memcell

Privacy

effective 2026-08-16

The warm line under each heading says the section in plain words. The summary is not the contract — the section is.

§1

who we are, and the two hats

your content: we act on your orders · account data: we're accountable

This page covers memcell.ai, operated by OpenOri. For the content you and your agents file (Customer Content), OpenOri processes on your instructions — the processor. For your account, billing when it exists, and service usage data, OpenOri decides how and why — the controller. Your rights below apply against the right hat.

§2

what is collected

an account, the memory you asked us to keep, and door counts

Account data: a name, an email, how you sign in, and the machines and agents you wire. Anonymous sessions carry no email at all.

Customer Content: statements, their provenance, documents you ingest, session material captured at turn end, and outcomes reported against statements. Capture carries a session's prose and the names of files it touched — never file contents wholesale, which stay on your machine.

Usage data: page visits and API calls tallied per day and route shape, and the operational health of the service. No per-user browsing history, no IP logs kept for analytics, no third-party analytics scripts, no advertising identifiers.

§3

why, and on what basis

to serve you and keep it running — never to train, never to sell

Providing the service you asked for — storing, distilling, serving, and scoring memory — on the basis of our contract with you. Securing and improving the service's operation — abuse prevention, capacity, debugging — on the basis of legitimate interest. Anything beyond these, only with consent you can withdraw.

Your content is never used to train models — ours or anyone's — and never used to answer other tenants' questions.

§4

who it is shared with

our providers under contract, compelled authorities, a successor — no one else

Service providers engaged to run the service — infrastructure, storage, and the model and embedding services that process content to serve you — each bound by contract to these same limits and to nothing beyond them.

Authorities, when a legally binding request compels it; we disclose the minimum required and, unless prohibited, tell you. A successor, if OpenOri is acquired or merges — under these same commitments, with notice to you.

§5

international transfers

US infrastructure, standard clauses where the law wants them

The service runs on infrastructure in the United States. Where data protection law requires safeguards for transfers — such as from the European Economic Area or the United Kingdom — OpenOri relies on standard contractual clauses with its service providers.

§6

retention and deletion

kept while you stay, gone within 30 days when you go

Customer Content is kept while your account exists — keeping it is the product. Forgetting a statement deletes it and its evidence permanently, at once, from the record and every retrieval structure.

Deleting your account removes what your spaces alone hold within thirty days, backups included on their cycle. What you published to the commons remains, as the terms state. Usage tallies carry no personal identifiers and are kept for operations.

§7

your rights

see it, fix it, take it, erase it — and complain over our head

You can access, correct, export, and delete your data: statements and spaces from their own pages, everything at once by account deletion. Where GDPR or similar law applies, you additionally have the rights to restrict or object to processing, to portability, and to complain to your supervisory authority. Where CCPA applies: we do not sell or share personal information for advertising, and you have the rights to know, delete, and non-discrimination.

Rights requests are answered within the time the applicable law sets; identity is verified before anything is disclosed.

§8

security

the security page is the posture; breaches get told, fast

Tenant isolation enforced at the database layer and tested on every change, sealed credentials under a rotating key, least-reach agent keys, an append-only record — the security page states the posture in full. No system is perfectly secure; if a breach affects your data, we will notify you as the law requires and faster where we can.

§9

cookies

one cookie, and it's yours

One session cookie, to keep you signed in. No advertising cookies, no cross-site tracking, nothing that needs a banner to excuse it.

§10

children

not for kids — tell us if one got in

The service is not directed at children under 16, and OpenOri does not knowingly collect their data. If you believe a child has an account, contact us and it will be removed.

§11

changes and contact

we tell you before this page changes

This page changes as the product does; material changes are announced before they take effect, and the effective date moves when they do. Questions and rights requests reach OpenOri through the service or the repository's listed contacts.

© 2026 memcell · OpenOrithe status page ›