Legal

Privacy Policy

Last updated: 2026-07-26. Readable in 4 minutes.

At Memchats, your privacy is not a statement: it is an architectural decision. Servers in Germany, self-hosted embeddings, messages never shared with third parties for training. This policy explains what data we collect, why, and how you protect it yourself.

1. Who is responsible for your data

The data controller is Codelabs Studio, S.L. (Tax ID B88708797), registered in Málaga (Spain), owner of the Memchats brand, with contact email hola@memchats.com. For data protection matters, write to dpo@memchats.com.

2. What data we collect

2.1 Account data

  • Email and name (if provided via Google login)
  • Unique Keycloak identifier (auth provider)
  • Subscription plan and billing status

2.2 Messaging data you import

When you import a WhatsApp, Telegram, email, or screenshot export, we store:

  • Plain text of messages, stored in our database on a dedicated, access-restricted server (without disk encryption)
  • Metadata: timestamps, sender (alias), source channel
  • Vector embeddings (mathematical representation) computed locally with self-hosted bge-m3
  • Derived structured memory (traits, commitments, timeline events) generated by LLMs

2.3 Usage data

  • Error logs via Sentry (no message content; stack traces only)
  • Product events (signup, upgrade, which tier, which advisor), no content

3. Third-party data (important)

When you import a chat with María, María did not sign a consent form. Memchats treats this data as personal use analogous to a diary:

  • The other party's data stays under your account: it is never shared with other accounts and never used to train models
  • You see a stable alias ("contact-1a2b" or the name you assign), not the raw identifying data
  • The original files you upload stay under your account in Cloudflare R2, encrypted at rest by the provider, and are never processed without your explicit action
  • If a person appears in your chat and requests deletion of their data from Memchats via hola@memchats.com, we process it within 30 days

4. What we use the data for

  • Product function: building your memory, responding with context, detecting patterns, remembering commitments
  • Product improvement: aggregated, anonymized usage analysis (e.g., "what % of users use Lexiel")
  • Security: detecting abuse, fraud, and violations
  • Communication: transactional emails (welcome, password reset, alerts) and, optionally, a newsletter (opt-in)

We never use your data to train AI models. We never sell it. We never share it with advertisers.

5. Who we share data with

A minimal set of subprocessors, all in the EU or covered by Standard Contractual Clauses (SCC):

  • Hetzner Online (Germany): hosting for the Postgres database + Redis + workers
  • Cloudflare R2 (EU): storage for original ingestion files
  • Google (Gemini, SCC signed): the language model that writes Alma's and the advisors' answers, through Google AI or Vertex AI in the EU. Google does not train on data sent through the API
  • Stripe (Ireland): payment processing. We have no access to your card
  • Sentry (USA, SCC signed): error tracking without PII
  • Mailcow self-hosted (Germany): transactional emails

Full, up-to-date list at /security.

6. GDPR and DPA (Data Processing Agreement)

If you are a company processing employee or customer data through Memchats, we can sign a specific DPA. Request one at dpo@memchats.com with the subject "DPA request".

7. Your rights

Under the GDPR, you have the right to:

  • Access: request a copy of your data in structured JSON format
  • Rectify: correct inaccurate data
  • Erase: request full deletion (processed within 30 days)
  • Portability: export your data to another service
  • Object: object to specific processing activities
  • Complain: to the AEPD (Spain) or the supervisory authority in your country

To exercise these rights: dpo@memchats.com.

8. Retention

  • Active account: for as long as the account exists
  • Cancelled account: 30-day grace period, then deletion from the live database and from stored files
  • Backups: up to 45 days. A deleted account is gone from the live database within the stated period, but may remain in backups already taken until those rotate out. They are never restored for any purpose other than recovering the service after an incident
  • Operational logs: 90 days
  • Billing data: 6 years (Spanish tax obligation)

9. Cookies

We use only strictly necessary cookies:

  • next-auth.session-token: authenticated session (HttpOnly, Secure, SameSite=Lax)
  • NEXT_LOCALE: the language you want the app shown in

We do not use Google Analytics, Facebook Pixel, or similar tools. We run no behavioural analytics at all: the only metrics we collect are the error and performance ones from Sentry, already listed above.

10. Children under 16

Memchats is not directed at children under 16. We do not knowingly collect data from minors. If we discover that a minor has created an account, we delete it immediately.

11. Changes to this policy

If we make material changes to this policy, we will notify you by email 30 days in advance and publish the changelog at /changelog. The "last updated" date above always reflects the version currently in force.

12. Contact

General email: hola@memchats.com
Privacy: dpo@memchats.com
Support: hola@memchats.com

Privacy Policy · Memchats