Privacy Policy
Codelabs Studio S.L. ("Codelabs", "we") operates MemoryFirst (the "Service"). This Privacy Policy explains how we collect, use and protect personal information when you use the Service. We are a data controller for account and account-billing data, and a data processor for content you add into the Service ("Workspace Data").
1. Information we collect
- Account information. Name, work email, password hash or OAuth identifier, organisation name.
- Billing information. Company name, VAT ID, billing address, payment-method last 4 digits (Stripe holds the full card data).
- Workspace Data. Content you and your AI agents add (documents, voice transcripts, chats, web sources, ops events). This is Your Data; you own it. We process it under your instructions per the DPA.
- Integration data. When you connect a third-party tool (Notion, Drive, Gmail, Calendar, GitHub, etc.) we receive OAuth tokens and the content you authorise the integration to read. Tokens are stored encrypted at rest.
- Usage data. Basic feature usage, error logs, performance metrics, used to operate, secure and improve the Service. Anonymised after 90 days.
- Communications. Emails to support, founders or sales addresses.
2. Legal basis (GDPR Art. 6)
- Contract performance (Art. 6(1)(b)): providing the Service you subscribed to.
- Legitimate interests (Art. 6(1)(f)): securing the Service, preventing fraud and abuse, anonymised analytics. You may object at any time.
- Consent (Art. 6(1)(a)): marketing emails, optional cookies. Withdrawable at any time.
- Legal obligation (Art. 6(1)(c)): tax records, lawful access requests.
3. How we use your information
- Provide, maintain, secure and improve the Service.
- Authenticate you and manage your account.
- Bill you and meet tax/accounting obligations.
- Communicate about the Service (transactional). Marketing only with consent.
- Comply with legal obligations and respond to lawful requests.
4. AI processing of Your Data
The Service uses AI models to embed, retrieve and reason over Workspace Data. We route prompts to third-party LLM providers (Anthropic, OpenAI, Google, Mistral) via a gateway, governed by the provider's no-training contractual commitments. We do not train shared models on Your Data. Enterprise customers may pin processing to specific providers or self-hosted models. The full subprocessor list is at /legal/dpa.
5. Sharing & subprocessors
We do not sell personal data. We share data only with subprocessors that operate under written contracts and EU-standard data-protection obligations. Current subprocessors are listed in the DPA and include cloud infrastructure (Hetzner Online GmbH, Germany), edge security (Cloudflare Inc., US, with SCCs), payments (Stripe Payments Europe Ltd., Ireland) and the LLM providers above. We notify customers 30 days before adding or replacing a subprocessor.
6. International transfers
Workspace Data is stored in Germany (EU) by default. Some subprocessors are located outside the EEA. Transfers rely on EU Standard Contractual Clauses (SCCs) (Commission Decision 2021/914) and, where applicable, additional technical and organisational measures (encryption in transit and at rest, pseudonymisation, access controls). Enterprise customers can pin data residency to EU-only.
7. Security
TLS 1.3 in transit. AES-256 encryption at rest, per-workspace keys. Multi-tenant isolation enforced at the database via row-level security. Bcrypt-hashed API keys (cost factor 12). Daily encrypted backups with 30-day retention. Annual penetration test (planned for FY 2026). Vulnerabilities can be reported to security@memoryfirst.ai; we follow a 90-day responsible-disclosure policy.
8. Retention
- Workspace Data: for the duration of your account. On termination, exported on request and permanently deleted within 30 days.
- Account & billing: kept for the duration of the contract plus statutory tax retention (6 years in Spain).
- Logs & metrics: raw 30 days; anonymised aggregates indefinitely.
- Support emails: 24 months after the last interaction.
9. Your rights (GDPR Arts. 15–22)
You have the right to access, rectify, delete, restrict or object to processing of your personal data, the right to data portability, and the right not to be subject to solely automated decisions with legal effect. To exercise any of these rights, email privacy@memoryfirst.ai. We respond within 30 days. You may also lodge a complaint with your national supervisory authority; in Spain, the AEPD ( aepd.es).
10. Cookies
We use only strictly-necessary authentication cookies. We do not use advertising or tracking cookies. Detail: /legal/cookies.
11. Children
The Service is intended for use in a business context and is not directed to children under 16. We do not knowingly collect personal data from children.
12. Changes to this Policy
We may update this Policy from time to time. Material changes will be announced by email at least 30 days before they take effect. The current effective date is shown at the top of this page.
13. Contact
Privacy questions: privacy@memoryfirst.ai · Security: security@memoryfirst.ai · Founders: founders@memoryfirst.ai.