Last updated 31 August 2026
Privacy
memorytether turns what you connect, import and approve from AI conversations into a portable memory. That only deserves your trust if the data flow is clear and reversible. This page describes the service as it runs today.
Who we are
Quick Lateral Ltd, a technology company based in the United Kingdom, registered in England and Wales, company number 15784293. We are the data controller for the personal data described below.
What we hold
- Your account. Your email address, and a hash of your password — never the password itself.
- What your connected sources return. When you connect a source, we read the content you have given it permission to read, and keep a copy so the memory can be built and kept current. We never write back to it.
- Your memories, suggestions and snapshots. This includes facts extracted from your sources, memories you add or import, suggestions made by a connected AI, their evidence, and encrypted daily snapshots. A suggestion awaiting review is not readable by an AI.
- Operational records. Logs of requests, syncs and errors, so the service can be run and abuse can be spotted. These are kept short and are not used to profile you.
- Support conversations. If you choose to open Help, we keep what you ask, the answer, your feedback and whether the question exposed a gap in our guidance. This lets an authorised operator answer missing questions and improve the approved help material.
- Privacy-minimised homepage measurement. Whether one homepage is selected or several designs are compared, a random first-party identifier keeps your page consistent for up to 90 days. We count a visit once, then whether it led to an account and a verified email. We do not store your IP address, browser details or browsing history for this, and we do not use the result to make a decision about you.
Who can see your memories
Your memories are not shared with every service named in this policy. Only the AI tools you connect can read them as memory, within the access rules you choose. memorytether’s hosting and optional embeddings infrastructure process content only to run the service.
- Can read memories
- Only AI tools you connect, when their access rules allow it
- Processes content to run memorytether
- Authorised operators, hosting, and an optional embeddings provider
- Is not automatically sent memory content
- X (no pixel is loaded), PostHog, Stripe, Resend, Google Fonts, and the support assistant
Services that can process memory content
- An AI you connect — and the provider running it. It receives only the memories its access rules allow, and only when it asks memorytether for them. A new AI can read by default unless you start it restricted; specific deny rules always win. Revoking the AI stops access. If you approve memory-write access, it can also suggest memories from your conversation.
- Our authorised operators and hosting provider. They run the servers and databases where memorytether stores and processes your data. Production access is limited to the people who operate the service.
- The configured embeddings provider, only when semantic recall is enabled. It receives source or memory text and search queries to create numeric embeddings. With no provider configured, recall stays lexical and no text is sent for embedding.
Services that do not receive your memories
These providers receive only the limited account, payment or operational data needed for their job — not connected-source content, memory text or AI search queries.
- Resend receives your email address and the verification, password-reset, or optional setup-guidance email it delivers. Setup emails include an unsubscribe link. We keep the recipient, exact setup message submitted, and its delivery status until the account is deleted so retries cannot change or duplicate it and we can honour that choice; replay receipts kept for webhook integrity contain no email address or message content and are removed after 90 days.
- Stripe receives checkout and payment information when you buy a plan. Card details are entered on Stripe’s hosted page and are not sent to memorytether.
- PostHog receives sanitised reports for unhandled server errors: a route pattern, status and generic error type, with the original error message, stack and request data removed. Its browser analytics library is not loaded.
- No X Pixel is loaded. memorytether does not send X visitor page views, browser identifiers or memory content from public, authentication or signed-in pages.
- Google Fonts, when enabled by the operator, receives the browser request needed to deliver the site’s typefaces.
- The support assistant, only after you open Help, receives what you type and uses OpenRouter and the configured language-model provider to draft its answer. On a signed-in page it also receives the current app section, release, closed setup stage, selected AI, whether setup and a successful recall are complete, and the number of active source connections. memorytether does not automatically provide your email, account identifier, provider or source names, memory text, connected-source content or credentials; anything you choose to type into Help is part of that support conversation. The Help frame is not loaded before you open it, and model requests require providers that deny data collection and support zero-data-retention processing.
We do not sell your connected-source content or memories, and we do not send either to analytics or advertising providers.
Homepage experiment results stay inside memorytether and are shown to authorised operators only as totals. They are not sent to PostHog, an advertiser or any other analytics provider.
How it is protected
Your data is private. We do not sell it, and we do not use your memories or connected-source content to train models or to build advertising profiles about you.
It is always encrypted in transit. Your credentials for connected sources, our backups and your daily snapshots are encrypted at rest, and your password is stored only as a one-way hash — never in plaintext. The database isolates every account from every other one at the row level, so a query cannot reach across accounts even if the code asking has a bug. Access to production is limited to the people who operate the service.
No service can promise it will never be breached. If yours is affected, we will tell you, and we will tell the ICO where the law requires it.
Keeping it, and getting rid of it
We hold your data for as long as your account exists. Disconnect a source and its content is removed. Delete an item and it is deleted — not hidden, not archived somewhere you cannot reach. Delete your account and we erase it and revoke the access tokens your sources gave us.
Backups are encrypted and are destroyed on a rolling schedule, so a deletion takes a short while to work through the copies we keep against disaster.
A homepage assignment stops being valid after no more than 90 days and is removed by routine cleanup. Its temporary link to an account is removed when the email is verified, after the assignment expires, when you opt out, or when the account is deleted — whichever happens first. The remaining visit and signup totals cannot be traced back to a visitor or account.
Your rights
Under UK GDPR you can ask us for a copy of your data, correct it, delete it, take it elsewhere, or object to how we use it. Most of that you can do yourself from inside the app, immediately, without asking anyone. For the rest, contact the operator and we will answer within a month.
Our legal bases are: performing our contract with you (running the service), your consent (each source you connect, which you can withdraw by disconnecting it), and our legitimate interests in keeping the service secure and improving the public site using aggregate, privacy-minimised statistics. You can object to the homepage experiment at any time.
If you think we have got this wrong you can complain to the Information Commissioner's Office at ico.org.uk. We would rather you told us first.
Cookies
memorytether sets essential cookies for sign-in, form security and choices you ask it to remember. memorytether does not load browser analytics or advertising trackers.
When homepage measurement is active, memorytether also sets one private, first-party identifier for up to 90 days. Its only purpose is to keep the page consistent and produce aggregate visit, account-created and email-verified totals so we can improve the site. It is not shared with external analytics services. A temporary account link attributes signup and verification; it is removed after verification, opt-out, account deletion or assignment expiry. Clearing this site's cookies removes the identifier from your browser, but a later visit may receive a new one. You can contact us to object to this measurement. A server-side opt-out deletes the assignment and leaves only a one-way revocation marker that stops delayed requests from restarting it until the original 90-day window ends; the marker contains neither the browser identifier nor an account link, it is no longer consulted after that point, and routine cleanup promptly removes it.
Changes
If this policy changes in a way that affects you, we will tell you before it takes effect rather than quietly moving the date at the top.