# Privacy Policy

> How Mnemo Memory handles your data.

Canonical URL: https://mnemohq.com/privacy

Last updated: 16 April 2026.

Mnemo (“we”) operates the Mnemo Memory API. This policy describes what we collect, how we use it, and the controls you have.

## Information we collect

- Account data: email, name, hashed password, MFA enrolment, SSO identifiers. Collected when you sign up.
- Workspace content: memories, documents, search queries, and metadata you submit via the API. Stored encrypted at rest; encrypted in transit.
- Usage data: per-tenant counters (request counts, latency), audit logs of admin actions, IP address, user agent. Used for billing, security, and service improvement.
- Cookies: a session cookie after login. No third-party advertising or cross-site tracking cookies.

## How we use your data

We do not train AI models on your content. Embedding computation uses first-party and third-party providers (see sub-processors below) but payloads are not retained for training.

- Operate the Service (store, index, retrieve your memories).
- Provide support, bill accurately, prevent abuse.
- Communicate product updates and security-relevant notices.
- Comply with legal obligations.

## Sub-processors

- US-hosted infrastructure — primary hosting.
- Stripe — payments.
- Resend — transactional email.
- OpenAI — embedding generation (zero-retention tier).
- Anthropic — extraction (zero-retention tier).
- Sentry — error telemetry (PII scrubbed).
- PostHog — product analytics (EU-hosted, opt-out).

## Data residency

Today, all data is US-hosted. Per-workspace region selection (EU) is on the roadmap. Transactional email and payments are routed through providers with global presence.

## Retention

Workspace content is retained for the lifetime of your account. When you delete a workspace, we start a 30-day grace period and then purge permanently. Audit logs are retained for 1 year on paid plans, 90 days on free. Backups follow the same timeline.

## Your rights

You can access, export, correct, or delete your data at any time via the dashboard. EU/UK residents have additional rights under the GDPR (right to object, right to restrict processing, right to lodge a complaint with a supervisory authority).

## Security

We use argon2id for password hashing, TLS 1.2+ for transport, AES-256 for encryption at rest, MFA on all admin accounts, and continuous audit logging. Report vulnerabilities to security@mnemohq.com.

## Contact

Questions? Email privacy@mnemohq.com. Our Data Protection Officer can be reached at the same address.

## Explore Mnemo

- [Mnemo API documentation](https://mnemohq.com/docs)
- [Pricing](https://mnemohq.com/pricing)
- [Benchmarks](https://mnemohq.com/benchmarks)
- [Company Brain for Slack](https://mnemohq.com/brain)
- [Ask Mnemo widget](https://mnemohq.com/widget)
- [Data-source connectors](https://mnemohq.com/connectors)
- [Framework integrations](https://mnemohq.com/integrations)
- [Trust and security](https://mnemohq.com/trust)
- [Contact](https://mnemohq.com/contact)
- [llms.txt](https://mnemohq.com/llms.txt)
- [OpenAPI 3.1 specification](https://mnemohq.com/openapi.json)

---

This is the Markdown representation of https://mnemohq.com/privacy, served by content negotiation on `Accept: text/markdown`. Machine-readable index: https://mnemohq.com/llms.txt · https://mnemohq.com/openapi.json · https://mnemohq.com/sitemap.xml
