Privacy Policy
Last updated: August 20, 2026
This is a convenience translation. The German version is the legally binding one.
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
Narveno
Owner: Thomas Iovine
c/o flexdienst – #20454
Kurt-Schumacher-Straße 76
67663 Kaiserslautern, Germany
Email: privacy@memexa.ai
No data protection officer has been appointed, as the legal requirements for a mandatory appointment (§ 38 BDSG, Art. 37 GDPR) are not met. We answer privacy requests at privacy@memexa.ai.
2. Principle: your data belongs to you
Memexa is a hosted, model-neutral “second brain”. Your notes, documents, emails and the resulting knowledge graph are processed solely to provide the service to you. We do not train AI models on your content, do not analyse it for advertising and do not pass it on to third parties for advertising or training purposes. AI services we use (see section 9) process content only to fulfil the respective function (text recognition, embeddings, answer generation, relevance ranking) and not for model training.
Your content — storage, search, graph, document processing — is processed on EU infrastructure operated by European providers. Which AI client reads it is your decision (section 8).
3. What data we process
- Account data: email address and login/session information (magic-link login, no passwords).
- Content data: the notes you create, uploaded documents, emails forwarded to your brain including attachments, and the texts, embeddings and links extracted from them.
- Usage and billing data: consumed pages/volume for limit calculation and — for paid plans — order and subscription status via our payment provider Creem (section 10). We do not store full payment details.
- Technical data: server logs (IP address, timestamp, endpoint) to ensure operation and security. If an error occurs, we process diagnostic data (error type, message, stack trace) via a self-hosted error-reporting service on our own EU infrastructure — without note content and without IP addresses; personal data is removed before transmission. For quality assurance of the AI features we also operate a self-hosted evaluation instance on our own EU infrastructure; no data is shared with third parties here either.
4. Purposes and legal bases
Processing is carried out to perform the user agreement (Art. 6 (1)(b) GDPR), to comply with legal obligations (Art. 6 (1)(c) GDPR, e.g. retention of billing records) and on the basis of our legitimate interest in a secure, functioning service (Art. 6 (1)(f) GDPR — e.g. server logs and abuse prevention). Where consent is required (Art. 6 (1)(a) GDPR), we obtain it; you can withdraw it at any time with effect for the future.
5. Cookies
Memexa only sets technically necessary cookies (session login). Details in the cookie policy. Legal basis: § 25 (2) no. 2 TDDDG, Art. 6 (1)(b) GDPR.
6. Email capture: emails forwarded to your brain
You can forward emails to a personal capture address of your account. These emails including attachments are received, processed and stored as content in your brain; related messages are merged into conversations.
In doing so we inevitably also process personal data of third parties — such as the name, email address and message content of senders and other participants in the email thread. This processing takes place exclusively on your behalf and for your private knowledge archive; the content is accessible only to you. Legal bases: Art. 6 (1)(b) GDPR (towards you) and Art. 6 (1)(f) GDPR (with regard to third parties; our and your legitimate interest in the filing of your correspondence initiated by you). You are responsible for only feeding in emails that you have lawfully received and are permitted to store. If you delete a conversation or your account, the associated data is deleted (section 11).
We use a European email service provider (EU, France) as a processor for receiving incoming emails (section 9).
7. Emails from us to you
We send you transactional emails (magic-link login, “document processed”, billing receipts) and — if enabled — summary digest notifications about your brain. Legal basis: Art. 6 (1)(b) GDPR. You can unsubscribe from digest notifications at any time in the settings. We only send marketing newsletters with your consent.
Waitlist: If you join the waitlist on our website, we store your email address, your optional message, the chosen language and the page you came from — solely to invite you and answer follow-up questions (Art. 6 (1)(b) GDPR, pre-contractual measure at your request). We do not store IP addresses in the process. The entry is deleted once you have an account or when you request its deletion.
8. MCP access by your AI clients
You connect your own AI clients (e.g. Claude, ChatGPT, local models) to your Memexa account via the Model Context Protocol (MCP). Access is granted via an OAuth token issued per account; a client reads and writes exclusively in your own brain.
Important: when your AI client retrieves content, it transmits it to the provider of the model you have chosen — depending on the provider, also outside the EU. What that provider does with the content is governed by its own privacy policy and is outside our control. The choice of client is your decision; our own processing scope (storage, search, graph, document processing) remains unaffected within the EU.
The Ask/chat feature in the dashboard uses the AI model of a European provider (EU, France — section 9): your question, relevant excerpts from your content and your profile details are passed to the model as context to generate the answer. You are therefore interacting with an AI system; answers may contain errors and are not binding information.
9. Processors and sub-processors
We use carefully selected service providers under data processing agreements (Art. 28 GDPR) and host and process primarily in the EU with European providers. The overview below lists the categories of recipients (Art. 13 (1)(e) GDPR). Where a provider or its subcontractors process data outside the EU (e.g. edge/log data of our CDN provider or subcontractors of our payment provider), this is safeguarded by appropriate guarantees under Chapter V GDPR — in particular Standard Contractual Clauses (SCC).
| Category | Purpose | Region |
|---|---|---|
| Cloud infrastructure (hosting, database, object storage) | Operating the application (app, MCP endpoint, workers), storing notes, metadata, account and billing status, embeddings and uploaded original files | EU (France) |
| Email delivery service | Transactional emails (magic link, notifications, receipts) | EU (France) |
| Email receiving service | Receiving incoming emails (email capture) | EU (France) |
| AI services | Text recognition (OCR), embeddings, link suggestions, answer generation (Ask/chat) and relevance ranking of search results — context may contain personal data; no model training on your data | EU (France, Germany) |
| CDN/network provider | DNS, CDN/edge plus WAF and DDoS protection | EU provider; global edge locations, log/request data possibly outside the EU (SCC) |
| Creem (payment provider, Armitage Labs OÜ) | Payment processing and subscription management as merchant of record (paid plans only) | Tallinn, Estonia; US subcontractors under SCCs (see section 10) |
We will provide a list naming the processors currently in use on request at privacy@memexa.ai.
10. Payment processing via Creem
Paid plans are handled by Creem as merchant of record. The provider is Armitage Labs OÜ, Rotermanni tn 14, 10111 Tallinn, Estonia (registry code 16977866). For the purchase, Creem acts as your contractual partner for the payment, processes your payment data under its own data protection responsibility and issues the invoice. Creem uses subprocessors in the US as well; these transfers are safeguarded by EU standard contractual clauses (SCCs) — details and the current list at creem.io/dpa. We do not receive full payment details from Creem, only the order and subscription status information required to activate your plan. Creem's privacy policy applies in addition.
11. Retention
We store content and account data for as long as your account exists. After you delete your account, your content is deleted; statutory retention periods (e.g. for billing records, § 147 AO, § 257 HGB) remain unaffected. You can delete individual notes, documents and email conversations yourself at any time. You can export your notes at any time as a ZIP archive (Markdown).
12. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection to processing based on legitimate interests (Art. 21). You can withdraw consent you have given at any time with effect for the future. To do so, contact privacy@memexa.ai.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR). Our competent authority: Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz, Hintere Bleiche 34, 55116 Mainz, Germany.
13. Data security
We implement technical and organisational measures pursuant to Art. 32 GDPR, including transport encryption (TLS), tenant-separated data storage with database-level access controls (row-level security), a per-account token model for MCP access, signature-verified webhooks for payment processing, and least-privilege access keys (automations receive only narrowly scoped tokens; central keys are kept in a managed secret store).
14. Changes to this policy
We update this privacy policy when the legal situation or our processing changes. The version published here applies. We will inform you of significant changes — such as new sub-processors for content data — by email or in the dashboard.