# Privacy Policy

**Controller:** Keynodex LLC, Florida, USA (contact@keynodex.com)
**Last updated:** 2026-09-26

Keynodex LLC publishes keynodex.com and the Keynodex Memory service. This policy
explains what we collect, why we collect it, how long we keep it, and the
choices you have. It is written in plain English and describes the system as it
actually works today.

---

## 1.0 Who we are

1.1 Keynodex LLC is a Florida limited liability company and the controller
responsible for the personal data described in this policy.

1.2 The best way to reach us about privacy is **security@keynodex.com**.
Our controller contact is **contact@keynodex.com**.

1.3 This policy covers keynodex.com, the Keynodex Memory service, and the
Keynodex connectors that let AI assistants call Memory tools. PingRep products
are separate services with their own privacy policy at pingrep.com.

---

## 2.0 The short version

2.1 We collect the minimum needed to run the website, the recruiting pipeline,
the ambassador programme, and Keynodex Memory.

2.2 We do not sell your personal data.

2.3 Your memories belong to your tenant. They are used to provide the Memory
tools — not to train Keynodex models and not for advertising.

2.4 Memory is encrypted in transit. It is not end-to-end encrypted;
section 4.4 explains exactly what that means.

2.5 You can access, export, correct, or delete your data. Section 8.0 explains
how.

---

## 3.0 What we collect

### 3.1 Visiting the website

3.1.1 Standard server logs needed to serve pages and stop abuse, plus, only with
your performance consent, page path, referring host, UTM campaign parameters and
a tab-scoped session identifier. The Cookie Policy lists every key.

### 3.2 Job applications

3.2.1 When you apply for a role: your name, email address, phone number, resume
and any links or free-text answers you submit, together with the IP address
used to submit them (for spam and abuse triage).

### 3.3 Ambassador programme, referrals, and surveys

3.3.1 Ambassador and referral records: name, email address, payout method,
tier, status, amounts and Stripe references.

3.3.2 Survey invites and responses: email address, name, referral codes,
payment amounts for paid surveys, and the free-text answers you provide.

### 3.4 Accounts, billing, and security

3.4.1 Account identifiers for the Keynodex Memory service (sign-in email,
tenant, plan, and Stripe subscription references), connector and OAuth data
needed for supported AI assistants to call the Memory tools on your behalf, and
operational and security logs used to run the service, investigate abuse, and
respond to support or legal requests.

---

## 4.0 Keynodex Memory notice

### 4.1 Memory data belongs to your tenant

4.1.1 Keynodex Memory is a model-agnostic memory service for AI assistants.
Your memories are stored for your tenant and are used to provide the memory
tools, not to train Keynodex models or sell your content.

### 4.2 What Keynodex Memory stores

4.2.1 Memory records you choose to store, including content, summaries, tags,
projects, entities, links, versions, verification metadata, and timestamps.

4.2.2 Account and billing identifiers, connector and OAuth data needed to let
supported AI assistants call the Memory tools on your behalf.

4.2.3 Operational and security logs used to run the service, investigate abuse,
and respond to support or legal requests.

### 4.3 How Keynodex Memory uses it

4.3.1 To provide tenant-scoped memory retrieval, storage, export, and deletion
workflows.

4.3.2 To enforce account access, billing entitlements, rate limits, and
connector permissions.

4.3.3 To debug, secure, and support the service when you ask for help or when
abuse or reliability issues require investigation.

### 4.4 How Keynodex Memory protects it

4.4.1 Memories are isolated per tenant and encrypted in transit. Access requires
an authenticated session scoped to your account.

4.4.2 Keynodex Memory does not use end-to-end encryption today. Authorized
operators can technically access stored data through administrative paths when
needed to operate the service, investigate abuse, comply with law, or act on
your request.

### 4.5 AI assistant handoff

4.5.1 When your assistant retrieves a memory, a copy of that memory is returned
to the assistant provider, such as Anthropic or OpenAI.

4.5.2 That provider then processes the copy under its own terms, privacy
policy, plan settings, and data-control choices.

4.5.3 Keynodex is responsible for the data we store and send through the
connector. You are responsible for configuring the assistant provider settings
for your own account or workspace.

### 4.6 Export and deletion

4.6.1 Export is part of the product promise. Self-serve open-format export is
being added to every plan, including Free.

4.6.2 Today, the `delete_memory` tool hides a memory from normal reads and
preserves a deleted record for history. For full erasure of memories or your
account, email **security@keynodex.com**. We acknowledge erasure requests
within 3 business days and target completion within 30 days.

### 4.7 Healthcare data

4.7.1 Do not store protected health information if your use requires a BAA or
HIPAA-covered workflow. HIPAA support is under review.

---

## 5.0 Why we process it, and our legal bases

5.1 **Contract.** To provide the services you sign up for, including Memory
storage and retrieval, accounts, and paid plans.

5.2 **Legitimate interests.** To secure the services, prevent abuse and spam,
debug reliability issues, and improve the website. We balance these interests
against your rights.

5.3 **Consent.** For analytics and advertising storage, which stay off until
you turn them on. You can withdraw consent at any time.

5.4 **Legal obligation.** To keep financial records for tax and accounting
purposes and to respond to lawful requests.

---

## 6.0 Who we share it with

6.1 We do not sell personal data. We share it only with service providers that
operate the services for us:

| Provider | Purpose | Data |
|---|---|---|
| Vercel | Hosting and delivery | Request logs |
| Managed Postgres | Primary database | All stored records |
| Cloudflare (R2, Turnstile) | Object storage, form security | Uploaded files, abuse signals |
| Redis | Rate limiting and caching | Short-lived keys, IP-derived counters |
| Stripe | Payments | Billing identifiers, payout details |
| Resend | Transactional email | Email address, message content |
| OpenAI | Memory processing features | Memory text sent for processing |
| Google (Tag Manager, Analytics) | Analytics, only with your consent | Usage data |
| PingRep | Tracking ingest for aggregate performance metrics, only with your performance consent | Session id, page path, referring host, UTM parameters |

6.2 When an AI assistant retrieves a memory, the assistant provider you
configured receives a copy under its own terms — see section 4.5.

6.3 We may disclose data when required by law, to protect rights and safety,
or as part of a merger or acquisition under this policy.

---

## 7.0 How long we keep it

7.1 We keep personal data only as long as needed for the purposes in this
policy, to meet legal obligations, and to resolve disputes.

7.2 Current practice, plainly stated:

- 7.2.1 **Financial records** (ambassador payouts, referrals, paid surveys) are
  kept as required for tax and accounting purposes.
- 7.2.2 **Job applications, résumés, IP addresses, and survey responses** have
  no automated purge today; records are kept while the hiring or research
  purpose remains active and are deleted on request (section 8.0).
- 7.2.3 **Security logs and rate-limit counters** are used for abuse
  prevention and forensics and are short-lived by design.

7.3 You can ask us to delete specific records at any time — section 8.0.

---

## 8.0 Your rights and how to exercise them

8.1 Depending on where you live, you may have the right to access, correct,
delete, export, or restrict processing of your personal data, and to object to
processing based on legitimate interests.

8.2 To exercise any right, email **security@keynodex.com**. Requests submitted
to security@keynodex.com are acknowledged within 3 business days and processed
within 30 calendar days.

8.3 We will not discriminate against you for exercising your privacy rights.

---

## 9.0 Cookies

9.1 Cookies and similar storage are described in the [Cookie Policy](/legal/cookies).
Analytics and advertising storage are optional and off by default. A Global
Privacy Control signal forces targeting off.

---

## 10.0 International transfers

10.1 We are based in the United States and use service providers in the United
States and other countries. Where personal data protected by GDPR or similar
laws is transferred, we rely on appropriate safeguards such as standard
contractual clauses.

---

## 11.0 Children

11.1 The services are not directed to children under 13, and we do not
knowingly collect their personal data. If you believe a child has provided us
data, contact us and we will delete it.

---

## 12.0 Changes to this policy

12.1 We will post changes on this page and update the date above. Material
changes are also surfaced in the product or by email where appropriate.

---

## 13.0 Region supplements

13.1 **EEA, UK, and Switzerland.** You have the GDPR rights described in
section 8.0, including the right to lodge a complaint with your local
supervisory authority. Where EU or UK law requires us to appoint a
representative, their contact details will be published in this section.

13.2 **United States.** California, Virginia, Colorado, Connecticut, Texas,
Oregon, Nevada, Utah, and Iowa residents have the rights described in section
8.0, including the right to opt out of sale or sharing. We do not sell personal
data.

---

## 14.0 Contact

14.1 Privacy requests: **security@keynodex.com**
14.2 Controller contact: **contact@keynodex.com**
