Back to signup
Privacy Policy
Last updated: July 31, 2026
This Privacy Policy explains how MemBytes collects, uses, protects, and shares information when customers use our secure AI memory platform.
1. Information we collect
We collect account information such as administrator email addresses, usernames, password hashes, roles, organization identifiers, namespaces, session scopes, verification status, and login activity. We may also collect billing, support, and communication details when customers contact us or subscribe to paid services.
2. Customer content
Customers may upload or sync emails, chat messages, documents, spreadsheets, notes, images, metadata, attachments, and other business records. This content is processed as customer data and is used to create searchable memories, embeddings, summaries, audit records, and AI-assisted answers inside the customer's authorized workspace.
3. Connector data
When an administrator or authorized user connects Gmail, Google Drive, Slack, Microsoft Teams, Microsoft 365, or another source, MemBytes stores the information needed to run that connector, such as provider name, account identifiers, sync status, token references, history identifiers, webhook events, and sync logs. We use this information to import new records, backfill historical records, renew syncs, and report connector health.
4. How we use information
We use information to provide the product, authenticate users, enforce role-based access control, import and index content, generate embeddings, answer memory search queries, show dashboards, run background jobs, send account emails, troubleshoot issues, improve reliability, prevent misuse, and comply with legal obligations.
5. AI processing
MemBytes may send selected decrypted content to configured AI providers only when needed to create embeddings, summarize imports, answer a query, or perform another requested AI action. Vector search can use stored embeddings without decrypting every memory. AI providers may process submitted content according to the customer's configuration and the provider terms that apply to the account.
6. Encryption and security
MemBytes is designed with application-level encryption for memory content, role-based access control, organization isolation, audit logging, secure connector handling, and restricted retrieval of relevant memories. Decrypted content is used only when required for an authorized operation, such as answering a chat query or preparing a response.
7. Access control and administrator responsibility
Customer administrators control users, roles, namespaces, categories, connector access, and import permissions. Administrators should assign the minimum access needed, review user activity, deactivate unused accounts, and ensure users only connect or upload data they are authorized to process.
8. Sharing of information
We do not sell customer content. We may share information with service providers that help operate MemBytes, such as hosting providers, database providers, email delivery providers, AI providers, payment providers, monitoring tools, and support systems. These providers are used only as needed to deliver, secure, and support the service.
9. Cookies and technical data
MemBytes uses necessary cookies and similar browser storage to keep users signed in, protect accounts, remember privacy choices, route requests, and operate the platform. With consent where required, MemBytes may also use optional analytics cookies to understand product usage and optional marketing cookies for campaign measurement. Optional cookies can be accepted, rejected, or managed from the Cookie Policy page.
Read the Cookie Policy or .
10. Retention
Customer content is retained according to workspace settings, subscription requirements, customer instructions, backup schedules, and legal or security obligations. Audit logs, billing records, security records, and connector logs may be retained for longer where needed for compliance, abuse prevention, troubleshooting, or dispute handling.
11. Export, correction, and deletion
Customers may request access to, export of, correction of, or deletion of workspace data. Some requests must be handled by the customer's administrator because MemBytes acts as a processor for content controlled by that customer. Certain records may be retained where required for security, legal, billing, or backup purposes.
12. International processing
MemBytes and its service providers may process information in locations where infrastructure, support, or third-party services operate. Customers are responsible for confirming that their use of MemBytes is permitted under the data protection rules that apply to their organization and users.
13. Children's data
MemBytes is a business product and is not intended for children. Customers must not knowingly upload or sync children's personal data unless they have the legal right and required consent to do so.
14. Data breach and incident handling
If we identify a security incident that affects customer data, we will investigate, take reasonable containment steps, and notify affected customers when required by law or contract. Customers should also maintain their own security monitoring and user access review process.
15. Changes to this policy
We may update this Privacy Policy when the product, legal requirements, providers, or security practices change. The updated version will show a new effective date. Continued use of MemBytes after an update means the updated policy applies.
16. Contact
Privacy questions, access requests, or deletion requests can be sent to [email protected].
This page is a product-ready starting version and should be reviewed by a qualified legal professional before public launch or customer contract use.