Skip to main content
working/memory
How Pricing Faq Blog Get started w/m

Privacy Policy

Last updated: July 21, 2026

Working Memory ("we", "our", "us"), operated by Dualis Logic, LLC (d/b/a WorkingMemory), is a personal knowledge management service available as a web app, installable PWA, native iOS and Android apps, and (for legacy users) WhatsApp. This policy describes the personal data we collect, how we use it, and the rights you have over it.

1. Data We Collect

  • Account identifiers: your email address (used for magic-link login); for legacy users, your phone number
  • Content you send: voice notes, text messages, and uploaded documents
  • Derived data: transcriptions of your voice notes, structured items ("cognitive nodes") classified from your input, and vector embeddings used for semantic retrieval
  • Reminders and preferences: scheduling info, timezone, language
  • Payment information: handled by Stripe; we receive subscription status and limited card metadata, never full card numbers
  • Push notification credentials: Web Push endpoint and keys (web), APNs or FCM tokens (mobile)
  • Device and usage data: IP address, browser and OS, app build version, and aggregate analytics on the marketing site
  • Cookies and similar technologies: see Section 9

2. How We Use Your Data

  • Transcribe voice notes into text
  • Classify and organize your input into structured items
  • Provide semantic search across your knowledge base
  • Deliver reminders via web push, mobile push, or message
  • Process subscription payments
  • Maintain service security, prevent abuse, and debug errors
  • Measure aggregate traffic on our marketing site (workingmemory.ai) to improve it

We do not use your content to train AI models, and our LLM providers operate under enterprise terms that prohibit training on customer data.

3. Third-Party Processors

We rely on the following categories of providers. A complete current list is available on request:

  • Cloud infrastructure: Cloudflare (Workers, D1 database, R2 storage, Email Routing, Workers AI); data encrypted at rest
  • Large language models & speech-to-text: Google Vertex AI (Gemini), Cloudflare Workers AI
  • Error and crash reporting: Sentry; payloads are scrubbed of message content
  • Payment processing: Stripe
  • Web analytics: Google Analytics 4, on our marketing site only (not the application)
  • Messaging delivery: WhatsApp Business API, for legacy users only

4. Connecting Third-Party AI Clients (MCP)

You can connect Working Memory to third-party AI assistants, such as Claude, ChatGPT, and Cursor, through the Model Context Protocol (MCP). Connecting is entirely your choice and uses OAuth: you sign in and explicitly grant access on a consent screen before any connection is made.

  • What the connected assistant can do: within the scopes you approve (read, and optionally save), it can search your memory and save new items. It accesses your memory only when you or the assistant invoke those actions.
  • What we share: we return the memory items relevant to a request back to the assistant you connected. We do not send your data to any AI provider you have not connected.
  • The other provider's handling: once information is returned to a connected assistant, that provider's own privacy policy governs how they process it. We do not control the connected client.
  • Revoking access: you can revoke any connection at any time in the app (Settings → Integrations). Revoking immediately stops the client from obtaining new tokens; an access token it already holds expires within one hour. To reconnect, the client must ask your permission again.

5. Legal Basis (UK / EU GDPR)

We process personal data on the following bases:

  • Contract: to provide the service you subscribed to
  • Legitimate interests: fraud prevention, debugging, aggregate analytics
  • Consent: push notifications, marketing-site analytics cookies (where required)
  • Legal obligation: tax records, responding to lawful requests

6. Data Retention

  • Recordings & captures: raw voice recordings, transcriptions, and structured items are retained while your account is active.
  • Soft-deleted items: memory items are recoverable for 30 days after deletion, then permanently removed. Voice recordings associated with deleted items are permanently removed within 12 months. This updated retention schedule is effective August 4, 2026.
  • After cancellation: all data retained for 90 days, then permanently deleted. A free trial that expires without conversion to a paid subscription is treated as account closure for retention purposes, with the same 90-day window running from the end of the trial.
  • Backups: production backups are kept for up to 30 days.
  • Server logs: kept for 30 days for security and debugging.

7. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access: request a copy of your data
  • Rectification: correct inaccurate data
  • Erasure: request deletion of your account and data (see our Data Deletion page)
  • Portability: receive a structured export of your data
  • Object: object to processing based on legitimate interests
  • Withdraw consent: disable push notifications, opt out of analytics

California residents have analogous rights under the CCPA / CPRA, including the right to know, delete, correct, and limit use of personal information. We do not sell personal information.

To exercise any right, email support@workingmemory.ai. We respond within 30 days.

8. International Transfers

We are based in the United States. If you access the service from outside the US, your data will be transferred to and processed in the US and in other jurisdictions where our processors operate. Where required by applicable law, we rely on Standard Contractual Clauses or equivalent safeguards.

9. Cookies and Tracking

  • The application (app.workingmemory.ai) uses a strictly necessary first-party cookie for authentication (HttpOnly refresh token). It is not used for tracking.
  • The marketing site (workingmemory.ai) uses Google Analytics 4, which sets _ga and _ga_* cookies for aggregate traffic analysis. You can opt out via the Google Analytics Opt-out Browser Add-on. Where legally required, we will display a consent banner.
  • We do not use third-party advertising or cross-site tracking cookies.

10. Data Security

Data is encrypted in transit (TLS) and at rest (Cloudflare D1 and R2). Authentication uses short-lived access tokens with refresh-token rotation; native mobile clients store tokens in the operating system's secure store (Keychain on iOS, EncryptedSharedPreferences on Android). Production access is limited to a small number of authorized personnel under multi-factor authentication.

Reporting a security issue. If you believe you've found a security vulnerability, email security@workingmemory.ai. We investigate every report and aim to acknowledge within three business days. Please give us a reasonable chance to address the issue before disclosing it publicly.

11. Children's Privacy

Working Memory is not intended for users under 16. We do not knowingly collect data from children. If we learn we have, we will delete it.

12. Changes to This Policy

We may update this policy. Material changes will be announced via in-app notification or email at least 14 days before they take effect. The "Last updated" date above always reflects the current revision.

13. Contact

Email: support@workingmemory.ai
Controller: Dualis Logic, LLC (d/b/a WorkingMemory), United States.

working memory (n.) · the four or so things a mind can hold at once · everything else needs a ledger

set in polymath · printed on #faf8f3 no popups · even the 404 remembers
© 2026 working memory changelog privacy terms security data deletion hello@workingmemory.ai
side by side vs built-in ai memory vs context files vs building your own
listed on smithery