Bit1 LLC is the controller of the personal data described here. Contact: privacy@extendedmemory.app
What you give us
| Account | Email address, password (stored only as a hash by our identity provider), display name, optional profile picture |
|---|---|
| Your library | Photographs, scanned documents, PDFs, files, notes, to-dos and saved links — including whatever personal information happens to be *inside* them |
| Household | Names, email addresses and pictures of people you invite; their role and permissions |
| Questions | The questions you type into the assistant |
| Email-in | Messages and attachments sent to your save-address, including sender and subject |
What the Service derives
Descriptions of your items, text read from them, suggested tags, detected labels, extracted details (dates, vendor, amounts, document type), transcripts of voice recordings, and numerical representations ("embeddings") used to make items searchable by meaning.
What we collect automatically
Sign-in times, last-active timestamps, storage used, questions used in the period, subscription tier, device identifiers used for syncing, and technical logs including IP addresses and error diagnostics.
What we never collect: card numbers and payment details. Those stay with Apple or Google.
| Purpose | Basis (GDPR Art. 6) |
|---|---|
| Providing the Service — storing, syncing, describing, indexing, searching, answering | Performance of a contract |
| Household sharing | Performance of a contract |
| Sending service email — verification, invitations, dormancy warnings | Performance of a contract |
| Security, abuse prevention, enforcing plan limits | Legitimate interests |
| Aggregate operational and financial statistics | Legitimate interests |
| Legal compliance | Legal obligation |
Your library may contain special category data — health documents, identity documents, and so on. We process it only to provide the Service to you, on the basis of your explicit consent given when you create an account and store such a document. You can withdraw it by deleting the document or closing your account.
We do not sell personal information, share it for cross-context behavioural advertising, or use it for advertising at all.
Your library, your account records and the search index are stored in Amazon Web Services, in the us-west-2 region (Oregon, United States).
Operational and billing metrics — which contain no library content and no document text — are also processed in us-east-1, because the AWS billing and cost services only exist there.
If you are outside the United States, your data is transferred there.
We use these providers, all within AWS unless stated:
| Provider | What it does | Sees |
|---|---|---|
| Amazon Bedrock (Amazon Nova, Amazon Titan) | Describes documents, reads text, extracts details, answers questions, builds the search index | Document images and text, your questions |
| Amazon Textract | Reads text and structured fields from documents | Document images |
| Amazon Rekognition | Detects labels in photographs | Photographs |
| Amazon Transcribe | Transcribes voice memos | Voice recordings |
| Amazon Cognito | Sign-in and passwords | Email, password hash |
| Amazon S3, DynamoDB, S3 Vectors | Storage and indexing | Everything stored |
| Amazon SES | Sends and receives service email | Email addresses, message contents |
| Apple / Google | Subscription billing | Purchase records — not your library |
We do not use advertising or analytics networks.
Your documents and questions are not used to train anybody's AI models.
Processing runs on Amazon Bedrock, where AWS states that customer input and output are not used to train the underlying models, are not shared with model providers, and are not stored by the service. Data sent for processing stays within the AWS network in the region above.
We do not train our own models on your content, and we will not begin to without asking you first, separately and explicitly.
A document marked "Only me" is processed like any other. Marking it private hides it from the other people in your household (§5); it does not withhold it from the processing described above, and it does not encrypt it in a way we cannot read. We say this plainly because a padlock in an interface invites the opposite assumption, and a promise we cannot keep is worse than a feature we did not build.
Automated processing produces descriptions, tags and extracted details, and influences the order of your search results. It does not produce decisions with legal or similarly significant effects about you (GDPR Art. 22). See §7 for its accuracy limits, which are a privacy matter too: an extracted detail may be wrong about you, and you can correct it in the app at any time.
| Items in your library | Until you delete them or close your account |
|---|---|
| Items in Trash | Until you empty it |
| Deleted items | Files are destroyed immediately. A marker recording that the item was deleted remains for 180 days, so that a device which has been offline learns the item is gone rather than restoring it |
| Free accounts unused for 365 days | Library emptied — see §11 |
| Backups (point-in-time recovery) | 35 days, then gone |
| Technical logs | 90 days |
| Financial and operational statistics | Aggregate only, no library content, kept up to 1 year |
| Records we must keep by law | As long as the law requires |
Depending on where you live, you may have the right to access your data, correct it, delete it, object to or restrict processing, port it, and to withdraw consent. You may complain to your data protection authority; in the EEA and UK that is the one where you live.
Much of this you can do yourself in the app — view, correct and delete anything, and export your library. For anything else, write to privacy@extendedmemory.app.
How quickly we answer. As fast as we can, and never slower than the law requires: one month in the EEA and the UK, 45 days in California, 15 days for an access request in Brazil. Where a request is complex, or you have made several, the law allows us longer — up to two further months in the EEA and UK, and a further 45 days in California. If we need that, we will tell you inside the original period and say why.
If we say no. We will tell you why, and you may ask us to reconsider by replying to the same address. We will answer an appeal within 45 days.
If you live in a US state with a consumer privacy law, you may request the categories and specific pieces of personal information we hold, and request deletion or correction. We do not sell your personal information, and we do not share it for cross-context behavioural advertising — this app contains no advertising identifier and no advertising or analytics SDK. There is nothing to opt out of. We will not discriminate against you for exercising these rights.
Individual items — delete them in the app. They go to Trash; emptying the Trash destroys the files immediately. Selecting many at once is how a library is emptied without closing the account.
Closing your account — Settings → Security → Delete account. It asks for your password, states what will be destroyed, and then does it immediately: your sign-in, every household membership you hold, and — for any household you *own* — its documents, its outstanding invitations, and every other member's access to it.
If you would rather we did it, write to privacy@extendedmemory.app from your account's email address and we will complete it within 30 days.
What survives account closure: aggregate statistics that identify nobody, records we must keep by law, and — for up to 35 days — encrypted backups from which the data ages out.
If you are one member of a shared household, closing your own account removes you and your sign-in; items you added remain in that household's library, because they are part of a shared collection other people also rely on. Delete them first if you want them gone.
If you own a household, closing your account destroys it — every document in it, and every other member's access. There is no way to hand a household to somebody else yet, so the app states this, with what it will destroy, before it asks for your password.
The Service is not for children under 16. We do not knowingly collect their data. If you believe a child has given us personal information, write to privacy@extendedmemory.app and we will delete it.
Parents: a child's documents that *you* store in *your* library are your records, and are treated as your data.
Encryption in transit and at rest; passwords never stored in plain form; household data separated by account with every request checked server-side against your verified identity; least-privilege access; multi-factor authentication on administrative access.
No system is perfectly secure. If a breach affects your personal data and is likely to result in a risk to you, we will notify you and the relevant authority as the law requires — in the EEA and UK, within 72 hours of becoming aware.
We will post any change here with a new date, and tell you in the app before a material change takes effect.
Contact: privacy@extendedmemory.app
← extendedmemory.app