Effective date: September 28, 2025 • Last updated: August 12, 2026
Your memories are yours. We built MemoryBridge AI with privacy-first architecture, collecting only what's necessary to provide cross-platform AI memory services. We never sell your data or use it to train AI models.
Service: MemoryBridge AI - Unified Personal AI Memory Platform
Company: Apex Leadership Lab, LLC
Type: Delaware Limited Liability Company
Address: 2261 Market Street STE 86401, San Francisco, CA 94114, United States
Contact: hello@memorybridge.ai | (510) 288-9594
This Privacy Policy applies to the MemoryBridge AI web application, Model Context Protocol (MCP) servers, REST APIs, browser extensions, and all related services (collectively, the "Service").
MemoryBridge AI is offered only to residents of the United States. We do not knowingly collect, store, or process personal information from individuals located in the European Economic Area (EEA), the United Kingdom, Switzerland, or any other jurisdiction outside the United States. If you believe you have created an account from outside the United States, please email privacy@memorybridge.ai and we will delete your account and all associated data.
Our marketing and signup pages are geofenced; access to those pages from non-US IP addresses returns a notice and a waitlist link.
Your memories are never used to train AI models — not ours, not our providers'. We send memory content to Anthropic (for chat and extraction) and Voyage AI (for embeddings) under commercial API terms that prohibit use of the content for model training. We do not sell, rent, or otherwise share your memory content with third parties for advertising or model-training purposes.
We use the following sub-processors to deliver the Service. All are US-based and bound by data processing terms equivalent to ours.
| Service | Purpose | Region |
|---|---|---|
| Supabase | Database, authentication | United States |
| Netlify | Web hosting, serverless functions | United States |
| Anthropic | AI inference (chat, extraction) | United States |
| Voyage AI | Embeddings for semantic search | United States |
| Stripe | Payments, subscription billing, tax | United States |
| Resend | Transactional email | United States |
Depending on where you live, you may have rights under one or more of the following: the California Consumer Privacy Act (CCPA) as amended by CPRA, the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), the Connecticut Data Privacy Act (CTDPA), the Utah Consumer Privacy Act (UCPA), and the Texas Data Privacy and Security Act (TDPSA).
These laws give you the right to: (a) know what personal information we collect about you; (b) request a copy of that information; (c) request that we correct inaccurate information; (d) request that we delete your information; (e) opt out of the sale or sharing of your information (we do not sell or share your information for targeted advertising); and (f) be free from discrimination for exercising these rights.
California residents also have the right to limit our use and disclosure of sensitive personal information. You may designate an authorized agent to exercise these rights on your behalf; we will verify the agent's authorization before responding.
To exercise any of these rights, delete your account in-app from Settings → Profile → Delete account, or email privacy@memorybridge.ai. We respond within 45 days as required by applicable law.
/app/settings/invites). The invite-code string is stored in plaintext so it can be redeemed.extract tool or a bulk import (ChatGPT and Claude exports, PDF, plain text, or markdown), held in the Memory Inbox with status='pending' until you approve themvalid_from, valid_until, and supersedes_trace_id. When set, they let a memory phase out of AI search and resources without being deleted, and let newer memories reference the older ones they replace.metadata.pii on the traceEvery server-side write path — REST /api/traces, MCP create, MCP extract, and the browser extension's captures — runs incoming content through a conservative regex-based scrubber before the row is persisted or the embedding is generated. We never store the raw secret in that case. Detected types include:
If your user_settings.privacy_mode is set to strict, the insert is refused entirely with a redacted preview returned to the caller. The default mode (standard) stores the redacted content with a "PII redacted" flag surfaced in the dashboard.
The optional MemoryBridge Chrome extension stores only your configured API key and base URL in chrome.storage.sync locally on your browser. Right- click "Save selection" and toolbar searches go directly to the same hosted REST endpoints the web app uses; no separate data pipeline. The extension does not run scripts on third-party pages except when you explicitly trigger a save, and the content you save is run through the same PII redaction described above.
MemoryBridge AI is currently offered to users in the United States only. We process your data:
We do not sell, rent, or trade your personal information. We share data only with:
/app/settings/invites). Only the recipient address, your account email (as Reply-To), and the rendered email content are sent. (US)extract tool, the bulk Import endpoint, browser-extension capture enrichment, and the "Ask your memory" chat surface (transcript / question + retrieved memory snippets are sent to Claude Haiku or Claude Sonnet to produce the response).Note: These providers only receive the specific memories retrieved for your query (or the transcript you're importing). They cannot access your entire memory database, and we explicitly prohibit them from using your data for model training.
We may disclose information if required by law, court order, or to protect rights and safety.
We implement industry-standard security measures:
You can delete individual memories anytime through the dashboard. To delete your entire account, use Settings → Profile → Delete account; deletion is immediate and permanent, and removes your memories, API keys, OAuth grants, settings, and login. You can also email privacy@memorybridge.ai and we will delete the account for you.
You have the right to:
Settings → Data & exportTo exercise these rights, email privacy@memorybridge.ai. We respond within 45 days as required by applicable law.
We keep client-side storage minimal and essential:
We don't use advertising cookies, third-party analytics, or tracking pixels. Clearing your browser storage signs you out and removes locally stored chat history.
We're based in the United States, and the Service is currently offered to US residents only. Your data is stored and processed in the United States. If you travel abroad and sign in to an existing account, your data is still processed in the US and protected with TLS encryption in transit. If we expand to other regions, we'll update this policy with the applicable transfer safeguards first.
MemoryBridge AI is not intended for users under 18 years old. We do not knowingly collect data from children. If you believe a child has provided us with personal information, please contact us immediately at privacy@memorybridge.ai.
California residents have additional rights:
To exercise these rights, email privacy@memorybridge.ai or call (510) 288-9594.
We require valid legal process (subpoena, court order, or warrant) to disclose user data. Unless legally prohibited, we'll notify affected users before disclosure.
If a data breach occurs that affects your personal information, we will:
We may update this Privacy Policy periodically. Material changes will be notified via:
Continued use after changes indicates acceptance. For significant changes affecting your rights, we may request explicit consent.
Privacy Contact
Apex Leadership Lab, LLC
2261 Market Street STE 86401
San Francisco, CA 94114
United States
Email: privacy@memorybridge.ai (privacy requests) or hello@memorybridge.ai (general)
Phone: (510) 288-9594
Response Time: Within 45 days for privacy requests
MemoryBridge AI believes in transparency. The platform's source code is published for reference on GitHub under a proprietary source-available license, and we maintain public documentation about our data practices, security measures, and API specifications.