Privacy Policy
Last updated: 16 April 2026.
Mnemo (“we”) operates the Mnemo Memory API. This policy describes what we collect, how we use it, and the controls you have.
Information we collect
- Account data: email, name, hashed password, MFA enrolment, SSO identifiers. Collected when you sign up.
- Workspace content: memories, documents, search queries, and metadata you submit via the API. Stored encrypted at rest; encrypted in transit.
- Usage data: per-tenant counters (request counts, latency), audit logs of admin actions, IP address, user agent. Used for billing, security, and service improvement.
- Cookies: a session cookie after login. No third-party advertising or cross-site tracking cookies.
How we use your data
We do not train AI models on your content. Embedding computation uses first-party and third-party providers (see sub-processors below) but payloads are not retained for training.
- Operate the Service (store, index, retrieve your memories).
- Provide support, bill accurately, prevent abuse.
- Communicate product updates and security-relevant notices.
- Comply with legal obligations.
Sub-processors
- US-hosted infrastructure — primary hosting.
- Stripe — payments.
- Resend — transactional email.
- OpenAI — embedding generation (zero-retention tier).
- Anthropic — extraction (zero-retention tier).
- Sentry — error telemetry (PII scrubbed).
- PostHog — product analytics (EU-hosted, opt-out).
Data residency
Today, all data is US-hosted. Per-workspace region selection (EU) is on the roadmap. Transactional email and payments are routed through providers with global presence.
Retention
Workspace content is retained for the lifetime of your account. When you delete a workspace, we start a 30-day grace period and then purge permanently. Audit logs are retained for 1 year on paid plans, 90 days on free. Backups follow the same timeline.
Your rights
You can access, export, correct, or delete your data at any time via the dashboard. EU/UK residents have additional rights under the GDPR (right to object, right to restrict processing, right to lodge a complaint with a supervisory authority).
Security
We use argon2id for password hashing, TLS 1.2+ for transport, AES-256 for encryption at rest, MFA on all admin accounts, and continuous audit logging. Report vulnerabilities to security@mnemohq.com.
Contact
Questions? Email privacy@mnemohq.com. Our Data Protection Officer can be reached at the same address.