← Back to appPrivacy Policy

Privacy Policy

Engram (theengramapp.com)  ·  Operated by Arun Kumar Rathinam

Effective date: June 7, 2026 ·  Last updated: June 23, 2026


1. Introduction

Engram ("we", "us", "our") is a memory and context layer that sits on top of AI providers. This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and your rights over it.

By using Engram, you agree to the practices described in this policy.


2. Who We Are

Engram is operated by Arun Kumar Rathinam, an individual based in Pune, Maharashtra, India. For privacy-related queries, contact us at:

Email: privacy@theengramapp.com


3. What Data We Collect

3.1 Account Data

  • Email address — used for authentication and account management
  • Encrypted password — managed by Supabase Auth, never stored in plain text

3.2 Conversation Data

  • Messages you send and receive during chat sessions
  • Conversation titles and metadata (timestamps, AI provider used)
  • All message content is encrypted at rest using AES-256-CBC encryption
  • Thumbs up/down feedback you give on AI responses — stored to help us understand response quality

3.3 AI Provider API Keys

  • API keys you provide for Claude, OpenAI, or Gemini
  • Stored encrypted at rest using AES-256-CBC encryption
  • Decrypted only at the moment of use, never logged or exposed

3.4 Profile Data

  • Your timezone — detected automatically on signup and used to provide accurate time context to the AI
  • Last seen timestamp — used to calculate time since your last session

3.5 Memory Data

  • Facts and preferences extracted from your conversations
  • Stored entirely in our own Supabase database — no third-party memory service is used
  • Encrypted at rest using AES-256-CBC encryption, the same as your messages
  • Organised by AI provider — your Claude memories are separate from your GPT-4 and Gemini memories
  • Memory extraction does not run in real time — it runs automatically after a conversation has been idle for 30 minutes

3.6 Vault Data

  • Ideas, notes, and items you save to your Vault (Power tier only)
  • Vault content is encrypted at rest using AES-256-CBC encryption
  • Vault items are also processed for memory extraction in the same way as conversation messages (see Section 6.4)
  • Use the Private Conversation toggle equivalent — if you do not want a Vault item processed for memory, delete it from your Vault

4. How We Use Your Data

PurposeLegal Basis
Providing the chat serviceContract performance
Injecting memory and time context into AI responsesContract performance
Improving response continuity across sessionsContract performance
Sending password reset emailsContract performance
Complying with legal obligationsLegal obligation

We do not use your data for advertising. We do not sell your data to third parties. Ever.


5. Data Retention

Data typeRetention period
Messages and conversations60 days from creation
Account and profile dataUntil account deletion
API keysUntil deleted by you or account deletion
Memory dataUntil deleted by you or account deletion

After 60 days, messages are automatically deleted from our database. Memories extracted from those conversations remain in our database until you delete them manually or delete your account.


6. Third Party Services

Engram uses the following third party services to operate. Each receives some of your data:

6.1 Supabase (Database and Authentication)

  • What they receive: Your email, encrypted passwords, encrypted messages, encrypted API keys, profile data, and your encrypted memory data
  • Purpose: Database storage, user authentication, and self-hosted memory storage. Memory extraction is performed by our own server using OpenAI's API (see Section 6.4) — Supabase only stores the resulting encrypted data, it does not perform extraction itself
  • Location: EU region
  • DPA: We have signed a Data Processing Addendum with Supabase.
  • Privacy policy: supabase.com/privacy

6.2 Vercel (Hosting)

  • What they receive: Request metadata, server logs
  • Purpose: Hosting and serving the application
  • Location: Global CDN
  • Privacy policy: vercel.com/legal/privacy-policy

Note: Engram currently operates on Vercel's Hobby plan, under which a formal Data Processing Addendum is not available. Vercel receives only request metadata and server logs — no user message content, API keys, or memory data is stored by Vercel.

6.3 AI Providers (Claude, OpenAI, Gemini, or Venice AI) — Your Own API Key

  • What they receive: Your messages and system context (including AI-generated memory summaries) at the time of each request
  • Important: You connect your own API key directly. You have a direct relationship with your chosen AI provider under their terms of service. Engram is not responsible for how AI providers process your data.
  • Note: Venice AI operates with zero data retention at inference — messages sent via Venice are not stored or used for training by Venice.
  • Anthropic privacy policy
  • OpenAI privacy policy
  • Google privacy policy
  • venice.ai/privacy

6.4 OpenAI — Engram's Own Key, Memory Extraction Only

  • What they receive: Your decrypted message text, sent to OpenAI's API (text-embedding-3-small and gpt-4o-mini) to extract and embed facts worth remembering
  • Important: This uses Engram's own OpenAI API key, not your personal key from Section 6.3 — it runs regardless of which AI provider you chat with. Extracted memories are encrypted before being stored in our database. If you do not want a conversation processed this way, use the Private Conversation toggle.
  • Location: United States
  • OpenAI privacy policy

6.5 Paddle (Billing)

  • What they receive: Your email address, payment method details, subscription tier, and billing history
  • Purpose: Payment processing, subscription management, and tax/VAT/GST compliance as Merchant of Record
  • Note: Paddle acts as the Merchant of Record for all Engram transactions. They handle global tax compliance on our behalf. Your payment details are entered directly into Paddle's hosted checkout — Engram never sees or stores your card number.
  • Privacy policy: paddle.com/legal/privacy

6.6 Cloudflare (DNS)


7. Your Rights

Regardless of where you are located, you have the following rights:

7.1 Right to Access

You can view all memories Engram has stored about you at any time via Settings → Memory.

7.2 Right to Rectification

You can delete individual memories that are incorrect via Settings → Memory.

7.3 Right to Erasure (Right to be Forgotten)

You can delete your entire account and all associated data via Settings → Delete Account. This permanently deletes:

  • Your profile and account
  • All conversations and messages
  • All stored API keys
  • All memories across all providers

7.4 Right to Data Portability

Contact us at privacy@theengramapp.com to request a full export of your data. We will respond within 30 days.

7.5 Right to Restrict Processing

You can mark any conversation as Private to prevent it from being used for memory extraction. Private conversations are never sent to OpenAI for memory extraction.

7.6 Right to Object

You can contact us at privacy@theengramapp.com to object to any processing of your data.

EU/UK Users — GDPR Rights

If you are located in the EU or UK, you have additional rights under GDPR including the right to lodge a complaint with your local supervisory authority.

Indian Users — DPDP Act Rights

If you are located in India, you have rights under the Digital Personal Data Protection Act 2023 including the right to access, correct, and erase your personal data.


8. Data Security

We take data security seriously:

  • All messages and API keys are encrypted at rest using AES-256-CBC
  • All data in transit is encrypted using HTTPS/TLS
  • API keys are decrypted only at the moment of use, never logged
  • We use Row Level Security in our database — you can only access your own data
  • We do not store passwords in plain text

9. Private Conversations

Engram provides a Private Conversation toggle on each conversation. When enabled:

  • That conversation is excluded from memory extraction
  • Its content is never sent to OpenAI for memory extraction
  • It is still stored encrypted in our database for your own reference

Use this for sensitive conversations you do not want used to build your memory profile.


10. Children's Privacy

Engram is not intended for users under the age of 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us at privacy@theengramapp.com and we will delete it promptly.


11. International Data Transfers

Your data may be transferred to and processed in countries outside your own, including the United States and the EU. Where required by law, we rely on Standard Contractual Clauses and Data Processing Agreements with our processors to ensure your data is protected.


12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by updating the effective date at the top of this page. Continued use of Engram after changes constitutes acceptance of the updated policy.


13. Contact Us

For any privacy-related questions, requests, or complaints:

Email: privacy@theengramapp.com
Operator: Arun Kumar Rathinam, Pune, Maharashtra, India

We aim to respond to all privacy requests within 30 days.


This Privacy Policy was last updated on June 23, 2026.