PUBLIC BETA
Early Access – Lifetime Deal

Privacy Policy (Beta)

Last updated: September 3, 2025

We prioritize your privacy and data protection. We collect minimal data, use secure practices, and never share your information with third parties.

Data Collection

What we collect:
- Account Information: Email, name, nickname for authentication and user experience
- Content Data: Notes, memories, and their associated embeddings that you create
- Usage Data: Creation/modification timestamps, sign-in counts, confirmation status
- Technical Data: Password hashes (bcrypt), authentication tokens (SHA256), session identifiers

What we DON'T collect:
- No tracking cookies, analytics, or behavioral data
- No third-party integrations that collect your data
- No personal data beyond what's necessary for service functionality

Cookies & Sessions

We use cookies exclusively for authentication - nothing else:
- Session cookies: Temporary login state (deleted when browser closes)
- Remember me cookies: Optional persistent login (if you check "Remember me")
- No tracking cookies: We do not use analytics, advertising, or third-party tracking
- Cookie consent: You can accept or reject optional cookies via our banner

Technical details:
- Cookies are signed for security and transmitted over HTTPS only
- Session data stored server-side, only session ID in cookie
- All cookies are httpOnly and secure in production

Data Storage & Security

Storage practices:
- Database: PostgreSQL with encrypted connections
- Passwords: Securely hashed using bcrypt (never stored in plaintext)
- Vector embeddings: Generated locally for semantic search functionality
- Server location: All data stored on secure servers with regular backups

Security measures:
- HTTPS/SSL encryption for all data transmission
- Secure authentication tokens with SHA256 hashing
- Role-based access control (admin, user, guest permissions)
- Regular security updates and monitoring

Data Sharing & Third Parties

Strong commitment: We NEVER share your data with third parties.
- No advertising networks: We don't use Google Analytics, Facebook Pixel, or similar
- No data brokers: Your information is never sold or shared commercially

- No external APIs: Embedding generation happens locally on our servers
- Legal compliance only: Data disclosed only if legally required (with notification when possible)

Internal access:
- Only authorized administrators can access data for technical support
- Access is logged and monitored for security purposes

Your Rights & Control

You have full control over your data:
- Access: View all your stored data through the web interface
- Modification: Edit or update your notes and account information anytime
- Deletion: Request complete account and data deletion at any time
- Export: Download your notes and data (contact support for full export)

To exercise your rights:
- Contact us at support@llm-memory.com
- Include your account email for verification
- We respond to all requests within 72 hours

Data Retention

How long we keep your data:
- Active accounts: Data retained indefinitely while account is active
- Account deletion: All data permanently deleted within 30 days of request
- Inactive accounts: Accounts inactive for 2+ years may be archived (with email notification)
- Backups: Deleted data removed from backups within 90 days

Automatic cleanup:
- Failed login attempts and temporary tokens are automatically purged
- Session data expires based on your login preferences

Contact & Questions

For privacy concerns or data requests:
- Email: support@llm-memory.com
- Response time: Within 72 hours
- Include: Your account email for verification

This policy may be updated to reflect service changes or legal requirements. Users will be notified of significant changes via email.