Memroot / Privacy

Privacy notice

Last updated October 11, 2026 at 11:26:21 UTC

Who we are and what this notice covers

Memroot is an engineering-memory product operated from Ukraine. The operator of Memroot is the data controller for the personal data described in this notice. Contact privacy@memroot.dev about privacy or your data, and support@memroot.dev about anything else.

This notice covers the website memroot.dev, the console at console.memroot.dev, sign-in at auth.memroot.dev, the Memroot MCP server (the connection your coding agent uses), the command-line tool, and subscription billing.

If you store content in Memroot for a business or another organization, Memroot processes any personal data in that content on that organization’s instructions. An organization that needs a data processing agreement can request one at privacy@memroot.dev.

The data we process

Cookies and local storage

Memroot uses only the cookies and browser storage needed to sign you in and remember display preferences. It uses no advertising or analytics cookies.

The sign-in pages at auth.memroot.dev are operated by WorkOS and may set the cookies needed to authenticate you. Checkout is operated by Creem. Paying for a subscription opens Creem’s checkout in your browser, which may set its own cookies; ordinary account sign-in does not open checkout.

Optional session capture

Session capture is off unless you turn it on in the command-line tool, in releases that include it. You can turn it off again at any time.

When it is on, a worker on your machine redacts the session transcript locally and passes a redacted excerpt to your own coding-agent CLI, run without tools, to extract candidate memories. Your coding-agent vendor processes that excerpt under your account with them and their terms. Memroot does not receive it.

Only the resulting structured memories are uploaded: statements, short evidence quotes, repository-relative paths and symbols, the repository’s remote URL in normalized form, salted hashes, and the names of the extractor and model. The capture worker also sends one retrieval request that includes the repository name. Memroot never receives raw transcripts or tool output on this path. The service validates these memories, labels them as session-extracted, and may reject them.

How we use data and our legal bases

Where the law that applies to you requires consent, we ask for it before that processing starts. Optional features such as social sign-in and session capture run only if you choose them, and you can stop using them.

Memroot does not make decisions about you by automated means that have legal or similarly significant effects.

What Memroot does not do

Service providers and sharing

Your coding-agent vendor is chosen by you and is not our service provider. We may also disclose data when the law requires it, or to a successor that takes over the service and keeps to this notice.

Where data is processed

The operator is in Ukraine. Cloudflare runs a global network and may process and store data in the United States and other countries; Memroot’s databases, the embedding model and the vector database are not restricted to one region. WorkOS stores and accesses account authentication data in the United States. Creem, the merchant of record for paid subscriptions, is established in Estonia and lists sub-processors in the European Union and the United States. Memroot is not an EU-only service.

Cloudflare’s and WorkOS’s published data processing terms include standard contractual clauses for transfers of personal data from the European Economic Area, the United Kingdom and Switzerland where those apply. Creem’s privacy notice says it uses safeguards such as standard contractual clauses for its service providers outside the European Union and the European Economic Area. Ukraine is not covered by a European Commission adequacy decision. When you buy a subscription, Creem shares your name, country and email address with the operator in Ukraine under its data sharing agreement at creem.io/dsa. That agreement makes the operator responsible for the safeguards on this sharing and includes no standard contractual clauses. The operator receives this data to handle billing, refunds and support for the subscription you bought; Memroot’s databases do not store it. A business customer that needs transfer terms can request them together with a data processing agreement. The safeguards named here are in the providers’ published terms; ask privacy@memroot.dev which of them apply to your data and where to read them.

Retention and your choices

There is no self-serve deletion or export yet. To request access, a copy, correction or deletion of your account or your content, email privacy@memroot.dev. Requests are handled by the operator, may require verification of account ownership, and are answered within 30 days.

When we delete an account, we delete its records and content in Memroot’s databases and its sign-in record at WorkOS; the embeddings of that content stop being used immediately and are then removed from the vector database by a background process. Deleted data may remain in our hosting provider’s short-term recovery copies for a limited period. Cloudflare’s documentation for its vector database does not say how long removed embeddings remain in its own systems. Creem keeps payment records for the periods in its own privacy notice, which gives seven years for accounting data.

In the console you can revoke a coding-agent or command-line connection yourself. You can also revoke a social sign-in authorization in your Google or GitHub account settings; revocation alone does not delete your Memroot account.

Your rights

Depending on where you live, laws such as the Law of Ukraine “On Personal Data Protection” and the EU and UK General Data Protection Regulation give you rights over your personal data. You can ask us to:

Email privacy@memroot.dev to use these rights. We do not charge for a request and do not treat you differently for making one.

You can complain to the data protection authority where you live. In Ukraine this is the Ukrainian Parliament Commissioner for Human Rights.

You do not have to give us personal data, but you cannot have an account without signing in.

Security

Data is encrypted in transit. Sign-in credentials that Memroot holds for your session are encrypted before they are stored, and the console session cookie cannot be read by page scripts. Each request is checked against your account, project and connection permissions, and stored data is separated by account. Access to production systems is limited to the operator.

No system is perfectly secure. Do not store secrets in Memroot. If we learn of a breach that affects your data, we will tell you as the law requires.

Children

Memroot is for adults. It is not directed to anyone under 18, and we do not knowingly collect their personal data. Contact us if you believe a child has created an account.

Changes and contact

We will update this notice when our data practices change, and post the new version on this page with a new date. New uses of Google data require an updated disclosure and any required consent before they begin.

For privacy questions, contact privacy@memroot.dev.

Related policies and contact