Back to home

Privacy Policy

Last updated: June 2026 · MnemonX (mnemonx.ai)

Covers: GDPR (EU/EEA) · UK GDPR · CCPA/CPRA (California) · LGPD (Brazil, when available) · PDPA (Singapore/Thailand, when available)

1. Overview

MnemonX ("we", "us", "our") operates the MnemonX neural context engine at mnemonx.ai. We are committed to protecting your personal data and being transparent about how we collect, use, store, and transfer it.

This Privacy Policy applies to all users globally. Additional jurisdiction-specific rights and obligations are detailed in dedicated sections below. By using MnemonX you agree to this policy. For questions: [email protected].

2. Data Controller

Controller: MnemonX

Website: mnemonx.ai

Privacy contact: [email protected]

DPO / EU Representative: [email protected]

3. What We Collect

  • Phone number: Required to create an account. Used for SMS-based authentication (OTP login). Stored securely by Supabase Auth.
  • SMS consent record: Date, time, consent version text, and IP address when you check the consent checkbox at registration. Required by Twilio A2P 10DLC regulations. Never used for advertising.
  • Encrypted wallet data: Your context wallet is encrypted with AES-256-GCM on your device before storage. Decryption is limited to specific, authorized code paths tied to your own requests — see our DPA for the full scope.
  • Encryption key: A per-user encryption key stored in our database (to enable multi-device sync). Server-side access to decrypt with it is limited to specific, authorized code paths tied to your own requests — see our DPA §9 for the full scope.
  • Subscription & billing: Your plan level and Stripe customer/subscription IDs to manage billing. We never store card numbers.
  • AI import text (transient): When you import memory from an AI tool, raw text is sent to an AI API for extraction, then immediately discarded. Not stored by us.
  • Product analytics (anonymised): PostHog tracks anonymous usage events (e.g. "wallet loaded", "import completed"). Uses localStorage — no tracking cookies. Never sold or used for advertising.
  • API access logs: Timestamps, endpoint paths, and OAuth scope used for each API call to your wallet. Retained 90 days for security auditing.
  • Data region preference: Which Supabase region (US/EU) stores your wallet — stored in your account tier record on our US database for routing and compliance purposes.
  • SCIM provisioning data (enterprise employees only): If your employer enables SCIM, your name, email, and role are received from their identity provider (Okta/Azure AD) to manage your org membership automatically. See our DPA §12b.

4. Lawful Basis for Processing (GDPR Art. 6)

For EU/EEA and UK users, every category of personal data we process has an identified lawful basis:

DataLawful BasisDetail
Phone number / OTPArt. 6(1)(b) — ContractNecessary to perform the service (authentication)
Encrypted wallet dataArt. 6(1)(b) — ContractCore service delivery; encrypted at rest, decrypted only to serve your own authorized requests
SMS consent recordArt. 6(1)(c) — Legal obligationA2P 10DLC / TCPA compliance requirement
Subscription tierArt. 6(1)(b) — ContractNecessary to manage your plan and billing
Re-engagement SMSArt. 6(1)(a) — ConsentExplicit opt-in at registration; withdraw anytime via STOP
Product analyticsArt. 6(1)(f) — Legitimate interestProduct improvement; anonymised; no profiling
API access logsArt. 6(1)(f) — Legitimate interestSecurity auditing; retained 90 days only
Data region preferenceArt. 6(1)(b) — ContractNecessary to route your data to the correct regional DB

5. Data Residency & Storage Locations

Your wallet is stored in your region

When you register, MnemonX detects your location and stores your encrypted wallet in the nearest available data region. Your wallet data and encryption keys never leave that region.

🇺🇸 United States Live

Supabase us-east-1 (Virginia)

Serves: US, Canada, and all others not in EU

🇪🇺 European Union Live · GDPR

Supabase eu-central-1 (Frankfurt)

Serves: EU, EEA, UK, Israel, Gulf states, North Africa

Pipeline regions (coming soon): 🇦🇺 Australia & Pacific · 🇸🇬 Southeast Asia · 🇧🇷 South America. Users in these regions see a "coming soon" page at signup — we will not silently store your data in the wrong region.

Billing data (all regions): Your subscription tier, Stripe IDs, and account metadata are always stored in our US database, regardless of wallet region. Stripe processes payments on their global infrastructure. These records do not contain your wallet content.

6. International Data Transfers

EU → US transfers (GDPR Chapter V)

Your EU wallet data stays in Frankfurt (eu-central-1). The only EU data transferred to the US is your subscription/billing record and anonymised analytics. These transfers are covered by EU Standard Contractual Clauses (SCCs, 2021 modules) incorporated in our DPA. A Transfer Impact Assessment (TIA) is available on request.

Sub-processors

When we use third-party services (Supabase, Twilio, Stripe, Resend, PostHog, Vercel — see Section 10), we have Data Processing Agreements in place. Twilio's A2P SMS delivery may route messages through US infrastructure for EU phone numbers; this is a delivery-side telecommunications requirement, not a data storage transfer.

🇪🇺

7. EU / EEA — GDPR Rights

If you are located in the EU, EEA, or a country treated as equivalent under GDPR (Iceland, Liechtenstein, Norway), you have the following rights under the General Data Protection Regulation:

Art. 15 — Right of access

Request a copy of all personal data we hold about you. Contact [email protected]; we will respond within 30 days.

Art. 16 — Right to rectification

Correct inaccurate personal data. Your wallet content can be edited directly in the app at any time.

Art. 17 — Right to erasure ("right to be forgotten")

Request deletion of your account and all associated data. Use the Delete Account function in wallet settings, or email [email protected]. Deletion is permanent and irreversible.

Art. 18 — Right to restriction

Request that we pause processing of your data while a dispute is resolved. Contact [email protected].

Art. 20 — Right to data portability

Receive your data in a machine-readable format. Export is available as .txt / .md / .json from your wallet dashboard, or programmatically via GET /api/v1/user/export.

Art. 21 — Right to object

Object to processing based on legitimate interests (Art. 6(1)(f)) — e.g. analytics. We will honour your objection unless we have compelling legitimate grounds. Objecting to analytics: disable PostHog by blocking the domain in your browser.

Art. 22 — Automated decision-making

MnemonX does not make any automated decisions that produce legal or similarly significant effects about you.

Art. 7(3) — Withdraw consent

Where processing is based on consent (re-engagement SMS), you may withdraw at any time by replying STOP or using the in-app opt-out. Withdrawal does not affect the lawfulness of processing before withdrawal.

Supervisory authority: If you believe we have violated your GDPR rights, you have the right to lodge a complaint with your national Data Protection Authority. In Germany: BfDI. In France: CNIL. Full DPA list: edpb.europa.eu.

🇬🇧

8. United Kingdom — UK GDPR

UK users are covered by UK GDPR (the retained EU GDPR as incorporated by the Data Protection Act 2018). Your rights are substantially identical to those in Section 7. Key differences:

Supervisory authority: Information Commissioner's Office (ICO). File a complaint at ico.org.uk.

Data storage: UK users' wallet data is stored in the EU region (Frankfurt, eu-central-1) by default — adequacy decision under GDPR Art. 45 covers UK→EU transfers. Post-Brexit adequacy decisions are subject to UK government renewal.

UK→US transfers: Covered by UK International Data Transfer Agreements (IDTAs) and/or UK Addendum to EU SCCs. Available on request.

🇺🇸

9. California — CCPA / CPRA

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you the following rights:

Right to know

Request disclosure of the categories and specific pieces of personal information we have collected, the sources, our business purposes, and the categories of third parties with whom we share it.

Right to delete

Request deletion of personal information we have collected, subject to legal exceptions (e.g. fraud prevention, legal obligation).

Right to correct

Request correction of inaccurate personal information we hold about you.

Right to opt out of sale / sharing

We do not sell personal information. We do not share personal information for cross-context behavioural advertising. No opt-out is required — we do not engage in these activities.

Right to limit use of sensitive PI

We collect phone numbers (sensitive PI under CPRA). Use is limited strictly to authentication and service delivery. No profiling, no inference.

Right to non-discrimination

We will not deny service, charge a different price, or provide a different quality of service because you exercised your CCPA/CPRA rights.

Exercise your rights: Email [email protected] with subject "CCPA Request". We will verify your identity and respond within 45 days (extendable by 45 days with notice). Authorised agents: provide a signed authorisation letter.

Categories collected (CCPA §1798.100): Identifiers (phone number) · Financial information (Stripe subscription ID, plan tier) · Commercial information (purchase history) · Internet activity (product analytics events). We do not collect: geolocation · biometric · health · racial/ethnic origin · sexual orientation.

🇧🇷

10. Brazil — LGPD (Lei Geral de Proteção de Dados)

Brazil is a pipeline region — MnemonX will open a South American data residency option when our São Paulo Supabase instance launches. Until then, Brazilian users will see a "coming soon" page and will not be enrolled.

When the BR region launches, data will be processed under LGPD legal bases: execution of contract (Art. 7(V)) for authentication and wallet storage; legitimate interest (Art. 7(IX)) for product analytics; consent (Art. 7(I)) for promotional SMS.

ANPD: The Autoridade Nacional de Proteção de Dados (ANPD) is Brazil's supervisory authority. Complaints: gov.br/anpd.

11. SMS Communications

How you opt in: By creating an account and checking the SMS consent checkbox at registration. Consent to marketing SMS is voluntary; authentication OTPs are required for login.
Message types: Authentication OTPs · Security alerts · Account/subscription notifications · Re-engagement messages (≤1× per 60–90 days).
Message frequency: Authentication messages: triggered by your actions only. Re-engagement: infrequently, at most once every 60–90 days.
Opt out: Reply STOP to any SMS, or use Wallet → Account Settings → SMS Notifications → "Opt out". You will still receive authentication OTPs (required for login).
Carrier disclaimer: Message and data rates may apply. MnemonX is not responsible for carrier charges. Not liable for delayed or undelivered messages.

12. Cookies & Local Storage

MnemonX uses strictly necessary browser storage only. No third-party tracking or advertising cookies are set:

  • Authentication session: Supabase auth token in localStorage — strictly necessary for login.
  • Encrypted wallet cache: Local copy of your encrypted wallet for smooth offline-capable performance.
  • mnx_region: Your resolved data region (e.g. "eu") stored in localStorage. Not a cookie — no ePrivacy consent required.
  • Cookie notice flag: Single localStorage flag recording that you acknowledged this notice.
  • PostHog analytics: Anonymous session identifier in localStorage. No personal information. Block posthog.com to disable.

13. Sub-processors & Third Parties

Supabase: Database & auth hosting. US wallet data: us-east-1 (AWS Virginia). EU wallet data: eu-central-1 (AWS Frankfurt). DPA: supabase.com/privacy
Stripe: Payment processing. PCI DSS Level 1. We never see card details. stripe.com/privacy
Twilio: SMS delivery. Bound by our DPA. US-based; A2P 10DLC compliant. twilio.com/legal/privacy
Resend: Transactional email (billing receipts, digests). resend.com/privacy
PostHog: Anonymous product analytics. No cookies. posthog.com/privacy
Vercel: Web application hosting. Server access logs (IP, timestamp). vercel.com/legal/privacy-policy
OpenAI / Anthropic / Google: AI import processing. Transient — raw text sent, processed, discarded. Not stored.

14. Data Retention

  • Account data: Retained while your account is active. Permanently deleted within 30 days of account deletion.
  • Encrypted wallet: Deleted immediately and irreversibly upon account deletion from the regional DB.
  • SMS consent record: Retained for account lifetime + minimum 4 years post-deletion (TCPA/CTIA requirement).
  • Billing records: Stripe retains per their policy. We retain subscription tier history up to 7 years (financial record-keeping law).
  • API access logs: 90 days for security auditing, then deleted.
  • Analytics events: PostHog anonymised data up to 1 year.

15. Your Rights — All Jurisdictions

  • Access — request a copy of all personal data we hold.
  • Deletion — delete your account and all wallet data (app setting or email us).
  • Correction / update — edit wallet content directly in the app.
  • Data portability — export as .txt / .md / .json, or via GET /api/v1/user/export.
  • Opt out of SMS — reply STOP, or in-app toggle.
  • Object to analytics — block posthog.com in your browser.
  • Restrict processing — email [email protected].
  • Withdraw consent — for any consent-based processing, withdraw at any time without affecting past processing.

All requests: [email protected]. We respond within 30 days (GDPR/UK GDPR), 45 days (CCPA/CPRA), or as required by applicable law.

16. Security

Wallet data: AES-256-GCM client-side encryption. Transit: TLS 1.3. Auth: SMS OTP + optional passkeys (Face ID / Touch ID), with login attempts rate-limited by our authentication provider. Our admin dashboard additionally enforces a specific 5-failed-attempt / 15-minute lockout for staff access. Sessions: 8-hour JWT hard expiry. See our Security page for full technical details.

17. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach (GDPR Art. 33). If the breach is likely to result in a high risk, we will also notify affected users directly without undue delay (GDPR Art. 34).

18. Children's Privacy

MnemonX is not directed to children under 13 (or the age of digital consent in your jurisdiction, whichever is higher). We do not knowingly collect data from children. Contact [email protected] if you believe a child has provided data.

19. Changes to This Policy

We update the "Last updated" date when changes are made. For material changes (SMS, data sharing, new regions), we will notify you via the Service. Continued use constitutes acceptance.

20. Contact & DPO

Privacy & data subject requests: [email protected]

DPO / EU Representative: [email protected]

SMS opt-out support: [email protected]

Security vulnerabilities: [email protected]

Data Processing Agreement (enterprise): View DPA

MnemonX · mnemonx.ai

MnemonX — Your AI Memory, Everywhere