Privacy Policy — Draft

This draft is written by the engineering team and does not constitute legal advice. It will be reviewed by a qualified lawyer before formal publication or submission for Anthropic Connector Directory review. It reflects what's actually deployed today (updated September 2026, once the API-key and OAuth 2.1 remote services went live) — nothing here describes a feature that doesn't exist yet.

1. What we collect

Local mode (the memory-core-mcp stdio server)

The text you import or type, the entities and relations extracted from it, and its source/provenance (which passage, when) — stored in a SQLite file on your own machine. Nothing is uploaded automatically.

Cloud remote mode (api.yliuai.com — both access paths share the same data)

2. What we don't collect

3. Which third parties your data passes through

Extracting memories requires an LLM call; retrieval requires an embedding model — the data flow differs for each, stated plainly:

4. Your rights: export and delete

5. How long we keep data

6. Encryption and transport security — stated honestly

7. Contact

A public contact channel hasn't been decided yet — this section is a placeholder. Anthropic's review process requires a privacy policy to include a real contact method, so this must be filled in with a real, intentionally-public channel before this policy is submitted for Connector Directory review or otherwise formally published.

8. Known gaps (to address, or at minimum disclose, before formal publication / review submission)

9. Compliance claims we deliberately don't make

We don't claim this product is "GDPR compliant" or "legally mandated to protect your data" — export and delete are product principles we chose on our own, ahead of where regulation currently stands, not an existing compliance benefit we're taking credit for (GDPR Article 20's data-portability right doesn't clearly cover AI-inferred personal profiles/memories today — which is exactly the gap we think is worth covering proactively).