Privacy Policy
Effective date: August 12, 2026
Last updated: August 12, 2026
This policy explains how CALLED IT INC., doing business as MemStrata (“MemStrata,” “we,” “us”), collects, uses, discloses, and protects personal information through the MemStrata websites, desktop applications, extensions, SDKs, licensing service, support, and related enterprise services (the “Services”). It does not govern a customer’s independent use of third-party AI providers or integrations.
1. Our roles
Section titled “1. Our roles”For account, website, licensing, billing, security, support, and product-usage administration, MemStrata generally acts as a controller/business. When an enterprise customer directs MemStrata to process personal data in hosted connectors or services, the customer is the controller/business and MemStrata acts as its processor/service provider under the Data Processing Addendum. Local-only data that never reaches MemStrata remains under the customer’s control.
2. Information we process
Section titled “2. Information we process”Account and identity
Section titled “Account and identity”- Email address, OAuth provider, provider account identifier, authentication events, and account creation timestamps.
- We do not receive the user’s OAuth password. GitHub or Google handles login.
Subscription, licensing, and device administration
Section titled “Subscription, licensing, and device administration”- Stripe customer and subscription identifiers, plan, trial and billing-cycle status, invoice/webhook identifiers, and credit records.
- A per-license salt and five HMAC-derived device-component hashes, optional device label, first/last-seen timestamps, license identifier, feature entitlements, token issuance records, and security/audit events.
- We design these hashes to reduce exposure of raw hardware identifiers, but they remain personal information when linkable to an account.
Savings and reliability information
Section titled “Savings and reliability information”- If enabled and submitted during license refresh, cycle start/end dates, aggregate measured savings, and a measurement-basis breakdown used to operate the published credit policy.
- Website request information supplied automatically to the hosting/CDN layer, such as IP address, user agent, requested URL, timestamps, and security logs.
- We do not enable advertising analytics. Strictly necessary security and service logs are minimized and handled as described in this policy and our Subprocessor Notice.
Support and business communications
Section titled “Support and business communications”- Messages, attachments, contact details, troubleshooting information, contract records, and preferences that a user or customer chooses to provide.
Customer-controlled local data
Section titled “Customer-controlled local data”Depending on configuration, the application may process source code, prompts, model responses, conversation history, retrieved context, indexes, file paths, usage telemetry, and structured records on the customer’s device or systems. The standard local product does not send that content to MemStrata. It may send content to a model or connector provider selected and configured by the customer. Customers should review those providers’ terms and privacy practices.
3. Purposes and legal bases
Section titled “3. Purposes and legal bases”We process information to provide and secure accounts; authenticate and license devices; deliver trials, subscriptions, credits and support; prevent fraud and abuse; maintain records; improve reliability where diagnostics are enabled; comply with law; and establish or defend legal claims.
Where GDPR/UK GDPR applies, the legal basis is performance of contract, legitimate interests in operating and securing the Services, compliance with legal obligations, and consent where required for optional analytics, diagnostics, or marketing. Consent may be withdrawn without affecting prior lawful processing. We do not condition the core Service on unnecessary consent.
4. Disclosure and subprocessors
Section titled “4. Disclosure and subprocessors”We disclose only what is necessary to providers supporting hosting/CDN, database and serverless infrastructure, authentication, payments, transactional email, customer support, security/error monitoring, and analytics. The current list, locations, purposes and change-notice process are maintained in the Subprocessor Notice. We may also disclose information to professional advisers, to comply with lawful process, to protect rights and safety, or in a corporate transaction subject to appropriate safeguards.
We do not sell personal information or share it for cross-context behavioral advertising. By default, we do not use Customer Data, prompts, code, documents, retrieved context, model responses, or other customer content to train or fine-tune MemStrata or a third-party general-purpose model. A customer may make a separate, granular, informed, revocable opt-in to a specifically described training or research program. That opt-in must identify the data, purpose, recipient/model provider, retention period, and withdrawal effect; it may not be bundled with acceptance of these terms, installation, a paid subscription, or marketing consent. No model-training program is enabled by default. A user may withdraw a separate training consent at any time without losing the core Service.
5. International transfers
Section titled “5. International transfers”Information may be processed in Canada, the United States, and the locations listed in the Subprocessor Notice. Where required, we use adequacy decisions, the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum or Agreement, and supplementary safeguards. Enterprise customers may request relevant transfer documentation.
6. Retention
Section titled “6. Retention”We retain each category only as long as necessary for the stated purpose, contract, security, dispute, and legal obligations. OAuth state is short-lived. Account and license records are deleted or de-identified after closure subject to fraud, tax, accounting, chargeback, security, backup-expiry, and legal-hold requirements. Local data is retained according to customer configuration and is not deleted merely by cancelling a subscription. Enterprise retention terms in an Order Form or executed DPA control for their subject matter.
7. Individual rights
Section titled “7. Individual rights”Depending on location, individuals may request access, correction, deletion, portability, restriction or objection; withdraw consent; appeal a decision; and complain to a regulator. California residents may request to know, correct, or delete covered information, opt out of sale/sharing, limit covered sensitive information, and receive non-discriminatory treatment. We currently do not sell/share covered information.
Submit a request to privacy@memstrata.dev. We will authenticate requests proportionately and respond within applicable legal deadlines. Authorized agents may submit requests where permitted. If we process data solely for an enterprise customer, we will direct the request to that customer and assist it under our DPA.
8. Security and incidents
Section titled “8. Security and incidents”We use administrative, technical, and organizational safeguards appropriate to the information and risks, including least privilege, secret stores, cryptographic signing, encrypted transport, audit logging, dependency and release controls, and incident response. No system is completely secure. We will notify affected customers, individuals, and regulators when required by law and contract.
9. Children
Section titled “9. Children”The Services are designed for organizations and developers, not children. A consumer account holder must be at least 18 years old and legally able to enter the agreement. An organization may not provision the Services to a person under 18 without a separately reviewed education/guardian program and all legally required authorizations; no such program is currently offered. We do not knowingly collect personal information from anyone under 18. If notified of such collection, we will investigate, restrict the account, and delete the data as required. This conservative launch rule avoids representing that age 13 is sufficient in every country.
10. Cookies and similar technologies
Section titled “10. Cookies and similar technologies”Strictly necessary storage may be used for security, authentication, language, and session continuity. Non-essential analytics or advertising technologies are not activated until any required consent is obtained. See the Cookie Notice.
11. Automated decisions and AI transparency
Section titled “11. Automated decisions and AI transparency”MemStrata memory, retrieval, and governance features assist users and systems; they do not independently make employment, credit, housing, insurance, medical, legal, or similarly significant decisions for MemStrata. Customers must provide appropriate human oversight and notices for their use cases. Interfaces will identify AI interactions where legally required.
12. Changes
Section titled “12. Changes”We may update this policy prospectively. We will post the revision date and use reasonable additional notice for material changes. Where consent is required for a new purpose, we will obtain it before that processing.
13. Contact
Section titled “13. Contact”Controller: CALLED IT INC. (Canada corporation no. 1785099-9; Ontario OCN/BIN
1001571777)
Privacy Officer: Neeraj Yadav
Privacy: privacy@memstrata.dev
Legal notices: legal@memstrata.dev
Security reports: security@memstrata.dev
Support: support@memstrata.dev
Registered office and trader address: CALLED IT INC., 6035 Bidwell Trail, 128, Mississauga, Ontario, L5V 3E1, Canada. Any legally required local representative details will be supplied where applicable.