Privacy Statement
Effective date: July 21, 2026. This statement describes the current hippocampOS account, connector, memory, AI, MCP, billing, analytics, retention, and deletion implementation.
Plain-English commitment
hippocampOS does not sell your data, does not use Google user data for advertising, does not train generalized AI models on Google user data, and accesses connected sources only after you authorize the relevant connector.
hippocampOS is a private context and memory workspace. It lets you create named brains, connect sources you choose, import notes and files, turn authorized content into searchable memories and facts, and invoke those memories from the product or supported AI clients.
This statement explains how the current product collects, uses, stores, shares, protects, retains, and deletes information. It covers the hippocampOS website and app, connected sources, AI processing, Model Context Protocol (MCP) access, billing, support, and operational services.
Account and identity information: when you create or use an account, our authentication provider may give us your user identifier, name, email address, profile image, session claims, and sign-in status. We also store workspace membership, approval, plan, and onboarding state.
Google authorization information: when you connect a Google service, we store the OAuth tokens, granted scopes, expiry information, provider account identifier, and authorization metadata needed to maintain that connection.
Gmail content: if you connect Gmail, hippocampOS uses read-only access to retrieve message and thread identifiers, sender and recipient fields, subject lines, labels, timestamps, snippets, body content, attachment metadata, and attachment content needed for the memory features you request. The Gmail permission does not allow hippocampOS to send, edit, or delete your email.
Google Photos content: hippocampOS uses the Google Photos Picker. We receive only the photos or videos you explicitly select, together with related identifiers, filenames, media types, dimensions, creation times, and temporary download information needed to import those selections.
Other connector content: if you connect Notion, Fireflies, Otter, or Granola, we may receive the authorization credential or API key you provide and the pages, meeting metadata, transcripts, summaries, participants, timestamps, or related records made available by that connector and selected for your workspace.
Direct imports: Freeform, ChatGPT Memory, and Claude Memory can collect the text, formatted notes, images, PDFs, documents, filenames, file metadata, and raw uploaded content that you submit. These imports occur only when you choose to add or replace them.
Workspace and derived memory: we store brain names and settings, connector state, source records, memory nodes, embeddings, facts, beliefs, graph relationships, summaries, categories, provenance, search queries and traces, MCP retrieval activity, AI outputs, and feedback created or generated while providing the service.
Billing and communications: we store plan, subscription, checkout, invoice-reference, trial, email-delivery, waitlist, invitation, and communication-preference information. Payment card details are collected and handled by Stripe rather than stored directly by hippocampOS.
Usage, device, and operational information: we may process route paths, interaction labels, approximate device and browser information, performance timings, network and AJAX diagnostics, request identifiers, IP-derived request metadata, logs, sync and processing job state, token usage, model and provider identifiers, errors, health signals, and security or audit events. Analytics paths are normalized to remove query strings and replace UUID-like identifiers.
hippocampOS and its authentication, analytics, performance, and security providers may use cookies, session storage, local storage, or similar technologies to keep you signed in, protect sessions, remember interface preferences, complete OAuth handoffs, measure product use, diagnose errors, and operate the service.
Blocking essential authentication or security storage may prevent account and connector features from working. Browser and device controls may let you limit non-essential analytics technologies, subject to the controls offered by the relevant provider and applicable law.
We use information to authenticate you, maintain your workspace, connect and sync sources you authorize, process direct imports, build and search memory graphs, retrieve brain-scoped context, provide MCP access, personalize features, meter usage, administer plans and billing, send transactional communications, answer support requests, prevent abuse, diagnose failures, secure the service, and comply with legal obligations.
We do not sell personal information. We do not use Google user data for advertising, retargeting, personalized or interest-based ads, credit decisions, lending, information resale, data brokerage, or surveillance.
We use Google user data only to provide or improve the user-facing hippocampOS features you request. We do not use Google user data to train generalized AI or machine-learning models.
hippocampOS may send relevant source content, direct imports, stored memories, and search context to an AI provider configured by hippocampOS or selected in your settings. Current functionality can use OpenAI or Anthropic models for tasks such as extraction, categorization, summarization, embeddings, query analysis, and generated search or recall answers.
We limit these transfers to the content and context needed to perform the requested product function. AI invocation records may include provider and model identifiers, task type, token counts, timestamps, and the prompt text used for operational review and cost accounting.
hippocampOS does not authorize an AI provider to use Google user data to train its general-purpose models. If you separately configure or invoke a provider account, custom GPT, Claude connection, or other third-party service, that provider's own terms and data controls also apply to its handling of information.
AI outputs can be inaccurate or incomplete. Derived facts retain source provenance where supported, but you should review important outputs against the underlying source before relying on them.
If you authorize Claude, ChatGPT, or another compatible MCP client, hippocampOS stores client and authorization metadata, hashed authorization credentials, the scopes you approve, connection status, and audit records. MCP currently exposes brain-listing and memory-retrieval functions under the limited brains:read and search:read scopes.
An authorized MCP client can receive memories and source context returned by the brain or Master Brain you invoke. Information received by that external client is also governed by the client's provider, account, workspace, and retention settings. Disconnect or revoke access when you no longer want that client to retrieve hippocampOS context.
Service providers: information is disclosed to providers that authenticate users, host the frontend and backend, operate databases, object storage and queues, provide analytics and application monitoring, deliver email, process payments, or supply AI functionality. The current service stack can include Clerk, Vercel, Amazon Web Services, New Relic, Resend, Stripe, OpenAI, and Anthropic.
Connected-source providers: when you enable a connector, hippocampOS communicates with that provider—such as Google, Notion, Fireflies, Otter, or Granola—to authorize access, refresh credentials, retrieve the data you requested, and perform connector actions you initiate.
We may disclose information if required by law or valid legal process, or when reasonably necessary to protect users, the public, hippocampOS, or our providers from fraud, abuse, security threats, or harm.
If hippocampOS is involved in a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, information may transfer as part of that transaction subject to this statement or materially comparable protections and any consent required by law or applicable platform policy.
hippocampOS's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
hippocampOS uses Google user data only to provide or improve prominent user-facing app functionality; does not sell or transfer it to advertising platforms, data brokers, or information resellers; does not use it for ads, retargeting, personalized advertising, credit-worthiness, lending, or surveillance; and does not use it to train generalized AI or machine-learning models.
Read the Google API Services User Data Policy ↗You choose which connectors to authorize, which Google Photos items to select, which brain receives a source, what to upload through direct imports, when to start a sync, which AI provider or model to configure where settings are available, and which brain or Master Brain an AI client invokes.
You can revoke Google access from your Google Account and revoke other provider access from that provider where supported. Revocation stops future authorized access but does not by itself delete information already imported into hippocampOS.
You can replace one-time ChatGPT Memory or Claude Memory imports and delete eligible brains in the product. Deleting a brain removes its scoped source records, memory, connector state and credentials, and associated processing work. The product keeps at least one brain in a workspace; contact us to request deletion of the remaining workspace or account.
Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, or portability of personal information. Submit a request through the Contact page or the privacy email below. We may need to verify your identity before completing it.
We keep account, workspace, connector, memory, billing-reference, and operational information while it is needed to provide the service, maintain an authorized connection, meet the purpose described in this statement, resolve disputes, enforce agreements, prevent abuse, or satisfy legal and accounting obligations.
When you delete a brain or we complete a verified account-deletion request, active user-scoped records and associated stored objects are deleted or de-identified according to the implemented workflow. Some security, fraud-prevention, transaction, support, audit, or legal records may be retained when necessary and permitted by law.
Copies held in temporary caches, logs, provider systems, or backups may remain for a limited period until their normal expiry or overwrite cycle. Revoking an external provider does not delete copies already received by that provider, and deleting hippocampOS data does not delete the original records in Gmail, Google Photos, Notion, or another source service.
We use safeguards designed to protect information, including authenticated access, server-derived tenant and user scope, brain-scoped retrieval, HTTPS in transit, restricted application origins, browser security headers, backend-only secrets, signed OAuth state, hashed MCP credentials, application-layer encryption for Notion tokens and connector API keys, input validation, audit records, and deletion workflows.
The production database is not publicly reachable, and the frontend does not connect directly to databases or worker queues. No internet service can guarantee perfect security, and hippocampOS does not claim end-to-end encryption.
You are responsible for securing your identity-provider account, connected-provider accounts, devices, sessions, API keys, and credentials. Contact us promptly if you believe your account or hippocampOS data has been accessed without authorization.
Read the hippocampOS Security overview →hippocampOS and its service providers may process and store information in the United States, India, and other countries where they or their infrastructure operate. Those countries may have privacy laws that differ from the laws where you live.
hippocampOS is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to hippocampOS, contact us so we can take appropriate action.
We may update this statement as the product, connectors, providers, or legal requirements change. If a change materially affects how we access, use, store, disclose, or delete Google user data or other personal information, we will provide appropriate notice and request consent where required before applying a materially different use.
The effective date at the top identifies the latest published revision.
For privacy requests, deletion requests, security concerns, or questions about this statement, contact the hippocampOS operator.
privacy@hippocampos.io