Memroot / Privacy
Privacy notice
Last updated October 11, 2026 at 11:26:21 UTC
Who we are and what this notice covers
Memroot is an engineering-memory product operated from Ukraine. The operator of Memroot is the data controller for the personal data described in this notice. Contact privacy@memroot.dev about privacy or your data, and support@memroot.dev about anything else.
This notice covers the website memroot.dev, the console at console.memroot.dev, sign-in at auth.memroot.dev, the Memroot MCP server (the connection your coding agent uses), the command-line tool, and subscription billing.
If you store content in Memroot for a business or another organization, Memroot processes any personal data in that content on that organization’s instructions. An organization that needs a data processing agreement can request one at privacy@memroot.dev.
The data we process
- Account and sign-in: WorkOS AuthKit hosts our sign-in pages at auth.memroot.dev and processes account information such as your name, email address, identity-provider identifier and authentication credentials. Memroot’s own databases hold identifiers for your account and for its isolated workspace (a tenant), a keyed hash of the provider identity used to route your account, and account status. They do not store your email address, and the account directory does not use your email address as its identity key. They store a display name only if you enter one in the console settings, and you can clear it there at any time.
- Social sign-in: If you choose Google sign-in when it is offered, Google shares basic profile information and email with WorkOS for authentication. If GitHub sign-in is offered and you choose it, GitHub shares your identity and email with WorkOS for the same purpose. Google and GitHub passwords stay with those providers; Memroot does not receive them. Email and password sign-in remains available through WorkOS.
- Sessions: A server-side session record keeps you signed in to the console. It holds WorkOS refresh credentials and the WorkOS session identifier in encrypted form. The browser receives only the cookies listed below.
- Connections for agents and the command-line tool: When you authorize a coding agent, the Memroot MCP server or the command-line tool, Memroot stores the client registration, your consent, a connection record, and the access and refresh tokens issued to that client. The command-line tool keeps its credentials in your operating system’s keychain.
- Engineering memory: The content that you or your authorized clients save: memory titles, summaries and statements, short evidence quotes, file paths, symbol names, repository identifiers, commit context, and where each memory came from. It is stored in our hosting provider’s databases and is visible to you in the console. It can include personal data if you put it there, such as a name in commit context. To make memories searchable by meaning, Memroot converts the titles, summaries and statements of your memories into embeddings (numeric representations that can reveal information about the text they were made from) with an embedding model hosted on Cloudflare’s Workers AI service, and stores the embeddings in Cloudflare’s vector database (Vectorize), a store for embeddings.
- Similarity between your memories: Memroot also compares the embeddings of the memories in a project with each other, so that the console graph can show which of your memories are close in meaning; the resulting similarity scores are stored in Memroot’s databases with the project, are treated as your content, and are removed after either memory is deleted or replaced.
- Usage and limits: Counts of projects, memory writes, total assertions, and retrievals, measured against your plan. An assertion is one atomic statement inside a memory.
- Retrieval requests: The query text is used to find matching memories: the same embedding model on Cloudflare’s Workers AI service converts it into an embedding, which is compared with the embeddings of your memories. Activity keeps the limited outcome metadata described below, not the query text or its embedding.
- Activity history: The console shows a limited history of new memory saves, completed retrievals (including requests with no matches), and some failed operations. Its records hold account and project identifiers, the time, operation and outcome, the agent and save source reported by the client, result counts, and up to 20 memory identifiers per event. These identifiers are your data even though they do not contain the memory text. Memory titles shown in Activity are read from memories you can currently access; titles and content are not copied into the history. Activity records contain no query text, transcripts or tokens. The history starts when recording is enabled and may have gaps: operations refused before they reach the project database, local capture status and background job status are not recorded, and recording limits or a recording failure can leave an event missing. Accepted session-extracted memories can appear as memory saves. A memory returned to an agent does not show whether the agent used it.
- Network data: Cloudflare, our hosting provider, processes IP addresses and request metadata to deliver and protect the service, including rate limiting. To limit sign-in and authorization attempts, Memroot keeps a hash of the IP address for a few minutes. Memroot runs no analytics or advertising trackers on its website or console.
- Billing: For paid subscriptions, Creem (Armitage Labs OÜ, Estonia) processes checkout and subscription payments as merchant of record. Creem collects your name, email address, billing address, payment details and order details as a controller, under its own privacy notice. Creem shares your name, country and email address and the order, customer and subscription identifiers with the operator, who uses them to handle billing, refunds and support; Creem also generates AI-based statistics for the operator, as described under Creem below. Memroot stores provider customer, transaction and subscription identifiers, the selected plan, subscription status and billing-period dates to manage access and usage limits. Memroot does not receive full payment-card details.
- Support email: If you email a memroot.dev address, Cloudflare forwards the message to the operator’s mailbox hosted by Google, where your address and message are stored. Replies may come from the operator’s personal email address.
Cookies and local storage
Memroot uses only the cookies and browser storage needed to sign you in and remember display preferences. It uses no advertising or analytics cookies.
__Host-memroot_session: Keeps you signed in to the console. It is an opaque, secure, HTTP-only cookie that lasts up to 12 hours.__Host-memroot_login: Protects the sign-in transaction. It lasts 10 minutes.sidebar_state: Remembers whether the console sidebar is open. It lasts 7 days.memroot-theme: Stores your light or dark theme preference in your browser’s local storage until you clear it.
The sign-in pages at auth.memroot.dev are operated by WorkOS and may set the cookies needed to authenticate you. Checkout is operated by Creem. Paying for a subscription opens Creem’s checkout in your browser, which may set its own cookies; ordinary account sign-in does not open checkout.
Optional session capture
Session capture is off unless you turn it on in the command-line tool, in releases that include it. You can turn it off again at any time.
When it is on, a worker on your machine redacts the session transcript locally and passes a redacted excerpt to your own coding-agent CLI, run without tools, to extract candidate memories. Your coding-agent vendor processes that excerpt under your account with them and their terms. Memroot does not receive it.
Only the resulting structured memories are uploaded: statements, short evidence quotes, repository-relative paths and symbols, the repository’s remote URL in normalized form, salted hashes, and the names of the extractor and model. The capture worker also sends one retrieval request that includes the repository name. Memroot never receives raw transcripts or tool output on this path. The service validates these memories, labels them as session-extracted, and may reject them.
How we use data and our legal bases
- To provide the service: We use account, session, connection, memory, activity, usage and billing data to authenticate you, route your account, store, search and return your memories, show recent operation outcomes, and apply plan limits. The legal basis is our contract with you.
- To keep the service secure: We use network data, session records and rate limits to protect accounts and prevent abuse. The legal basis is our legitimate interest in a secure service.
- To answer you: We use support email to reply and to keep a record of your request. The legal basis is our contract with you or our legitimate interest in supporting users.
- To meet legal obligations: We keep billing identifiers and respond to lawful requests where the law requires it. The legal basis is a legal obligation.
- To understand subscription sales: When you buy a subscription, Creem generates AI-based statistics for the operator from your name, email address and IP address, acting as the operator’s processor. The legal basis is our legitimate interest in understanding how the service is bought. To object to this processing, write to privacy@memroot.dev; we pass your objection to Creem, which carries out the processing.
Where the law that applies to you requires consent, we ask for it before that processing starts. Optional features such as social sign-in and session capture run only if you choose them, and you can stop using them.
Memroot does not make decisions about you by automated means that have legal or similarly significant effects.
What Memroot does not do
- Memroot does not send your memory content to any AI model provider other than Cloudflare, and does not use it to train models. Cloudflare, which already hosts Memroot’s service and databases, runs the embedding model that makes memories searchable by meaning (see “The data we process”). Embeddings are treated as your content and are removed after the memory they belong to is deleted. If you turn on session capture, your own coding-agent vendor processes the redacted excerpt as described above.
- Memroot uses your content only to serve the account and projects it belongs to. It is not shared between accounts.
- Memroot does not sell personal information, share it for cross-context behavioral advertising, or use it for advertising.
- Memroot does not sell Google identity data, use it for advertising, or send it to AI models for training.
- Signing in does not give Memroot access to Gmail, Google Drive, or GitHub repositories. Social sign-in is limited to identity information; it is not a connection for accessing those services on your behalf.
Service providers and sharing
- Cloudflare: Hosts the website, console, API and databases, and protects them from abuse. It processes service traffic, stores account records and memory content, runs the embedding model (Workers AI) that processes the text of memories and search queries, stores the resulting embeddings in its vector database, and routes email sent to memroot.dev addresses. Cloudflare’s Workers AI documentation says that Cloudflare does not use customer content to train the AI models offered on Workers AI or to improve Cloudflare or third-party services without explicit consent, and does not make it available to other Cloudflare customers. Cloudflare’s Workers AI documentation does not say how long the service keeps the text it processes or in which country the model runs, so Memroot cannot promise either. Cloudflare privacy policy · Cloudflare Workers AI data usage
- WorkOS: Hosts sign-in and stores account authentication data in the United States. WorkOS privacy policy
- Google: Stores email you send to memroot.dev addresses, in the operator’s mailbox hosted by Google. It also takes part in sign-in if you choose Google sign-in. Google acts under its own privacy practices. Google privacy policy
- GitHub: Only if you choose GitHub sign-in. GitHub acts under its own privacy practices. GitHub privacy statement
- Creem: Merchant of record for paid subscriptions, operated by Armitage Labs OÜ in Estonia. Creem handles billing and payment information as a controller and shares your name, country, email address and order identifiers with the operator. To generate AI-based statistics for the operator, Creem also processes your name, email address and IP address as the operator’s processor, under its data processing agreement at creem.io/dpa. Annex 3 of that agreement lists Creem’s sub-processors and the countries where they process data; most process data in the United States. Creem privacy notice
Your coding-agent vendor is chosen by you and is not our service provider. We may also disclose data when the law requires it, or to a successor that takes over the service and keeps to this notice.
Where data is processed
The operator is in Ukraine. Cloudflare runs a global network and may process and store data in the United States and other countries; Memroot’s databases, the embedding model and the vector database are not restricted to one region. WorkOS stores and accesses account authentication data in the United States. Creem, the merchant of record for paid subscriptions, is established in Estonia and lists sub-processors in the European Union and the United States. Memroot is not an EU-only service.
Cloudflare’s and WorkOS’s published data processing terms include standard contractual clauses for transfers of personal data from the European Economic Area, the United Kingdom and Switzerland where those apply. Creem’s privacy notice says it uses safeguards such as standard contractual clauses for its service providers outside the European Union and the European Economic Area. Ukraine is not covered by a European Commission adequacy decision. When you buy a subscription, Creem shares your name, country and email address with the operator in Ukraine under its data sharing agreement at creem.io/dsa. That agreement makes the operator responsible for the safeguards on this sharing and includes no standard contractual clauses. The operator receives this data to handle billing, refunds and support for the subscription you bought; Memroot’s databases do not store it. A business customer that needs transfer terms can request them together with a data processing agreement. The safeguards named here are in the providers’ published terms; ask privacy@memroot.dev which of them apply to your data and where to read them.
Retention and your choices
- Account records: Kept while your account exists. Session expiry or signing out ends session access; it does not delete your account or every stored record.
- Engineering memory: Kept until you ask us to delete it. It has no automatic expiry. Embeddings of a memory are kept only for as long as the memory is in use. When a memory is deleted or replaced, its embeddings stop being used for search immediately and are then removed from the vector database by a background process.
- Session records: A session stops working after 12 hours without use, or 30 days in total. Expired session records are not yet removed automatically; they are deleted with the account.
- Connections and tokens: Access tokens last 15 minutes and refresh tokens up to 30 days. Pending sign-in and consent records last about 10 minutes. A revoked connection can no longer be used. Connection records are deleted with the account.
- Rate-limit records: Hashed IP addresses used for rate limiting expire within a few minutes.
- Usage counts: Kept with the account. The count of total memory writes and the count of total assertions are not reduced when memories are deleted.
- Activity history: Events stop appearing in Activity after 30 days. Expired records are removed from the database by background cleanup in bounded batches; this is not a promise of physical erasure at exactly 30 days. Deleting a memory stops its title and content being shown in Activity, while the limited operation record and memory identifier may remain until the history expires. Account or project deletion stops access to its history and includes the activity records in deletion cleanup. Hosting-provider recovery copies may retain deleted data for a limited period.
- Billing records: Payment records may be retained to meet accounting, tax, fraud-prevention and legal obligations even after an account is closed.
- Support email: Kept for as long as needed to handle your request and keep a record of it.
There is no self-serve deletion or export yet. To request access, a copy, correction or deletion of your account or your content, email privacy@memroot.dev. Requests are handled by the operator, may require verification of account ownership, and are answered within 30 days.
When we delete an account, we delete its records and content in Memroot’s databases and its sign-in record at WorkOS; the embeddings of that content stop being used immediately and are then removed from the vector database by a background process. Deleted data may remain in our hosting provider’s short-term recovery copies for a limited period. Cloudflare’s documentation for its vector database does not say how long removed embeddings remain in its own systems. Creem keeps payment records for the periods in its own privacy notice, which gives seven years for accounting data.
In the console you can revoke a coding-agent or command-line connection yourself. You can also revoke a social sign-in authorization in your Google or GitHub account settings; revocation alone does not delete your Memroot account.
Your rights
Depending on where you live, laws such as the Law of Ukraine “On Personal Data Protection” and the EU and UK General Data Protection Regulation give you rights over your personal data. You can ask us to:
- tell you what personal data we hold about you and give you a copy;
- correct data that is wrong or incomplete;
- delete your account and your content;
- give you your content in a portable format;
- restrict processing, or object to it;
- stop processing that relies on your consent.
Email privacy@memroot.dev to use these rights. We do not charge for a request and do not treat you differently for making one.
You can complain to the data protection authority where you live. In Ukraine this is the Ukrainian Parliament Commissioner for Human Rights.
You do not have to give us personal data, but you cannot have an account without signing in.
Security
Data is encrypted in transit. Sign-in credentials that Memroot holds for your session are encrypted before they are stored, and the console session cookie cannot be read by page scripts. Each request is checked against your account, project and connection permissions, and stored data is separated by account. Access to production systems is limited to the operator.
No system is perfectly secure. Do not store secrets in Memroot. If we learn of a breach that affects your data, we will tell you as the law requires.
Children
Memroot is for adults. It is not directed to anyone under 18, and we do not knowingly collect their personal data. Contact us if you believe a child has created an account.
Changes and contact
We will update this notice when our data practices change, and post the new version on this page with a new date. New uses of Google data require an updated disclosure and any required consent before they begin.
For privacy questions, contact privacy@memroot.dev.