Skip to content
InboxAsk a human

Privacy, security, and your data

The short version

Your memories are private to your account or organization. Your content is used to provide the service — the privacy policy is the authoritative statement on how it's handled, and the security and compliance page covers our security posture. You can export your data and you can delete it.

Is my data used to train models?

Your content is used to provide the service you asked for: storing, indexing, and retrieving your memories, and powering features you choose to use. Our security documentation states that paid production usage is not treated as a training corpus for unrelated public models.

When you use AI features, your content may be processed by third-party AI providers in order to deliver that feature. Those providers are named in the privacy policy, which is the authoritative statement here. If you need contractual commitments in writing (a DPA, for example), contact support.

Who can see my memories?

  • In the app, your memories are private to your account. They aren't shared with other users unless you deliberately share them.
  • In the API, data belongs to your organization, and container tags are the isolation boundary between your end users. Each container tag gets its own namespace, so search and retrieval do not cross between tags.
  • Requests are authenticated by API key. If a client or session should only reach one user's data, issue a container-scoped key rather than an organization-wide one — a scoped key cannot read other containers.

If you're building a multi-user product, giving every end user their own container tag is what makes per-user isolation and per-user deletion straightforward later.

Encryption

Traffic to the API and Console is protected with TLS in transit, and stored data is encrypted at rest using industry-standard encryption in the managed cloud. Full details, including current compliance status, are on the security and compliance page. For formal documentation, contact support.

Where is my data stored?

Managed cloud is the default. Data may be processed in jurisdictions other than your own — see the privacy policy. If you have specific data-residency requirements, contact support: self-hosted and dedicated deployment options exist for stricter needs. Please don't assume a particular region without confirming it with us first.

Exporting your data

  • App: you can export what you've saved as plain files you can open anywhere. Look for the export option in Settings.
  • API: use the document list and get endpoints to pull your documents and memories out programmatically. See document operations in the docs.

If you need a full export and can't get what you need from either route, contact support and describe what you're after.

Deleting your data

  • Individual memories or documents in the app: delete them from the item itself. Deleted means deleted — it isn't just hidden from view.
  • Via the API: delete a document by ID or custom ID, bulk delete documents, or forget a specific memory entry. To remove one end user entirely, delete the content under that user's container tag.
  • Your whole account: see the “Managing your account: email, team members, and deletion” article in this help center.

Deletion is not reversible, so export first if you might want the data later.

GDPR and other privacy requests

You can request access to the information held about you, correction of anything inaccurate, deletion of your account and its data, and portability of your data. The privacy policy describes these rights in full. To exercise them — including an erasure request on behalf of one of your own end users — email support@supermemory.com with the account email and what you're asking for. Some data may be retained where the law requires it, and processing a request takes a short amount of time.

"What do you actually know about me?"

You can see this yourself in the app:

  1. Open app.supermemory.ai and browse your memories and spaces — this is everything that has been saved.
  2. Check your profile, which holds the context built up about you from what you've saved.
  3. Delete anything you don't want kept. Removing a memory removes it from what gets recalled going forward.

If you're using the API, the same view is available programmatically through the documents and user profile endpoints.

Questions we haven't answered here

For DPAs, subprocessor lists, security questionnaires, or anything contractual, email support@supermemory.com. Please don't rely on this article for compliance decisions — the privacy policy governs.