Privacy Policy

Embedchain, Inc. ("Embedchain," "we", "us" or "our") provides a universal, self-improving memory layer for LLM applications ("Mem0.ai"). This Privacy Policy describes how Embedchain processes personal information in connection with Mem0.ai that we collect through our digital or online properties or services that link to this Privacy Policy (including as applicable, our Mem0.ai website and Mem0.ai social media pages) as well as our marketing activities, live events and other activities described in this Privacy Policy (collectively, the "Service").

This Privacy Policy does not apply to information that we process on behalf of our business customers (such as businesses and other organizations) while providing the Mem0.ai service to them. Our use of information that we process on behalf of our business customers may be governed by our agreements with such customers, including in our Data Processing Addendum with such customers. If you have concerns regarding your personal information that we process on behalf of a business customer, please direct your concerns to that enterprise customer.

Your access to and use of our Service may be as a website visitor, a Free Plan user, or a Paid Plan user. The type of subscription you choose may impact how we process the personal information we collect through the service, as described in the Model Training section below. For more information on our different subscription tiers, please visit https://mem0.ai/pricing.

Controller and data protection contacts

For the purposes of the EU General Data Protection Regulation ("GDPR") and the UK GDPR, the data controller responsible for your personal information is Embedchain, Inc. (DBA Mem0).

  • Data Controller: Embedchain, Inc. (DBA Mem0). Email: [email protected]

  • Data Protection Officer: We are not required to appoint a statutory Data Protection Officer under Article 37 of the GDPR and have not appointed one. Data protection questions can be sent to [email protected]. (If a DPO is later appointed, their contact details will be listed here.)

  • EU Representative and UK Representative: We have appointed representatives under Article 27 of the GDPR and the UK GDPR. Their full contact details are set out in the "How to contact us, exercising your rights and complaints" section below.

Summary of this Privacy Policy

This summary highlights the key points of how we handle your personal information. Please read the full policy below for complete details.

  • Who will use my data? Embedchain, Inc. (DBA Mem0), as data controller, together with our service providers and processors acting on our instructions.

  • What for? To provide and operate the Service, personalize your experience, improve the Service and our analytics, market our products (where permitted), meet legal and security obligations, and, for Free Plan users only, help train our AI models.

  • What will happen if I contact you? We will use your contact details and the content of your message to respond to and manage your request.

  • What data will be stored? Contact, profile, communications, transactional, marketing, inputs/prompts and user-generated content, payment, device, and usage data, as described below.

  • What data will be shared? Data may be shared with affiliates, service providers, payment processors, advertising and business partners, professional advisors, and authorities, as described in "How we share your personal information".

  • How long? We keep personal information only as long as necessary for the purposes described in this policy (see "Data retention" below).

  • Who can access my data? Authorized personnel and vetted service providers/processors bound by confidentiality and data protection obligations.

  • How is my data kept secure? Through technical, organizational and physical safeguards described in "Security" below.

Personal information we collect

Information you provide to us. Personal information you may provide to us through the Service or otherwise includes:

  • Contact data such as your first and last name, salutation, email address, billing and mailing addresses, professional title and company name, and phone number.

  • Profile data such as the username and password that you may set to establish an online account on the Service, interests, preferences, "memories" extracted or updated from interactions (e.g., preferences, goals, past actions) and any other information that you add to your account profile.

  • Communications data based on our exchanges with you, including when you contact us through the Service, social media, or otherwise.

  • Transactional data, such as information relating to or needed to complete your orders on or through the Service, including order numbers and transaction history.

  • Marketing data, such as your preferences for receiving our marketing communications and details about your engagement with them.

  • Inputs, prompts, and user-generated content data, such as photos, images, music, videos, comments, questions, messages, works of authorship, and other content or information that you upload/use as an input or prompt to generate, transmit, or otherwise make available on the Service, as well as associated metadata.

  • Payment data needed to complete transactions is collected and processed directly by our payment processors, such as Stripe and Chargebee.

  • Other data not specifically listed here, which we will use as described in this Privacy Policy or as otherwise disclosed at the time of collection.

Third-party sources. We may combine personal information we receive from you with personal information falling within one of the categories identified above that we obtain from other sources, such as:

  • Public sources, such as government agencies, public records, social media platforms, and other publicly available sources.

  • Data providers, such as information services and data licensors.

  • Customers

  • Service providers that provide services on our behalf or help us operate the Service or our business.

  • Business transaction partners. We may receive personal information in connection with an actual or prospective business transaction.

  • Third-party services, such as social media services, that you use to log into, or otherwise link to, your Service account.

Automatic data collection. We, our service providers, and our business partners may automatically log information about you, your computer or mobile device, and your interaction over time with the Service, our communications and other online services, such as:

  • Device data, such as your computer or mobile device's operating system type and version, manufacturer and model, browser type, screen resolution, RAM and disk size, CPU usage, device type, IP address, unique identifiers, language settings, mobile device carrier, radio/network information, and general location information such as city, state or geographic area.

  • Online activity data, such as pages or screens you viewed, how long you spent on a page or screen, the website you visited before browsing to the Service, navigation paths, information about your activity on a page or screen, access times and duration of access, and whether you have opened our emails or clicked links within them.

  • Precise geolocation data when you authorize the Service to access your device's location.

  • Communication interaction data such as your interactions with our email, text or other communications. We may do this through the use of pixel tags, which may be embedded invisibly in our emails.

Data about others. We may offer features that help users invite their friends or contacts to use the Service, and we may collect contact details about these invitees so we can deliver their invitations. Please do not refer someone to us or share their contact details with us unless you have their permission to do so.

Tracking & Other Technologies

Cookies and other technologies. Some of the automatic collection described above is facilitated by cookies and other tracking technologies. For more information, see our Cookie Notice.

For information concerning your choices with respect to the use of tracking technologies, see the Your choices section of our Cookie Notice.

Cookie Policy

We and our service providers use cookies and similar tracking technologies to operate and personalize the Service, analyze usage, and support marketing. The main categories are:

  • Strictly necessary cookies: required for the Service to function (e.g., authentication, security, load balancing). These cannot be switched off in our systems.

  • Functional cookies: remember your preferences and settings to improve your experience.

  • Analytics/performance cookies: help us understand how visitors use the Service (e.g., pages visited, time on page) so we can improve it.

  • Advertising/targeting cookies: used by us and third-party advertising partners to deliver and measure interest-based advertising.

These technologies may collect data such as your IP address, device and browser identifiers, pages viewed, and interactions with our emails (via pixel tags). Where required by law, we obtain your consent before setting non-essential cookies, and you can withdraw consent or manage your preferences at any time through our cookie banner or your browser settings. For more detail, see our Cookie Notice.

How we use your personal information

We may use your personal information for the following purposes or as otherwise described at the time of collection:

Service delivery and operations. We may use your personal information to:

  • provide the Service and operate our business, including to help users remember user preferences and past interactions;

  • enable security features of the Service;

  • establish and maintain your user profile on the Service;

  • communicate with you about the Service, including by sending Service-related announcements, updates, security alerts, and support and administrative messages; and

  • provide support for the Service, and respond to your requests, questions and feedback.

Service personalization, which may include using your personal information to:

  • personalize experiences for end users (e.g., recalling preferences, goals, and prior interactions);

  • understand your needs and interests;

  • personalize your experience with the Service and our Service-related communications; and

  • remember your selections and preferences as you navigate webpages.

Service improvement and analytics. We may use your personal information to analyze your usage of the Service, improve the Service, improve the rest of our business, help us understand user activity on the Service, as well as user interactions with our emails, and to develop new products and services.

Marketing and advertising. We, our service providers and our third-party advertising partners may collect and use your personal information for marketing and advertising purposes:

  • Direct marketing. We may send you direct marketing communications and may personalize these messages based on your needs and interests. You may opt-out of our marketing communications as described in the Opt-out of marketing section below.

  • Interest-based advertising. We, our service providers, and third-party advertising partners may use cookies and other technologies to collect information about your interaction with the Service over time, and use that information to serve online ads that we or they think will interest you.

Events. We may use your personal information to contact or market to you after collecting your personal information at an event.

Compliance and protection. We may use your personal information to:

  • comply with applicable laws, lawful requests, and legal process, such as to respond to subpoenas, investigations or requests from government authorities;

  • protect our, your or others' rights, privacy, safety or property (including by making and defending legal claims);

  • audit our internal processes for compliance with legal and contractual requirements or our internal policies;

  • enforce the terms and conditions that govern the Service; and

  • prevent, identify, investigate and deter fraudulent, harmful, unauthorized, unethical or illegal activity, including cyberattacks and identity theft.

To create aggregated, de-identified or anonymized data. We may create aggregated, de-identified or anonymized data from your personal information and other individuals whose personal information we collect. We may use this data and share it with third parties for our lawful business purposes.

Model training. We use certain information collected or derived from our users' interactions with the Service to train our AI models and for other machine learning purposes, including aggregated, de-identified or anonymous data derived from any of our users and, from our Free Plan users, inputs, prompts, and user-generated content data. We do not train our AI models on inputs, prompts, and user-generated content data collected from Paid Plan users.

Purpose and legal bases for processing

Where the GDPR or UK GDPR applies, we rely on the following legal bases to process your personal information. The purposes for each type of processing are described in "How we use your personal information" above.

  • Performance of a contract (Article 6(1)(b)): to create and manage your account, provide the Service, process transactions, and deliver support.

  • Consent (Article 6(1)(a)): for direct marketing where required, non-essential cookies and similar technologies, precise geolocation, and (for Free Plan users) use of inputs and user-generated content to train our AI models. You may withdraw consent at any time.

  • Legitimate interests (Article 6(1)(f)): to secure, improve and analyze the Service, prevent fraud and abuse, carry out aggregated/de-identified analysis, and manage corporate transactions, provided these interests are not overridden by your rights.

  • Legal obligation (Article 6(1)(c)): to comply with applicable laws, lawful requests and legal process.

  • Vital interests, public interest and legal claims: where necessary to protect someone's vital interests or to establish, exercise or defend legal claims.

Where we process special category data or criminal offense data (which we do not routinely collect), we will do so only where an additional condition under Articles 9 or 10 GDPR applies.

Legitimate interests

Where we rely on legitimate interests as a legal basis (including when we share data with third parties such as service providers, advertising and business partners, and in the context of corporate transactions), our legitimate interests include operating, securing and improving the Service, understanding how it is used, developing new products, preventing fraud and abuse, and pursuing our lawful business interests. Before relying on legitimate interests, we balance them against your interests, rights and freedoms. You have the right to object to this processing at any time (see "Your rights under the GDPR"). To request more information about a specific legitimate interests assessment, contact [email protected].

How we share your personal information

We may share your personal information with the following parties (or as otherwise described in this Privacy Policy, in other applicable notices, or at the time of collection).

  • Affiliates. Our corporate parent, subsidiaries, and affiliates.

  • Service providers. Third parties that provide services on our behalf or help us operate the Service or our business (such as hosting, information technology, customer support, AI providers such as OpenAI and Anthropic, email delivery, marketing, consumer research and website analytics).

  • Payment processors. Any payment card information you use to make a purchase on the Service is collected and processed directly by our payment processors, such as Stripe and Chargebee.

  • Advertising partners. Third-party advertising companies for the interest-based advertising purposes described above.

  • Third parties designated by you. We may share your personal information with third parties where you have instructed us or provided your consent to do so.

  • Business and marketing partners. Third parties with whom we partner.

  • Linked third-party services. If you log into the Service with, or otherwise link your Service account to, a social media or other third-party service, we may share your personal information with that third-party service.

  • Professional advisors. Professional advisors, such as lawyers, auditors, bankers and insurers.

  • Authorities and others. Law enforcement, government authorities, and private parties, as we believe in good faith to be necessary or appropriate for the Compliance and protection purposes described above.

  • Business transferees. We may disclose personal information in the context of actual or prospective business transactions.

Your choices

In this section, we describe the rights and choices available to all users.

  • Access, correct, or update your information. If you have registered for an account with us through the Service, you may review and update certain account information by logging into the account.

  • Delete your personal information. If you have registered for an account with us through the Service, you may request to delete your information by contacting us.

  • Opt-out of communications. You may opt-out of marketing-related emails by following the opt-out or unsubscribe instructions at the bottom of the email, or by contacting us.

  • Cookies and other technologies. For information about cookies and other technologies employed by the Service and how to control them, see our Cookie Notice.

  • Do Not Track. Some Internet browsers may be configured to send "Do Not Track" signals. We currently do not respond to "Do Not Track" signals.

  • Declining to provide information. We need to collect personal information to provide certain services. If you do not provide the information we identify as required or mandatory, we may not be able to provide those services.

  • Linked third-party platforms. If you choose to connect to the Service through your social media account or other third-party platform, you may be able to use your settings in your account with that platform to limit the information we receive from it.

Your rights under the GDPR

If you are located in the European Economic Area, the United Kingdom or Switzerland, you have the following rights in relation to your personal information. To exercise any of these rights, contact us at [email protected]. We will respond within the timeframes required by law.

  • Right of access: to obtain confirmation of whether we process your personal information and a copy of that information.

  • Right to rectification: to have inaccurate personal information corrected and incomplete information completed.

  • Right to erasure ("right to be forgotten"): to have your personal information deleted in certain circumstances.

  • Right to restriction of processing: to request that we limit the processing of your personal information in certain circumstances.

  • Right to object to processing: to object to processing based on our legitimate interests and to object to direct marketing at any time.

  • Right to data portability: to receive the personal information you provided to us in a structured, commonly used, machine-readable format and to have it transmitted to another controller where technically feasible.

  • Right to withdraw consent: where we rely on consent, to withdraw it at any time without affecting the lawfulness of processing before withdrawal.

  • Right to lodge a complaint: to complain to your local supervisory authority (see "How to contact us, exercising your rights and complaints").

You will not have to pay a fee to exercise your rights in most cases, and we will not discriminate against you for exercising them.

Other sites and services

The Service may contain links to websites, mobile applications, and other online services operated by third parties. In addition, our content may be integrated into web pages or other online services that are not associated with us. These links and integrations are not an endorsement of, or representation that we are affiliated with, any third party. We do not control websites, mobile applications or online services operated by third parties, and we are not responsible for their actions. We encourage you to read the privacy policies of the other websites, mobile applications and online services you use.

Security

We employ technical, organizational and physical safeguards designed to protect the personal information we collect. Depending on the context, these measures include: encryption of data in transit (and, where appropriate, at rest); access controls and role-based permissions applying the principle of least privilege; authentication and, where available, multi-factor authentication; network security and monitoring; regular backups; secure software development practices and vulnerability management; vendor security due diligence and data processing agreements; and staff confidentiality obligations and security training. We also maintain incident response procedures and will notify affected individuals and the relevant supervisory authorities of a personal data breach where required by law. However, security risk is inherent in all internet and information technologies, and while we work to protect your personal information, we cannot guarantee its absolute security.

Data retention

We retain personal information for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law. To determine the appropriate retention period, we consider:

  • the amount, nature and sensitivity of the personal information;

  • the potential risk of harm from unauthorized use or disclosure;

  • the purposes for which we process the information and whether we can achieve those purposes through other means; and

  • applicable legal, tax, accounting, and regulatory requirements.

By way of example, we generally retain account and profile data for the life of your account and for a limited period afterwards; transactional and billing records for the period required by tax and accounting law; and marketing data until you opt out. "Memories" and other inputs are retained while your account is active and are deleted or de-identified when no longer needed. When personal information is no longer required, we securely delete or anonymize it.

Where and how we store and process your data

Your personal information is stored and processed on cloud infrastructure operated by our hosting and service providers. Access is limited to authorized personnel and vetted processors who are bound by contractual confidentiality and data protection obligations, including data processing agreements. Some of these providers, and our own operations, are located in the United States and other countries, which may involve international transfers as described below.

International data transfer

We are headquartered in the United States and may use service providers that operate in other countries. Your personal information may be transferred to the United States or other locations where privacy laws may not be as protective as those in your state, province, or country.

Children

The Service is not intended for use by anyone under 18 years of age. If you are a parent or guardian of a child from whom you believe we have collected personal information in a manner prohibited by law, please contact us. If we learn that we have collected personal information through the Service from a child without the consent of the child's parent or guardian as required by law, we will comply with applicable legal requirements to delete the information.

Our obligations

As a data controller (and, where we process personal information on behalf of our business customers, as a data processor), we are committed to handling personal information in accordance with the GDPR, the UK GDPR and other applicable data protection laws. In particular, we:

  • process personal information lawfully, fairly and transparently, and only for the purposes and on the legal bases described in this policy;

  • collect only the personal information that is adequate, relevant and limited to what is necessary (data minimization);

  • keep personal information accurate and up to date, and retain it only as long as necessary;

  • implement appropriate technical and organizational measures to keep personal information secure;

  • enter into data processing agreements with our processors and ensure appropriate safeguards for international transfers;

  • maintain records of processing activities and cooperate with supervisory authorities as required; and

  • respect and facilitate the exercise of data subject rights and notify breaches where legally required.

Where we act as a processor for our business customers, we process personal information only on their documented instructions as set out in our Data Processing Addendum.

Changes to this Privacy Policy

We reserve the right to modify this Privacy Policy at any time. If we make material changes to this Privacy Policy, we will notify you by updating the date of this Privacy Policy and posting it on the Service or other appropriate means. Any modifications to this Privacy Policy will be effective upon our posting the modified version. Your use of the Service after the effective date of any modified Privacy Policy indicates your acknowledging that the modified Privacy Policy applies to your interactions with the Service and our business. We keep our privacy notice under regular review to make sure it is up to date and accurate.

How to contact us, exercising your rights and complaints

If you have any questions about this Privacy Policy, or if you wish to exercise any of your data protection rights, you can contact us:

If you remain dissatisfied, you can make a complaint about the way we process your personal information to the supervisory authority in your country of residence, place of work, or where an alleged infringement occurred. In the UK, this is the Information Commissioner's Office (ICO), www.ico.org.uk. In the EU, you can find your local Data Protection Authority via the European Data Protection Board (edpb.europa.eu). We would, however, appreciate the chance to address your concerns before you approach the supervisory authority, so please consider contacting us first.

Our EU Representative

Under Article 27 of the GDPR, we have appointed an EU Representative to act as our data protection agent. Our nominated EU Representative is:

  • Instant EU GDPR Representative Ltd.

  • Adam Brogden, [email protected]

  • Tel +353 1 554 9700

  • Office 2, 12A Lower Main Street, Lucan, Co. Dublin, K78 X5P8, Ireland

Our UK Representative

Under Article 27 of the UK GDPR, we have appointed a UK Representative to act as our data protection agent. Our nominated UK Representative is:

  • GDPR Local Ltd.

  • Adam Brogden, [email protected]

  • Tel +44 1772 217800

  • 1st Floor Front Suite, 27-29 North Street, Brighton, England