Privacy Policy
Engram (theengramapp.com) · Operated by Arun Kumar Rathinam
Effective date: June 7, 2026 · Last updated: June 23, 2026
1. Introduction
Engram ("we", "us", "our") is a memory and context layer that sits on top of AI providers. This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and your rights over it.
By using Engram, you agree to the practices described in this policy.
2. Who We Are
Engram is operated by Arun Kumar Rathinam, an individual based in Pune, Maharashtra, India. For privacy-related queries, contact us at:
Email: privacy@theengramapp.com
3. What Data We Collect
3.1 Account Data
- Email address — used for authentication and account management
- Encrypted password — managed by Supabase Auth, never stored in plain text
3.2 Conversation Data
- Messages you send and receive during chat sessions
- Conversation titles and metadata (timestamps, AI provider used)
- All message content is encrypted at rest using AES-256-CBC encryption
- Thumbs up/down feedback you give on AI responses — stored to help us understand response quality
3.3 AI Provider API Keys
- API keys you provide for Claude, OpenAI, or Gemini
- Stored encrypted at rest using AES-256-CBC encryption
- Decrypted only at the moment of use, never logged or exposed
3.4 Profile Data
- Your timezone — detected automatically on signup and used to provide accurate time context to the AI
- Last seen timestamp — used to calculate time since your last session
3.5 Memory Data
- Facts and preferences extracted from your conversations
- Stored entirely in our own Supabase database — no third-party memory service is used
- Encrypted at rest using AES-256-CBC encryption, the same as your messages
- Organised by AI provider — your Claude memories are separate from your GPT-4 and Gemini memories
- Memory extraction does not run in real time — it runs automatically after a conversation has been idle for 30 minutes
3.6 Vault Data
- Ideas, notes, and items you save to your Vault (Power tier only)
- Vault content is encrypted at rest using AES-256-CBC encryption
- Vault items are also processed for memory extraction in the same way as conversation messages (see Section 6.4)
- Use the Private Conversation toggle equivalent — if you do not want a Vault item processed for memory, delete it from your Vault
4. How We Use Your Data
| Purpose | Legal Basis |
|---|---|
| Providing the chat service | Contract performance |
| Injecting memory and time context into AI responses | Contract performance |
| Improving response continuity across sessions | Contract performance |
| Sending password reset emails | Contract performance |
| Complying with legal obligations | Legal obligation |
We do not use your data for advertising. We do not sell your data to third parties. Ever.
5. Data Retention
| Data type | Retention period |
|---|---|
| Messages and conversations | 60 days from creation |
| Account and profile data | Until account deletion |
| API keys | Until deleted by you or account deletion |
| Memory data | Until deleted by you or account deletion |
After 60 days, messages are automatically deleted from our database. Memories extracted from those conversations remain in our database until you delete them manually or delete your account.
6. Third Party Services
Engram uses the following third party services to operate. Each receives some of your data:
6.1 Supabase (Database and Authentication)
- What they receive: Your email, encrypted passwords, encrypted messages, encrypted API keys, profile data, and your encrypted memory data
- Purpose: Database storage, user authentication, and self-hosted memory storage. Memory extraction is performed by our own server using OpenAI's API (see Section 6.4) — Supabase only stores the resulting encrypted data, it does not perform extraction itself
- Location: EU region
- DPA: We have signed a Data Processing Addendum with Supabase.
- Privacy policy: supabase.com/privacy
6.2 Vercel (Hosting)
- What they receive: Request metadata, server logs
- Purpose: Hosting and serving the application
- Location: Global CDN
- Privacy policy: vercel.com/legal/privacy-policy
Note: Engram currently operates on Vercel's Hobby plan, under which a formal Data Processing Addendum is not available. Vercel receives only request metadata and server logs — no user message content, API keys, or memory data is stored by Vercel.
6.3 AI Providers (Claude, OpenAI, Gemini, or Venice AI) — Your Own API Key
- What they receive: Your messages and system context (including AI-generated memory summaries) at the time of each request
- Important: You connect your own API key directly. You have a direct relationship with your chosen AI provider under their terms of service. Engram is not responsible for how AI providers process your data.
- Note: Venice AI operates with zero data retention at inference — messages sent via Venice are not stored or used for training by Venice.
- Anthropic privacy policy
- OpenAI privacy policy
- Google privacy policy
- venice.ai/privacy
6.4 OpenAI — Engram's Own Key, Memory Extraction Only
- What they receive: Your decrypted message text, sent to OpenAI's API (text-embedding-3-small and gpt-4o-mini) to extract and embed facts worth remembering
- Important: This uses Engram's own OpenAI API key, not your personal key from Section 6.3 — it runs regardless of which AI provider you chat with. Extracted memories are encrypted before being stored in our database. If you do not want a conversation processed this way, use the Private Conversation toggle.
- Location: United States
- OpenAI privacy policy
6.5 Paddle (Billing)
- What they receive: Your email address, payment method details, subscription tier, and billing history
- Purpose: Payment processing, subscription management, and tax/VAT/GST compliance as Merchant of Record
- Note: Paddle acts as the Merchant of Record for all Engram transactions. They handle global tax compliance on our behalf. Your payment details are entered directly into Paddle's hosted checkout — Engram never sees or stores your card number.
- Privacy policy: paddle.com/legal/privacy
6.6 Cloudflare (DNS)
- What they receive: Request metadata
- Purpose: DNS resolution and DDoS protection
- Privacy policy: cloudflare.com/privacypolicy
7. Your Rights
Regardless of where you are located, you have the following rights:
7.1 Right to Access
You can view all memories Engram has stored about you at any time via Settings → Memory.
7.2 Right to Rectification
You can delete individual memories that are incorrect via Settings → Memory.
7.3 Right to Erasure (Right to be Forgotten)
You can delete your entire account and all associated data via Settings → Delete Account. This permanently deletes:
- Your profile and account
- All conversations and messages
- All stored API keys
- All memories across all providers
7.4 Right to Data Portability
Contact us at privacy@theengramapp.com to request a full export of your data. We will respond within 30 days.
7.5 Right to Restrict Processing
You can mark any conversation as Private to prevent it from being used for memory extraction. Private conversations are never sent to OpenAI for memory extraction.
7.6 Right to Object
You can contact us at privacy@theengramapp.com to object to any processing of your data.
EU/UK Users — GDPR Rights
If you are located in the EU or UK, you have additional rights under GDPR including the right to lodge a complaint with your local supervisory authority.
Indian Users — DPDP Act Rights
If you are located in India, you have rights under the Digital Personal Data Protection Act 2023 including the right to access, correct, and erase your personal data.
8. Data Security
We take data security seriously:
- All messages and API keys are encrypted at rest using AES-256-CBC
- All data in transit is encrypted using HTTPS/TLS
- API keys are decrypted only at the moment of use, never logged
- We use Row Level Security in our database — you can only access your own data
- We do not store passwords in plain text
9. Private Conversations
Engram provides a Private Conversation toggle on each conversation. When enabled:
- That conversation is excluded from memory extraction
- Its content is never sent to OpenAI for memory extraction
- It is still stored encrypted in our database for your own reference
Use this for sensitive conversations you do not want used to build your memory profile.
10. Children's Privacy
Engram is not intended for users under the age of 16. We do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us at privacy@theengramapp.com and we will delete it promptly.
11. International Data Transfers
Your data may be transferred to and processed in countries outside your own, including the United States and the EU. Where required by law, we rely on Standard Contractual Clauses and Data Processing Agreements with our processors to ensure your data is protected.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the effective date at the top of this page. Continued use of Engram after changes constitutes acceptance of the updated policy.
13. Contact Us
For any privacy-related questions, requests, or complaints:
Email: privacy@theengramapp.com
Operator: Arun Kumar Rathinam, Pune, Maharashtra, India
We aim to respond to all privacy requests within 30 days.
This Privacy Policy was last updated on June 23, 2026.