Skip to content
Memoturn
trust

Where your content lives, who handles it, what we never do with it.

This page covers the hosted service at memoturn.ai. Memoturn is open source under MIT — if you self-host, you control the substrate and the policy. The legally binding version is the privacy policy.

Stage
Open source · MIT
Runtime
Edge-only · Cloudflare
Response time
3 business-day response

Who handles your data, and why.

Every party that processes a byte of your project content. No silent third parties — if it's not on this list, it doesn't see your data.

Sub-processor breakdown for Memoturn.
ProviderRoleWhat it processes
CloudflareEdge runtimeWorkers, Durable Objects, Vectorize, Workers AI, KV, R2, Hyperdrive, Queues. Hosts every read and write of your project content. Embeddings generated by Workers AI via @cf/baai/bge-large-en-v1.5; R2 stores turn payloads and skill bundles; Queues drive the ingest pipeline.
NeonManaged PostgresStores account, project, turn, memory, fact, candidate, rule, skill, and observability rows. Connection-pooled through Cloudflare Hyperdrive.
Google, GitHubOAuthUsed only if you sign in via OAuth. The provider returns a subject ID we store against your account; we never see the upstream password.

Three things we will not do with your data.

Each one is a property of how the service is built, not a policy we could quietly reverse. The sub-processor list above is the complete set of parties that touch your content.

no training

We don't train on your data

Project content is read by the service to power search and broadcast. It is never used to train models — ours or anyone else's.

no tracking

We don't run third-party tracking

No analytics scripts, no ad pixels, no session-replay tools on the dashboard or the marketing surface. The only events we log are operational (request metadata, 30-day retention).

no resale

We don't sell personal data

Account email, OAuth subject ID, and project content are processed only to deliver the service. They are not shared with advertisers, brokers, or affiliates.

What this does not cover yet.

Memoturn is pre-1.0. Behavior can change between releases, including breaking API changes, and the hosted service carries no formal SLA — uptime is best-effort.

Operational logs (request metadata: IP, user agent, response status, latency) are retained 30 days for rate-limiting, abuse prevention, and the observability dashboard. Project content is retained for the lifetime of the project. Vendor reviews, security questionnaires, and DPAs are handled directly — we respond within 3 business days.

Vulnerability disclosure is documented in SECURITY.md. Coordinated, private disclosure only. Do not open a public issue.

Talk to us.

Vendor reviews, security questionnaires, DPAs, or a private disclosure — we respond within 3 business days.