This Privacy Policy ("Policy") describes how Memora ("we," "us," or "our") collects, uses, shares, and protects personal information obtained through our website at memora.company, our web application at app.memora.company, our APIs, and any other services we provide (collectively, the "Services"). By accessing or using our Services, you acknowledge that you have read, understood, and agree to be bound by this Policy. If you do not agree with this Policy, please do not use our Services.
1. Information We Collect
We collect information in the following categories:
1.1 Information You Provide Directly
- Account Registration Data: When you create an account, we collect your full name, email address, password (stored in hashed form using bcrypt), company or organization name, and job title.
- Billing Information: If you subscribe to a paid plan, we collect payment card details, billing address, and transaction history. Payment processing is handled by our third-party payment processor (Stripe, Inc.), and we do not store full credit card numbers on our servers. Only the last four digits and card type are retained for display purposes.
- Communications: When you contact us via email, support chat, or feedback forms, we collect the content of those communications along with your name, email address, and any information you voluntarily share.
- User Content: Any documents, files, text, meeting transcripts, knowledge base entries, agent configurations, chat history, or workspace data you upload, submit, or create within the Services.
- Profile Information: Optional information such as your profile photo, phone number, or LinkedIn profile URL that you choose to add to your account.
1.2 Information Collected Through Integrations
When you connect third-party services to Memora (such as GitHub, Slack, Jira, Confluence, Notion, Google Drive, Zoom, Microsoft Teams, or other supported platforms), you explicitly authorize us to access and retrieve data from those services on your behalf. This may include:
- Repository names, issues, pull requests, commit messages, code review comments, and CI/CD pipeline data (GitHub, GitLab, Bitbucket).
- Channel names, message history, user profiles, file attachments, and direct messages where the integration has been granted access (Slack, Microsoft Teams).
- Project data, ticket details, comments, status updates, and sprint information (Jira, Linear, Asana, ClickUp).
- Documents, pages, databases, and wikis (Confluence, Notion, Google Drive, SharePoint).
- Meeting recordings, transcripts, and calendar events (Zoom, Google Meet, Outlook).
- Any other data types explicitly described during the OAuth authorization flow for each integration.
This data is used exclusively to power Memora's AI-driven context engine and knowledge graph. It is processed in accordance with the permissions you grant during authorization. You may revoke integration access at any time from your workspace settings, which will immediately stop further data retrieval. Previously indexed data will be purged within 7 days of disconnection.
1.3 Information Collected Automatically
- Device and Browser Information: IP address, browser type and version, operating system, device type, screen resolution, and language preferences.
- Usage Data: Pages and features accessed, clickstream data, session duration, referral URLs, search queries within the application, and feature interaction logs.
- Cookies and Similar Technologies: We use cookies, local storage, and similar tracking technologies as described in our Cookie Policy.
- Log Data: Server logs that record requests to our infrastructure, including timestamps, request URLs, HTTP status codes, response times, and error traces.
- Crash Reports: Diagnostic data automatically submitted when an error or crash occurs within the application, including stack traces and the state of the application at the time of the error.
2. How We Use Your Information
We use the information we collect for the following purposes:
- Service Delivery: To create, maintain, and manage your account; to provide, operate, and continuously improve the Services; and to process transactions.
- AI Processing and Knowledge Graph: To power Memora's AI context engine, which analyzes, indexes, and semantically connects content from your integrated sources to provide intelligent search, knowledge retrieval, and contextual recommendations within your workspace.
- Personalization: To customize your workspace experience, remember your preferences (such as theme, layout, and pinned integrations), and deliver relevant content and feature suggestions.
- Communication: To send transactional emails (e.g., account verification, password resets, billing receipts, security alerts), product announcements, and, with your explicit consent, promotional or newsletter communications. You may unsubscribe from marketing emails at any time.
- Security and Fraud Prevention: To detect, investigate, and prevent unauthorized access, security incidents, abuse, fraud, and other malicious activities that may harm users or the integrity of our Services.
- Analytics and Product Improvement: To understand how users interact with the Services in aggregate, identify usage patterns, diagnose issues, and make informed decisions about new features and performance improvements. We use anonymized and aggregated data wherever possible for this purpose.
- Legal Compliance: To comply with applicable laws, regulations, legal processes, court orders, or enforceable governmental requests, and to exercise or defend our legal rights.
- Customer Support: To respond to your inquiries, troubleshoot issues, and provide technical assistance.
3. Legal Bases for Processing (EEA, UK, and Swiss Users)
If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, we process your personal data based on the following legal grounds under the General Data Protection Regulation (GDPR):
- Contractual Necessity: Processing necessary to perform our contract with you (e.g., providing the Services you signed up for, processing payments, and managing your account).
- Legitimate Interests: Processing necessary for our legitimate business interests, such as improving the Services, preventing fraud, ensuring security, and conducting analytics, provided these interests are not overridden by your fundamental rights and freedoms.
- Consent: Processing based on your explicit, freely given consent, which you may withdraw at any time without affecting the lawfulness of processing carried out before withdrawal (e.g., marketing communications, optional analytics).
- Legal Obligation: Processing necessary to comply with a legal obligation to which we are subject under applicable EU, UK, or Member State law.
4. How We Share Your Information
We do not sell, rent, or trade your personal information to third parties. We may share your information only in the following limited circumstances:
- Service Providers: With trusted third-party vendors who perform services on our behalf under strict data processing agreements, including cloud infrastructure providers (AWS, Google Cloud), payment processors (Stripe), email delivery services (Resend, SendGrid), error monitoring (Sentry), and customer support tools. These providers may only use your data as instructed by us and for no other purpose.
- AI and Machine Learning Providers: With third-party AI model providers (such as OpenAI and Anthropic) to process your queries and content within the Services. Data sent to these providers is transmitted securely over TLS, and we have Zero-Retention Agreements (ZRAs) in place that explicitly prohibit these providers from using your data to train their models.
- Legal Requirements: When required by applicable law, valid legal process (such as a subpoena, court order, or government investigation), or when we have a good-faith belief that disclosure is reasonably necessary to protect the rights, property, or safety of Memora, our users, or the public.
- Business Transfers: In connection with a merger, acquisition, reorganization, bankruptcy proceeding, or sale of all or substantially all of our assets, your personal information may be transferred as part of such a transaction. We will notify you with at least 30 days' notice via email and a prominent notice on our website before such a transfer occurs, and the successor entity will be bound by a privacy policy that offers equivalent protections.
- With Your Consent: In any other circumstances where you provide us with explicit, prior, informed consent to share your data with specific third parties.
5. Data Retention
We retain your personal information for as long as your account is active or as necessary to provide you with the Services, resolve disputes, enforce our agreements, and comply with our legal obligations. The specific retention periods are as follows:
- Account Data: Retained for the duration of your account. Upon account deletion, your personal data is permanently deleted within 30 days, except where required to be retained for legal or regulatory purposes.
- Integration Data: Data fetched from connected third-party integrations is deleted within 7 days of disconnecting the integration or deleting your account.
- Billing Records: Retained for 7 years for tax and accounting compliance purposes, as required by applicable financial regulations.
- Server Logs: Retained for a maximum of 90 days and then automatically purged.
- Support Communications: Retained for 2 years after the closure of a support ticket, to assist with any follow-up inquiries.
6. Data Security
We implement comprehensive technical and organizational measures to protect your personal information from unauthorized access, disclosure, alteration, and destruction. These measures include:
- Encryption of all data in transit using TLS 1.3 or higher.
- Encryption of sensitive data at rest using AES-256 encryption.
- Secure API key and credential management using industry-standard cryptographic vaults (AWS KMS).
- Password hashing using bcrypt with salt rounds of at least 12.
- Strict role-based access controls (RBAC) ensuring only authorized personnel can access production systems and user data.
- Regular security assessments, vulnerability scanning, and annual third-party penetration testing.
- Multi-factor authentication (MFA) enforced for all Memora employees with access to production systems.
- An internal security incident response plan with defined escalation procedures and notification timelines.
Despite these measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security, and we encourage you to use strong, unique passwords and enable two-factor authentication on your account. In the event of a data breach that affects your rights and freedoms, we will notify you and relevant data protection authorities as required by applicable law.
7. Your Privacy Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Right of Access: Request a copy of the personal data we hold about you, along with information about how it is processed.
- Right to Rectification: Request correction of any inaccurate, incomplete, or outdated personal data we hold about you.
- Right to Erasure ("Right to Be Forgotten"): Request the permanent deletion of your personal data, subject to certain legal exceptions (e.g., legal hold obligations).
- Right to Restriction of Processing: Request that we limit the processing of your personal data in certain circumstances, such as while a dispute is being resolved.
- Right to Data Portability: Request a machine-readable export (JSON or CSV format) of the personal data you provided to us, which you can transfer to another service.
- Right to Object: Object to the processing of your personal data based on legitimate interests or for direct marketing purposes. Where you object to marketing, we will immediately stop processing your data for that purpose.
- Right to Withdraw Consent: Where processing is based on your consent, withdraw that consent at any time. This will not affect the lawfulness of processing that occurred before withdrawal.
- Right Not to Be Subject to Automated Decisions: Request human review of any automated decision-making that significantly affects you.
To exercise any of these rights, please contact us at [email protected]. We will acknowledge your request within 72 hours and aim to fulfill it within 30 days (or within the timeframe required by applicable law). If we require more time, we will notify you. If you are in the EEA or UK, you also have the right to lodge a complaint with your local supervisory authority (e.g., the ICO in the UK or your national data protection authority in the EU).
8. California Privacy Rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) provides you with additional rights. These include:
- Right to Know: The right to know what personal information we collect, use, disclose, and sell (or share), and the categories of sources from which it is collected.
- Right to Delete: The right to request the deletion of your personal information, subject to certain exceptions.
- Right to Correct: The right to request correction of inaccurate personal information.
- Right to Opt-Out of Sale or Sharing: We do not sell or share personal information with third parties for cross-context behavioral advertising purposes.
- Right to Limit Use of Sensitive Personal Information: The right to limit the use or disclosure of sensitive personal information to only what is necessary to perform the Services.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA/CPRA rights.
To exercise your California privacy rights, contact us at [email protected] or submit a request through your account settings. We will verify your identity before processing your request.
9. International Data Transfers
Memora is headquartered in the United States. Your personal data may be transferred to and processed in countries other than your country of residence, including the United States, which may have data protection laws that differ from those in your country. We take the following safeguards to ensure your data remains protected:
- Standard Contractual Clauses (SCCs): For transfers from the EEA, UK, or Switzerland to countries not deemed to offer adequate protection, we rely on the Standard Contractual Clauses approved by the European Commission (Module 1 for controller-to-controller, Module 2 for controller-to-processor transfers).
- UK IDTA: For transfers from the UK, we use the UK International Data Transfer Agreement (IDTA) as an appropriate safeguard.
- Data Processing Agreements: We ensure all sub-processors who receive personal data have signed Data Processing Agreements (DPAs) that include appropriate transfer mechanisms.
10. Children's Privacy
The Services are not directed at individuals under the age of 16, and we do not knowingly collect personal information from children under 16. If we become aware that we have inadvertently collected personal data from a child under 16 without verifiable parental consent, we will take immediate steps to delete that information from our systems. If you are a parent or guardian and believe your child has provided personal information to Memora without your consent, please contact us immediately at [email protected].
11. Third-Party Links and Services
The Services may contain links to third-party websites, applications, or services that are not operated, controlled, or endorsed by Memora. This Privacy Policy does not apply to those third-party services. We are not responsible for the privacy practices, content, or data handling of any linked third-party services. We strongly encourage you to review the privacy policy of every website or service you visit or use.
12. Do Not Track
Some web browsers include a "Do Not Track" (DNT) signal that indicates you do not wish to be tracked across websites. As there is currently no universally accepted standard for how websites must respond to DNT signals, the Services do not currently respond to DNT signals. You can, however, control tracking through the cookie management methods described in our Cookie Policy.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data practices, applicable laws, or the features of our Services. We will notify you of any material changes by:
- Posting the updated Policy on this page with a revised "Last Updated" date.
- Sending an email notification to your registered email address at least 14 days before the changes take effect for significant changes.
- Displaying a prominent banner or in-app notification for significant changes.
Your continued use of the Services after the effective date of any changes constitutes your acceptance of the revised Policy. If you do not agree to the revised Policy, you must stop using the Services and may request account deletion.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us through any of the following channels:
We are committed to working with you to resolve any privacy concerns promptly and transparently.