Privacy Policy

Last Updated: Feb 28, 2026

Welcome to MyMemoryBox ("MemoryBox", "we", "us", "our"). This Privacy Policy explains how we access, use, store, and process your personal data, including Google user data, when you use https://mymemorybox.ai and related applications.

1. Information We Collect

When you create an account, we collect:

  • Email address

  • Authentication credentials (encrypted)

When you use the service, you may upload or import:

  • Notes

  • Documents

  • Images

  • Other personal content

We also collect technical information automatically, including:

  • IP address

  • Browser type

  • Device information

  • Usage data and interaction logs

2. Google Account Sign-In

If you sign in using Google OAuth, we may access:

  • Your Google account email address

  • Your name

  • Your Google account unique identifier

  • Profile picture (if available)

This data is used strictly for authentication and account creation. We do not access your Google password.

3. Google Drive Access

If you explicitly connect your Google Drive account, we may access:

  • File metadata (file name, file ID, mime type, modification date)

  • File content for files you choose to import

Our application uses the drive.file scope. This means we can only access files that you specifically select, open with, or explicitly grant access to MyMemoryBox. We do not have access to your entire Google Drive library and cannot browse or read files that you have not chosen to share with us.

We only access files you explicitly authorize.

Google Drive data is used solely to:

  • Extract text

  • Create search indexes

  • Enable semantic and keyword-based search

We do not access unrelated files.

4. Data Transformation and Indexing

Imported files are transformed into text fragments ("chunks") for indexing.

We:

  • Do not retain original file binaries unless explicitly stored by the user

  • Store only textual content necessary for search functionality

  • Generate derived search data, including:

    • Vector embeddings (semantic search)

    • Keyword-based search indexes (e.g., BM25)

These indexes are derived data used exclusively to provide search functionality.

5. Use of AI Services

Certain features, such as semantic search and document understanding, require AI processing.

To provide these features, portions of text fragments may be transmitted to third-party AI providers (such as OpenAI) for:

  • Generating vector embeddings

  • Performing search result reranking

  • Generating summaries (if requested)

Data Minimization

  • Only the minimum necessary text fragments are transmitted

  • Content is processed in small chunks

  • No full account export occurs automatically

No Model Training

User content, including Google user data:

  • Is not used to train generalized AI models

  • Is not sold

  • Is not used for advertising or profiling

Where supported, AI processing requests are sent with logging disabled (store=false).

AI providers may temporarily retain limited metadata for security and abuse prevention in accordance with their own policies.

6. Google API Services Limited Use Compliance

MyMemoryBox's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We strictly use Google user data to provide and improve core application features and do not use this data for any other purposes, such as advertising or unauthorized profiling.

7. Data Storage and Security

User data is stored using Supabase as our backend infrastructure provider.

We implement:

  • Encryption in transit (HTTPS)

  • Access controls

  • Infrastructure-level security safeguards

Files are not currently protected with end-to-end encryption. While access is restricted by design, uploaded content is not encrypted in a way that only the user can decrypt.

8. Data Retention and Deletion

We retain data only as long as necessary to provide the service.

If you delete:

  • A file → associated text fragments, embeddings, and keyword indexes are deleted.

  • Your account → all associated data is permanently removed from active systems.

If you disconnect Google Drive:

  • We immediately stop accessing new Google data.

  • All content previously imported from Google Drive is automatically deleted.

  • All associated embeddings and keyword indexes are deleted.

9. Third-Party Providers

We may use trusted third-party providers strictly for delivering core service functionality, including infrastructure and AI processing.

We do not authorize third parties to use user data for independent purposes.

10. Your Rights

Depending on applicable laws (including GDPR and LGPD), you may have the right to:

  • Access your data

  • Correct your data

  • Delete your data

  • Withdraw consent

  • Request a copy of your data

You may contact us at: privacy@mymemorybox.ai

11. Children's Privacy

MemoryBox is not intended for children under 13 years old, or under 16 where local law requires a higher minimum age.

12. International Data Transfers

Because we rely on cloud services, your data may be processed in countries other than your own. We take reasonable steps to ensure your data is handled securely and in accordance with this policy.

13. Changes to This Policy

We may update this Privacy Policy periodically. The latest version will always be available at: https://mymemorybox.ai/legal/privacy-policy

Continued use of the service after updates constitutes acceptance of the revised policy.

14. Contact Information

For questions or privacy-related requests: privacy@mymemorybox.ai

15. About the Owner

MyMemoryBox is developed and operated by:

Pavel Dmitriev
Based in Brazil