← backprivacy

your memory, held like it matters.

Last updated: 2026-07-08

What we store

For every signed-in user we store the projects you create, the dimensions and nodes inside them, and an append-only commit log of changes. We also store OAuth state (clients you've connected, access and refresh tokens) and any long-lived API keys you've issued for CLI use.

Memory is intimate data. We treat dimension content as more sensitive than the average notes-app row and apply the practices in our security policy to protect it.

How we protect it

  • Row-level security on every table — only you can read your projects.
  • Tokens hashed at rest — a database dump does not yield usable access credentials.
  • Optional encryption at rest for dimensions — opt in per project, with a passphrase only you hold. We cannot recover encrypted content if the passphrase is lost. We say so before you enable it.
  • Audit log of privileged events on your account, retained 90 days, visible to you only.
  • Session cookies are HttpOnly and Secure. We set no advertising or cross-site tracking cookies, so there is no cookie banner. Both our analytics tools are usage-only and never read your memory content. Google Analytics runs in cookieless consent-mode (consent denied by default — no cookies, no identifiers, anonymous aggregate pings). PostHog (product analytics, self-proxied through innernet.live) is also cookieless — it keeps its state in local storage, not cookies, and never records your screen. It counts anonymous usage for visitors; after you sign in, events are linked to your account (your user id and email) so we can understand how members use the product. Authentication tokens are stripped from any URL it captures.

What we share

We do not sell or rent your data. We do not feed your dimensions to anyone's training set. Your project content is sent to the AI clients youconnect (Claude Desktop, Cursor, ChatGPT, etc.); those providers' own privacy policies apply once the data enters their systems.

innernet's own memory agent also processes your content server-side — consolidating captures into facts, folding artifacts, running imports. Those model calls go to our inference sub-processors (DeepInfra and Fireworks, both running DeepSeek) under our keys, solely to provide the service. Your memory is never used to train our models or anyone else's.

Sub-processors

  • Supabase (database, auth) — US East
  • Vercel (hosting) — global edge
  • DeepInfra (memory-agent inference, DeepSeek models) — when the agent runs
  • Fireworks (memory-agent inference second pass, DeepSeek models) — when the agent runs
  • Google Analytics (cookieless, consent-mode behaviour analytics) — when invoked
  • PostHog (product analytics) — US cloud, proxied through innernet.live
  • Resend (transactional email) — when we email you
  • Notion (only if you connect it) — your token, your workspace
  • Anthropic (only when you connect Claude) — when invoked

Your rights

You can export everything we hold about you at /account. You can delete your account from the same page. Deletion is immediate and irreversible; backups are purged within 30 days.

Contact

Suspected security issues: email yours@innernet.live (see the security policy). Privacy questions: same address.