Last updated: June 2026 · MnemonX (mnemonx.ai)
Covers: GDPR (EU/EEA) · UK GDPR · CCPA/CPRA (California) · LGPD (Brazil, when available) · PDPA (Singapore/Thailand, when available)
MnemonX ("we", "us", "our") operates the MnemonX neural context engine at mnemonx.ai. We are committed to protecting your personal data and being transparent about how we collect, use, store, and transfer it.
This Privacy Policy applies to all users globally. Additional jurisdiction-specific rights and obligations are detailed in dedicated sections below. By using MnemonX you agree to this policy. For questions: [email protected].
Controller: MnemonX
Website: mnemonx.ai
Privacy contact: [email protected]
DPO / EU Representative: [email protected]
For EU/EEA and UK users, every category of personal data we process has an identified lawful basis:
| Data | Lawful Basis | Detail |
|---|---|---|
| Phone number / OTP | Art. 6(1)(b) — Contract | Necessary to perform the service (authentication) |
| Encrypted wallet data | Art. 6(1)(b) — Contract | Core service delivery; encrypted at rest, decrypted only to serve your own authorized requests |
| SMS consent record | Art. 6(1)(c) — Legal obligation | A2P 10DLC / TCPA compliance requirement |
| Subscription tier | Art. 6(1)(b) — Contract | Necessary to manage your plan and billing |
| Re-engagement SMS | Art. 6(1)(a) — Consent | Explicit opt-in at registration; withdraw anytime via STOP |
| Product analytics | Art. 6(1)(f) — Legitimate interest | Product improvement; anonymised; no profiling |
| API access logs | Art. 6(1)(f) — Legitimate interest | Security auditing; retained 90 days only |
| Data region preference | Art. 6(1)(b) — Contract | Necessary to route your data to the correct regional DB |
When you register, MnemonX detects your location and stores your encrypted wallet in the nearest available data region. Your wallet data and encryption keys never leave that region.
Supabase us-east-1 (Virginia)
Serves: US, Canada, and all others not in EU
Supabase eu-central-1 (Frankfurt)
Serves: EU, EEA, UK, Israel, Gulf states, North Africa
Pipeline regions (coming soon): 🇦🇺 Australia & Pacific · 🇸🇬 Southeast Asia · 🇧🇷 South America. Users in these regions see a "coming soon" page at signup — we will not silently store your data in the wrong region.
Billing data (all regions): Your subscription tier, Stripe IDs, and account metadata are always stored in our US database, regardless of wallet region. Stripe processes payments on their global infrastructure. These records do not contain your wallet content.
Your EU wallet data stays in Frankfurt (eu-central-1). The only EU data transferred to the US is your subscription/billing record and anonymised analytics. These transfers are covered by EU Standard Contractual Clauses (SCCs, 2021 modules) incorporated in our DPA. A Transfer Impact Assessment (TIA) is available on request.
When we use third-party services (Supabase, Twilio, Stripe, Resend, PostHog, Vercel — see Section 10), we have Data Processing Agreements in place. Twilio's A2P SMS delivery may route messages through US infrastructure for EU phone numbers; this is a delivery-side telecommunications requirement, not a data storage transfer.
If you are located in the EU, EEA, or a country treated as equivalent under GDPR (Iceland, Liechtenstein, Norway), you have the following rights under the General Data Protection Regulation:
Request a copy of all personal data we hold about you. Contact [email protected]; we will respond within 30 days.
Correct inaccurate personal data. Your wallet content can be edited directly in the app at any time.
Request deletion of your account and all associated data. Use the Delete Account function in wallet settings, or email [email protected]. Deletion is permanent and irreversible.
Request that we pause processing of your data while a dispute is resolved. Contact [email protected].
Receive your data in a machine-readable format. Export is available as .txt / .md / .json from your wallet dashboard, or programmatically via GET /api/v1/user/export.
Object to processing based on legitimate interests (Art. 6(1)(f)) — e.g. analytics. We will honour your objection unless we have compelling legitimate grounds. Objecting to analytics: disable PostHog by blocking the domain in your browser.
MnemonX does not make any automated decisions that produce legal or similarly significant effects about you.
Where processing is based on consent (re-engagement SMS), you may withdraw at any time by replying STOP or using the in-app opt-out. Withdrawal does not affect the lawfulness of processing before withdrawal.
Supervisory authority: If you believe we have violated your GDPR rights, you have the right to lodge a complaint with your national Data Protection Authority. In Germany: BfDI. In France: CNIL. Full DPA list: edpb.europa.eu.
UK users are covered by UK GDPR (the retained EU GDPR as incorporated by the Data Protection Act 2018). Your rights are substantially identical to those in Section 7. Key differences:
Supervisory authority: Information Commissioner's Office (ICO). File a complaint at ico.org.uk.
Data storage: UK users' wallet data is stored in the EU region (Frankfurt, eu-central-1) by default — adequacy decision under GDPR Art. 45 covers UK→EU transfers. Post-Brexit adequacy decisions are subject to UK government renewal.
UK→US transfers: Covered by UK International Data Transfer Agreements (IDTAs) and/or UK Addendum to EU SCCs. Available on request.
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you the following rights:
Request disclosure of the categories and specific pieces of personal information we have collected, the sources, our business purposes, and the categories of third parties with whom we share it.
Request deletion of personal information we have collected, subject to legal exceptions (e.g. fraud prevention, legal obligation).
Request correction of inaccurate personal information we hold about you.
We do not sell personal information. We do not share personal information for cross-context behavioural advertising. No opt-out is required — we do not engage in these activities.
We collect phone numbers (sensitive PI under CPRA). Use is limited strictly to authentication and service delivery. No profiling, no inference.
We will not deny service, charge a different price, or provide a different quality of service because you exercised your CCPA/CPRA rights.
Exercise your rights: Email [email protected] with subject "CCPA Request". We will verify your identity and respond within 45 days (extendable by 45 days with notice). Authorised agents: provide a signed authorisation letter.
Categories collected (CCPA §1798.100): Identifiers (phone number) · Financial information (Stripe subscription ID, plan tier) · Commercial information (purchase history) · Internet activity (product analytics events). We do not collect: geolocation · biometric · health · racial/ethnic origin · sexual orientation.
Brazil is a pipeline region — MnemonX will open a South American data residency option when our São Paulo Supabase instance launches. Until then, Brazilian users will see a "coming soon" page and will not be enrolled.
When the BR region launches, data will be processed under LGPD legal bases: execution of contract (Art. 7(V)) for authentication and wallet storage; legitimate interest (Art. 7(IX)) for product analytics; consent (Art. 7(I)) for promotional SMS.
ANPD: The Autoridade Nacional de Proteção de Dados (ANPD) is Brazil's supervisory authority. Complaints: gov.br/anpd.
MnemonX uses strictly necessary browser storage only. No third-party tracking or advertising cookies are set:
All requests: [email protected]. We respond within 30 days (GDPR/UK GDPR), 45 days (CCPA/CPRA), or as required by applicable law.
Wallet data: AES-256-GCM client-side encryption. Transit: TLS 1.3. Auth: SMS OTP + optional passkeys (Face ID / Touch ID), with login attempts rate-limited by our authentication provider. Our admin dashboard additionally enforces a specific 5-failed-attempt / 15-minute lockout for staff access. Sessions: 8-hour JWT hard expiry. See our Security page for full technical details.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach (GDPR Art. 33). If the breach is likely to result in a high risk, we will also notify affected users directly without undue delay (GDPR Art. 34).
MnemonX is not directed to children under 13 (or the age of digital consent in your jurisdiction, whichever is higher). We do not knowingly collect data from children. Contact [email protected] if you believe a child has provided data.
We update the "Last updated" date when changes are made. For material changes (SMS, data sharing, new regions), we will notify you via the Service. Continued use constitutes acceptance.
Privacy & data subject requests: [email protected]
DPO / EU Representative: [email protected]
SMS opt-out support: [email protected]
Security vulnerabilities: [email protected]
Data Processing Agreement (enterprise): View DPA
MnemonX · mnemonx.ai