MayaMemo is context infrastructure for coding agents: it stores the notes, decisions, checkpoints and activity your agents produce, so a different agent can pick up where the last one stopped. This policy explains — in plain language — what we store, where it lives, who touches it, and how you get it back or get it deleted. The operator is MayaMemo, an independent project operated by Satyam Arya (India).
1. What we store
- Account data — your name, email address, a securely hashed password (we never store the password itself), session records, and — if you use social sign-in — the provider identity you authenticate with.
- Workspace content — the memories, checkpoints, events, context versions, entities, attachments and extraction profiles you or your agents submit. This is your data; you keep ownership.
- Usage metering — counts and cost telemetry per operation (for quotas and honest 402s), not the content of your prompts beyond what the operation itself requires.
- Billing data — subscription state and payment identifiers from our payment processor (Razorpay). Card numbers and UPI credentials never reach our servers.
- Technical logs — IP address, user agent, request timestamps and error traces, used for security, rate limiting and debugging.
2. Where it lives
Content is stored in PostgreSQL on Oracle Cloud Infrastructure (Hyderabad region, India). Traffic is encrypted in transit (TLS). Encrypted backups are written daily and rotated (7 daily / 4 weekly), with an offsite copy in Oracle Object Storage. Backups are restorable and the restore process is drilled, not assumed.
3. AI processing
Two kinds of AI processing touch your content, and only the minimum necessary:
- Embeddings — memory statements are sent to an embedding provider (default: Jina AI) to make them searchable.
- Extraction and compilation — text you ask to be turned into memories, or context compiled for a handoff, is processed by the configured LLM provider for that workspace.
We do not use your content to train models, and we do not sell it. Hashing, parsing, filtering and authorization are deterministic — no AI is used for those, by design.
4. What we never do
- We do not sell your data or share it with advertisers.
- We do not place advertising or tracking cookies. The only cookie is your session.
- We do not read your memories to build profiles of you.
5. Retention
- Workspace content is kept while your workspace exists.
- Workspaces registered by an agent but never claimed by a human are purged after 30 days.
- Daily backups rotate out after 7 days; weekly backups after 4 weeks.
- When you delete content (or purge a project), it is removed from the live database immediately and disappears from backups as they rotate.
6. Your rights and how to use them
- Export — full JSON export of a project is available in one API call and from the dashboard. No lock-in: your data leaves in a documented format.
- Deletion — purge a project via
DELETE /v1/projects/:id?purge=trueor the dashboard. To delete your whole account, use Dashboard → Account → Danger zone: type your account email to confirm and everything — workspaces, memories, checkpoints, attachments, keys — is erased in one transaction (live subscriptions are cancelled first; if that fails, nothing is deleted). You can also email us and we action deletion requests within 30 days (usually much faster). - Correction & access — you can read and edit everything through the dashboard, API and CLI at any time.
If you are in India, these rights track the Digital Personal Data Protection Act, 2023. If you are in the EU/UK, they track the GDPR. Either way, the practical answer is the same: your data is exportable and deletable, on request.
7. Grievance officer & contact
Questions, requests and complaints: satyamarya1511+mayamemo@gmail.com. We acknowledge privacy requests within 7 days and resolve them within 30.
8. Children
MayaMemo is a developer tool. It is not intended for anyone under 18, and we do not knowingly store their data.
9. Changes
If this policy changes materially, we will announce it in the product and by email to registered users at least 14 days before it takes effect.