Your account
Passwords are stored as salted bcrypt hashes, never as text. Two-factor authentication is available on your account. Sessions are HTTPS-only, not readable by scripts, and expire after 30 days.
Trust
Among the most personal things you could hand to software. Here is how they are handled, and where work remains.
Passwords are stored as salted bcrypt hashes, never as text. Two-factor authentication is available on your account. Sessions are HTTPS-only, not readable by scripts, and expire after 30 days.
Traffic between your device and Memora is served over HTTPS, and session cookies are refused over anything else.
What you write is encrypted at rest under a key specific to your account. Encryption of photos and other media is in progress and will be noted here when it ships.
Take a full copy of your archive with you at any time.
Remove a single memory, disconnect a source, or delete your account. Deleting means deleted, not archived.
Anything Memora infers about a person, place, or date can be corrected or removed by you.
We do not sell your memories, show advertising against them, or share them with anyone you have not chosen.
We do not train models on your memories. Memora builds no models of its own and fine-tunes none on your content. To answer a question or describe a photo, the relevant part is sent to the AI providers listed in our subprocessors page and used only to produce that result.
Where we are
Memora is early and deliberately small. We hold no independent security audit yet, and formal internal access and incident-response programs are still being written. We would rather tell you that than imply otherwise, and we will publish both here once they exist.
If you find a security issue, tell us and we will act on it. Reach us at hello@mem0ra.com.