Privacy Policy
Last updated: August 6, 2026
1. Information We Collect
We collect information that you provide directly to us, including but not limited to:
- Account information (name, email address)
- Chat conversations and agent runs in the web application
- Files and documents you upload (for example, to DataHub)
- Billing information and usage metering (processed by Stripe; we never store card numbers)
- Usage data and analytics, collected via PostHog with cookies
- Technical information about your device and system
2. Your Code and the CLI
The Memcode CLI runs on your machine. Your source code and its memory stay local; we do not upload or store your repository. When the agent needs a model, the context relevant to that request is sent through the Memcode gateway to the model provider. The gateway is stateless: it holds prompts only in transit and does not persist your code or conversations. The web application stores only what you put in it.
3. How We Use Your Information
We use the information we collect to:
- Provide and maintain our services
- Route your requests to AI model providers and return responses
- Meter usage and process billing
- Analyze usage patterns and optimize performance
- Communicate with you about updates and changes
We do not use your code, conversations, files, or any other customer data to train AI models, ours or anyone else's.
4. Sign-In Data
You sign in to Memcode with Google or GitHub via OAuth 2.0. We receive only your basic profile information (name, email address, avatar) to create and identify your account. We do not request access to your Gmail, Google Drive, calendar, repositories, or any other data on those platforms. You can revoke Memcode's access at any time from your Google Account permissions or GitHub application settings. Any use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
5. Information Sharing
We do not sell or rent your personal information or your data to third parties. We share information only in the following circumstances:
- With your consent
- With AI model providers (OpenAI, Anthropic, Google, xAI, and Fireworks) to process the requests you make — these providers process data under enterprise API terms that prohibit retaining your data for model training
- With the infrastructure providers that run our service (Vercel, Supabase, Google Cloud, Stripe, PostHog), each acting as a processor on our behalf
- To comply with legal obligations
- To protect our rights and safety
- In connection with a business transfer or acquisition
6. Data Security
We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include encryption of data in transit and at rest, authentication via OAuth 2.0, and access controls on all stored data. If you bring your own provider API keys, they are encrypted in a dedicated secrets vault, are never written to the application database or logs, and can be read only by the service that routes your requests. Customer data is hosted in the United States. See our Security page for details.
7. Data Retention
We retain your account data and chat history for as long as your account is active. When you delete a chat, file, or your account, the associated data is permanently removed from our systems. Billing records are retained as required by law.
8. Your Rights
You have the right to:
- Access your personal information
- Correct inaccurate data
- Request deletion of your data
- Object to data processing
- Request data portability
- Revoke sign-in access at any time
To exercise any of these rights, contact us at the address below.
9. Contact Us
If you have questions about this Privacy Policy, please contact us at tim@memcode.ai