MemoRoot.xyz
Sign in Start free

Privacy Policy

Last updated: June 26, 2026

Introduction

This Privacy Policy explains how MemoRoot ("MemoRoot," "we," "us," or "our") collects, uses, stores, and shares information when you use the MemoRoot application and website (collectively, the "Service"). MemoRoot is an independently operated personal knowledge base application. By using the Service, you agree to the practices described in this policy.

MemoRoot does not target users in Japan and does not direct its Service toward any specific country or region.


What Information We Collect

Account information

When you sign up, we collect the information provided by our authentication provider (Clerk), which may include your name, email address, and a profile identifier. If you sign in using Google, we receive basic profile information (name, email address) as permitted by your Google account settings.

Content you provide

Any note, task, or text you submit to MemoRoot ("your content") is collected and processed in order to provide the Service to you. This includes the raw text you capture, AI-generated summaries and structuring of that text, and any associated metadata (tags, dates, domain classifications).

Vault storage connection data

If you connect a GitHub repository or a Google Drive account as your storage vault, we access and store the minimum information needed to read and write your notes to that storage location on your behalf. This includes:

  • For GitHub: an OAuth access token, and the name of the repository you designate as your vault.
  • For Google Drive: an OAuth access token and refresh token, and identifiers for the folder and files MemoRoot creates and manages in your Drive.

API keys (optional)

If you choose to provide your own API key for an AI model provider ("Bring Your Own Key"), that key is encrypted before storage and is never logged or displayed in plain text after submission.

Usage data

We collect limited technical data necessary to operate the Service, including error logs (via Sentry) and basic request metadata. We do not use third-party advertising trackers or analytics cookies that build cross-site profiles.


How We Use Your Information

We use the information described above solely to:

  • Provide, maintain, and improve the Service's core functionality (capturing, organizing, storing, searching, and retrieving your notes).
  • Authenticate your account and connect you to your chosen storage provider (GitHub or Google Drive).
  • Process your notes and questions through the AI model provider you select (Anthropic by default, or OpenAI, Z.ai, or Google), under your own API key, to generate structure, tags, and answers.
  • Generate semantic search embeddings (via Voyage AI, under MemoRoot's own API key) so you can search and ask questions about your own notes. Note content and Ask questions are sent to Voyage AI for this purpose.
  • Answer product-help questions asked in the Help widget, which are processed by Anthropic under MemoRoot's own API key and retained so we can review and improve the answers. Questions asked anonymously on the marketing site are stored without your IP address (only a salted hash used for rate limiting) and are deleted after 90 days.
  • Deliver reminder notifications through your browser vendor's push service (Google, Mozilla, or Apple). Notification content is end-to-end encrypted in transit, so the push service can see that a notification was sent but not its contents.
  • Diagnose and fix technical errors.
  • Communicate with you about your account or the Service, if necessary (for example, responding to a support request).

We do not use your content or your Google user data to train AI models, to build advertising profiles, or for any purpose unrelated to providing you the Service.


How We Use Google User Data Specifically

If you connect Google Drive as your vault storage provider, MemoRoot accesses Google Drive solely to:

  • Create and manage a dedicated folder and files for your MemoRoot notes within your own Google Drive.
  • Read, write, and update those files when you capture, edit, or delete a note.

MemoRoot does not access any other files, folders, or data in your Google Drive outside of what it creates for its own use. MemoRoot does not share, transfer, or use your Google user data for advertising, for training generalized AI models, or for any purpose other than providing the note storage functionality you requested. Our use of Google user data complies with the Google API Services User Data Policy, including its Limited Use requirements.


Who We Share Information With

We do not sell your personal information or your content to any third party.

We share information only with the following service providers, each of which processes data solely to help us operate the Service:

Provider Purpose Data involved
Clerk Authentication Account/profile information
GitHub Vault storage (if selected) Your notes, OAuth token
Google Drive Vault storage (if selected) Your notes, OAuth tokens
Neon (PostgreSQL) Database storage Account data, note content and search embeddings, settings, task and reminder text, your questions, usage records
AI model providers: Anthropic (default), OpenAI, Z.ai, Google (whichever you select) AI note processing and answers, under your own API key Note content and questions (processed per the provider's API terms, not used by MemoRoot for training)
Voyage AI Search embeddings Note content (processed for embedding generation)
Cloudflare Hosting and infrastructure All Service traffic
Cloudflare Turnstile Bot protection on public question forms Browser characteristics used for bot detection, per the Cloudflare Turnstile Privacy Addendum
Browser push services (Google, Mozilla, Apple) Delivering reminder notifications Encrypted notification payloads; the push service cannot read the contents
Sentry Error monitoring Technical error logs; these can include a note's title when a storage provider's error message names the file, but never note contents

We may also disclose information if required by law, or to protect the rights, property, or safety of MemoRoot, our users, or others.


Data Retention and Deletion

We retain your account information and content for as long as your account remains active, or as needed to provide the Service to you. This includes your questions to Ask and to the Help widget and your task and reminder text, which are retained verbatim while your account is active.

You may delete individual notes at any time within the Service. A deleted note is removed from your connected vault storage (GitHub or Google Drive) and moved to Trash in our database, where it remains recoverable for 30 days before being permanently removed. Using "Delete forever" in Trash removes it from our database immediately.

You may request full deletion of your account and all associated data by contacting support@memoroot.xyz. Upon a verified deletion request, we will delete your account information, stored notes metadata, and search embeddings from our systems, and revoke our application's access tokens to your connected GitHub or Google Drive account. We will complete deletion requests within a reasonable time, generally within 30 days. Note that disconnecting a storage provider does not delete the notes already written to your own GitHub repository or Google Drive folder; those remain yours and under your control, since you own that storage.


Data Security

We take reasonable technical and organizational measures to protect your information, including:

  • Encryption of stored API keys (AES-256-GCM) and OAuth tokens.
  • Encrypted connections (HTTPS/TLS) for all data in transit.
  • Access controls limiting which systems and processes can read sensitive data.

No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.


Children's Privacy

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If we become aware that we have collected such information, we will take steps to delete it.


Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify users through the Service or by other reasonable means before the changes take effect. Continued use of the Service after a change takes effect constitutes acceptance of the revised policy.


Contact Us

If you have questions about this Privacy Policy or how your data is handled, contact us at support@memoroot.xyz or visit our Support page.

MemoRoot.xyz
Pricing Docs Support Privacy Terms

© 2026 MemoRoot.xyz