LEGAL
Privacy Notice
Memento is a place to put things you care about, so it is worth being precise about what happens to them. This notice says what we collect, why, and what you can make us do about it.
LAST UPDATED 31 AUGUST 2026
1. Who is responsible
The data controller is Klodu, a sole trader (enkeltmandsvirksomhed) registered in Denmark under CVR 28046901, at Jenstrup Huse 26, 4690 Haslev, Denmark. For anything in this notice, write to privacy@mementokeep.com.
We are small enough not to need a Data Protection Officer, which means these requests come to a person rather than a queue.
2. What we collect, and why
Account data — your email address, your name if you give one, and a hash of your password. Needed to give you an account and let you sign in. Lawful basis: performance of our contract with you.
Your content — the notes, links, files, pages, meeting recordings and chat messages you put into Memento, and what the agent writes from them. Held so the service can do its job. Lawful basis: performance of our contract.
Connected credentials — the AI provider credential you connect, stored encrypted, so the agent can run as you. Lawful basis: performance of our contract.
Operational data — server logs, error reports, agent run records and approximate usage counts, used to keep the service working, to enforce plan limits and to find bugs. Lawful basis: our legitimate interest in running a reliable, secure service.
Billing data — your subscription status and what Paddle tells us about it. Paddle collects your payment details; we do not see or store card numbers. Lawful basis: performance of our contract, and our legal obligation to keep records.
Website analytics — on this public site, and not inside the app, we count page views: which page, what referred you to it, your screen size and your browser language. We also record the bare fact that a “join the beta” button was clicked, so we can tell which pages and which sources actually lead somewhere. That record is the event alone — nothing about you or your account is attached to it. No cookie is set and nothing is stored on your device. To tell one visit apart from another we keep a one-way hash of your IP address and browser, re-salted every day, so by tomorrow today’s visitor is no longer connectable to the same person. It runs on our own servers. Lawful basis: our legitimate interest in knowing which pages are worth keeping. Your browser’s Do Not Track setting turns it off.
We do not run advertising trackers, we do not sell personal data, and nothing on this site follows you to another one.
3. What happens when the agent runs
Memento drives an AI coding agent using credentials you connect yourself — your own Anthropic (Claude), OpenAI (ChatGPT/Codex) or other provider account. When the agent works on your library, the content it reads is sent to that provider under your agreement with them, not ours.
This is the most important paragraph in this notice, so plainly: content leaves our systems for the AI provider you chose, and their terms — not ours — govern what they do with it. Choose a provider whose terms you are content with, and check whether their settings let you opt out of training. We do not use your content to train models, and we do not send it anywhere else.
Agent runs happen in an isolated sandbox with restricted outbound network access, so the agent cannot quietly send your library somewhere you did not approve.
4. Meeting recordings and transcription
Speech-to-text runs on our own infrastructure — audio is transcribed by a model we host ourselves and is not sent to any third-party transcription service. The resulting text is then treated like the rest of your content, which includes being sent to your AI provider if you ask the agent to work with it.
Recording other people may require their consent where you live. That is your call to make, not ours.
5. Who else processes your data
These are the only third parties involved, each under a data processing agreement and each limited to what its role requires:
- Hetzner Online GmbH — hosting and storage. Runs the servers holding the application, database and your files. (Germany (EU).)
- Cloudflare, Inc. — network, cdn and access control. Traffic to the site and app passes through Cloudflare, which also authenticates administrator logins. (Global, under EU Standard Contractual Clauses.)
- Paddle.com Market Ltd — payments and merchant of record. Sells the subscription to you, handles payment, invoicing, VAT and refunds. We never see or store your card details. (United Kingdom / EU.)
- Resend (Plus Five Five, Inc.) — transactional email. Delivers account email such as sign-in, password reset and beta invitations. Not used for marketing. (United States, under EU Standard Contractual Clauses.)
- Help Scout PBC — support widget and helpdesk. Runs the help widget on this site and the mailbox behind it. Sees your IP address and whatever you type into a support conversation. Not present on builds without the widget. (United States, under EU Standard Contractual Clauses.)
Notably not on that list: transcription, error tracking and the website analytics described above — all three run on our own machines rather than someone else’s — and your wiki content store, which lives on our own servers too.
We may also disclose data where the law requires it, or to establish or defend a legal claim. If we are ever compelled to hand over your data and are permitted to tell you, we will.
6. Where your data lives
Your account, your content and your files are stored in the European Union. Two processors above may handle limited data outside the EU; where they do, transfers rely on the European Commission’s Standard Contractual Clauses.
7. How long we keep it
- Your content and account — until you delete them, or until you close your account.
- After account deletion — removed from live systems immediately, and from our rotating backups within seven days, as those nightly archives age out. We do not edit history inside a backup: archives that get selectively rewritten are archives that stop restoring.
- Operational logs — kept for a short period for debugging and security, then discarded.
- Website analytics — kept as counts. Because the visitor hash is re-salted every day, the records stop being linkable to a person once the day they describe is over.
- Billing records — kept as long as accounting and tax law requires, which in Denmark is five years from the end of the financial year.
8. Your rights
Under the GDPR you can ask us to:
- give you a copy of your personal data, or tell you what we hold;
- correct anything inaccurate;
- delete your data;
- restrict or object to how we process it;
- export it in a portable, machine-readable form;
- withdraw consent, where consent is what we relied on.
For export you do not need to ask: Memento has a built-in full export that gives you your pages as ordinary Markdown with your original files. That is deliberate — portability you have to request is not really portability.
Deletion is the same: Settings → Account → Delete account erases your account, every space and page in it, the files you captured, your agent history and the credentials you connected. It happens straight away and cannot be undone, so export first if you want a copy. Billing records are the one exception — we keep those for as long as tax law requires, with the link to you removed.
Write to privacy@mementokeep.com and we will respond within one month. If you think we have handled your data badly you can complain to your local supervisory authority; in Denmark that is Datatilsynet.
9. Security
Traffic is encrypted in transit. Connected AI credentials are encrypted at rest. Passwords are stored hashed, never in plain text. Agent sandboxes are isolated from each other and from our infrastructure, with outbound network access denied by default. Administrative access is restricted and requires a second factor.
No system is perfect. If we discover a breach affecting your personal data we will notify the supervisory authority and, where the risk to you is high, tell you directly.
10. Cookies
The app sets one essential cookie to keep you signed in. It is not used for tracking, and there is nothing to consent to because there is nothing optional in it. The marketing site you are reading sets no cookies at all — its analytics included, which is why there is no consent banner in front of this page.
11. Changes
If we change this notice materially we will tell you before the change takes effect. The date at the top always reflects the last substantive revision. Questions go to privacy@mementokeep.com, or support@mementokeep.com for anything else.
Memento