the parts of the memorial it needs in order to answer, and a photograph when you ask for a caption for it.

What we keep. A record of each AI call: which feature made it, how long it took, a one-way hash of the prompt rather than the prompt itself — and the model’s reply in full, because that is the record of what was proposed to you. So a draft you read and rejected can still exist in that record. It is deleted when the memorial is.

Training. Our AI provider is Anthropic. Under the commercial terms we use, what we send is not used to train their models.

Nothing is published by the AI. Anything it writes that asserts a fact about a person is a draft until you approve it.

Photographs

A photograph taken on a phone usually carries the exact coordinates of where it was taken — which, for family photographs, is very often somebody’s home. We re-encode every image as it is uploaded, and that destroys the coordinates along with the rest of the embedded camera data. The stored file does not have them, so neither do we.

We read exactly one thing out of a photograph before that happens: the date it was taken, so the timeline can suggest a day you might want to add. Nothing else survives the upload.

Photographs on a memorial you have published are as public as that memorial is — which you control in its settings.

How long we keep it

WhatHow long
A memorial you delete30 days, restorable, then erased permanently
Your account, if you delete itImmediately, with no restore window
Your sign-in session30 days
A sign-in link or password reset30 minutes
A contributor invitation7 days
Records of AI callsUntil the memorial is deleted; they go with it
Payment records7 years, because tax law requires it — the amount, the date and Stripe’s reference, never a card number

That last row is a real exception to “delete means delete”, which is why it is in the table rather than in a footnote. Everything else about a deleted memorial or a closed account is gone, and we hold no second copy of it.

People who did not sign up

Most of this policy speaks to the person who made a memorial. But a memorial is built out of other people too, and they never agreed to anything.

If a family invited you to contribute, we have your email address because they typed it in. We use it to send you that invitation and to let you know when something you shared is published. You can ask us to remove it at any time.

If you left a tribute, an AI reads it first, to screen for abuse, before a person decides whether it appears. That screening happens on every submission and is not something a family can switch off.

If you are in a photograph or a story on a memorial, the family who made it can take it down in a few seconds, so asking them is the fastest way. If that is not possible, or you would rather not, write to us — we will look at it and act.

And the person the memorial is about. The privacy laws that apply to us protect living people, which means that, legally, the person being remembered has no rights in any of this at all — every protection here belongs to their family. We say that plainly because it is true, and then we ignore it: a product whose whole purpose is the careful handling of somebody’s life story cannot let a definition in a statute set its standard. Their story is treated as carefully as yours.

Your rights, and how to use them

Neither the California nor the Texas privacy law currently applies to a company our size. We are not going to lean on that, and there is no “California residents” section here implying everybody else gets less. These are for everyone who reads this page.

  • Know and see what we hold. Most of it is answered by the two tables above; ask us for the rest.
  • Take it with you. Already self-service, and more than a data extract: Download everything in your account gives you the whole memorial as files.
  • Correct it. Every field is editable in the admin, for as long as the memorial exists.
  • Delete it. Self-service, with the restore window and the one exception described above.
  • Be left alone. No sale, no sharing, no targeted advertising, no profiling — see the list further up.
  • Ask without consequence. Nothing about your memorial changes because you exercised any of this.
  • Appeal, if we say no. If we refuse a request we will tell you why, and you can ask us to look again — a second look by a person, within a reasonable time. If we still say no, the Texas Attorney General accepts complaints about it.

How to ask. Email [email protected]. So that we do not hand somebody’s family history to a stranger, write from the address on the account where you can — where you cannot, we will ask you enough to be sure who you are. We reply usually within two business days.

How it is protected

Passwords are stored as one-way hashes. So is every sign-in link, invitation and unsubscribe link — we keep only a fingerprint of each, so even we cannot reuse one. The site is served over an encrypted connection, and each memorial’s data is separated from every other memorial’s at the point where it is read.

No system is perfect and we are a small company, so here is the honest commitment instead of a guarantee: if something happened to your information, we would tell you, quickly, in plain words, and say what we were doing about it.

Children

HonorDawn is not meant for children, and we do not knowingly collect anything from anyone under 13. Contributors are invited by a family rather than by us, so if a child was invited and something of theirs is here, write to us and we will remove it.

Changes to this policy

If we change how any of this works, we will change this page and the date at the top of it. If the change matters to what you have already trusted us with, we will say so here rather than quietly editing a sentence.

Questions about any of it — [email protected], or Tunabear Inc., 11711 Hillcrest Rd., Dallas, TX 75230-3109.