Privacy Policy
Last updated: July 1, 2026
Engramma Memory Cloud ("Engramma", "we", "us") is committed to protecting your privacy. This policy explains how we collect, use, and safeguard your information when you use our platform at engramma-memory.com and our API services.
1. Information We Collect
Account Data
- Email address and name (at registration)
- Organization name (optional)
- Billing information (processed by Stripe — we never store card numbers)
Usage Data
- API call metadata (timestamps, endpoint, response codes)
- Pattern counts and storage metrics
- Session duration and feature usage on the dashboard
Memory Data
Patterns, memories, and context you store via the API are encrypted at rest (AES-256) and in transit (TLS 1.3). We do not access, read, or use your memory data for any purpose other than providing the service.
2. How We Use Your Information
- Provide, maintain, and improve the Engramma service
- Process billing and prevent fraud
- Send transactional emails (confirmations, alerts, invoices)
- Generate anonymized, aggregated analytics to improve performance
- Comply with legal obligations
3. Data Sharing
We do not sell your data. We share information only with:
- Stripe — payment processing
- Infrastructure providers — cloud hosting (data encrypted at rest)
- Law enforcement — only when legally required with valid process
4. Data Retention
- Account data: retained while your account is active + 30 days after deletion
- Memory data: deleted within 72 hours of account deletion or explicit API call
- Logs: retained for 90 days, then purged
- Billing records: retained for 7 years per financial regulations
5. Your Rights
Under GDPR, CCPA, and applicable law, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Delete your data ("right to be forgotten")
- Export your data in machine-readable format
- Object to processing
- Withdraw consent at any time
Exercise these rights via your dashboard settings or by emailing [email protected].
6. Security
- AES-256 encryption at rest
- TLS 1.3 for all data in transit
- Multi-tenant isolation with per-tenant encryption keys
- SOC 2 Type II compliance (in progress)
- Regular penetration testing and security audits
7. International Transfers
Data may be processed in the EU and US. We use Standard Contractual Clauses (SCCs) for transfers outside the EEA. Enterprise customers may choose data residency region.
8. Children
Engramma is not directed at individuals under 16. We do not knowingly collect data from children.
9. Changes
We may update this policy. Material changes will be notified via email 30 days in advance. Continued use after changes constitutes acceptance.
10. Contact
Data Protection Officer: [email protected]
General privacy inquiries: [email protected]