Skip to main content
For families who want their stories to last. learn about the founding circle.

Blog

Private memory infrastructure

Why the memory problem is an infrastructure problem, and what follows if you refuse to solve it with engagement. A plain reading of Confinity's architecture.

Written to last.

By Confinity · February 10, 2026 · 3-minute read
Quiet tools, kept out of the way.
Illustration for: Private memory infrastructure
A photo, a voice note, a handwritten letter. None of these is "content" in any interesting sense. They become memory when a family returns to them decades later and they still resolve. The internet is very good at moving content around. It's almost comically bad at letting a thing still be there, in a form you recognise, in thirty years. That gap isn't a feature gap. It's an infrastructure gap. Most of what makes a memory survivable across generations is decisions made long before a user ever sees the product: where the bytes live, who can subpoena them, what schema they're stored in, what happens if the company dies, what happens if the user dies, how the account passes to the next person. If those decisions go the wrong way once, you spend the next forty years paying for it.
  • Storage is addressable. Everything inside Confinity has a durable identifier that survives a migration. When we move a user from one region to another, or one storage tier to another, links inside the journal stay valid. If we ever went out of business, an export would be navigable by a stranger with a text editor. Durability means "can be read without us being alive to help you."
  • Encryption is envelope-based. We do not claim "end-to-end" because that claim leaks: recovery flows, family sharing, and moderation all require servers that read. What we do do is encrypt data at rest with per-user keys, separate key custody from data custody, and publish our exact posture in the Trust Centre. Being honest about what "private" means is more protective than being aspirational.
  • Succession is first-class. Every account has a successor contract: who inherits it, on what trigger, with what permissions. It's boring, it isn't a feature you open an app to use, and it's the single thing that separates memory infrastructure from a photo app. If Confinity goes away, succession is what keeps the work doing its job.
  • Portability is unconditional. Export is free, complete, and machine-readable. No "download a preview, pay for the rest." No lock-in by schema obscurity. The implicit pact is that you could leave us tomorrow and lose nothing structural. That pact is what earns us the right to be the archive.
A memory infrastructure that takes these four decisions seriously can't host advertising, can't train models on user content without explicit per-asset consent, and can't run growth experiments that compromise retention guarantees. It also can't pretend to be "free forever" for a product whose promise is "forever." Somebody pays, and when the somebody isn't the family, the family is the product. We wrote our pricing page around that refusal. Confinity is paid, subsidised at the thin end for people who can't afford it, and loud about where the money goes. The Family tier funds the storage, the engineering, and the quiet work nobody will ever thank us for: disaster recovery drills, export format stability, key rotation, succession rehearsals. The best memory infrastructure is the one you stop noticing. You open the app on the anniversary. The note is still there. The voice note still plays. The family group you set up in 2026 still has the people you expected, minus the ones who died, plus the ones they added. Nothing about the layout or the terms has changed under you. That quiet continuity is the product. The rest of what we ship is in service of it.
What we preserve here

Confinity writing exists to turn memory, identity, and technology into practices families can actually keep.

More from the Confinity journal

Back to blog
Heritage library
Start your own archive