memoturn.ai
Privacy
Scope
Memoturn is open-source software licensed under MIT. This policy covers the hosted service operated by Memoturn at memoturn.ai and api.memoturn.ai. If you self-host from the source code, you are the controller — this policy does not apply to your deployment.
Data we collect
When you use the hosted service we process:
- Account data. Email, hashed password (or OAuth subject id), display name, and the organization the account belongs to.
- Project content. Turns, claims, reviews, decisions, rules, presence, and any other content you record through the API, MCP, or CLI. Used only to operate the service (storage, coordination, broadcast).
- Redaction signals. The deterministic secret scanner runs on every recorded turn. Spans matched by 25+ credential patterns are replaced with placeholders before storage; the original credential value is never persisted.
- Operational logs. Request metadata (IP, user agent, response status, latency, query telemetry) for rate-limiting, abuse prevention, and the observability dashboard. Retained 30 days.
Sub-processors
The hosted service runs on the following sub-processors:
- Cloudflare (Workers, Durable Objects, KV, R2, Hyperdrive). Hosts the edge worker, the per-project coordinator, and payload object storage.
- Neon (managed Postgres). Stores account, project, turn, decision, rule, and presence rows.
- Google and GitHub. OAuth providers; used only if you sign in via OAuth, in which case the provider sees the sign-in flow and returns a subject id we store against your account.
Retention and deletion
Project content is retained for the lifetime of the project. Operational logs are retained 30 days.
Per-turn deletion is available today through the dashboard's redactions tab (the forget-redacted-turn action) and the corresponding API endpoint. Project, organization, and account deletion currently runs through the privacy contact below; a self-serve delete endpoint is planned.
Your rights and contact
If you are in the EU, UK, or California, you have rights to access, correct, export, or delete your data, and to object to or restrict its processing. To exercise any of these rights, or for any other privacy question, email privacy@memoturn.ai. We respond within 30 days.
We do not sell personal data, do not use your project content to train models, and do not run third-party tracking on the hosted dashboard or marketing pages.