Privacy Policy
Effective date: March 25, 2026
1. What We Collect
We collect the minimum data necessary to provide and improve the Service:
- Email address: Used for account creation, authentication, password resets, and service communications.
- Authentication (Firebase): Email/password, Google, and Apple sign-in are handled by Google Firebase Authentication. Firebase processes credentials and verification emails according to Google's Firebase privacy documentation.
- Display name: Optionally provided during signup. Used only for personalisation within the dashboard.
- Memory & briefcase data: The key-value memory items and briefcases you create and store through the Service. This is your content — we process it only to deliver the Service to you.
- Session tokens: Securely generated tokens stored in your browser to keep you signed in. These expire automatically.
- Usage data: Aggregated, non-identifiable metrics such as API request counts and storage usage, used to enforce plan limits and monitor service health.
We do not collect device fingerprints, advertising identifiers, or behavioural tracking data beyond what is described above.
2. How We Use Your Information
Your data is used solely to provide and operate the Service:
- Authenticating you and securing your account
- Storing and retrieving your briefcase memory data on your behalf
- Enforcing plan limits and processing billing (for paid accounts)
- Sending transactional emails (password resets, billing receipts)
- Diagnosing and fixing bugs or performance issues
We do not sell your personal data. We do not use your memory content to train AI models. We do not serve advertising.
3. Third-Party AI Services
Your briefcase data leaves our servers when you use AI integrations
When you click "Open in [AI]" or connect an AI tool via MCP, the contents of your selected briefcase are transmitted directly to that AI provider. This is the core function of the Service — your context is shared so the AI can use it.
Each integration transmits your briefcase data to the respective provider:
- ChatGPT (OpenAI): Briefcase context is sent as part of the conversation when you open a briefcase in ChatGPT.
- Claude (Anthropic): Briefcase data is exposed via MCP or direct link and becomes part of the Claude session context.
- Gemini (Google): Briefcase content is transmitted when you use the Gemini integration.
- Perplexity: Briefcase context is included in the query when you open a briefcase in Perplexity.
Once data is transmitted to these providers, it is governed by their respective privacy policies. We have no control over how they process, retain, or use data received through these integrations.
4. Sub-Processors
We use the following third-party sub-processors to operate the Service. Each processes only the data necessary for their function:
| Sub-processor | Purpose | Data processed |
|---|---|---|
| OpenAI | AI integration (ChatGPT) | Briefcase content (when integration used) |
| Anthropic | AI integration (Claude / MCP) | Briefcase content (when integration used) |
| AI integration (Gemini) & OAuth | Briefcase content; email (if Google auth used) | |
| Perplexity | AI integration (Perplexity) | Briefcase content (when integration used) |
| Razorpay | Payment processing | Billing email, payment details |
5. Your Rights
You have the following rights regarding your personal data:
- Access & export: You can export all your briefcase data at any time from Account Settings → Export my data. The export is delivered as a JSON file.
- Deletion: You can permanently delete your account and all associated data from Account Settings → Delete account. Deletion is completed within 30 days.
- Correction: You can update your email or display name through account settings or by contacting us.
- Portability: Your exported data is in standard JSON format and can be imported into any compatible system.
6. Data Security
We use industry-standard practices to protect your data: passwords are hashed with bcrypt, session tokens are cryptographically random, API communication is encrypted over HTTPS, and file writes use atomic operations to prevent data corruption. No system is perfectly secure; if you discover a vulnerability, please disclose it responsibly to memorybriefcase@gmail.com.
7. Contact
For privacy-related questions, requests, or complaints, contact us at memorybriefcase@gmail.com. We aim to respond within 5 business days.