HOME
HOW IT WORKS WHY IT MATTERS COMPLIANCE CASE STUDIES MI™ BETA

What We Collect

When you join our waitlist or contact us

Your email address and name (if you provide it). That's it. We use this solely to keep you in the loop about product launches. We don't add you to third-party lists. We don't sell leads.

When you use the MemoryIntelligence™ cloud API and portal (beta)

Your captures are sent to our servers, processed there, and stored there. That's what makes the product work: the engine reads your content to extract entities, topics, and claims, and it can't extract meaning from content it can't read.

Here is exactly where encryption stands in the beta. In transit, everything moves over TLS. At rest, every memory in the vault is already sealed in an encrypted envelope, and we run a cryptographic audit that proves every envelope decrypts back to its exact content. One legacy step remains: the original plaintext copy still sits beside those envelopes until a final removal that is irreversible, so we gate it behind a fresh backup and a clean re-run of that audit rather than rushing it. We'll update this page when it lands.

And to be precise about what encryption at rest buys you: it protects your data if the database is stolen. It does not stop the service itself from reading content, because the engine has to decrypt captures to process them. During beta, the small team that operates the service can access stored content for support and debugging. We treat that access as a liability, not a perk: it's limited, logged, and we're building it down to a break-glass exception rather than a default.

Beta guidance: don't capture regulated or highly sensitive data yet. No health records, no credentials, no other people's private information. Work notes, ideas, meetings: yes. Anything you'd need a compliance officer for: not yet. We'll update this page as the guarantees strengthen.

When you use our local products

Desktop capture runs on your device. Where a local product syncs to your cloud vault, the same server-side rules above apply to what it syncs.

Analytics

We use basic, privacy-respecting analytics to understand how people find our website, not what they do on it. No fingerprinting. No cross-site tracking. No ad networks. No pixels from companies who think your browsing history is their business model.

Cookies

We use one kind of cookie: a strictly necessary session cookie that keeps you signed in to the developer portal. It holds your login session and nothing else, it isn't shared with anyone, and it clears when your session ends. We don't set advertising, tracking, or cross-site cookies, which is why there's no consent banner to click through. If we ever add a cookie that isn't essential, we'll ask first.

Data Ownership

This is where most companies get creative with language. We'll be direct: you own your data. Not "you retain certain rights." Not "you grant us a perpetual license." You own it. Full stop.

Our infrastructure creates data receipts: cryptographic proof of provenance. This means you can always verify what data you have, where it came from, and how it's been used. That's not a feature we added for marketing. It's the foundation of everything we build.

Third Parties

We don't share your personal information with third parties for their marketing purposes. We don't have data-sharing agreements with ad networks. We don't participate in data brokerages. We use Cloudflare for hosting and basic email infrastructure to send you updates you asked for. That's the full list.

Security

Data moves over TLS. At rest, the vault uses envelope encryption with a managed key held separately from the database: every stored memory is sealed, and our audit proves each envelope round-trips to its exact content before we change anything. The one remaining step is removing the legacy plaintext that still sits beside those envelopes; it's irreversible, so it waits on a fresh backup and a clean re-audit. Until it lands, a database breach would expose stored content, and we'd rather tell you that plainly than round up. Once it lands, a stolen database yields ciphertext without the key. Provenance is hashed and receipted at every stage, so you can verify what exists and prove what was deleted. That's also why the beta guidance above says to keep regulated and highly sensitive data out for now.

Your Rights

You have the right to access, correct, or delete any personal information we hold. You can request a complete export at any time. You can opt out of communications with one click. These aren't rights we're grudgingly giving you because a regulation told us to. They're principles we built the company on.

Questions? We don't hide behind a legal@ email that nobody reads. Reach out through our Connect form and a real person will respond.