Back

Privacy Policy

Last updated June 2026

Plain-language template. This document describes how mmmry actually works, in good faith and in everyday English. It is template text that has not been reviewed by an attorney. Have qualified counsel review and adapt it for your jurisdiction and entity before relying on it in production.

mmmry (“mmmry,” “we,” “us”) is a private, AI-assisted place to save the things you find and surface the ones that match your goals. This policy explains what we collect, why, and the control you keep over it. The short version: we collect the minimum needed to run the service, we encrypt your saved content with a key unique to you, and we never sell your data, run ads, or use third-party behavioral tracking.

Who we are

mmmry is operated by mmmry, based in the United States. For any privacy question, the data controller's contact is [email protected].

What we collect

  • Things you save (your content). The cards you capture — notes, quotes, web pages, images and the text inside them, plus any title, tags, or goals you add. The sensitive text of each card is encrypted at rest with a per-user key (see “How we protect it”).
  • Account basics. Your email address and, if you use single sign-on, the account identifier returned by your provider (Google or Apple). We support passwordless email sign-in and SSO; we do not store passwords.
  • Image and file assets. Stored in object storage under a per-user prefix.
  • Derived search data. To make search work without decrypting your library on every query, we store non-human-readable derived artifacts — a full-text search index, numeric “embedding” vectors that represent meaning, and dominant-color values. These are computed from your content and used only to find and rank it for you.
  • Operational counters. Aggregate, first-party counts (for example, how many cards were created or searches run on a given day). These carry no payload — no search text, no card content, no profile of you.
  • Billing data (paid plans only). If you subscribe, our payment processor (Stripe) handles your card details directly. We receive only a customer/subscription identifier and plan status — we never see or store your full card number.
  • Basic technical logs. Standard server logs (such as IP address and request metadata) needed to operate the service, keep it secure, and debug problems. We keep these for a limited period.

What we do NOT collect

We do not use Google Analytics, advertising pixels, session-replay, or any third-party behavioral analytics or tracking SDK. We do not build advertising profiles, and we do not sell or “share” your personal information for cross-context behavioral advertising (as those terms are defined under California law).

How we use it

  • To provide the core service — store, organize, search, and surface what you save.
  • To run AI enrichment (see below): summaries, tags, OCR, color, semantic search, and goal-alignment scoring.
  • To send you transactional and reminder emails you've enabled (see “Email”).
  • To keep the service secure, prevent abuse, enforce limits, and fix bugs.
  • To process payments and manage subscriptions, for paid plans.
We process your content to deliver features you ask for and to operate and secure the service (our legitimate interest, and your consent where required by law). We do not use your content to train third-party AI models, and we instruct our AI providers not to either, where that option is available to us.

AI processing — read this

Several features (auto-tagging, summaries, OCR, semantic search, and goal alignment) work by sending the relevant content of a card to AI model providers through gateways we operate. That means, for those features, your content is processed server-side and transmitted to a model provider to compute a result. The encryption-at-rest protection above does not extend to content while it is being processed by an AI model. We disclose this plainly so the trade-off is clear. Results are cached by content hash so we don't re-send identical content. The current list of AI and infrastructure providers is on our Subprocessors page.

How we protect it

  • Per-user encryption at rest. Sensitive text columns are encrypted with AES-256-GCM using a per-user key, which is itself wrapped by a master key. A database or disk dump alone does not reveal your readable content.
  • Honest limit. Because AI features run server-side — including while you are logged out — the running server must be able to decrypt content to process it. Encryption protects against a stolen database or disk; it does not protect against a fully compromised, running application server. We design and operate to reduce that risk but state it plainly rather than over-promise.
  • Transport is encrypted (HTTPS/TLS). Access to production systems is limited.

Email

Transactional messages (sign-in links, account notices) are required to use the service. Goal-aligned reminder emails are optional— you turn them on or off in Settings, and every reminder includes an unsubscribe link. We send through a third-party email provider (Resend).

Cookies

We use a small number of strictly necessary, first-party cookies — chiefly to keep you signed in (session) and to protect against cross-site request forgery. We do not use advertising or cross-site tracking cookies. Because we don't track you across sites, there is nothing to opt out of for advertising; we honor Global Privacy Control (GPC) signals where applicable.

Sharing & disclosure

We share personal information only with service providers who process it on our behalf to run mmmry (hosting, AI gateways and model providers, email, payments) — listed on our Subprocessors page — under contracts that limit their use to providing the service. We may also disclose information if required by law, to protect rights and safety, or in connection with a merger or acquisition (in which case we'll notify you and this policy continues to govern your data).

Retention

We keep your content for as long as your account is active. When you delete an item or your account, we remove it from our systems, including object-storage assets, as described in “Your controls.” Some records (for example, basic logs and billing records we're required to keep) persist for a limited, legally appropriate period. Backups roll off on their normal cycle.

Your controls & rights

  • Export — download all of your data (cards as plain text, collections, goals, and image files) as a single zip from Settings.
  • Delete — permanently delete your account and everything in it, including object-storage assets, from Settings. This is irreversible.
  • Access / correction — you can view and edit your content directly in the app at any time.

Depending on where you live, you may have additional rights — to know, access, correct, delete, or port your personal information, and to be free from discrimination for exercising them. California residents (CCPA/CPRA): we do not sell or share personal information and do not use sensitive personal information for purposes requiring an opt-out. EU/EEA/UK residents (GDPR/UK GDPR): you may also object to or restrict processing and lodge a complaint with your supervisory authority. To exercise any right, email [email protected] — we'll verify and respond within the period your law requires. Many of these rights are already self-serve via Export and Delete above.

Children

mmmry is not directed to children and is not intended for anyone under 13 (or the minimum age of digital consent in your country, if higher). We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

International users

We operate in the United States; if you use mmmry from outside the U.S., your information is processed in the U.S. and other countries where our providers operate. We rely on appropriate safeguards (such as standard contractual clauses) where required for cross-border transfers.

Changes

We may update this policy as the product evolves. We'll change the “last updated” date and, for material changes, give reasonable notice in-app or by email.

Contact

Questions about privacy? Email [email protected]. See also our Terms of Service and Disclaimer.