Every decision we make, from how we store your reminders to how we handle your calendar, is made with your privacy in mind. Here's what that looks like in practice.
View Trust Center
Industry-leading practices across our entire infrastructure, from how data moves to how it's stored and who can access it.
All data is encrypted with AES-256 at rest and TLS 1.2+ in transit. No exceptions, no plain text.
Hosted on AWS with multi-region redundancy, auto-scaling, and enterprise-grade availability guarantees.
Continuous scanning, regular third-party penetration tests, and a responsible disclosure program.
Every access request is authenticated and authorized regardless of where it originates. There is no implicit trust, not even inside our network.
Multi-factor authentication is mandatory for all internal systems. Role-based access control ensures employees only see what they need to do their job.
Every request must present valid credentials and MFA token
Our IAM layer validates identity against your organization's policies
Access is granted only to the exact resources required, nothing more
Every access is logged, timestamped, and retained for 12 months
Measured, verified, and independently audited.
Our security posture is verified by third parties, not just self-reported. Full documentation is available in our Trust Center.
Assessed by Atom Assurances LLC, March 2026. DPAs, EU Standard Contractual Clauses and Transfer Impact Assessments in place for all international transfers.
International information security management standard. Certified May 2026, providing independent validation of our technical and organisational measures.
We don't sell your data. We don't use it to train AI models without your consent. And we give you full control over it.
Selling user data to third parties
Never. Your data is never sold or monetized without consent.
Training AI models with your data
Only with explicit opt-in, off by default. Contractually enforced with all AI sub-processors including Recall and OpenAI.
Data retention after account deletion
Permanently deleted within 30 days of account deletion.
Data portability
Export all your data in standard formats at any time, from your account settings.
Sub-processor transparency
Full list published and updated monthly at trust.memorae.ai.
EU Data Residency
European users' data is stored in EU-based data centers (Frankfurt).
Your data is stored on AWS infrastructure. European users are served from our EU region (Frankfurt), US users from us-east-1. You can request data residency preferences in your account settings.
No employee can read your memories. Access is strictly role-based, logged, and limited to the systems that deliver your reminders — never to human browsing.
Your data is processed privately to organize and anticipate your tasks. It is never used to train external models without your explicit opt-in, which is off by default.
Everything is permanently deleted within 30 days of account deletion, including encrypted backups. Once it's gone, it's gone for good.
Yes. A signed DPA with EU Standard Contractual Clauses is available for all customers — request it from our Trust Center or your account manager.
We run a responsible disclosure program. Email security@memorae.ai with details and we'll acknowledge within 24 hours and keep you updated on the fix.

Certificates, DPAs, sub-processor lists, and security documentation are all available at our Trust Center.