Skip to content
memford
ImpressumPrivacyTerms

Privacy policy

How Memford processes personal data when you visit the website, sign in, store project knowledge and connect agents.

Updated 6 October 2026

Who is responsible

Datargo GmbH

Omniturm, Neue Mainzer Straße 52–58, 60311 Frankfurt am Main, Germany

Privacy requests: hello@datargo.com

Website access and security

Requests pass through Cloudflare, which provides hosting, network delivery and security. Connection information includes your IP address and request metadata. Memford uses rate limits to protect sign-in and the service. Fonts and website assets are served with the website. The current application does not include advertising trackers or an analytics script.

Account and sign-in

You can sign in with GitHub or, when offered, an email verification code. For GitHub, Memford stores your GitHub account ID, display name and email address when available; you do not give Memford your GitHub password. For email sign-in, Memford verifies control of the address before creating or opening the email account. Memford stores the verified address, an account identifier and a session. Email and GitHub accounts are not automatically merged because they share an email address. GitHub sign-in remains subject to GitHub’s privacy policy.

Email verification and registration notices

The Regfish mail service receives the destination address and verification message to deliver your sign-in code. Codes expire after ten minutes and can be used once; the application stores a keyed hash instead of the plain code. Verification records include the email address, browser and IP-derived hashes, attempt counts and timestamps for abuse prevention. Records older than 24 hours are removed by scheduled cleanup and subsequent email sign-in requests. After a new account is confirmed, a separate operational registration notice is sent to the service operator with the account email or available GitHub display name, sign-in method and registration time. That notice contains no sign-in code, credential or project content. Notification jobs are retried after delivery failures. Sent jobs are removed 30 days after sending; exhausted jobs are removed 30 days after creation once no delivery attempt is active. Pending jobs remain until delivery or retry exhaustion. Copies delivered to the operator’s mailbox are subject to the storage and deletion principles below.

Necessary cookies

The memory_session cookie maintains your signed-in session for up to seven days. The memory_oauth cookie binds GitHub sign-in to your browser for up to ten minutes. The memory_email_auth cookie binds an email-code attempt to the browser that requested it for up to ten minutes. Signing out removes the current session cookie. These cookies support authentication, not advertising.

Project knowledge and agent connections

Memford stores project names, descriptions and groups; submitted notes and their original content; revisions, status and timestamps; shared standards and assignments; and connection and author metadata. Agent connections and project keys allow authorized clients to access the selected project. Keep passwords and private credentials out of notes. Only submit information you are entitled to share. Your connected agent and its model provider may separately process the context they receive.

Optional AI review

When you request AI review, or enable automatic consolidation, eligible project notes are submitted to Cloudflare Workers AI. The resulting draft, source references, model and usage metadata, and review decisions are stored with the project. AI review can suggest summaries and identify possible conflicts; it does not establish that the content is correct. Publishing a new main version requires approval. Disabling automatic consolidation stops future automatic runs. EU database storage does not establish that every inference request is processed in the EU.

Purposes and legal bases

We process account details and project information to provide the service you request (Article 6(1)(b) GDPR). Technical delivery, access controls and abuse prevention serve our legitimate interests in operating a secure service (Article 6(1)(f) GDPR). Where a legal obligation requires retention or disclosure, Article 6(1)(c) GDPR applies. Optional AI processing is initiated through the feature you request or enable; do not include personal information about others unless you have a lawful basis for that processing.

Recipients and international processing

Cloudflare supplies the application infrastructure, database and optional AI inference. The Regfish mail service handles sign-in emails and operational registration notices. GitHub supplies the GitHub identity provider. Clients you authorize receive project context. The project database is configured with EU jurisdiction. Cloudflare and GitHub operate internationally, including in the United States. Their published privacy and data processing terms describe applicable transfer safeguards, including standard contractual clauses where required. These terms do not mean that all processing is restricted to the EU. You can request information about the safeguards applicable to your data from the contact above.

Storage and deletion

Removing a note from active context is not the same as erasing its original or revision history. The service preserves originals and revisions so changes can be inspected and restored. Account and project records remain stored while needed to provide your workspace and its history. There is no automatic age-based deletion of project notes. A project deletion removes its project records from the active database; an erasure or account closure request can be sent to the contact above. Necessary legal retention and the establishment, exercise or defence of legal claims may justify limited continued retention. Security information is retained according to its protective purpose and the applicable provider arrangements. Deletion from the active service does not promise immediate deletion of every provider backup. Session and sign-in validity periods are listed above; expired entries are cleaned up during subsequent authentication activity.

Your rights

Where the legal requirements apply, you may request access, rectification, erasure, restriction and data portability. You may object to processing based on legitimate interests and withdraw consent for future processing where consent is the legal basis. You may lodge a complaint with a data protection supervisory authority, including in the EU country where you live or work. Contact the address above to exercise your rights; identity verification may be needed to protect your account.

Required information and automated decisions

Account identity is needed to associate your projects and protect access. Without sign-in, authenticated storage and agent authorization are unavailable. AI summaries are suggestions reviewed by the user; Memford does not use this feature to make decisions with legal or similarly significant effects about individuals.

Provider information

Cloudflare data processing terms

GitHub privacy statement

ImpressumPrivacyTermsBack to Memford