Plain language, no dark patterns. This policy explains what Memoa collects, why, and the controls you hold over all of it.
We collect what's needed to run your vault and nothing we can't justify. We never sell your data, never train AI on it, and never show it to anyone unless you turn that on. You can export or delete everything, anytime.
Two categories, kept separate in our minds and our systems:
To run Memoa for you: structure your notes into artifacts, power your résumé, job-fit, and recruiter profile, and keep the service secure and working. We use aggregate, content-free usage data to understand what to build next. That's the whole list.
Extraction and generation run through the OpenAI API. Your note text is sent for processing and returned — it is not used to train models, and we do not opt in to any training. No raw note content is written to our operational logs or analytics.
You can access and export your full record at any time, correct anything the AI got wrong (you confirm every artifact), and delete your account and its data outright. Where the GDPR or CCPA apply, we honor those rights for everyone, not just where required.
A short, purpose-bound list of subprocessors helps us operate — AI processing, hosting, payments, and email. Each handles only what its function requires. The current list and what each one sees is on our Security page.
We keep your record while your account is active. When you delete it, we remove your content from production systems promptly and purge it from backups on our normal rotation. We don't retain deleted records to train anything — gone means gone.
If this policy changes materially, we'll post the update here and note it before it takes effect. Questions, requests, or concerns: privacy@mymemoa.ai.
If anything here is unclear, ask us before you capture a word.