Privacy

Privacy Policy

Last updated: 29 June 2026

memrelay is a hosted service that gives your company's AI tools access to your company's own knowledge, under your control. This policy explains what personal data we handle, why, and the rights you have over it.

1. Who we are

memrelay is a hosted service that connects your company's knowledge to your AI tools. In this policy, "memrelay", "we" and "us" mean the team that operates the service. For any privacy question, contact us at [email protected].

2. Controller and processor

There are two different relationships, and our role differs in each:

  • For your own account data (the people who sign in and use memrelay), we are the controller.
  • For the knowledge a customer brings into their workspace (which may contain personal data of the customer's own staff or clients), the customer is the controller and memrelay is the processor, acting only on the customer's instructions. A data processing agreement is available on request to govern that relationship.

3. What we collect

Account data

Your name, work email, company name and team size, and the identity returned by your sign-in provider (Google or Microsoft via our authentication broker). We do not store your password - sign-in is handled by your provider.

Customer knowledge content

The documents, notes and files a customer chooses to bring into their workspace. This content belongs to the customer. We process it only to provide the service (search, read, governed write-through-PR), as a processor.

Usage and technical data

Logs needed to run and secure the service: requests, timestamps, IP address, browser type, and which features were used. We use these for security, debugging, abuse prevention and basic product analytics.

4. Why we use it, and our legal bases

  • To provide the service you or your company asked for - performance of a contract.
  • To keep it secure and working (logging, abuse prevention, support) - our legitimate interest.
  • To meet legal obligations where the law requires it.
  • With your consent, where we ask for it (for example optional product emails) - you can withdraw it any time.

5. We do not train AI on your data

memrelay makes no AI model calls of its own on the ingest, search or write path. The intelligence comes from your own AI client (Claude, ChatGPT and others) connecting to your knowledge over MCP. We do not send your content to any model provider for training, and we do not use your content to train any model. Your knowledge stays plain, readable and exportable - never a black box.

6. Who we share it with (subprocessors)

We do not sell your data. We rely on a small set of vetted providers to run the service, for example:

  • Authentication: our identity broker and your chosen sign-in provider (Google, Microsoft).
  • Application hosting: EU-region cloud infrastructure.
  • Source-of-truth storage: git repository hosting for your knowledge base.
  • Website hosting and email delivery.

Each subprocessor is bound to protect data and to use it only to provide its service to us.

7. Where your data lives

memrelay is hosted in the European Union. If any processing happens outside the EU, we rely on appropriate safeguards (such as EU Standard Contractual Clauses).

8. How long we keep it

We keep account data for as long as you have an account, and logs for a limited period needed for security and operations. Knowledge content is retained for the customer under their workspace; we never hard-delete - changes and removals are versioned in git, and content is exportable at any time. On account or contract termination we delete or return data per the agreement and applicable law.

9. Security

Access is scoped per person, per team and per company, so people and their AI only see what they are allowed to. Nothing enters the knowledge base without approval (write goes through a reviewable pull request), and actions are auditable. We use encryption in transit and apply least-privilege access on our side.

10. Your rights

Under the GDPR you can ask to access, correct, delete, restrict or object to processing of your personal data, and to receive it in a portable format. To exercise any of these, email [email protected]. If memrelay holds the data as a processor for your employer, we will direct the request to them as the controller. You also have the right to complain to your local data protection authority.

11. Cookies

The marketing site uses only essential local storage (for example to remember your language choice). The application uses a session cookie to keep you signed in. We do not use advertising or cross-site tracking cookies.

12. Children

memrelay is a tool for businesses and is not intended for children. We do not knowingly collect data from anyone under 16.

13. Changes to this policy

If we make a material change, we will update the date above and, where appropriate, notify you. Continuing to use memrelay after a change means you accept the updated policy.

14. Contact

Questions about privacy or this policy: [email protected].