← Back to memrith.com

Privacy Policy

Effective and last updated: June 3, 2026
The short version. Memrith is a local-first desktop application. Your journal entries, conversations, uploaded documents, and memories stay on your device — they are not transmitted to Memrith's servers. The data Memrith does see is limited to operational metadata required to license, update, and (if you opt in) crash-debug the Software. Your prompts and selected portions of your data are sent to the AI Provider you connect using your own API key; that processing is governed by the AI Provider's own privacy policy, not this one.
  1. Who we are
  2. Information we collect
  3. Information we do not collect
  4. How we use information
  5. Legal bases (GDPR / UK GDPR)
  6. Third parties we share with
  7. International transfers
  8. Retention
  9. Security
  10. Your rights (GDPR / UK / CCPA / Canada / others)
  11. Cookies and the website
  12. Children
  13. Do Not Track / Global Privacy Control
  14. Changes to this policy
  15. How to contact us

1. Who we are

Memrith LLC, a Tennessee limited liability company, is the controller of the personal information described in this policy. References to "Memrith," "we," "us," and "our" refer to Memrith LLC. We can be reached at legal@memrith.com and at the postal address in Section 15.

2. Information we collect

We deliberately collect as little personal information as possible. The categories below are exhaustive for ordinary use of the Service:

2.1 Information you provide directly

CategoryExamplesHow collected
Account / transaction Name, email, billing country, payment method (last four digits and brand only), License Key Provided to Polar at checkout (Polar is the Merchant of Record; see Section 6)
Support communications Your email, the content of your message, attachments you choose to send You email legal@memrith.com

2.2 Information collected automatically by the Software

CategoryWhat it isWhy
License activation label A short label of the form Memrith on <hostname>, plus the timestamp of activation. We hash this label server-side when used for repeat-trial enforcement so the raw hostname is not retained. Activate the License Key, enforce device-activation limits, prevent repeat-trial abuse
Update-check pings HTTP request to fetch the release manifest at memrith.com/releases/latest.json. Includes the User-Agent string (Memrith/<version>) and your IP address, as with any HTTP request. Auto-update the Software
Entitlement checks HTTP request to www.memrith.com/api/entitlement to issue or refresh the signed entitlement stored on your device. Includes the User-Agent string and your IP address; carries your license identifier, never your entries, memory, or conversations. Confirm your license is valid and issue the signed entitlement
Crash reports (opt-in, off by default) If, and only if, you opt in: stack traces, error messages, software version, OS version. Personal information is filtered out before sending (file paths under $HOME are replaced with ~; stack-frame local variables are dropped; API-key-shaped strings are redacted). Diagnose and fix bugs

2.3 Information collected automatically by the website

CategoryWhat it isWhy
Server logs IP address, User-Agent, requested URL, timestamp, referrer Standard web hosting (Vercel); used to operate the Site and protect against abuse

3. Information we do not collect

Memrith does not, in its ordinary course of operation:

  • read, transmit, or store the content of your journal entries, conversations, uploaded documents, memories, or any other content you create in the Software;
  • read, transmit, or store the prompts you send to your AI Provider, or the AI Provider's responses, on Memrith servers (those flow directly between your device and the AI Provider you have configured);
  • collect your API keys for AI Providers — on macOS they are stored in the macOS Keychain; on Windows in the Credential Manager; on any system where a secure keychain is unavailable, they fall back to an owner-read/write-only file (chmod 0600) on local disk with a logged warning, and the Software uses them locally to call the AI Provider directly;
  • track your activity across other apps or websites;
  • sell, rent, or share personal information with data brokers or advertising networks;
  • use your data to train any model.

4. How we use information

We use the limited information described in Section 2 only for:

  1. Operating the Service — licensing, activation, updates, security, abuse prevention, fraud detection;
  2. Communicating with you — responding to your support requests, sending transactional notices (receipts, refunds, license deliveries), and (only with consent or on a legitimate-interests basis with clear opt-out) occasional product updates;
  3. Improving the Software — diagnosing crashes from opt-in reports;
  4. Complying with law — including responding to lawful requests and protecting our rights, your rights, and the rights of third parties.

5. Legal bases under GDPR and UK GDPR

If you are in the European Economic Area, the United Kingdom, or Switzerland, our legal bases for processing your personal data are:

  • Contract (Art. 6(1)(b) GDPR) — to provide the Software you purchased (license activation, updates).
  • Legitimate interests (Art. 6(1)(f) GDPR) — to operate and secure the Service, prevent abuse and fraud, and communicate transactional information. Our interests do not override your fundamental rights and freedoms; you may object as set out in Section 10.
  • Consent (Art. 6(1)(a) GDPR) — for crash reporting (which is opt-in and revocable) and any marketing emails.
  • Legal obligation (Art. 6(1)(c) GDPR) — to comply with tax, accounting, and other legal requirements (largely handled by Polar as Merchant of Record).

6. Third parties we share with

We share personal information only with the following categories of recipients, each acting under a written agreement with appropriate protections:

RecipientRoleWhy
Polar (Polar Software Inc.) Merchant of Record; payment + licensing processor Handles the entire purchase transaction, license-key issuance, sales-tax / VAT / GST collection and remittance, refunds, and customer billing communications. Their privacy policy governs their processing.
Vercel Website + serverless hosting Hosts memrith.com and our update-manifest and entitlement endpoints. Receives server-log data.
GitHub Release binary hosting Hosts the downloadable installers on a public release mirror. Standard HTTP logs.
Hugging Face (Hugging Face, Inc.) On-device model hosting On first launch, Memrith downloads the local embedding model used for on-device search (~130 MB) from Hugging Face's servers — a one-time download to your machine. Like any download, it exposes your IP address to their servers in standard HTTP logs. No entries, memory, or account data are sent.
Sentry (Functional Software, Inc.) Crash reporting (opt-in only) Receives crash reports only if you have opted in. Personal information is scrubbed before sending.
Upstash / Vercel KV (if enabled) Optional repeat-trial throttle storage Stores only hashed install-labels for the purpose of preventing repeat-trial abuse.
Your AI Provider (e.g., Anthropic, OpenAI, OpenRouter) Independent controller — not our processor You contract directly with the AI Provider using your own API key. Your prompts and selected portions of your data are sent to them under their own terms and privacy policy. Memrith is not party to that processing.
Law enforcement, regulators, courts Legal compliance When required by valid legal process or to protect rights, safety, or property.
Successor entities Corporate transactions In the event of a merger, acquisition, financing, or sale of assets — subject to confidentiality and your continued rights under this policy.

7. International transfers

Memrith is based in the United States. If you are located outside the U.S. (including in the EEA, UK, Switzerland, or Canada), the limited personal information described in Section 2 will be transferred to and processed in the United States and other countries where our service providers are located. Where required, we rely on the European Commission's Standard Contractual Clauses (or UK equivalents) for such transfers; the same applies to our sub-processors (Polar, Vercel, Sentry, GitHub, Hugging Face). You may request a copy of the safeguards we use by emailing legal@memrith.com.

8. Retention

We keep information for only as long as necessary for the purposes for which it was collected, unless a longer period is required by law:

  • Account / transaction data (with Polar) — retained for the duration of your relationship with us and for the period required by tax and accounting law (typically up to 7 years).
  • Crash reports — typically 90 days, then deleted or aggregated.
  • Trial-throttle hashes — retained for the duration of trial enforcement; no raw hostnames are stored, only hashes.
  • Support correspondence — retained for up to 3 years for service and audit purposes.
  • Server logs — retained per Vercel's standard retention (typically short-term).

9. Security

We use commercially reasonable technical and organizational measures, including: TLS encryption for data in transit; restricted access to administrative systems; secrets stored in encrypted environment variables; signed software updates (Ed25519) so users can verify the authenticity of the update they install; signed entitlement files where applicable; and ongoing monitoring.

Memrith is local-first by design, which itself materially reduces our and your exposure: the body of your data never leaves your device.

Data at rest on your device. Memrith stores your data on your local disk in standard application files. Your device's operating system (file-system permissions, FileVault on macOS, BitLocker on Windows, your login password) is the security boundary for that data. Memrith does not add an additional encryption layer at rest. If your device is shared or its disk is unencrypted, treat that as the relevant security boundary.

No security measure is perfect. If we become aware of a personal data breach affecting you, we will notify you and the relevant regulators where required by applicable law, in the timelines required by law.

10. Your rights

Depending on where you live, you may have some or all of the following rights with respect to your personal information. To exercise any of them, email legal@memrith.com from the address associated with your account. We will respond within the timelines required by applicable law (no later than 30 days under most regimes; we will tell you if we need an extension).

10.1 EEA / UK / Switzerland (GDPR / UK GDPR / Swiss FADP)

  • Right of access — receive a copy of the personal data we hold about you.
  • Right to rectification — correct inaccurate or incomplete data.
  • Right to erasure ("right to be forgotten") — subject to legal exceptions.
  • Right to restriction of processing.
  • Right to object — in particular to processing based on legitimate interests, and to direct marketing absolutely.
  • Right to data portability — receive your data in a structured, commonly used, machine-readable format.
  • Right to withdraw consent — for processing based on consent (e.g., crash reporting), at any time, without affecting prior lawful processing.
  • Right to lodge a complaint with your local data-protection authority. We encourage you to contact us first so we can try to resolve the issue.

10.2 California (CCPA / CPRA)

If you are a California resident:

  • Right to know what personal information we collect, use, disclose, and the categories of sources and recipients.
  • Right to delete personal information, subject to legal exceptions.
  • Right to correct inaccurate personal information.
  • Right to opt out of "sale" or "sharing" of personal information. We do not sell or share personal information as those terms are defined under California law.
  • Right to limit use of sensitive personal information. We do not use sensitive personal information beyond what is necessary to provide the Service.
  • Right to non-discrimination for exercising these rights.

To exercise these rights, email legal@memrith.com. We will verify your request as required by law (typically by matching identifiers you provide against our records). You may designate an authorized agent to act on your behalf with appropriate written authorization.

10.3 Other U.S. states

If you are a resident of Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Tennessee (TIPA), or another U.S. state with a comprehensive privacy law, you may have rights similar to those described above (access, deletion, correction, opt-out of certain processing, appeal of denials). To exercise them, email legal@memrith.com from the address on your account.

10.4 Canada (PIPEDA / Québec Law 25)

If you are in Canada, you have rights of access and correction with respect to your personal information, and you may withdraw consent subject to legal or contractual restrictions. Contact us at legal@memrith.com. You may also contact the Office of the Privacy Commissioner of Canada or, for Québec residents, the Commission d'accès à l'information.

11. Cookies and the website

The memrith.com marketing website sets no cookies, runs no third-party analytics, advertising, or tracking scripts, and creates no fingerprint or behavioural profile of visitors. The site loads static HTML, CSS, JavaScript, and images served by Vercel; aside from the single strictly-necessary item disclosed below, no session, identifier, or persistent storage is created in your browser by us. If we add analytics or any other non-essential cookies in the future, we will update this policy and obtain consent where required by law.

Strictly-necessary storage we use. The site stores a single key in sessionStorage — memrith.privacy.ack — when you click "Got it" on the no-tracking notice banner. This is solely to avoid re-showing the banner on every page navigation within the same browser session. It clears automatically when you close the browser tab and contains no identifier, profile, or behavioural data. Under the EU ePrivacy Directive (Article 5(3)) and equivalent UK rules, storage that is "strictly necessary for the provision of a service explicitly requested by the user" does not require prior consent; the dismiss-banner preference is, in our reasonable view, exactly that.

The only external service called from the website itself is Formspree (United States), used to deliver the email-signup form. When you submit the form, your email address (and only that) is transmitted to Formspree, which forwards it to us. Formspree may set cookies on its own form-handling domain as part of submission; those are governed by Formspree's privacy policy. We do not embed Formspree into the page in a way that creates cookies on the memrith.com domain.

The Polar checkout flow (visitors are routed to the Polar-hosted checkout page from the Buy button) is operated by Polar and may set cookies necessary for the checkout. Polar's cookies are governed by its own privacy and cookie notices.

The Memrith desktop application stores its own configuration on the device where you run it (see Sections 1–3); none of that is a "website cookie".

12. Children

The Service is not directed to children under the age of 13 (or 16 where required by local law). We do not knowingly collect personal information from children. If you believe a child has provided personal information to us, please contact legal@memrith.com and we will delete it.

13. Do Not Track / Global Privacy Control

Some browsers transmit "Do Not Track" or "Global Privacy Control" (GPC) signals. We do not currently respond to DNT signals because there is no industry consensus on how to interpret them. We treat valid GPC signals received via the memrith.com website as an opt-out of "sale" or "sharing" of personal information for California residents, to the extent any such activity occurs (note that we do not currently sell or share personal information).

14. Changes to this policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top reflects the most recent revision. If we make material changes, we will provide additional notice (for example, an in-app banner or email to active customers) before they take effect. Your continued use of the Service after a revised policy takes effect constitutes acceptance, except where additional consent is required by law.

15. How to contact us

Memrith LLC
Attn: Privacy
752 Bench Ln
Mount Juliet, TN 37122, U.S.A.
Email: legal@memrith.com

If you are in the EU/EEA or the UK and would like to use the postal channel, the address above is the correct one; we currently do not have an EU representative under GDPR Art. 27 because we do not meet the threshold criteria. We will appoint one if and when required.

© 2026 Memrith LLC. All rights reserved. · Terms · Refunds · AI disclaimer · DMCA