Memocore Knowledge Base
0 followers
Your guide to Memocore. Memocore is your persistent memory for AI — it saves notes, ideas, and knowledge so they stay with you across chats and tools. Here you'll learn what Memocore does and how it works, discover its features and best tips, and see real ways to use it in everyday work. Browse the articles or search for answers to the most common questions.
Shared project
This is Memocore
Memocore is the memory your AI clients share. Save something once and every assistant you use already knows it — nothing to re-explain, nothing to copy between chats.
Data Processing Agreement
Memocore's GDPR Article 28 data processing agreement for company customers — roles, security, subprocessors, breach notice, deletion, audits and international transfers.
Memocore Data Processing Agreement (DPA). Last updated: 4 August 2026. Written to be self-executing: a customer accepts it by using the Service, so no signature is needed, though we will sign a countersigned copy on request. It is drafted for GDPR Article 28 and works alongside the Terms of Service at https://memocore.ai/terms and the Privacy Policy at https://memocore.ai/privacy, not instead of them. Not reviewed by counsel. 1. WHO THIS IS BETWEEN, AND WHEN IT APPLIES This DPA is entered into between アン株式会社 (An Co., Ltd.), corporate number 8010601065441, of 新東陽ビル4階49, 東陽二丁目4番39号, 江東区, 東京都 135-0016, Japan ("Processor", "we") and the customer that has created a company workspace in Memocore ("Controller", "you"). It applies whenever you use the Service to store personal data about other people — for example when your team saves memos that name customers, employees or partners. It forms part of the Terms of Service. Where the two conflict on the handling of personal data, this DPA prevails. You accept this DPA by using the Service. If your organisation needs a signed copy, write to [email protected] and we will return one countersigned. 2. ROLES You are the controller: you decide who joins your workspace, what your team stores, and for what purpose. We are the processor: we hold and process that data to run the Service for you. For data about your own account holders — their email addresses, names and login records — we act as controller, and our Privacy Policy governs that processing. 3. OUR INSTRUCTIONS We process personal data only on your documented instructions. Your use of the Service, including the settings you choose and the integrations you enable, is such an instruction. We also process where the law we are subject to requires it; in that case we will tell you before processing unless the law forbids it. We will tell you if, in our opinion, an instruction breaches data protection law. 4. CONFIDENTIALITY Everyone we allow to process your data is bound by confidentiality obligations and is granted access only to the extent their work requires. 5. SECURITY We apply the technical and organisational measures set out in Annex II, taking account of the state of the art, the costs of implementation, and the risk to the people whose data it is. 6. SUBPROCESSORS You give us general authorisation to engage subprocessors. Those we use today are listed in Annex III and in our Privacy Policy. We will give you at least 30 days' notice before adding or replacing a subprocessor, by email to your workspace owner or by updating the Privacy Policy where the change is announced. If you object on reasonable data protection grounds within that period, we will work with you to find a solution; if we cannot, you may terminate the affected part of the Service and receive a refund of fees paid for the unused period. Each subprocessor is bound by data protection obligations no less protective than these, and we remain liable to you for their performance. 7. HELPING YOU WITH PEOPLE'S RIGHTS The Service lets you read, correct, export and delete the data in your workspace yourself, which is normally enough to answer a request from a data subject. Where it is not, we will help you with reasonable measures. If a data subject contacts us directly about data held in your projects, we will not answer on your behalf; we will pass the request to you. 8. PERSONAL DATA BREACHES We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting your data. The notice will describe what happened, the categories and approximate number of records concerned, the likely consequences and the measures taken or proposed. 9. IMPACT ASSESSMENTS We will provide reasonable assistance with data protection impact assessments and prior consultations with a supervisory authority, so far as they relate to our processing and taking account of the information available to us. 10. RETURN AND DELETION You may export your data at any time through the Service, including while a subscription is unpaid. On termination, you may delete your workspace and its contents yourself. Deleted memos move to an archive and are erased permanently 45 days later, together with attached files. If you ask us in writing before that period ends, we will delete them sooner. We keep data only where the law requires us to. 11. AUDIT We will make available the information reasonably needed to demonstrate compliance with Article 28, and will contribute to audits conducted by you or an auditor you appoint. Audits are limited to once in any twelve months unless a supervisory authority or a personal data breach requires otherwise, must be scheduled with reasonable notice and during business hours, must not disrupt the Service or the confidentiality of other customers, and are at your cost. 12. INTERNATIONAL TRANSFERS Your data is stored in Japan. For controllers in the European Economic Area and the United Kingdom, Japan benefits from an adequacy decision, so no additional safeguards are required for that storage. Where a subprocessor processes data outside Japan — in particular OpenAI in the United States — transfers rely on that subprocessor's own transfer mechanism, such as Standard Contractual Clauses in its data processing terms. For UK controllers, the UK International Data Transfer Addendum applies to those clauses. 13. LIABILITY Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service. 14. CHANGES We may update this DPA where the law, our subprocessors or the Service change. We will give at least 30 days' notice of a material change, in the same way as for the Terms of Service. ANNEX I — DETAILS OF THE PROCESSING Subject matter: provision of the Memocore persistent memory service. Duration: for as long as your workspace exists, plus the retention periods in clause 10. Nature and purpose: storing, indexing, searching, retrieving, sharing and deleting the notes and files your team saves, and making them available to the AI clients you authorise. Categories of data subjects: your personnel, and any other individuals your team chooses to mention in memos — typically customers, partners and prospects. Categories of personal data: whatever your team puts into memos, memo titles, retrieval notes, tags and attached files; plus the account data of your workspace members (email address, display name, role) and their technical data (IP address, user agent, timestamps). Special categories: none are required by the Service. Do not store them in Memocore; if your team does, you remain responsible for the additional safeguards the law demands. Frequency: continuous, for as long as your team uses the Service. ANNEX II — SECURITY MEASURES Encryption of data in transit, and encryption at rest at our hosting providers. Authentication by one-time email code; no passwords are stored. API key secrets and authentication tokens are stored only as hashes. Access control scoped by project and company role, enforced on every read and write; private files are served only through short-lived signed URLs. Rate limiting and abuse protection on authentication and API endpoints. Segregation of customer data at the record level, with every query filtered by the requester's access. Backups of the production database, restorable in the event of loss. Access by our personnel to production data is limited to those who need it to operate and support the Service, and is subject to confidentiality obligations. Deleted content is archived, then permanently erased on the schedule in clause 10. ANNEX III — SUBPROCESSORS Stripe — payment processing and subscriptions. Amazon Web Services, S3, Tokyo region — file storage. MongoDB Atlas, Tokyo region — database hosting. Postmark — transactional email delivery. OpenAI, United States — search embeddings and the in-product assistant; memo text is sent when a memo is saved or updated and when the assistant answers a question drawing on your memory. Telegram — only if you link the Telegram bot; messages you send it and memos it returns pass through Telegram's servers. Notion — only if you connect Notion; we read the pages you select in order to import them.