Legal

privacy policy

Last updated: April 20, 2026 · Phase A (alpha)

We think privacy is a feature, not a nice-to-have. This document explains what Anamnesis collects, why we collect it, and — more importantly — what we refuse to do with it.

The one-paragraph version. We store the memories you send us, encrypted at rest with a key derived from your account. We serve those memories back only to you. We do not train AI on them. We do not sell them. We do not read them for marketing. If you delete them, they're gone.

01What we collect

We collect only what the service actually needs to work.

02What we don't collect

03How your memories are protected

Each user has a set of per-user keys derived from their account credentials using HKDF-SHA256. Memory payloads are encrypted with AES-GCM before being written to disk. Two facts follow from this:

Transport is TLS 1.3 end-to-end. API keys, session cookies, and memory payloads never travel in cleartext between you and our servers.

04What we don't do with your data

05Subprocessors

To run Anamnesis we use a small number of infrastructure providers. They store or transmit your encrypted data but don't receive the keys needed to read it.

We'll update this list when it changes. If a subprocessor is added in a way that materially changes the privacy posture, existing users get notice by email.

06Cookies

We use one first-party cookie: the session cookie that keeps you signed in after login. It's HttpOnly, Secure, and SameSite=Lax. No analytics cookies. No advertising cookies. No third-party trackers.

07Your rights

Regardless of where you live, Anamnesis gives you:

08Data retention

We hold account data and memories as long as your account exists. When you delete an account:

09Children

Anamnesis is not for children under 13. If we learn that a child under 13 has created an account, we'll delete it and any associated data.

10International users

Our servers are in the United States. If you use Anamnesis from outside the U.S., your data is transferred to and stored in the U.S. We rely on Standard Contractual Clauses where applicable and on the encryption architecture above to protect the data in transit and at rest.

11Security incidents

If we discover a breach that puts your account or memories at risk, we'll notify you without undue delay — in no case longer than 72 hours after we've confirmed the breach. Notifications include what happened, what data was affected, and what you should do.

12Changes

We may update this policy as Anamnesis evolves. Material changes are announced by email to the address on file and by updating the "last updated" date above.

13Contact

Questions, concerns, takedown requests, or legal notices: hello@smtry.ai.