Privacy Policy

Last updated: September 4, 2026

1. Who We Are

SmartMemory is a memory system for people and AI agents. The service is operated by Regression Analytics LLC, doing business as SmartMemory, a Florida limited liability company. This policy explains what we collect, why we collect it, who processes it on our behalf, and what you can do about it.

We are the data controller for the personal data described here. We are located in Florida, United States. You can reach us at privacy@smartmemory.ai.

2. What We Collect

Account data

Your email address, name if you provide one, authentication identifiers, and workspace and team membership. Accounts are created and managed through Clerk, our authentication provider.

Memory content

The text, notes, documents, code, conversations, tags, and metadata that you save, or that an AI client saves on your behalf through our API or a connector. This is the content the product exists to store, and it can contain anything you choose to put in it, so please do not store data you are not permitted to share with a cloud service.

Usage and analytics data

Pages viewed, features used, and interaction events in our web applications, collected with PostHog. This includes cookie identifiers and session data. We use it to understand which parts of the product work and which do not.

Payment metadata

Plan, subscription status, billing period, and invoice history. Payments are handled by Stripe. We never receive or store your full card number.

Technical logs

Request timestamps, endpoints called, response codes, error traces, and IP addresses. Our hosted connector service records client IP addresses for per-IP rate limiting and abuse prevention.

3. How We Use It

  • To store, index, search, and retrieve your memories
  • To run the extraction pipeline that structures your content into a knowledge graph
  • To authenticate you, keep workspaces separate, and secure your account
  • To process payments and manage your subscription
  • To diagnose errors, prevent abuse, and keep the service reliable
  • To understand product usage in aggregate and decide what to build next
  • To send you service, security, and billing messages

We do not sell your data. We do not use your memory content to train AI models, and we do not share it for advertising.

4. AI Processing and Subprocessors

To structure your content we send text to a language model provider. Today that provider is Groq, which we use for extraction, structuring, and chat features. The vector embeddings used for semantic search are computed locally on our own servers and are not sent to any third party. We do not send account identifiers along with the text we submit for processing.

These are the companies that process data on our behalf:

ProviderPurposeRegion
HetznerServer hosting for the application, databases, and memory storageHelsinki, Finland (EU)
ClerkAccount creation, sign-in, session management, and OAuth for connectorsUnited States
StripeSubscription billing and payment processingUnited States
PostHogProduct analytics and session data for our web applicationsUnited States
GroqLanguage model inference for entity extraction, structuring, and chat featuresUnited States
ResendTransactional email such as account and billing noticesUnited States
AgentMailEmail inboxes used for automated testing and agent email featuresUnited States
SentryError and crash reporting, where enabledUnited States

If we add or replace a subprocessor we will update this list. Material changes are announced as described in the Changes section below.

5. Connectors and OAuth

SmartMemory runs a hosted connector server at https://mcp.smartmemory.ai/mcp that lets a third-party AI client, such as Claude or ChatGPT, work with your memories on your instruction. Connecting a client uses OAuth 2.1 through Clerk. You sign in to SmartMemory, you see what the client is asking for, and you decide whether to approve it.

Once you approve a connection, that client can read, search, create, update, and delete memories in the workspace you selected, using the same permissions your own account has. It cannot reach workspaces you did not select, and it cannot reach other users.

We never see the credentials you use with the AI client itself, and we never receive your conversations with that client except for the content it sends us as a memory or a query. In connection with a connector we store a client registration record for up to 30 days, short-lived authorization transaction records, an access token that lives for the lifetime Clerk assigns to it, and your session and workspace selection in Redis.

To end a connection, disconnect SmartMemory inside the AI client. You can also delete any SmartMemory API key from the API Keys tab in your account settings, which immediately stops anything using that key. To revoke an OAuth authorization or ask us to clear stored connector state, write to support@smartmemory.ai.

6. API Keys

A SmartMemory API key acts as its owner. Anything holding the key can do what you can do in the workspaces the key covers, so treat it like a password. Create and delete keys in your account settings, and delete any key you believe has been exposed.

7. Other Integrations

Browser extension

The SmartMemory browser extension captures web content only when you ask it to, by clicking Capture or using the right-click menu. It does not run in the background and it does not track your browsing history. What it captures, such as the page title, the URL, selected text, and any screenshot you take, is sent to your SmartMemory account and to nowhere else.

Maya on Discord

Maya is a SmartMemory companion that operates on Discord. When you talk to her we process the messages you send her, a short window of recent channel messages when you mention her so that her reply makes sense, reactions you add to her messages, and your Discord user ID and display name. This is used to generate her replies and to build your conversation memory. You can tell Maya to stop contacting you at any time, and you can ask us to delete your Discord conversation data.

8. Retention and Deletion

We keep your memory content for as long as your account exists, because storing it is the service. You can delete individual memories at any time from the app or the API, and you can export everything you have stored as an open bundle in the Open Knowledge Format.

To delete your account and everything in it, contact support@smartmemory.ai. We will confirm and complete the deletion.

Deleted data is removed from the live system straight away. Copies may remain in operational backups and logs for a limited period before they age out. Billing records are kept as long as tax and accounting law requires.

9. Security

  • All traffic to and from the service is encrypted in transit with TLS
  • Every request is scoped to a workspace, and queries cannot cross workspace boundaries
  • Access to production systems is limited to the people who need it to run the service
  • API keys are stored so that we can verify them without displaying them again

No system is perfectly secure. If you find a security problem, please tell us at support@smartmemory.ai before disclosing it publicly.

10. International Transfers

Your memories are stored on servers in Helsinki, Finland, inside the European Union. We are a United States company, and several of the providers listed above are based in the United States, so some data leaves the EU when it passes through them. Where that happens we rely on the standard contractual clauses and the data processing terms offered by each provider.

11. Your Rights

Wherever you live, you can ask us to do the following, and we will not treat you differently for asking:

  • See what personal data we hold about you
  • Get a copy of your data in a portable format
  • Correct anything that is wrong
  • Delete your memories or your whole account
  • Object to or restrict a particular use of your data
  • Withdraw consent where we relied on consent

These are the rights the GDPR gives people in the European Union and the United Kingdom, and the rights the CCPA gives California residents, written in plain words. We do not sell personal information and we do not share it for cross-context behavioural advertising. Send any request to privacy@smartmemory.ai. If you are in the EU or the UK and you are unhappy with our answer, you can complain to your local data protection authority.

12. Cookies

We use cookies and similar browser storage to keep you signed in, to remember your workspace and interface preferences, to complete payments, and to measure product usage with PostHog. Clerk, Stripe, and PostHog each set cookies as part of doing their job. You can block or clear cookies in your browser, but sign-in will not work without the ones that carry your session.

13. Children

SmartMemory is not for children under 13, or under the higher age your country sets. We do not knowingly collect data from them. If you believe a child has created an account, tell us and we will remove it.

14. Changes to This Policy

We may update this policy. For material changes we will notify you by email or an in-app notice at least 14 days before they take effect, and we will move the date at the top of this page.

15. Contact

Privacy questions and data requests: privacy@smartmemory.ai. Everything else: support@smartmemory.ai. Our Terms of Service govern your use of the product.

Regression Analytics LLC, doing business as SmartMemory, Florida, United States.

© 2026 SmartMemory. All rights reserved.