Plain language, no dark patterns. This policy explains what Memoa collects, why, and the controls you hold over all of it.
We collect what's needed to run your vault and nothing we can't justify. We never sell your data, never train AI on it, and never show it to anyone unless you turn that on. You can export or delete everything, anytime.
Two categories, kept separate in our minds and our systems:
To run Memoa for you: structure your notes into artifacts, power your résumé, job-fit, and recruiter profile, and keep the service secure and working. That's the whole list.
We also use content-free product events — that an action happened, not what you wrote — to understand what to build next. Those go to a third party, and only if you say yes first. See “Who else touches it” below.
Extraction and generation run through the OpenAI API. Your note text is sent for processing and returned.
We do not use your content to train models, and we do not opt in to any provider training on it. Under OpenAI's API data-use policy, content submitted through the API is not used to train their models by default. No raw note content is written to our operational logs or analytics.
You can access and export your full record at any time, correct anything the AI got wrong (you confirm every artifact), and delete your account and its data outright. Where the GDPR or CCPA apply, we honor those rights for everyone, not just where required.
A purpose-bound list of subprocessors helps us operate: AI processing and text preprocessing, hosting, payments, email, error monitoring, rate limiting, bot protection, maps and location search, and mobile push. Each handles only what its function requires.
Analytics is separate, and it is opt-in. If you accept the analytics banner, product events go to PostHog and page-performance data to Vercel Analytics. Decline — or ignore the banner — and neither runs at all. Neither ever receives your note or résumé text, and PostHog does not receive your email address. You can change your mind at any time.
The authoritative list, naming every subprocessor and what it sees, is our Subprocessor List; the Security page summarises the same set.
We keep your record while your account is active. When you delete it, we remove your content from production systems promptly and purge it from backups on our normal rotation. We don't retain deleted records to train anything — gone means gone.
If this policy changes materially, we'll post the update here and note it before it takes effect. Questions, requests, or concerns: privacy@mymemoa.ai.
If anything here is unclear, ask us before you capture a word.