Under the hood

Exactly what happens to your files.

For anyone who wants the technical details behind our privacy promises. Every statement on this page describes how the system is built today. If something here changes, this page changes first.

The short version

  • Your upload goes straight to storage. Your browser sends the files directly to our storage bucket in the EU. Our web servers never handle the file contents.
  • Processed in the EU. A dedicated server in Germany or Finland fixes your memories, then is deleted when idle.
  • Deleted automatically. Originals when processing ends (at most 24 hours); fixed files 72 hours after they're ready; or everything right now, with one tap.
  • No AI, no people. Standard open-source media tools do the work. Nobody looks at your photos, and nothing is used to train anything.
  • Only Memories are opened. Chats, friends, account details and the rest of your Snapchat data are never read.
  • Narrow, temporary access. Google and Dropbox permissions only let us add files, and we drop them as soon as sending ends.

The journey of a file

  1. Upload

    When you start, our API creates a job and gives your browser short-lived signed upload addresses (valid for one hour) for a Cloudflare R2 bucket created with EU jurisdiction, which keeps the data stored inside the European Union. Your browser uploads the ZIP files there in parts, over HTTPS. Our servers only hand out the addresses; the bytes go from your device to storage. If your connection drops, the browser asks which parts arrived and sends only the rest.

  2. Waiting

    While you upload, the page tells our API roughly how long is left, so a processing server can be started just before you finish. Nothing is processed until every file has arrived.

  3. Processing

    Processing runs on a Hetzner server in the EU (currently Nuremberg or Falkenstein in Germany, or Helsinki in Finland), created for the work. Our code refuses to create one anywhere else. It has no public network access at all: its firewall accepts no incoming connections. It reads your ZIP files directly from storage and handles a few memories at a time on its own disk. As each memory is finished, the fixed file goes back to storage and the working copies are deleted straight away, so the server never holds your whole library. When there's no more work, the server itself is deleted.

  4. What we read

    Snapchat's export contains much more than Memories. Our code opens only the memories/ folder and the two files that list your Memories ( memories_history.json and .html), plus chat_media/ if you ticked "also save chat photos and videos". Everything else (chats, friends, account information, location history) is skipped without being opened, and deleted with the originals.

  5. The fixing

    Dates, places and captions are restored with standard open-source tools: FFmpeg for video, ExifTool for photo and video information, and Pillow for images. Time zones are looked up from each memory's coordinates with an offline map of time zones, so your locations are never sent to a map or geocoding service. No AI model runs on your media, and nothing is used for training.

  6. Getting them back

    Download links are signed and expire after 15 minutes; the results page quietly fetches fresh ones. If you send your memories to Google Photos, Google Driveā„¢ or Dropbox, a separate background process on our API server uploads them with the access you granted, then discards it (details below).

  7. Deletion

    Your originals are deleted as soon as processing ends. Fixed files are deleted 72 hours after they're ready, or immediately when you press "Delete my files now". The schedule below has the details and the safety nets.

Deletion schedule

Deletion is enforced three ways: by the job itself when it finishes, by a clean-up task that runs every 5 minutes, and by storage lifecycle rules as a last line of defence that doesn't depend on our code.

What When it's deleted Safety net
Your uploaded export As soon as processing finishes Clean-up task: 24 h maximum. Storage rule: anything older than 1 day.
Fixed photos and videos, ZIP downloads 72 h after they're ready Storage rule: anything older than 4 days.
Uploads you started but didn't finish When you press "Start over" Clean-up task after 24 h; storage rule aborts unfinished uploads after 1 day.
Working copies on the processing server As each memory is finished The whole server is deleted after 15 idle minutes.
Your email address and the job record With your files, after one final "files deleted" email Same clean-up task.
Google or Dropbox access When sending ends Also when the job is deleted, even mid-send.
Your IP address Never stored. Only a keyed hash is kept, for rate limiting. Hash rows deleted after 24 h.

"Delete my files now" removes your files and the job record immediately, and cancels any delivery in progress.

Where everything runs

Provider What it does for us Where
Cloudflare R2 Stores your uploads and fixed files, encrypted at rest EU (bucket with EU jurisdiction)
Hetzner Servers that process your files and run our API EU: Germany and Finland (API server in Germany)
Neon Database: job status, your email address, file names and counts Frankfurt, Germany
Cloudflare Serves this website, connects to our API, bot check Global network; no file contents
Resend Sends our emails, from its EU region, with open and click tracking turned off Receives only your email address and the message

Our API server has no open ports to the internet. Requests reach it only through an outbound Cloudflare Tunnel, and its firewall blocks everything else.

Who can see what

Your private link

There are no accounts. Your results page is protected by a secret in the link we email you: a 256-bit value derived from the job with a server-side key. We store only a SHA-256 hash of it, so even a copy of our database wouldn't contain working links. The secret sits after the # in the address, a part browsers never send to web servers, so it doesn't appear in website logs. Anyone with the link can see your results, so treat it like a password.

Us

We have no tool for viewing your files, and our processes never open them for any purpose other than fixing them. Our logs never contain file names, memory dates, places, links or email addresses: a filter strips them before anything is written. Technically, someone holding our infrastructure keys could reach stored files while they exist, which is exactly why they're deleted so quickly.

Opting in to emails

If you tick "email me when the photo library launches", your address is kept on a separate list, apart from your job, until launch. Ask us at support@backupmemories.com and we'll remove it.

Google and Dropbox permissions

We ask for the narrowest permission each service offers for adding files.

Destination Permission we ask for What it allows
Google Drive drive.file Create files and see only the files we created. Nothing else in your Drive.
Google Photos photoslibrary.appendonly Add photos and videos to a new album. We can't see your library.
Dropbox App folder, files.content.write Write into Apps/BackupMemories only.

While a delivery runs, its access token is stored encrypted (Fernet: AES-128 with an HMAC) and used only by the sending process. When sending finishes, fails or is cancelled, the token is deleted from our database and revoked with Google or Dropbox, so the access ends on their side too. Our use of information from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements.

The website itself

  • No tracking cookies and no advertising scripts.
  • Fonts and images are served from our own domain, so loading a page doesn't contact Google or any font or image service.
  • Bot check: Cloudflare Turnstile, which runs in the background on the upload page instead of showing image puzzles.
  • Resuming an upload: the upload page remembers your unfinished upload on your device, in your browser's own storage. It's never sent to us, and it's cleared when the upload completes.

What we can't promise

  • Once you send memories to Google Photos, Google Drive or Dropbox, or download them, those copies follow that service's rules or are yours to manage. We can't delete them for you.
  • Email travels through Resend and your own email provider.
  • Anyone you share your private link with can see and download your results until they're deleted.

This page explains how the system works; the privacy policy is the formal statement of your rights. Questions or doubts: support@backupmemories.com.