Skip to main content
Memoa
Security & Trust — Data Handling
Doc. SEC-01
Rev. 2026
Security & trust

Your career, under lock.

You're handing Memoa the most personal asset you own — the full record of your work. That demands more than a promise. Here is exactly how it's held, who can touch it, and how you take it back.

Encrypted · Private by default · Yours to leave with
01Encryption & access

Locked in transit, at rest, and by row.

Encrypted at rest

Every record in your vault is encrypted on disk with industry-standard AES-256. Backups carry the same protection.

AES-256

Encrypted in transit

Nothing travels in the clear. Every request between you and Memoa is protected with modern TLS.

TLS 1.3

Row-level security

Access is enforced at the database row. Your content is scoped to your account — no other user, and no stray query, can reach it.

Postgres RLS · enforced

SOC 2-aligned practices

Access controls, audit logging, and least-privilege operations follow SOC 2 principles as we grow toward formal attestation.

In progress
02Data ownership

Your data leaves when you do. No lock-in.

A career record is only trustworthy if it's genuinely yours. Memoa is built to be left — not to trap you.

Export anytime

Take your full record — raw notes, confirmed artifacts, and generated documents — with you whenever you want. Your evidence is portable by design.

Delete completely

Close your account and your data is removed — not archived indefinitely, not quietly retained to train something. Gone means gone.

Private by default

Nothing in your vault is shared, published, or shown to a recruiter unless you explicitly turn it on — field by field, reversible at any time.

03AI & privacy

AI reads your work. It never learns from it.

Not training data

Extraction runs through the OpenAI API, which is not used to train models — and we don't opt in. Your text is processed to generate your outputs and returned, never absorbed into a training set.

No training on your data

No raw text in telemetry

Our logs and analytics measure that something happened — never what you wrote. The content of your notes stays out of operational telemetry.

Content-free logging

You are the decision boundary

AI only ever proposes. Every extracted artifact waits for your confirmation before it becomes part of your record. No silent writes.

Human-in-the-loop

Your words, preserved

Memoa structures your notes into artifacts but never edits or overwrites the original capture. The source is always there to audit against.

Immutable source
04Subprocessors

Who touches your data, and why.

Every provider here is purpose-bound — each processes only what its function requires, and nothing more.

ProviderPurposeData handled
OpenAIAI extraction & generationNote text at processing time — used to generate your outputs, not to train models
SupabaseDatabase & authenticationEncrypted records (row-level scoped to your account) and sign-in data
VercelApplication hosting & performanceRequest and usage metadata — no raw note content
PostmarkTransactional emailYour email address and message contents (magic links, notices)
StripePaymentsBilling details only — never your career content
PostHogProduct analyticsProduct events and account identifiers, including your email address
SentryError monitoringDiagnostic error data to keep the service reliable
RailwayNLP preprocessing (Memoa's spaCy service)Raw note text at capture time, for entity and number extraction
UpstashRate limiting & ephemeral cacheIP address; submitted note text on the anonymous try flow (15-min TTL)
CloudflareBot protection (Turnstile)IP address on signup, sign-in, password reset, and the try flow

This reflects our current processors during private beta and may evolve. Material changes are published here before they take effect.

Private by design, not by policy

Trust, on the record.

Questions about how your data is handled? We answer them straight — before you ever capture a word.

Evidence record · Memoa 2026