Privacy

Privacy Policy

Last updated: 7 September 2026

This policy is in English. A Croatian version is available on request: [email protected].

memrelay is a hosted service that gives your company's AI tools access to your company's own knowledge, under your control. This policy explains what personal data we handle, why, and the rights you have over it.

1. Who we are

memrelay is a hosted service that connects your company's knowledge to your AI tools. In this policy, "memrelay", "we" and "us" mean the team that operates the service. For any privacy question, contact us at [email protected].

2. Controller and processor

There are two different relationships, and our role differs in each:

  • For your own account data (the people who sign in and use memrelay), we are the controller.
  • For the knowledge a customer brings into their workspace (which may contain personal data of the customer's own staff or clients), the customer is the controller and memrelay is the processor, acting only on the customer's instructions. A data processing agreement is available on request to govern that relationship.

3. What we collect

Account data

Your name, work email, company name, and the identity returned by your sign-in provider (Google or Microsoft via our authentication broker). We do not store your password - sign-in is handled by your provider.

Customer knowledge content

The documents, notes and files a customer chooses to bring into their workspace. This content belongs to the customer. We process it only to provide the service (search, read, governed write-through-PR), as a processor.

Usage and technical data

Logs needed to run and secure the service: requests, timestamps, IP address, browser type, and which features were used. We use these for security, debugging, abuse prevention and basic product analytics.

For signed-in users, product analytics is tied to your work email, so we can see which features your team actually uses, how long they take, and which errors hit you specifically - that is what lets us fix your problem instead of an average one. We record the action, never the content: the name of the feature or tool, whether it succeeded, how long it took, the type of error, and your company, role and plan. Your documents, your search terms and anything from inside your knowledge base stay out of it. You can ask us to delete this at any time, and deleting your account removes it automatically.

Usage your workspace administrator can see

The administrator of your workspace also sees this usage metadata, per member: how many calls each member made, which classes of command they used, and when they were last active. Administrators never see the content of queries, documents or search terms. This exists so the person who brought memrelay into your company can tell whether the team is getting value from it. Where you use memrelay through an employer or client workspace, that organisation decides who holds administrator rights and why they review this view: for it they are the controller and we act on their instructions, so a request to explain or restrict it goes to them, and we will help them act on it.

4. Why we use it, and our legal bases

  • To provide the service you or your company asked for - performance of a contract.
  • To keep it secure and working (logging, abuse prevention, support) - our legitimate interest.
  • To show a customer how their own team uses the service - on that customer's instructions, as their processor.
  • To meet legal obligations where the law requires it.
  • With your consent, where we ask for it (for example optional product emails) - you can withdraw it any time.

5. We do not train AI on your data

memrelay makes no AI model calls of its own on the ingest, search or write path. The intelligence comes from your own AI client (Claude, ChatGPT and others) connecting to your knowledge over MCP. We do not send your content to any model provider for training, and we do not use your content to train any model. Your knowledge stays plain, readable and exportable - never a black box.

6. Who we share it with (subprocessors)

We do not sell your data. We rely on a small set of vetted providers to run the service:

  • Authentication: Auth0 (identity broker) and your chosen sign-in provider (Google or Microsoft).
  • Application hosting: Fly.io, in the EU region.
  • Knowledge storage: GitHub, which hosts your knowledge base as git repositories.
  • Website hosting and delivery: Hetzner (EU) and Cloudflare.
  • Transactional email: Postmark, used only to send account emails such as invitations and admin notifications.
  • Product analytics: PostHog, in the EU region.
  • Meeting recordings, only if you use the TalkLog app: Soniox transcribes the recorded audio, and Anthropic turns that transcript into the summary and coaching notes. This pair is tied to TalkLog recording only. It never touches your knowledge base, and if you do not use TalkLog these two providers process nothing of yours.

Each subprocessor is bound to protect data and to use it only to provide its service to us.

7. Where your data lives

memrelay is hosted in the European Union. If any processing happens outside the EU, we rely on appropriate safeguards (such as EU Standard Contractual Clauses).

8. How long we keep it

We keep account data for as long as you have an account, and logs for a limited period needed for security and operations. Knowledge content is retained for the customer under their workspace; we never hard-delete - changes and removals are versioned in git, and content is exportable at any time. On account or contract termination we delete or return data per the agreement and applicable law.

9. Security

Access is scoped per person, per team and per company, so people and their AI only see what they are allowed to. Nothing enters the knowledge base without approval (write goes through a reviewable pull request), and actions are auditable. We use encryption in transit and apply least-privilege access on our side.

10. Your rights

Under the GDPR you can ask to access, correct, delete, restrict or object to processing of your personal data, and to receive it in a portable format. To exercise any of these, email [email protected]. If memrelay holds the data as a processor for your employer, we will direct the request to them as the controller. You also have the right to complain to your local data protection authority.

11. Cookies

Our website uses local storage for essential preferences, for example to remember your language choice, and it remembers your cookie choice itself in a first-party cookie that lasts one year.

We use privacy-aware product analytics (PostHog, EU region) to understand how the site is used. These run from your first visit. A banner offers you "Accept cookies" or "Reject cookies": if you reject, we stop measuring you, no further analytics requests are made, and the choice is remembered on later visits. You can change your mind at any time through the "Cookies" link in the footer of every page. We do not use advertising or cross-site tracking cookies.

The application at app.memrelay.com is a signed-in product rather than a public website, and product analytics there are part of the service; the banner applies to this marketing website.

The application uses a session cookie to keep you signed in.

12. Children

memrelay is a tool for businesses and is not intended for children. We do not knowingly collect data from anyone under 16.

13. Changes to this policy

If we make a material change, we will update the date above and, where appropriate, notify you. Continuing to use memrelay after a change means you accept the updated policy.

14. Contact

Questions about privacy or this policy: [email protected].

ProductTalkLogUse casesSecurityPricingManifestoCompareFAQBook a demoBlogPrivacyTerms