Your data, under your control
Privacy Policy
Effective and last updated: September 17, 2026
1. Scope
This policy explains how MemoStem handles information in the MemoStem website and iOS and Android apps. MemoStem is a private learning and knowledge-review service. A connected AI may notice independently teachable knowledge in the current conversation and suggest one specific item worth keeping. That suggestion sends nothing to MemoStem. If you ask to save the knowledge or confirm the suggestion, it may be saved to a private temporary guest shelf. The shelf holds up to 10 cards for 90 days. Creating or connecting an account moves those cards into private pending review; nothing is approved or published automatically. We do not harvest historical conversations.
2. Information we process
- Account data, such as your email address, authentication status, and a service-specific user identifier.
- Learning data, including notes, reviewed drafts, saved concepts, ratings, progress, and private graph relationships.
- Up to 10 account-free conversation cards that you ask a connected AI to save to a private temporary guest shelf, retained for up to 90 days.
- Technical data needed to operate and secure the service, such as request metadata, locale, guest/session identifiers, rate-limit records, and error logs.
- Subscription and transaction references, entitlement status, plan, store, renewal status, and provider event identifiers. MemoStem does not collect or store raw payment-card details.
- Advertising and consent signals needed to show, measure, limit, or remove sponsored cards. The current mobile implementation requests non-personalized ads only after the applicable consent flow permits an ad request.
3. How we use information
We use information to authenticate you, sync your private learning state, generate and review learning cards, provide search and practice, prevent abuse, maintain subscriptions, honor ad-free access, show consent-gated ads, debug failures, and comply with legal obligations. We do not publish your private notes or use them to mutate the public knowledge graph.
4. Optional AI connections
An AI connection is separate from your MemoStem account sign-in. MemoStem does not ask for or store your OpenAI or Anthropic password, subscription OAuth token, or browser cookie. Knowledge detection and the initial suggestion happen inside the connected AI service. MemoStem receives nothing from that suggestion. If you directly request capture or clearly confirm its suggestion, the AI service may send one or more strict general-knowledge bundles you asked it to save to a private guest shelf, up to 10 cards total. MemoStem stores only hashed continuation and single-use view credentials, and never asks the AI service for a transcript. The view link binds the shelf to a secure browser guest session. At the limit—or earlier if you choose—account connection moves the same cards into private pending review. They are not confirmed knowledge until you review and approve them.
If you separately allow confirmed-context access, MemoStem may return a bounded set of your active, confirmed knowledge to the connected AI service. Pending drafts, deleted or superseded items, and another person's knowledge are excluded. Learning state is returned only when the request asks for it. Disconnecting an AI app blocks later tool requests but does not delete your existing MemoStem learning data; knowledge deletion remains a separate control. Connection history keeps only a bounded operation category, accepted/failed result, and timestamp—not the request content or credential.
OpenAI, Anthropic, or another AI provider independently processes prompts, tool requests, and tool results under that provider's own terms, account settings, retention choices, and privacy policy. MemoStem's policy does not replace those provider policies.
5. Service providers
MemoStem uses vendors that process information for specific operational purposes: Clerk for authentication; Neon/Postgres for application data; Cloudflare for hosting and security; Creem for hosted web checkout, subscription management, and tax/payment processing; Superwall, Apple, and Google for mobile purchase and subscription infrastructure; Google Mobile Ads and its consent tooling for mobile advertising; and Expo/EAS for mobile builds and delivery. Each provider handles information under its own terms and privacy commitments.
6. Retention and deletion
Active account and learning data is kept while you use the service. A note moved to Trash is scheduled for permanent deletion after 14 days unless you restore it. When you delete your account, MemoStem deletes your authentication record, private notes, drafts, tokens, graph data, ratings, and progress. Limited billing, fraud-prevention, security, or tax records may be retained where reasonably necessary or legally required, without keeping your live MemoStem account.
Notes and conversation cards saved while signed out are tied to a guest session or opaque guest workspace and are automatically deleted after 90 days. Sign in before relying on longer-lived, account-controlled private knowledge.
Deleting a MemoStem account does not itself cancel an App Store or Google Play subscription. Cancel store renewal before deletion if you do not want billing to continue. MemoStem attempts to cancel supported renewing web billing before completing deletion.
7. Your choices and rights
- Review, edit, restore, or delete private notes from My Notes.
- Change supported ad privacy choices from Account in a configured mobile build.
- Restore purchases or manage a subscription through Creem, the App Store, or Google Play according to where you subscribed.
- Export private knowledge or permanently delete individual import jobs without deleting already approved knowledge.
- Delete your account and associated product data from the web or the in-app Account screen.
- Contact privacy@memostem.com for access, correction, deletion, or privacy questions.
8. Security and international processing
We use access controls, encrypted transport, owner-scoped data queries, secure mobile token storage, bounded requests, and provider signature checks. No system is perfectly secure. Service providers may process data in countries other than your own, subject to their applicable transfer safeguards.
9. Children
MemoStem is not directed to children who cannot legally consent to an online account in their jurisdiction. A parent or guardian who believes a child provided personal information should contact us so we can review and delete it.
10. Changes and contact
We may update this policy as the product or legal requirements change. We will change the effective date and provide additional notice when appropriate. For help, visit Support or email privacy@memostem.com.