Privacy
Effective 25 September 2026. Covers the Memogram app, the service at api.getmemogram.com, and this website.
Memogram is a vault for the facts your AI assistants need about you. This page says plainly what we store, what we can and cannot read, who else sees anything, and what you control. Where the current version falls short of the ideal, it says so.
What is stored, and how
- Your memories, people, and categories are encrypted on your phone before they leave it, with keys derived on the phone from a vault key that only the phone and your recovery code can reproduce. We store the encrypted form. Each category has its own key.
- Your account: the email address or Apple ID relay address you sign in with, and an account identifier.
- Connections: which assistants you connected, when, which categories you allowed them, and when each was last used. Allowing a category releases that category's key to our server, sealed so that only the server can open it, for as long as the connection lasts.
- The activity log: which assistant called which function, when, for which categories, and how many results it received. The search text and the exact results are sealed to your phone's key; we store them but cannot open them.
- Proposals from assistants wait in your inbox sealed to your phone's key until you approve or reject them.
- Search vectors for memories in categories you have shared, encrypted under the same category keys.
- A push registration for each phone on which you turn notifications on.
- Server logs with identifiers, counts, and timings. Memory text, search text, and credentials are never written to logs.
What we can read, and what we cannot
Categories you have never shared with an assistant cannot be read by us or by anyone with access to our systems: no key for them exists outside your phone.
For categories you have shared, our server decrypts them in memory while it answers a request from that assistant, then discards the plaintext. During that moment an operator with access to the server could read those categories. Search text and proposed memories reach the server unencrypted before being sealed. We do not describe Memogram as zero-knowledge, because for shared categories it is not.
Even without any connection, we can see how many memories you have, which built-in category each belongs to, when they were created and changed, and their encrypted size. Categories you define appear to us as opaque identifiers; their names are encrypted.
The activity log is tamper-evident from the first time your phone verifies it: the app keeps the last entry it checked and warns if the log stops connecting to it. It is not yet anchored anywhere outside our systems.
Who else sees anything
- Assistants you connect receive the memories in the categories you allowed, when they ask. They keep whatever they received under their own terms; disconnecting removes their access from that moment but cannot make them forget.
- Google Cloud hosts the service and the database in the United States (us-central1), and provides sign-in and push delivery. Requests to the service pass through Google's front end before reaching our code.
- Apple handles Sign in with Apple and delivers push notifications. A push carries the assistant's name and the number of proposals waiting, never a memory.
- Vercel serves this website. The website sets no cookies and runs no analytics.
We do not sell data and we do not use your memories for advertising or to train models.
Cookies
The page where an assistant asks for your permission uses a short-lived cookie to complete that sign-in flow. Nothing else sets cookies.
What you control
- Nothing an assistant proposes enters your vault until you approve it in the app.
- You choose the categories each assistant may read, and you can disconnect it at any time. Connections expire after ninety days unless renewed.
- You can export your whole vault as a readable file, and import it into another vault.
- Deleting your account removes your vault, connections, log, and account at once. If you signed in with Apple, we also ask Apple to revoke its token. The database keeps prior versions for one hour for its own consistency, and we keep no separate backups of vault data.
- Your memories are only as safe as your phone and your recovery code. Losing both loses the vault; we cannot recover it.
Other people's information
A vault often holds facts about family, friends, and colleagues. You are responsible for what you store about others. Export and deletion cover that information too.
Children
Memogram is not directed at children under 13 and we do not knowingly hold accounts for them.
Changes
When this page changes in a way that matters, the app and the effective date above will say so.
Contact
Questions and requests about your data: info@getmemogram.com.