Who we are and scope
This Privacy Policy is provided by SAMPLE TEXT™ (“we”, “us”, “our”), which operates Memory Clone. For the purposes of the UK General Data Protection Regulation, the EU General Data Protection Regulation and similar laws, we are the controller of the personal information described in this policy that we process on our servers.
This policy covers the Memory Clone Windows application (the “app”), the website at memoryclone.com (the “website”), your Memory Clone account, purchases, support and our communications with you. It should be read together with our Cookie & Storage Notice and AI Transparency Notice.
Questions or requests: contact@memoryclone.com or our data request form. Our full business details are in the Legal Notice.
How Memory Clone is built: local-first
Memory Clone is designed so that the most personal material never reaches us:
- On your computer only: imported chat exports (for example WhatsApp, Messenger, Instagram or Discord), notes, the parsed messages, the searchable memory index, the clone’s style analysis, the Persona Blueprint after delivery, your chat threads with clones and your app settings. These live in your Windows user profile. You control them and can delete them in the app.
- On our servers: your account, consent records, licence and billing state, a short registration record for each clone (described below), credit usage records, security records and your messages to support.
- Sent for AI processing only with your consent: when cloud processing is switched on for a clone, the app sends a bounded selection of excerpts and local style analysis needed for the specific task. Whole archives and local databases are never uploaded.
Information we collect
| Category | What it includes | Source |
|---|---|---|
| Account | Email address, password (stored only as a secure one-way hash), Google account identifier if you use Google sign-in, account status, role and creation date. | You; Google if you choose Google sign-in |
| Consent and age records | Confirmation that you are 18 or older, the versions of our policies you accepted and when, and your digital-delivery consent at checkout. | You |
| Clone registration | For each clone: an app-generated identifier, the clone name you choose, whether it represents you, a living person or someone who has died, your stated relationship, the time and policy version of your permission confirmation, whether cloud processing is enabled, and its status (active, archived, deleted). No chat content. | The app |
| Billing | Stripe customer identifier, orders, subscriptions, amounts, currency, tax and service fee, promotion applied, invoice references and status. Card details are collected and stored by Stripe, never by us. | You; Stripe |
| Credits and usage | Your credit balances and a ledger of grants and charges, including the AI model used, token counts, cost, time and the clone concerned. No message text. | The app and our server |
| AI processing content (transient) | Only with cloud processing on: the excerpts, style notes and the current conversation turn needed to generate a Persona Blueprint or a reply. See section 5. | The app |
| Security and technical | Session and refresh-token records, IP address, browser or app version, request times, rate-limit counters (stored as keyed hashes), audit events such as sign-ins, purchases and policy acceptance, email delivery status, and web server logs kept by our hosting provider. | Your device; our systems |
| Support and requests | Messages you send us, the contact details you provide and records of privacy requests. | You |
| Newsletter | Your email address, sign-up source (website form, account or profile), time, the exact notice or consent wording and its version, confirmation and unsubscribe status, and connection address at sign-up. | You |
We do not use advertising identifiers, cross-site tracking, analytics cookies, fingerprinting or social media pixels.
How and why we use information
We use personal information only for the purposes below, and we rely on the legal bases shown (UK and EU GDPR). Where other laws apply, we use the information only for the same purposes.
| Purpose | Information | Legal basis |
|---|---|---|
| Create and run your account, sign you in, keep it secure | Account, security | Contract; legitimate interests in security |
| Provide the app and website, register clones, apply slots and credits | Account, clone registration, credits | Contract |
| Generate a Persona Blueprint and clone replies with cloud AI | AI processing content, credits | Your consent (cloud processing switch) and contract |
| Take payments, issue receipts, calculate tax, handle renewals, refunds and disputes | Billing, account | Contract; legal obligation (tax and accounting) |
| Prevent fraud, abuse, credential attacks and misuse of credits | Security, billing, usage | Legitimate interests in protecting users and the service; legal obligation where applicable |
| Respond to support, complaints and privacy requests | Support and requests | Contract; legal obligation |
| Send service messages (verification, security, receipts, cancellation and plan-end reminders, important changes) | Account, billing, email delivery status | Contract; legitimate interests |
| Send product news and offers to account holders | Account, newsletter | Legitimate interests in telling customers about our own similar products (soft opt-in); you can opt out at any time |
| Send release and discount news to people who sign up on the website | Newsletter | Consent, confirmed by email, which you can withdraw at any time |
| Keep records and defend legal claims | Billing, audit, consent records | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we have balanced them against your rights and you can object (section 11). Where we rely on consent, you can withdraw it at any time without affecting processing that already took place.
Cloud AI processing in detail
Cloud processing is off until you switch it on for a clone, after a clear explanation in the app. You can switch it off at any time; the clone then stops sending new excerpts.
What is sent
- Persona Blueprint: a bounded evidence package of selected excerpts and local style statistics, so the AI can describe how the person writes.
- Each clone reply: the current message, recent turns of that conversation and a small number of relevant memory snippets selected locally from the matching relationship.
How it is protected
- Requests travel encrypted from the app to our server and from our server to our AI provider, OpenAI. Our server adds billing checks and does not store the message content of chats.
- Chat requests are sent with provider-side storage disabled. Persona Blueprint jobs run in the provider’s background mode, which requires temporary storage; we delete that stored response as soon as the result has been collected.
- A copy of a delivered Persona Blueprint is kept with its usage record for up to 7 days so that a retry can be answered without charging you again. The Blueprint then exists only on your computer.
- OpenAI states that it does not use API data to train its models unless the customer opts in; we have not opted in. OpenAI may keep abuse-monitoring logs for up to 30 days under its own policy, and may keep data longer only where required by law.
- We never use your content to train models, never sell it and never review it manually, except where you send it to us yourself (for example in a support request) or where the law requires.
Information about other people in your chats
Conversations naturally contain information about the people you talked with. When you import them, you decide what is processed. Local processing on your own computer is under your control. If you enable cloud processing, we process the selected excerpts only to provide the feature you asked for, under strict minimisation, short retention, no training and no human review. We rely on our legitimate interest, and yours, in preserving memories and providing the service you requested, and you confirm in the app that you have the necessary permission or other lawful right (see the Acceptable Use Policy).
Relationship boundaries are built in: a clone talking with one person is designed not to reveal what it learned from conversations with other people.
If you believe your information is being used in someone’s Memory Clone without a lawful basis, contact us at contact@memoryclone.com. Because chats stay on that person’s device we cannot access or delete them, but we can act on any data we hold and on accounts that break our rules.
Who we share information with
We share personal information only with service providers that help us run Memory Clone, under contracts that limit their use of it, or where the law requires. We do not sell personal information and do not share it for cross-context behavioural advertising.
| Provider | Role | Location | Information |
|---|---|---|---|
| LH.pl Sp. z o.o. | Website and database hosting, email delivery | Poland (EU) | All server-side information listed in section 3 |
| Stripe (Stripe Payments UK Ltd and its affiliates, including Stripe, Inc.) | Payments, tax calculation, receipts, fraud prevention | United Kingdom, EU, United States | Billing, email, payment details you enter at checkout and, if you dispute a payment, the order, delivery and consent records needed to respond |
| OpenAI, L.L.C. | AI processing for Persona Blueprints and replies | United States | AI processing content, only with cloud processing on |
| Google LLC | Optional Google sign-in; web fonts on the website | United States | Sign-in: Google identifier and email. Fonts: IP address and browser details |
We may also disclose information to professional advisers, to a buyer or successor if the business is reorganised or sold (with this policy continuing to apply), or to authorities when we are legally required to, or to protect the rights, safety or property of users, the public or us.
International transfers
We are based in the United Kingdom and our servers are in the European Union. Some providers process information in the United States. Where information leaves the UK or EEA, we rely on adequacy regulations or decisions (including the UK–EU adequacy arrangements and, where a provider is certified, the EU–US Data Privacy Framework and its UK Extension) or on the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, together with additional safeguards where needed. You can ask us for more information about these safeguards.
How long we keep information
| Information | Retention |
|---|---|
| Account and clone registrations | While your account is open. After a verified deletion request, deleted or anonymised within 30 days, except the records below that we must keep. |
| Invoices, payments, tax and refund records | At least 6 years after the end of the financial year they relate to, as required for UK tax and accounting, or longer where another law requires. |
| Detailed checkout and webhook payloads | Reduced to the essential record after 90 days. |
| Persona Blueprint copy on our server | Up to 7 days after delivery. |
| Signed-in sessions and refresh tokens | Until they expire or you sign out, then removed within 30 days. |
| Password reset and email verification links | Expire after 30 minutes and 24 hours respectively. |
| Rate-limit counters (keyed hashes) | Up to 2 days. |
| Google sign-in requests | Up to 1 day. |
| Security and audit logs | As long as needed for security, fraud prevention and legal claims, normally no longer than 6 years. |
| Support messages and privacy requests | Up to 3 years after the matter is closed, or longer if needed for a legal claim. |
| Newsletter subscription | Unconfirmed website sign-ups expire if not confirmed. Subscription details are kept while you subscribe. After unsubscribe, the address and suppression evidence are retained only as needed to honour the opt-out and demonstrate compliance. |
| Information on your computer | Until you delete it. Uninstalling the app does not automatically delete your workspace; delete clones in the app first if you want them removed. |
Security
We use measures appropriate to the risk, including encrypted connections (HTTPS with HSTS), one-way password hashing, server-side control of licences and credits, idempotent billing, rate limits on sign-in and sensitive endpoints, per-session authorisation of the app’s local interface, Windows data protection for stored sign-in sessions on your computer and checksum-verified app updates.
No system is perfectly secure. If a personal data breach is likely to put your rights at risk, we will notify you and the relevant authority as the law requires. Please report suspected vulnerabilities to contact@memoryclone.com.
Your rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you and receive a copy;
- Correct inaccurate or incomplete information;
- Delete your information, subject to the records we must keep;
- Restrict or object to certain processing, including processing based on legitimate interests and any direct marketing;
- Data portability: receive information you gave us in a structured, machine-readable format;
- Withdraw consent at any time, for example by switching cloud processing off or unsubscribing;
- not be subject to decisions based solely on automated processing that have legal or similarly significant effects. We do not make such decisions.
To exercise a right, use the data request form or email contact@memoryclone.com. We may need to verify your identity, normally by confirming access to your account email. We respond within one month (extendable by two months for complex requests, in which case we will tell you), or within the time your local law sets. Exercising your rights is free unless a request is manifestly unfounded or excessive.
The information on your computer is under your direct control: you can view, export from the original sources, and delete clones and their local data in the app at any time.
If you are unhappy with how we handle your information, please contact us first so we can try to resolve it. You also have the right to complain to a data protection authority: in the UK the Information Commissioner’s Office (ico.org.uk); in the EEA the authority in your country of residence or work; in Switzerland the FDPIC.
Region-specific information
United States (including California)
In the last 12 months we have collected the categories of personal information described in section 3: identifiers (such as email and account IDs), commercial information (purchases), internet and electronic activity (security logs), and the content you choose to send for AI processing. We collect them for the purposes in section 4 and disclose them only to the service providers in section 7. We do not sell or share personal information (as those terms are defined in the California Consumer Privacy Act), do not use sensitive personal information to infer characteristics about you, and honour Global Privacy Control signals, although we use no tracking that such a signal would affect. Residents of California and other states with comprehensive privacy laws can exercise the rights to know, access, correct, delete and appeal a decision by contacting us; you may use an authorised agent, and we will not discriminate against you for exercising your rights. If we decline a request you can appeal by replying to our decision; if the appeal is denied you may contact your state attorney general.
Canada
We process personal information in accordance with PIPEDA and applicable provincial laws. You may access and correct your information and withdraw consent, subject to legal or contractual restrictions, and you may complain to the Office of the Privacy Commissioner of Canada.
Brazil
Under the LGPD you have rights of confirmation, access, correction, anonymisation, blocking or deletion, portability, information about sharing, and revocation of consent. You may also petition the ANPD.
Australia, New Zealand and elsewhere
We handle personal information consistently with the Australian Privacy Principles and the New Zealand Privacy Act 2020, and you may complain to the OAIC or the Office of the Privacy Commissioner (NZ). Wherever you live, we apply this policy’s protections, and you can contact us to exercise the rights your local law provides.
Age requirement
Memory Clone is for adults aged 18 or older. We do not knowingly collect personal information from anyone under 18 as a user. If you believe a minor has created an account, contact us and we will delete it. Imported chats may mention children; please take particular care with such material and follow the Acceptable Use Policy.
Marketing communications
Account holders. When you create a Memory Clone account, we email you product news and offers about Memory Clone. The sign-up form tells you this before you create the account. We rely on our legitimate interest in telling customers about our own similar products and services (the “soft opt-in” for electronic marketing). You can turn this off at any time, free of charge: in your profile under Security → Email preferences, with the one-click unsubscribe link in every marketing email, or by emailing contact@memoryclone.com. If you have opted out before, creating an account does not subscribe you again.
Website sign-ups. If you join the newsletter or waiting list on the website without an account, we use double opt-in: we send product news, release updates and discounts only after you confirm by email, and you can withdraw your consent at any time.
We keep the exact notice or consent wording you saw and its version, the source (website form, account or profile), the time and the confirmation or opt-out state, so that we can demonstrate the basis for each message. Every marketing email identifies Memory Clone and includes an immediate unsubscribe link. We never sell or share your email address for others’ marketing.
Service messages, such as email verification, password reset, purchase confirmation, cancellation confirmation, a reminder for a cancelled plan with a recorded end date, security alerts and notices of important service changes, are not marketing. They are limited to operating the account or contract and do not require a marketing subscription.
Changes to this policy
We will update this policy when our practices change. The effective date and version appear at the top. If a change is material, we will tell you in advance by email or in the app and, where required, ask for your consent. Previous versions are available on request.
Contact us
| Trading name | SAMPLE TEXT™ |
|---|---|
| Brand | Memory Clone |
| contact@memoryclone.com | |
| Privacy and data requests | contact@memoryclone.com or the data request form |
| Website | memoryclone.com |
These documents are provided in English. If we provide a translation, the English version applies to the extent permitted by law. Nothing in our documents limits rights you have under mandatory consumer or data protection law where you live.