Privacy Policy
Effective August 15, 2026. Operated by Zenthor.
This policy describes how Zenthor collects, uses, and shares information when you use Steve Memo, including the web app, REST API, and MCP interfaces.
Who we are
Zenthor operates Steve Memo and is responsible for the processing described in this policy. Privacy questions and requests can be sent to privacy@steve-memo.com.
Information we collect
- Account and workspace identity from Clerk, including name, email, profile image URL, organization details, memberships, invitations, and the Clerk webhook records used to keep that information current.
- Workspace content submitted by you, other members, or connected agents. This includes memory text, tags, metadata, dates, entities, graph labels, extraction source text, Dream proposals, lifecycle history, and uploaded images, plain-text files, or Markdown files.
- Workspace configuration, including custom instructions, categories, retention and model settings, agent-key metadata, webhook URLs and event selections, webhook delivery payloads and errors, and audit events. Newly created API-key secrets are shown once and are not written to logs, events, webhooks, or browser storage.
- Vector embeddings generated from memory text so search can work. Embeddings are not included in user exports.
- Request metadata such as method, path, status, request ID, duration, error code, and API key ID. Request bodies and API-key secrets are not stored in these request logs.
- Messages and other information you send when asking for support or exercising a privacy right.
- Clerk session cookies and storage required to stay signed in, a first-party cookie for sidebar state, and first-party local storage for color theme and extract drafts. We do not use advertising cookies or sell personal information.
- Cookieless Vercel Web Analytics data, which may include time, hostname and page path, referrer origin, coarse location, device type, browser and version, operating system, and analytics-script version. Page-view URLs are reduced to their path before sending, so query strings and fragments such as memory search text are excluded. Vercel uses a daily request hash rather than a cookie or cross-site identifier.
Family memories can contain sensitive information about you or other people. Do not store passwords, authentication secrets, payment-card details, or government identification numbers. Only submit personal information when you have the right to do so.
Where information comes from
We receive information from you, other members of your workspace, connected agents and webhooks, Clerk, and automatically from your use of the service. Workspace administrators choose membership, integrations, settings, and organization content. Members and agents can submit information about other people, including family members.
How we use information
- Authenticate users and enforce private and organization access.
- Store, search, extract, deduplicate, supersede, curate, export, import, and delete memories.
- Generate embeddings and, when enabled, run extraction, reranking, media review, graph extraction, and Dream curation.
- Operate webhooks and connected agents that workspace members configure.
- Secure, maintain, troubleshoot, and improve the service.
- Measure use of public and signed-in pages with aggregated web analytics. We do not use analytics for advertising or to identify individual users.
- Comply with law, enforce our terms, and protect users, Zenthor, and others.
Legal bases
Where applicable law requires a legal basis, we rely on:
- Contract, to create and administer accounts and provide the features you request.
- Legitimate interests, to secure, maintain, troubleshoot, and understand use of the service, where those interests are not overridden by your rights.
- Legal obligations, when we must keep or disclose information under law.
- Consent, when we specifically ask for it. You may withdraw it at any time.
Processors and other recipients
These providers receive information as needed to operate Steve Memo:
- Clerk for sign-in, organizations, invitations, and organization API keys.
- Convex for the application database, file storage, scheduled jobs, and HTTP API.
- OpenRouter and model providers it routes to for extraction, embeddings, reranking, Dream, graph extraction, and media review. Depending on the feature, they may receive source or memory text, search queries, selected memory excerpts and temporal metadata, custom instructions, and uploaded images. Provider logging, retention, and training practices vary by the selected provider and model.
- Vercel for hosting the web app and providing cookieless Web Analytics.
We may also disclose information when required by law, to protect rights and safety, or in connection with a merger, financing, acquisition, reorganization, or sale of assets. We will require a successor to handle personal information consistently with this policy where applicable law requires it.
Organization members can send data to configured webhooks and connected agents. Copies delivered to those recipients are governed by their own terms and are outside Steve Memo's control.
Who can see workspace data
Private memories are visible to their owner and agents acting with a key permitted to read that private scope. Organization memories are visible to active organization members and authorized agents. Steve Memo does not make workspace content public.
Retention
- Memories, account mirrors, workspace settings, audit events, and webhook records do not have a fixed automatic expiry today. They remain until removed through an available control or deployment maintenance. A memory can have an expiration time. Expiration soft-deletes it; a later hard purge or cleanup removes the active record.
- Request logs are kept for 30 days by default. Workspace administrators can configure a different period.
- Export and import job files expire after one hour. Hard-purge job files expire after 24 hours.
- Unused media upload grants expire after 15 minutes. Orphaned media is deleted after 72 hours by default; workspace administrators can configure up to 168 hours.
- Vercel discards the visitor request hash after 24 hours. Aggregated analytics remain available for the reporting period included with our Vercel plan and may be retained longer by Vercel for plan upgrades or legal and operational needs.
Closing a Clerk account or leaving an organization stops new use of that identity but does not itself delete workspace memories. Processor backups, security records, and copies retained for legal obligations may remain temporarily after deletion.
Your choices and rights
- Read, edit, export, and soft-delete memories available to you.
- Ask a workspace administrator to run a hard purge when that deployment feature is enabled. Hard purge removes selected memories from active Steve Memo records and files; it cannot recall copies already sent to a webhook, agent, or model provider.
- Leave an organization or close your Clerk account.
- Depending on where you live, request access, correction, deletion, restriction, objection, or portability, and withdraw consent where processing relies on consent.
- Complain to your local data-protection authority. You may contact us first, but you do not have to.
Send a request to privacy@steve-memo.com. We may need to verify your identity and may direct organization-data requests to the relevant workspace administrator.
Children
You must be at least 18 to create an account. Steve Memo is not directed at children, and we do not knowingly create accounts for anyone under 18. Family memories may mention minors. If you store that information, you are responsible for having the right to do so.
Security
We use technical and organizational measures intended to protect information, including access controls, scoped API keys, and secret filtering. No service can guarantee absolute security. Keep account and API-key credentials confidential and revoke keys you no longer trust.
International processing
Our providers may process information in the United States and other countries. Where required, their terms and data-processing addenda may make safeguards available, such as an adequacy decision, standard contractual clauses, or another lawful transfer mechanism. The applicable mechanism depends on the provider, deployment, and processing location. Contact us for more information relevant to your information.
Automated decisions
AI features help search, extract, organize, and suggest memories. They do not make decisions that produce legal or similarly significant effects about people.
Changes
We will post updates here and change the effective date. For a material change, we will provide reasonable advance notice by email or in the product when practicable. Related rules are in the Terms of Service.