Skip to the content

Privacy

What MemorySpace does with your data

You write things here that you would not write anywhere public. This page says what is kept, why, who else ever sees it, and what you can ask for at any time.

Last updated September 21, 2026

Who is responsible for your data

Everything described here is in the hands of Sergiu Ionita, a private individual — the controller, as the law calls him. Every question about this page and every request under it goes to [email protected], and the answer comes from there.

What is kept

Five kinds of thing, and only two of them are anything you typed on purpose.

Your account
The e-mail address you signed up with, your first and last name if you gave them, the language you read the interface in, and whether your address has been confirmed. Your password is kept as a hash and never as itself, so nobody here can read it or hand it back to you.
Signing in with Google
Use the Google button and Google tells this application your address, your name and your Google account identifier, which is what finds or creates the account. Nothing more is asked for, and nothing about what you do here goes back to Google.
What you write
Your memory spaces and memories with everything in them — titles, text, dates, options, the threads between them, comments, and the instructions you leave for an assistant. This is your content. It is stored so that it can be given back to you, and it is not mined, sold or used to train anything.
Technical records
Every request leaves a line in a log: when it arrived, what was asked for, what was answered, the IP address it came from and the browser that sent it. They exist so that a fault can be found and an attack stopped, and they are not assembled into a picture of you.
Assistant access
Connect an assistant over MCP and the application keeps the client you registered, what you allowed it to do and the tokens issued to it — so that the access can be shown to you and taken back by you.

Why, and on what legal basis

Each purpose rests on a basis in Article 6 of the GDPR, and they are not interchangeable.

To give you the service (contract)
Holding your account, storing what you write, showing it back to you, and sending the mail the application has to send — confirming your address, resetting your password. Without this there is no account.
To keep it working and safe (legitimate interest)
Logs, limits on how often a request may be repeated, protection against abuse, and finding the cause when something breaks. The interest is an application that stays up and is not broken into; against it stands the fact that these records are technical and short-lived.
To remember your preferences (consent)
Everything this browser keeps beyond what signing in requires — the language, light or dark, how you like lists shown. You are asked before any of it is written, and you can take the answer back whenever you like.
Because the law requires it (legal obligation)
Where a rule of accounting or security says something must be kept, it is kept for exactly as long as that rule says.

Cookies and what this browser keeps

Two kinds. The strictly necessary ones sign you in, keep you signed in, and prove that a form you submitted came from the page it appears to come from; they cannot be switched off, because without them there is no application to use. Everything else is preference — the language, light or dark, how you like lists shown — written only if you allowed it and deleted if you take the permission back. Nothing here follows you onto other websites, and there is no advertising of any kind.

Your answer is kept in this browser for six months and only in this one, so the same account on another machine is asked again.

Who else sees it

What you write is not sold, not given to advertisers, and not passed to anybody for purposes of their own. A few parties handle it because the application cannot run without them, each under contract and on instruction only.

Hosting and infrastructure
Nobody. The servers and the database are the operator’s own machine in the Republic of Moldova, so there is no hosting company holding your data on his behalf.
Sending mail
The confirmation, password and account-deletion messages go out through an e-mail service outside the application. It sees your address and the text of that one message, and nothing else.
Google
Only if you choose to sign in with Google, and only for that: Google learns that you signed in here, which is what signing in with somebody means. What they then do with it is governed by their own privacy policy.
Assistants you connect
An assistant connected over MCP reads and writes your memories with a token you issued it, within the permissions you gave it. That is you handing somebody a key, and the key can be taken back here; what the assistant’s provider does with what it read is governed by their terms and not by this page.
Authorities
Only where a law or a valid order requires it, and no further than the request reaches.

Nobody in this list is given your content to keep or to use for themselves.

Where the data is

The servers and the backups stand in the Republic of Moldova, on a machine of the operator’s own, outside the European Economic Area. Nothing passes through another provider: what you write arrives here directly and goes no further. The Republic of Moldova is not covered by an adequacy decision of the European Commission.

How long it is kept

Nothing is held because it might one day be useful.

Your account
For as long as you want it. There is a button in your account settings that starts the deletion: it asks for your password, a link goes to the address of the account, and opening that link deletes it at once — with every memory and every memory space, your settings, the ways you could sign in, and every permission an assistant held on your behalf. Two steps, so that nobody can do it to you from a browser you left open. The link is good for one hour, and what it does cannot be undone.
What you write
Until you delete it. A memory you delete is gone from the application, and a memory space you delete takes what hangs under it with it.
Backups
The database is copied once a day and the last seven copies are kept, each dropping off the end as a new one arrives. What you delete is gone from the application at once, and out of the copies within a week at the latest.
Technical records
The server logs are kept for thirty days and then deleted. Nobody looks into them unless something has broken or somebody is trying to get in where they should not.
Your cookie answer
Six months in this browser, after which you are asked again.

How it is kept safe

Everything travels over HTTPS. Passwords are stored as hashes made with a modern algorithm, so a copy of the database hands nobody your password. The session cookie cannot be read by scripts, every form that changes something carries a token proving where it came from, and access to the servers is limited to those who must have it. No system is beyond reach; if a breach ever does put you at risk, you and the supervisory authority will be told, as the law requires.

Age

MemorySpace is not meant for children under 16 and no account should be created for one. If you believe a child has an account here, write to the address above and it will be removed.

Changes to this page

It changes when the application does, and the date at the top says when it last did. Anything that materially changes what happens to your data will be told to you in the application or by e-mail before it takes effect, rather than slipped in quietly.

Cookies, and what this browser remembers

A few are needed to sign you in and to keep your forms safe, and those cannot be turned off. Beyond them this browser remembers only how you like the interface set up — and only if you let it. Nothing is tracked, nothing is advertised, nothing goes to anybody else.

Privacy policy