What we collect
Memory Vault receives material when a person intentionally types or adds it, shares a capture, chooses a supported source action, or asks a connected assistant to submit context. Depending on the feature, this can include notes, pasted text or conversations, selected documents, images, audio, a person-chosen public page, selected Google Drive files, an open Gmail thread, selected GitHub repositories, and context that an authorised assistant supplies at the person's request. A connected assistant cannot ask Memory Vault to fetch its conversation without supplying the content.
We also process the account, workspace, project-membership, permission and connection information needed to authenticate people, apply access controls and associate material with the right project. We retain provenance and operational information such as source details, proposal status, query evidence, credential-revocation events and MCP/audit metadata. Encrypted connection credentials may be stored for connected sources; Memory Vault does not ask for a person's AI-account password.
Why we use it
We use this information to store a person's submission and its provenance, return approved project context to an authorised assistant, create pending material for human review, import a selected source, operate the account, apply permissions, protect the service and maintain an audit trail.
When a selected feature needs model processing, selected content may be sent to OpenAI for vision, transcription, embeddings or reasoning. Some reasoning requests usestore:false, but that request flag does not establish zero provider retention. Deterministic text, paste and supported imports can be processed without a model when the feature path permits it.
Pending material is not approved Truth
Pending or rejected material is not returned as approved project knowledge. A person decides what becomes approved Truth. ChatGPT submissions and other assistant submissions create pending material; they do not approve, edit or delete approved Truth.
Who receives it
- Vercel for the hosted application and its runtime infrastructure.
- Supabase for the database, authentication, row-level access control and Storage boundary.
- OpenAI for the selected model operations described above.
- Google when a person authorises and selects a permitted Drive or Gmail source.
- GitHub when a person connects the GitHub App and selects repositories.
The information may be returned to the requesting person, an authorised connected assistant, or members of an authorised workspace. It is not made public by the MCP connection. Providers may also process security, runtime, backup or abuse-monitoring data under their own current terms.
How long we keep it
The current Memory Vault implementation has no scheduled purge for durable captures, pending proposals, approved knowledge, imported artefacts, knowledge-query evidence, MCP audit records or OAuth events. Those records remain available under the implemented account, project, review and connection controls unless a supported deletion action removes them. A few short-lived connection/link state rows are cleaned up opportunistically after expiry when a new flow starts.
Deleting an account removes the account and the personal records covered by the deletion function. Shared contributions may remain for the shared workspace's history with the contributor's attribution cleared, and a dated deletion record without the email itself is retained. Project deletion removes the project-owned records covered by its deletion function. Disconnecting or removing a source stops future reads but does not automatically erase material already imported into Memory Vault. There is currently no general per-capture delete control.
Connected assistants and sources
An authorised connected assistant can retrieve approved project context within the projects and permissions granted to it. Account authentication, workspace or project membership, connection permissions and row-level access controls apply to connected access. Read access returns approved material; submission access is limited to user-requested pending material.
Memory Vault does not sign in to a person's AI accounts or ask for those account passwords. Source-specific actions are started by the person and are subject to the connection's own access controls. The ChatGPT plugin cannot directly modify or delete approved Truth.
Your controls and questions
You control what you submit and which sources you connect. You can review, edit or reject pending material; delete your account or an owned project; revoke Memory Vault credentials; disconnect a connected account; and remove or deselect a selected source. Removing a source stops future reads but may not erase material already imported into Memory Vault.
Provider logs, backups, security records and copies outside Memory Vault may follow the provider's documented retention and deletion terms. This policy does not promise a provider-specific retention period, deletion of provider backups or a legal role that is not established here.
For a privacy question or a request that is not covered by these controls, contact support@irisfutures.com.