Privacy Policy for MemoryBridge AI

Effective date: September 28, 2025 • Last updated: August 12, 2026

Our Privacy Promise (TL;DR)

Your memories are yours. We built MemoryBridge AI with privacy-first architecture, collecting only what's necessary to provide cross-platform AI memory services. We never sell your data or use it to train AI models.

  • No data sales: We will never sell your personal data to anyone, ever.
  • Your control: Export or delete your memories anytime. Full data ownership guaranteed.
  • Security first: TLS 1.3 encryption in transit, encryption at rest, PostgreSQL row-level security, SHA-256 hashed API keys.
  • Minimal collection: We only store what you explicitly save as memories.
  • Transparency: Open about our practices, third-party services, and your rights.

1. Who We Are

Service: MemoryBridge AI - Unified Personal AI Memory Platform
Company: Apex Leadership Lab, LLC
Type: Delaware Limited Liability Company
Address: 2261 Market Street STE 86401, San Francisco, CA 94114, United States
Contact: hello@memorybridge.ai | (510) 288-9594

This Privacy Policy applies to the MemoryBridge AI web application, Model Context Protocol (MCP) servers, REST APIs, browser extensions, and all related services (collectively, the "Service").

1a. Service Region — US Only

MemoryBridge AI is offered only to residents of the United States. We do not knowingly collect, store, or process personal information from individuals located in the European Economic Area (EEA), the United Kingdom, Switzerland, or any other jurisdiction outside the United States. If you believe you have created an account from outside the United States, please email privacy@memorybridge.ai and we will delete your account and all associated data.

Our marketing and signup pages are geofenced; access to those pages from non-US IP addresses returns a notice and a waitlist link.

1b. We Never Train AI Models on Your Memories

Your memories are never used to train AI models — not ours, not our providers'. We send memory content to Anthropic (for chat and extraction) and Voyage AI (for embeddings) under commercial API terms that prohibit use of the content for model training. We do not sell, rent, or otherwise share your memory content with third parties for advertising or model-training purposes.

1c. Sub-Processors

We use the following sub-processors to deliver the Service. All are US-based and bound by data processing terms equivalent to ours.

ServicePurposeRegion
SupabaseDatabase, authenticationUnited States
NetlifyWeb hosting, serverless functionsUnited States
AnthropicAI inference (chat, extraction)United States
Voyage AIEmbeddings for semantic searchUnited States
StripePayments, subscription billing, taxUnited States
ResendTransactional emailUnited States

1d. Your Rights Under US State Privacy Laws

Depending on where you live, you may have rights under one or more of the following: the California Consumer Privacy Act (CCPA) as amended by CPRA, the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), the Connecticut Data Privacy Act (CTDPA), the Utah Consumer Privacy Act (UCPA), and the Texas Data Privacy and Security Act (TDPSA).

These laws give you the right to: (a) know what personal information we collect about you; (b) request a copy of that information; (c) request that we correct inaccurate information; (d) request that we delete your information; (e) opt out of the sale or sharing of your information (we do not sell or share your information for targeted advertising); and (f) be free from discrimination for exercising these rights.

California residents also have the right to limit our use and disclosure of sensitive personal information. You may designate an authorized agent to exercise these rights on your behalf; we will verify the agent's authorization before responding.

To exercise any of these rights, delete your account in-app from Settings → Profile → Delete account, or email privacy@memorybridge.ai. We respond within 45 days as required by applicable law.

2. Information We Collect

Account Information

  • • Email address and password (via Supabase Auth; passwords are stored hashed, and sign-in is email/password only)
  • • Account preferences and settings
  • • API keys (SHA-256 hashed, we never store plain text keys)
  • • OAuth client configurations
  • • Invite codes you create, plus optional recipient email and personal note (used to send the invite and surface it on /app/settings/invites). The invite-code string is stored in plaintext so it can be redeemed.
  • • Waitlist email address and signup source, if you join the waitlist (including from a region where signup is not yet available)

Memory Content (Traces)

  • • Memory titles and content you explicitly create
  • • Memory candidates auto-extracted from conversation transcripts via the MCP extract tool or a bulk import (ChatGPT and Claude exports, PDF, plain text, or markdown), held in the Memory Inbox with status='pending' until you approve them
  • • Categories (personal, work, preference, fact, context)
  • • Tags and importance levels you assign
  • • Vector embeddings generated via Voyage AI for semantic search (always computed from PII-redacted content — see below)
  • • Optional temporal fields: valid_from, valid_until, and supersedes_trace_id. When set, they let a memory phase out of AI search and resources without being deleted, and let newer memories reference the older ones they replace.
  • • Detected-PII metadata: when our server-side scrubber finds secrets in incoming content, the per-type count is recorded under metadata.pii on the trace
  • • Timestamps and access patterns

Automatic PII Redaction

Every server-side write path — REST /api/traces, MCP create, MCP extract, and the browser extension's captures — runs incoming content through a conservative regex-based scrubber before the row is persisted or the embedding is generated. We never store the raw secret in that case. Detected types include:

  • • Credit cards (Luhn-validated), US Social Security numbers
  • • Provider API keys: OpenAI, Anthropic, AWS, Stripe, GitHub, Slack, Google
  • • JWT tokens and PEM private keys

If your user_settings.privacy_mode is set to strict, the insert is refused entirely with a redacted preview returned to the caller. The default mode (standard) stores the redacted content with a "PII redacted" flag surfaced in the dashboard.

Browser Extension Data Flow

The optional MemoryBridge Chrome extension stores only your configured API key and base URL in chrome.storage.sync locally on your browser. Right- click "Save selection" and toolbar searches go directly to the same hosted REST endpoints the web app uses; no separate data pipeline. The extension does not run scripts on third-party pages except when you explicitly trigger a save, and the content you save is run through the same PII redaction described above.

Technical Information

  • • IP addresses (for security and rate limiting)
  • • Browser type and version
  • • Device information
  • • Short-lived request and error logs from our hosting provider, used for debugging and security

Usage Data

  • • AI usage metering: query units consumed per billing month (chat, imports, extension enrichment), used to enforce plan quotas
  • • Memory access telemetry: which memories were retrieved by which connected integration (this powers your dashboard insights)
  • • MCP tool invocations from AI assistants

3. How We Use Your Information

  • Provide the Service: Store, index, and retrieve your memories across AI platforms
  • Enable MCP Integration: Allow ChatGPT, Claude, Cursor, and other AI assistants to access your memories
  • Semantic Search: Create vector embeddings for intelligent memory retrieval
  • Security: Detect and prevent unauthorized access, abuse, or attacks
  • Improvements: Analyze usage patterns to enhance features and performance
  • Support: Respond to your inquiries and provide technical assistance
  • Legal Compliance: Meet legal obligations and enforce our Terms of Service

4. Why We Process Your Data

MemoryBridge AI is currently offered to users in the United States only. We process your data:

  • To provide the Service: The memory storage, search, and MCP services you requested
  • To keep it safe: Security, fraud prevention, and service improvements
  • With your consent: For marketing communications (which you can opt out of anytime)
  • As required by law: To comply with applicable laws and regulations

5. Data Sharing and Third Parties

We do not sell, rent, or trade your personal information. We share data only with:

Service Providers

  • Supabase: Database, authentication, and storage (US)
  • Voyage AI: Vector embeddings for semantic search (US)
  • Netlify: Hosting and serverless functions (US)
  • Resend: Transactional email delivery (welcome emails after signup, optional friend-invite emails when you check "Email the invite now" on /app/settings/invites). Only the recipient address, your account email (as Reply-To), and the rendered email content are sent. (US)
  • Stripe: Payment processing, subscription billing, and sales tax for the Pro plan (US). Card details go directly to Stripe; we never see or store your full card number.

AI Providers (Only When You Use MCP)

  • OpenAI: When using ChatGPT with MCP
  • Anthropic: When using Claude with MCP, and server-side for the MCP extract tool, the bulk Import endpoint, browser-extension capture enrichment, and the "Ask your memory" chat surface (transcript / question + retrieved memory snippets are sent to Claude Haiku or Claude Sonnet to produce the response).
  • Other MCP and REST clients: Any assistant or tool you choose to connect (for example Cursor or Claude Code) receives the memories it retrieves on your behalf.

Note: These providers only receive the specific memories retrieved for your query (or the transcript you're importing). They cannot access your entire memory database, and we explicitly prohibit them from using your data for model training.

Legal Requirements

We may disclose information if required by law, court order, or to protect rights and safety.

6. Data Security

We implement industry-standard security measures:

  • Encryption: TLS 1.3 for data in transit, AES-256 for data at rest
  • Access Control: PostgreSQL row-level security ensures data isolation
  • API Security: SHA-256 hashed keys with prefix identification
  • Infrastructure: Secure cloud hosting with DDoS protection
  • Monitoring: Automated dependency health checks every 30 minutes with operational alerting, plus per-minute and per-day rate limits on every endpoint
  • Backups: Managed encrypted database backups through Supabase
  • Code Security: Signature-verified webhooks (Stripe, Resend), a strict Content Security Policy, and automated checks on every code change

7. Data Retention and Deletion

  • Memory Content (Pro): Retained until you delete it or close your account
  • Memory Content (Free tier): Memories are archived 30 days after creation. Archived memories are held for a further 30 days (and restored if you upgrade), then permanently deleted.
  • Chat conversations: "Ask your memory" chat history is stored only in your browser's local storage, never on our servers
  • Account Data: Retained while your account is active
  • Usage and access telemetry: Retained while your account is active; deleted with your account
  • Operational Logs: Short-lived and rotated automatically by our hosting provider
  • Backups: Deleted data removed from backups within 30 days
  • Legal Records: Financial records retained as required by law (typically 7 years)

You can delete individual memories anytime through the dashboard. To delete your entire account, use Settings → Profile → Delete account; deletion is immediate and permanent, and removes your memories, API keys, OAuth grants, settings, and login. You can also email privacy@memorybridge.ai and we will delete the account for you.

8. Your Rights and Choices

You have the right to:

  • Access: Request a copy of your personal data
  • Correct: Update inaccurate or incomplete information
  • Delete: Request deletion of your account and data
  • Export: Download your memories in JSON or Markdown format from Settings → Data & export
  • Object: Opt-out of certain processing activities
  • Restrict: Limit how we process your data
  • Portability: Transfer your data to another service

To exercise these rights, email privacy@memorybridge.ai. We respond within 45 days as required by applicable law.

9. Cookies, Local Storage, and Tracking

We keep client-side storage minimal and essential:

  • Authentication: Your sign-in session is kept in your browser's local storage (Supabase Auth tokens), not in tracking cookies
  • Preferences and chat: UI settings and "Ask your memory" chat history live in your browser's local storage
  • Payments: Stripe's hosted checkout and billing portal may set their own cookies, governed by Stripe's privacy policy

We don't use advertising cookies, third-party analytics, or tracking pixels. Clearing your browser storage signs you out and removes locally stored chat history.

10. Where Your Data Lives

We're based in the United States, and the Service is currently offered to US residents only. Your data is stored and processed in the United States. If you travel abroad and sign in to an existing account, your data is still processed in the US and protected with TLS encryption in transit. If we expand to other regions, we'll update this policy with the applicable transfer safeguards first.

11. Children's Privacy

MemoryBridge AI is not intended for users under 18 years old. We do not knowingly collect data from children. If you believe a child has provided us with personal information, please contact us immediately at privacy@memorybridge.ai.

12. California Privacy Rights (CCPA)

California residents have additional rights:

  • • Know what personal information we collect and how it's used
  • • Request deletion of personal information
  • • Opt-out of the sale of personal information (we don't sell data)
  • • Non-discrimination for exercising privacy rights

To exercise these rights, email privacy@memorybridge.ai or call (510) 288-9594.

13. Law Enforcement Requests

We require valid legal process (subpoena, court order, or warrant) to disclose user data. Unless legally prohibited, we'll notify affected users before disclosure.

14. Data Breach Notification

If a data breach occurs that affects your personal information, we will:

  • • Notify affected users within 72 hours of discovery
  • • Provide details about what information was affected
  • • Explain steps we're taking to address the breach
  • • Offer guidance on protecting yourself
  • • Notify relevant regulatory authorities as required

15. Changes to This Policy

We may update this Privacy Policy periodically. Material changes will be notified via:

  • • Email notification to your registered address
  • • In-app notification banner
  • • Updated "Last updated" date at the top

Continued use after changes indicates acceptance. For significant changes affecting your rights, we may request explicit consent.

16. Contact Us

Privacy Contact

Apex Leadership Lab, LLC

2261 Market Street STE 86401

San Francisco, CA 94114

United States

Email: privacy@memorybridge.ai (privacy requests) or hello@memorybridge.ai (general)
Phone: (510) 288-9594
Response Time: Within 45 days for privacy requests

17. Source Availability and Transparency

MemoryBridge AI believes in transparency. The platform's source code is published for reference on GitHub under a proprietary source-available license, and we maintain public documentation about our data practices, security measures, and API specifications.