← backprivacy

your memory, held like it matters.

Last updated: 2026-09-07

What we store

For every signed-in user we store the projects you create, the dimensions and nodes inside them, and an append-only commit log of changes. We also store OAuth state (clients you've connected, access and refresh tokens) and any long-lived API keys you've issued for CLI use.

Memory is intimate data. We treat dimension content as more sensitive than the average notes-app row and apply the practices in our security policy to protect it.

How we protect it

  • Row-level security on every table — only you can read your projects.
  • Tokens hashed at rest — a database dump does not yield usable access credentials.
  • Optional encryption at rest for dimensions — opt in per project, with a passphrase only you hold. We cannot recover encrypted content if the passphrase is lost. We say so before you enable it.
  • Audit log of privileged events on your account, retained 90 days, visible to you only.
  • Session cookies are HttpOnly and Secure. We set no advertising or cross-site tracking cookies, so there is no cookie banner. Both our analytics tools are usage-only and never read your memory content. Google Analytics runs in cookieless consent-mode (consent denied by default — no cookies, no identifiers, anonymous aggregate pings). PostHog (product analytics, self-proxied through innernet.live) is also cookieless — it keeps its state in local storage, not cookies, and that stays true of the screened recordings described below. It counts anonymous usage for visitors; after you sign in, events are linked to your account (your user id and email) so we can understand how members use the product. Authentication tokens are stripped from any URL it captures.

Screened recordings

To find where people get stuck, we record replays of sessions on our own app surfaces — innernet.live and nowhere else. A replay reconstructs the page you moved through: clicks, scrolls, and navigation, so we can watch a flow break instead of guessing at it. We do not follow you anywhere off our own site.

Recordings are masked by default, and the masking covers everything readable: all text on the page and every form input is replaced before the recording leaves your browser. So your memory is never captured — not dimensions, not nodes, not captures or artifacts, not anything you or the agent wrote — and neither is anything you type. What comes back is the shape of the page and where you moved in it, never what it said.

The surfaces that hold your memory go further than masking: your files and folders, an artifact’s text, your conversation with netti, and your search results are blocked rather than masked — each is replaced by a blank shape before the recording is made, so neither what it said nor the labels underneath it are ever recorded. We also never record what the page prints to the browser console, and never the contents of a network request. A recording can show that you opened a folder; it cannot show which one.

Replay is sampled, not universal: only a fraction of sessions is recorded, so most visits are never captured at all. A recording carries the same identity as your other usage events — anonymous before you sign in, linked to your account after. And it runs through the same cookieless PostHog setup as everything else: replay state lives in local storage, not cookies. Nothing above changes — still no advertising or cross-site tracking cookies, still no banner.

What we share

We do not sell or rent your data. We do not feed your dimensions to anyone's training set. Your project content is sent to the AI clients youconnect (Claude Desktop, Cursor, ChatGPT, etc.); those providers' own privacy policies apply once the data enters their systems.

innernet's own memory agent also processes your content server-side — consolidating captures into facts, folding artifacts, running imports. Those model calls go to our inference sub-processors (DeepInfra and Fireworks, both running DeepSeek) under our keys, solely to provide the service. Your memory is never sold, and it is never fed to a third party's training set. Where training helps us improve innernet itself, it only ever uses anonymised, aggregated data — never content that can be tied to you.

Sub-processors

  • Supabase (database, auth) — US East
  • Vercel (hosting) — global edge
  • DeepInfra (memory-agent inference, DeepSeek models) — when the agent runs
  • Fireworks (memory-agent inference second pass, DeepSeek models) — when the agent runs
  • Google Analytics (cookieless, consent-mode behaviour analytics) — when invoked
  • PostHog (product analytics, and the masked screened recordings above) — US cloud, proxied through innernet.live
  • Resend (transactional email) — when we email you
  • Notion (only if you connect it) — your token, your workspace
  • Anthropic (only when you connect Claude) — when invoked

Payment

innernet is free today, and we hold no card or payment details for anyone. Paid plans are coming: a free innernet stays free, and the paid step lifts the ceiling on how much netti thinks for you each month. When they open, payment will be handled by a PCI-compliant payment processor — card details go to them and never to us. We will keep only the subscription record (which plan, its status, its renewal date) and whatever billing address the law requires of us. That processor will be named in the sub-processor list above before the first charge is ever made, and this page will be updated in the same commit.

Nothing is sold inside a connected AI tool. Any plan change happens on innernet.live, signed in as you.

Your rights

You can export everything we hold about you at /account. You can delete your account from the same page. Deletion is immediate and irreversible; backups are purged within 30 days.

Contact

Suspected security issues: email yours@innernet.live (see the security policy). Privacy questions: same address.