trust, itemized.

the premiseplain language

Your data is yours. We keep it that way.

This page stays plain about how: where your data lives, who can read it, what deleting really does, and the limits we won't paper over. No badge wall, no theater. Just the actual mechanics, kept true.

held in one place.

where it livescloudflare

One account, encrypted.

Everything you save lives in our Cloudflare account: the database, the file storage, and the search index built from your memories, side by side.

  • Encrypted in transit. Every hop travels over TLS: your AI to us, us to our providers.
  • Encrypted where it's stored. Cloudflare encrypts the storage underneath our database and files.
  • Fenced per person. Your search index is provisioned for your account alone, and every database query is scoped to your account id on top of that. Two fences, and both would have to fail.
  • No public side doors. Our own services reach the database over Cloudflare's internal bindings, not endpoints on the open internet.

two names. not a shrug.

who can read itthe whole list

Everyone who can read it, named.

A service that organizes and recalls your memory has to read it. Anyone telling you otherwise is selling theater. Here is the full list.

  • Cloudflare stores everything, encrypted, as above.
  • Google's Gemini reads each capture once, transcribing voice and filing the thought, under enterprise terms that forbid training on your data.
  • The AIs you connect see what they ask for on your behalf: only after you click Allow, only within the scopes you approved, revocable any time.
  • Stripe learns that you subscribed, never what you saved. Card numbers never touch our servers.
  • Sentry, our crash reporting, receives error reports scrubbed of your content.
  • Us. Production access is limited to a small number of people behind multi-factor authentication, and debugging runs on masked logs, not your memories (section 6).

keys that expire.

how sign-in holdsoauth 2.1

Tokens that die young.

There's no password to steal: sign-in is a magic link to your email, or Google. Connecting an AI never shares credentials at all:

  • A consent screen, not a key handoff. Connections use OAuth 2.1: you approve exactly what a client may do (read, or read and save) before it gets anything.
  • Access tokens expire within the hour. Short-lived, signed tokens; nothing long-lived sits in your AI client.
  • Refresh tokens are single-use. Each use swaps it for a new one. If a stolen token is ever replayed, we revoke the whole family, and the client has to ask you again, on the consent screen.
  • Revoking is honest about timing. Cut a connection in the app's settings and it can't get new tokens from that moment; a token it already holds dies within the hour.

your ledger, not our asset.

your datanothing sold · every change audited

Your data. Your call.

  • We don't sell your data. Not to advertisers, not to “partners”, not at all.
  • We won't open your data without your permission. Not for support, not for debugging, not for curiosity. If the law ever compels something, the privacy policy says exactly how that works.
  • Every change is on the record. Creates, edits, and deletes are audited: what changed, who did it, and why.
  • Delete works. A deleted memory leaves search immediately, has a 30-day undo window, then is purged for good (voice recordings clear on a slower cycle, up to a year). Deleting your account takes one email: deactivated within a business day, permanently removed within 90 days. How →
  • Take it all with you. A full structured export of everything: memories, voice transcripts, the lot. Any time.

logs without your words.

what we logmasked by default

Debugging without reading your diary.

Logs exist to fix bugs and stop abuse. They're built to be safe to keep:

  • Your words stay out of them. What you save is never written to our logs: not in errors, not in traces.
  • Identifiers are masked before logging: enough to trace an incident, not enough to name you.
  • Filenames are reduced to their extension. A filename can be as private as the file.
  • Short-lived. Logs age out within 30 days.

no theater.

honest limitsread this part

What this page won't claim.

The limits, in the same plain language:

Not end-to-end encrypted (yet)

Recall means the service has to read a memory to file it and find it again; end-to-end encryption that keeps recall working is an open problem, and one we're actively researching. Until we ship it, we won't claim it. If you need it, please contact us.

No compliance badges (yet)

There's no SOC 2 certificate to show you. We're a small team, and we'd rather keep this page specific and true than imply an audit we haven't had. If you need one, please contact us.

We can't police the AI you connect

Once a memory is returned to an assistant you authorized, that provider's own privacy policy governs it. Pick confidants accordingly.

Processed in the United States

We're a US company; your data is processed in the US and wherever our named providers operate. If you need EU-only residency, please contact us.

we read every report.

disclosuresecurity.txt

Found something? Tell us first.

Security reports go straight to the people who can fix them. There are only a few of us, and we read everything.

  • Email security@workingmemory.ai. We aim to acknowledge within three business days and to keep you posted while we fix it.
  • Test only against your own account, and give us a reasonable window to fix before you publish.
  • Machine-readable details live at /.well-known/security.txt.

no bounty program yet · a fast fix and our thanks, always

kept true by hand · reviewed july 2026