no training
We don't train on your data
Project content is read by the service to power search and broadcast. It is never used to train models — ours or anyone else's.
This page covers the hosted service at memoturn.ai. Memoturn is open source under MIT — if you self-host, you control the substrate and the policy. The legally binding version is the privacy policy.
Every party that processes a byte of your project content. No silent third parties — if it's not on this list, it doesn't see your data.
| Provider | Role | What it processes |
|---|---|---|
| Cloudflare | Edge runtime | Workers, Durable Objects, Vectorize, Workers AI, KV, R2, Hyperdrive, Queues. Hosts every read and write of your project content. Embeddings generated by Workers AI via @cf/baai/bge-large-en-v1.5; R2 stores turn payloads and skill bundles; Queues drive the ingest pipeline. |
| Neon | Managed Postgres | Stores account, project, turn, memory, fact, candidate, rule, skill, and observability rows. Connection-pooled through Cloudflare Hyperdrive. |
| Google, GitHub | OAuth | Used only if you sign in via OAuth. The provider returns a subject ID we store against your account; we never see the upstream password. |
Each one is a property of how the service is built, not a policy we could quietly reverse. The sub-processor list above is the complete set of parties that touch your content.
no training
Project content is read by the service to power search and broadcast. It is never used to train models — ours or anyone else's.
no tracking
No analytics scripts, no ad pixels, no session-replay tools on the dashboard or the marketing surface. The only events we log are operational (request metadata, 30-day retention).
no resale
Account email, OAuth subject ID, and project content are processed only to deliver the service. They are not shared with advertisers, brokers, or affiliates.
Memoturn is pre-1.0. Behavior can change between releases, including breaking API changes, and the hosted service carries no formal SLA — uptime is best-effort.
Operational logs (request metadata: IP, user agent, response status, latency) are retained 30 days for rate-limiting, abuse prevention, and the observability dashboard. Project content is retained for the lifetime of the project. Vendor reviews, security questionnaires, and DPAs are handled directly — we respond within 3 business days.
Vulnerability disclosure is documented in SECURITY.md. Coordinated, private disclosure only. Do not open a public issue.
Vendor reviews, security questionnaires, DPAs, or a private disclosure — we respond within 3 business days.