Privacy Policy

Last updated: January 30, 2026

Introduction

MemNexus (“we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

Information We Collect

Information You Provide

  • Account information (email, name)
  • Conversation data and memories you create
  • Payment information (processed by our payment provider)
  • Support communications

Information Collected Automatically

  • Usage data (features used, interaction patterns)
  • Device information (browser type, operating system)
  • Log data (IP address, access times)

How We Use Your Information

  • Provide and improve our services
  • Process transactions and send related information
  • Send technical notices and support messages
  • Respond to your comments and questions
  • Analyze usage patterns to improve user experience

Data Security

We implement industry-standard security measures to protect your data:

  • Encryption in transit (TLS 1.3)
  • Encryption at rest at the storage layer — database files are encrypted
  • Field-level encryption of memory content (AES-256-GCM-SIV, under a key unique to your account)

One exception, stated in full: search indexes and embedding vectors are stored unencrypted so that keyword and semantic search work. A searchable plaintext copy of your memory content is stored alongside the encrypted copy. It sits inside the encrypted storage layer, but field-level encryption does not cover it.

Data Retention

We retain your data according to your subscription tier:

  • Free tier: 90-day retention
  • Pro tier: Forever retention
  • Enterprise: Custom retention policies

You can export or delete your data at any time from your account settings.

Account Activity Records

Separately from your memory data, we keep a limited audit trail of account lifecycle events — account creation, invite redemption, and deletion requests and completions. We keep these records to meet our security and legal obligations and to defend against abuse.

We retain these records no longer than we need them for security and legal purposes, and we are implementing a 12-month retention limit. Because we rely on them for compliance and abuse prevention, they are kept for that period even if you delete your account — a limited exception to erasure permitted under GDPR Article 17(3). Each record holds the event type, your account identifier, your IP address, and a timestamp, along with event metadata; these records aren't used for any other purpose.

Your Rights

You have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Delete your data
  • Export your data
  • Opt out of marketing communications

Contact Us

If you have questions about this Privacy Policy, please contact us at [email protected]