Privacy policy
This policy explains what personal data we process when you use Agentic Memory, what for, for how long and what rights you have. Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD) apply.
1. Data controller
- Controller: [Full name or company name]
- Tax ID (NIF or CIF): [NIF or CIF]
- Address: [Full address]
- Privacy contact: [contact email, e.g. [email protected]]
2. What data we process
- Account data. Your email address and your password, which is stored encrypted with a hash algorithm and never in readable text. If you sign in with Google, we receive your email from Google and, if your profile has one, your name.
- Content you store. The Spaces and memories that you create or that the AI agents you connect to your account create: titles, descriptions and the text of each document.
- Technical data. The IP address, browser and access logs generated by our servers, and the technical cookies described in the Cookie policy.
- Billing data. Only if you subscribe to a paid plan: the data needed to issue the invoice. Card details are processed directly by the payment provider and never reach our servers.
We ask you not to store specially protected data (health, ideology, ethnic origin and similar) or personal data of other people in your memory without a legal basis for doing so. You decide what content you store and you are responsible for it.
3. What we use it for and on what legal basis
| Purpose | Legal basis (art. 6 GDPR) |
|---|---|
| Creating and maintaining your account, storing your memory and giving it to your agents | Performance of the contract (6.1.b) |
| Keeping the service secure, preventing abuse and resolving incidents | Legitimate interest (6.1.f) |
| Issuing invoices and meeting tax and accounting obligations | Legal obligation (6.1.c) |
| Answering your enquiries | Performance of the contract or legitimate interest |
| Sending you product news by email | Consent (6.1.a), only if you expressly accept |
We do not sell your data, we do not use it for advertising and we do not use the content of your memory to train artificial intelligence models. We do not make automated decisions with legal effects on you.
4. AI agents you connect
When you connect an agent (for example Claude, Codex, Cursor or Antigravity), that agent can read and write your memory following your instructions. What the agent does with that information in its own service is governed by the terms and privacy policy of its provider, with whom you have your own relationship.
5. How long we keep it
- Account data and content: for as long as your account is active.
- Memories in the Trash: until you delete them permanently or your account is deleted.
- When you close your account we delete your content. Some data may remain in backups until they are renewed, and the data that the law obliges us to keep (for example, invoices, for the tax periods) is kept blocked.
- Technical access logs: the time strictly necessary for the security of the service.
6. Who we share it with
Only with providers we need to deliver the service, who act as processors under a contract that obliges them to protect your data:
- Server and database hosting: [Server provider and country where the data is hosted].
- Cloudflare, Inc.: stores the images you attach to your memories (Cloudflare R2) and, for semantic search, receives the text of your memories and of your searches to compute numerical representations (embeddings) with Cloudflare Workers AI. That text leaves our server for this purpose.
- Google, only if you choose to sign in with your Google account, to verify your identity.
- The payment provider, only if you subscribe to a paid plan.
We may also disclose data to public authorities when a law requires us to.
7. International transfers
If you sign in with Google, some data may be processed outside the European Economic Area. Google LLC adheres to the EU-US Data Privacy Framework, which the European Commission considers an adequate level of protection. Cloudflare, Inc. is headquartered in the US and may process data outside the EEA: [Safeguard applied to Cloudflare, e.g. the EU-US Data Privacy Framework or standard contractual clauses]. If in the future we use another provider outside the EEA, we will say so here together with the safeguard applied.
8. Your rights
You can exercise the following rights at any time, free of charge:
- Access to your data.
- Rectification of inaccurate data.
- Erasure of your data and of your account.
- Objection to and restriction of processing.
- Portability: receiving your content in a structured format.
- Withdrawing any consent you have given, without affecting the above.
Write to us at [contact email, e.g. [email protected]] saying which right you want to exercise. We will reply within one month. If you believe we have not handled your request properly, you can complain to the Spanish Data Protection Agency at www.aepd.es.
9. Security
Connections are encrypted, passwords are stored hashed and each account is isolated in the database with row-level access policies: nobody can read another account’s memory. If a security breach affecting your data were to occur, we will notify the supervisory authority and, where appropriate, you.
10. Minors
The service is not aimed at children under 14. If you are under that age, do not create an account.
11. Changes to this policy
If we change this policy in a significant way, we will tell you by email or inside the application before the change applies.