Sources Privacy Pricing Try Memora

Trust

Protecting a personal archive.

Among the most personal things you could hand to software. Here is how they are handled, and where work remains.

What is true today

Your account

Passwords are stored as salted bcrypt hashes, never as text. Two-factor authentication is available on your account. Sessions are HTTPS-only, not readable by scripts, and expire after 30 days.

In transit

Traffic between your device and Memora is served over HTTPS, and session cookies are refused over anything else.

At rest

What you write is encrypted at rest under a key specific to your account. Encryption of photos and other media is in progress and will be noted here when it ships.

What you control

Export

Take a full copy of your archive with you at any time.

Delete

Remove a single memory, disconnect a source, or delete your account. Deleting means deleted, not archived.

Correct

Anything Memora infers about a person, place, or date can be corrected or removed by you.

What we do not do

We do not sell your memories, show advertising against them, or share them with anyone you have not chosen.

We do not train models on your memories. Memora builds no models of its own and fine-tunes none on your content. To answer a question or describe a photo, the relevant part is sent to the AI providers listed in our subprocessors page and used only to produce that result.

Where we are

Memora is early and deliberately small. We hold no independent security audit yet, and formal internal access and incident-response programs are still being written. We would rather tell you that than imply otherwise, and we will publish both here once they exist.

Reporting a problem

If you find a security issue, tell us and we will act on it. Reach us at hello@mem0ra.com.

Read how permissions work.

Permissions