Back to signup

Privacy Policy

1. Information we collect

We collect account information such as administrator email addresses, usernames, password hashes, roles, organization identifiers, namespaces, session scopes, verification status, and login activity. We may also collect billing, support, and communication details when customers contact us or subscribe to paid services.

2. Customer content

Customers may upload or sync emails, chat messages, documents, spreadsheets, notes, images, metadata, attachments, and other business records. This content is processed as customer data and is used to create searchable memories, embeddings, summaries, audit records, and AI-assisted answers inside the customer's authorized workspace.

3. Gmail and Google Workspace data

When an administrator or authorized user connects Gmail or another Google Workspace source, MemBytes requests only the permissions needed to provide memory import, search, chat, summarization, and connector sync features selected by that user or workspace administrator.

For Gmail, depending on the connector settings and permissions granted, MemBytes may read email account identifiers, message IDs, thread IDs, history IDs, labels, sender and recipient fields, subject lines, dates, snippets, message bodies, and attachments or inline images that are needed for the selected import or sync. MemBytes uses Gmail history sync and webhook notifications to detect new or changed mail after authorization.

MemBytes reads Gmail data so customers can create searchable company memories, ask AI questions over authorized records, retrieve relevant emails or image notes, backfill historical records, and keep connected memories updated without manually importing files each time.

Gmail content, metadata, embeddings, connector status, sync logs, and OAuth token references are stored in the customer's MemBytes workspace database and hosting environment. Memory content and image attachments are protected with application-level encryption where enabled. OAuth tokens are stored only for connector operation and are not displayed in the product.

4. Other connector data

When an administrator or authorized user connects Google Drive, Slack, Microsoft Teams, Microsoft 365, Excel, or another source, MemBytes stores the information needed to run that connector, such as provider name, account identifiers, sync status, token references, webhook events, and sync logs. We use this information to import new records, backfill historical records, renew syncs, and report connector health.

5. How we use information

We use information to provide the product, authenticate users, enforce role-based access control, import and index content, generate embeddings, answer memory search queries, show dashboards, run background jobs, send account emails, troubleshoot issues, improve reliability, prevent misuse, and comply with legal obligations.

Google user data, including Gmail data, is used only to provide or improve visible MemBytes features requested by the user or workspace, such as memory import, search, chat answers, source retrieval, image search, summaries, connector health, and security controls.

6. AI processing

MemBytes may send selected decrypted content to configured AI providers only when needed to create embeddings, summarize imports, answer a query, or perform another requested AI action. Vector search can use stored embeddings without decrypting every memory. AI providers may process submitted content according to the customer's configuration and the provider terms that apply to the account.

MemBytes does not use Gmail data to train or improve a general AI model. Gmail data is used only for the customer's own authorized memory, search, chat, summarization, and retrieval experience.

7. Encryption and security

MemBytes is designed with application-level encryption for memory content, role-based access control, organization isolation, audit logging, secure connector handling, and restricted retrieval of relevant memories. Decrypted content is used only when required for an authorized operation, such as answering a chat query or preparing a response.

MemBytes does not allow employees, contractors, or support personnel to read Gmail content unless the customer gives explicit permission for a specific support request, access is necessary for security or abuse investigation, or access is required by law.

8. Access control and administrator responsibility

Customer administrators control users, roles, namespaces, categories, connector access, and import permissions. Administrators should assign the minimum access needed, review user activity, deactivate unused accounts, and ensure users only connect or upload data they are authorized to process.

9. Sharing, sale, and advertising

We do not sell customer content, Gmail data, Google user data, connector data, memories, embeddings, or uploaded files. We do not use Gmail data or Google user data for advertising, retargeting, personalized ads, interest-based ads, data broker services, credit scoring, or lending decisions.

We may share limited information with service providers that help operate MemBytes, such as hosting providers, database providers, email delivery providers, AI providers, payment providers, monitoring tools, and support systems. These providers are used only as needed to deliver, secure, and support MemBytes features requested by the customer, or where required for security, legal compliance, or an explicit customer-approved transfer.

10. Google API Limited Use compliance

MemBytes' use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. MemBytes uses Google API data only for user-facing product features that are visible in the MemBytes interface and requested by the customer or authorized user.

MemBytes does not transfer Google user data except as needed to provide or improve authorized MemBytes features with user consent, to protect security, to comply with applicable law, or as part of a business transfer after obtaining required user consent. MemBytes does not transfer, sell, or use Google user data for ads or unrelated third-party services.

11. Disconnecting Gmail and deleting Google data

Customers can disconnect Gmail from the Connectors page. Disconnecting Gmail disables future sync, stops new imports from that connector, and clears or revokes stored OAuth tokens where the provider allows token revocation.

Customer administrators can request or perform deletion of imported memories, Gmail synced memories, connector accounts and tokens, uploaded files and images, user data, or the company workspace from the Data Deletion area. Deleted Gmail memory content and related image attachment rows are removed from the active MemBytes database. Audit, billing, security, and legal records may be retained where needed to prove account activity, prevent abuse, resolve disputes, or comply with law.

12. Cookies and technical data

MemBytes uses necessary cookies and similar browser storage to keep users signed in, protect accounts, remember privacy choices, route requests, and operate the platform. With consent where required, MemBytes may also use optional analytics cookies to understand product usage and optional marketing cookies for campaign measurement. Optional cookies can be accepted, rejected, or managed from the Cookie Policy page.

Read the Cookie Policy or .

13. Retention

Customer content is retained according to workspace settings, subscription requirements, customer instructions, backup schedules, and legal or security obligations. Audit logs, billing records, security records, and connector logs may be retained for longer where needed for compliance, abuse prevention, troubleshooting, or dispute handling.

14. Export, correction, and deletion

Customers may request access to, export of, correction of, or deletion of workspace data. Some requests must be handled by the customer's administrator because MemBytes acts as a processor for content controlled by that customer. Certain records may be retained where required for security, legal, billing, or backup purposes.

15. International processing

MemBytes and its service providers may process information in locations where infrastructure, support, or third-party services operate. Customers are responsible for confirming that their use of MemBytes is permitted under the data protection rules that apply to their organization and users.

16. Children's data

MemBytes is a business product and is not intended for children. Customers must not knowingly upload or sync children's personal data unless they have the legal right and required consent to do so.

17. Data breach and incident handling

If we identify a security incident that affects customer data, we will investigate, take reasonable containment steps, and notify affected customers when required by law or contract. Customers should also maintain their own security monitoring and user access review process.

18. Changes to this policy

We may update this Privacy Policy when the product, legal requirements, providers, or security practices change. The updated version will show a new effective date. Continued use of MemBytes after an update means the updated policy applies.

19. Contact

Privacy questions, access requests, or deletion requests can be sent to [email protected].