vibe-memory — Privacy Policy
DRAFT — not yet finalized. Bracketed items are placeholders pending confirmation before this policy is submitted to any connector directory.
Effective date: [DATE]
Data controller: Acrylic Code Inc. ("we", "us", "our")
Contact: colton.dyck@acryliccode.com
Service: vibe-memory — a persistent personal-memory connector (an MCP server) you connect to an AI assistant such as Claude or ChatGPT.
1. What vibe-memory does
vibe-memory gives your AI assistant a long-term memory. When you connect it, your assistant can save notes ("memories") and recall them in later conversations. You may also import your own exported chat history from Claude or ChatGPT so your memory starts populated. We process your data only to provide this service to you.
2. Information we collect
- Identity. When you connect, you authenticate through our identity provider (WorkOS AuthKit). We receive a stable account identifier and the email/issuer associated with your sign-in. We derive an internal per-user tenant ID from this; we do not receive your password.
- Memories you store. The content your assistant saves on your behalf — text you or your assistant choose to remember.
- History you import (optional). If you use the import feature, you upload your own Claude/ChatGPT export file. We extract memories from it and then process the file as described below.
- Usage metadata. Operational records such as counts of memories, embedding/token usage, and timestamps, used to run and rate-limit the service.
We do not ask for, and you should not store, payment-card numbers, government IDs, health records, or login credentials. vibe-memory is a general note-style memory and does not request sensitive data categories.
3. How we use your information
- To store and retrieve your memories and provide the connector's features.
- To generate vector embeddings so your assistant can find relevant memories (see sub-processors).
- To extract memories from history you choose to import.
- To secure, rate-limit, debug, and maintain the service.
We do not sell your data, serve ads, or use your memories to train AI models — ours or anyone else's. We use your data solely to provide the service to you.
4. Sub-processors (who else processes your data)
We rely on these providers. Each processes data only to deliver our service:
| Provider | Role | Data it receives |
|---|---|---|
| Cloudflare, Inc. | Hosting / compute / upload staging | Requests in transit; imported export files during processing |
| Supabase (data hosting) | Primary database (your stored memories + embeddings) | Your memories, embeddings, account/tenant IDs, usage metadata |
| Voyage AI | Text embeddings | The text content of memories, to compute search vectors |
| Google (Gemini API) | Memory extraction during import | The conversation content from history you choose to import |
| WorkOS (AuthKit) | Authentication / identity | Your sign-in identifier and email/issuer |
If we add or change a material sub-processor, we will update this list.
5. Data isolation
Your memories are stored under your own tenant and are isolated from other users at the database level. We do not commingle one user's memories with another's.
[Note for review: do NOT claim project-level or per-conversation segregation within a single account — imported Claude history carries no conversation→project link, so imported memories are not separated by source project. State this plainly where relevant.]
6. Data retention and deletion
- We retain your memories until you delete them. There is no fixed expiry.
- You can delete an individual memory (your assistant's "forget" tool) or erase all of your memory from your dashboard at any time. Deletion removes your stored memories and their embeddings from our database.
- Imported export files are processed to extract memories and are [retained for [X] / deleted after processing — Colton to confirm the actual upload-staging retention].
- Operational logs are retained for [LOG RETENTION PERIOD] and do not include the body of your memories (see §8).
7. Your rights
You may, at any time: access your memories (via your assistant or dashboard), delete some or all of them, and disconnect the connector. To make a request or ask about your data, contact colton.dyck@acryliccode.com. Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA; we honor applicable requests.
8. Logging and security
We operate on Cloudflare and Supabase infrastructure with encrypted transport. We restrict access to production data. Our operational logs record metadata (timestamps, tenant IDs, tool names, error codes) and exclude the body content of your memories. We authenticate every request and enforce per-user isolation on every database operation.
9. Children
vibe-memory is not directed to children under [13/16] and we do not knowingly collect their data.
10. Changes to this policy
We may update this policy; we will revise the effective date and, for material changes, provide notice through the service.
11. Contact
Acrylic Code Inc. — [BUSINESS ADDRESS, if required by jurisdiction] — colton.dyck@acryliccode.com.