Privacy Policy / Datenschutzerklärung

Privacy PolicymemTITAN® application

Article-by-article privacy policy · Switzerland · Last updated 28 July 2026

Article 1

Controller and contact

The controller responsible for data processing in connection with memTITAN® is:

Product: memTITAN®
Country: Switzerland
Provider: Katarina Jovanov
Postal address: Dorfstrasse 8, 8322 Russikon ZH, Switzerland
Email: info@memtitan.ai
Website: https://memtitan.ai

Privacy requests and questions about the processing of personal data can be sent to info@memtitan.ai.

Article 2

Summary

memTITAN® is local-first, user-controlled AI software that functions as a memory agent and curator. The personal Core runs on the user's own device.

Personal memories, conversations, uploaded screenshots, documents, local contexts and local memory indexes are not automatically transferred to memTITAN® and are not stored in a central memTITAN® cloud memory account.

This Privacy Policy covers personal data for which memTITAN® determines the purpose and means of processing, in particular data connected with the website, Early Access and support communication, the official relay, product distribution and consent-based website analytics. Content that remains exclusively in the user's personal Core is not accessible to memTITAN®.

Article 3

Local-first processing in the personal Core

The memTITAN® Core processes and stores data locally on the user's device. This may include:

  • chat messages between the user and memTITAN®
  • personal facts shared by the user, such as name, pets, preferences, relationships, corrections or work context
  • local memory stores and search indexes
  • local conversation and context data
  • uploaded images, screenshots or text for OCR/text recognition
  • documents, notes or research sources added by the user
  • locally generated security data, such as Core access keys
  • local settings, such as Desktop/Mobile pairing information

These local contents are not automatically transferred to memTITAN® and are not stored in a central memTITAN® account.

Local content may include sensitive personal data if the user chooses to store it, for example health-related notes, private communications or information about personal beliefs. Such content remains under the user's control in the personal Core and is not disclosed to memTITAN® unless the user deliberately transmits it, for example in a support request or through an external service selected by the user.

Article 4

Mobile application and connection to the Core

The mobile memTITAN® application can connect to the memTITAN® Core. For this connection, the application may locally store technical connection data, such as the Core address or server URL, pairing status and technical session information.

Depending on the features used, the application may also store information locally on the mobile device, including saved contacts, conversation context, recent upload references, calendar links, a local action history and onboarding or interface preferences. This information remains on the user’s device and is not automatically transmitted to memTITAN®.

Private cryptographic keys are not stored in ordinary application storage. On mobile devices, they are stored using the secure key storage provided by the operating system.

The Android application is configured to exclude its locally stored application data from automatic platform cloud backups. User-controlled backups, recovery copies and exports of data stored in the personal Core are not affected.

Article 5

Local connection and official relay

The mobile application can connect to the user's own Core on the same local network or through the official memTITAN® relay for remote access.

Both connection paths use the memTITAN® Connect protocol. After pairing, private content—including chat messages, memories, images, documents, meeting notes and AI answers—is transmitted only as end-to-end encrypted data packets. Private cryptographic keys remain on the user’s devices.

The official memTITAN® relay is hosted in Switzerland. To establish and operate a connection, the relay processes limited technical pairing, session and routing data, such as pairing information, public keys, temporary identifiers, request identifiers, timestamps and encrypted data packets.

The relay does not store personal Core memory and cannot decrypt the end-to-end encrypted content or access private cryptographic keys or the local Core access key.

Article 6

End-to-end encryption

For encrypted remote access, memTITAN® uses established cryptographic methods. Private keys do not leave the respective device.

  • Core and application generate local keys.
  • Only public keys are exchanged during pairing.
  • The pairing code is not an encryption key.
  • Session keys are derived locally on the devices.
  • Message packets are authenticated and encrypted.
  • The official relay stores no private keys and cannot decrypt content.

There is no plaintext fallback through the relay if end-to-end encryption is unavailable.

Article 7

No Core or application telemetry

The memTITAN® Core and application do not send telemetry, usage analytics or automatic crash reports to memTITAN®. In particular, memTITAN® does not automatically transmit chat messages, stored memories, uploaded images/documents, usage behavior or local debug logs.

If optional diagnostics or crash reporting are introduced later, this policy will be updated first and the function will be described transparently.

Article 8

Website, domain, downloads and Early Access

The website memtitan.ai and the controller's email infrastructure are hosted in Switzerland by Swiss hosting and infrastructure providers. When visiting the website or downloading memTITAN®, technically necessary access data may be processed, such as IP address, time of request, requested page or file, browser, operating system, referrer URL and technical server logs.

Technical hosting logs are used only for security, operation and troubleshooting and are normally deleted after 7 days unless longer retention is legally required or necessary for a security investigation.

The Early Access form transmits the first name, last name, email address and selected platform to the Infomaniak Newsletter service operated by Infomaniak Network SA in Switzerland. These details are required to identify and manage Beta and Early Access registrations, provide private Beta download access, and send Early Access, launch and availability-related messages. Registration uses double opt-in and becomes active only after the user confirms the email address. To protect the form against automated abuse, Infomaniak may also process technical request data such as IP address, timestamp and the result of the anti-abuse challenge. Consent may be withdrawn at any time through the unsubscribe link in an email or by contacting info@memtitan.ai.

Download files are not publicly available in the web root. In accordance with the current purchase information on the landing page, private download access is provided after payment confirmation once the planned hosted checkout is active.

Article 9

Payment processing

The current landing page offers Early Access registration. No payment is currently taken on the landing page, and the Early Access form is not a checkout. The website does not currently collect or store payment-card details.

The landing page announces a planned hosted checkout supporting TWINT, PayPal and credit cards. Once the hosted checkout is activated, payment and transaction data will be entered directly with and processed by the selected payment provider. Complete payment-card details will not be stored on the memTITAN® website. Private download access will be provided after payment confirmation.

Before the hosted checkout is activated, this Privacy Policy will be updated to identify the selected payment provider, the categories of data processed, the purposes and legal basis, the applicable retention period, the recipient countries and any safeguards used for disclosures abroad.

Article 10

Website analytics and cookies

The memTITAN® website uses Google Analytics 4 (“GA4”), supplied in Europe by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, only after the user has actively allowed analytics. If analytics is declined or no choice has been made, the Google Analytics script is not loaded and no GA4 measurement is performed.

GA4 is used to understand aggregated website use and improve pages, navigation and product information. Depending on the interaction, GA4 may process an online identifier, approximate location, browser and device information, operating system, language, referrer, pages viewed, timestamps, session information and website interactions. An IP address is technically received when a connection is established. Google states that, for traffic from Switzerland, the European Union and the United Kingdom, the IP address is used only to derive approximate location information and is then immediately discarded without being logged or stored by Google Analytics. memTITAN® does not send personal Core content, memory data, chat content, uploaded screenshots, documents or local memory indexes to GA4.

After consent, GA4 may set the first-party cookies _ga and _ga_<container-id> to distinguish visitors and sessions. Google specifies a default lifetime of up to two years, although browsers may impose a shorter period and users can delete the cookies earlier. Event-level data in the GA4 property is retained for no longer than 14 months; aggregated reporting data may be retained for a longer period.

The necessary privacy-choice value memtitan_analytics_consent is stored locally in the browser so that the website remembers whether analytics was allowed or declined. It remains until the user changes the choice or deletes browser storage.

Consent can be refused without disadvantage and withdrawn at any time through the “Privacy settings” control displayed on the website. Withdrawal prevents future GA4 loading and removes GA cookies accessible to the website. Processing already carried out before withdrawal remains lawful.

Technical server and security logs generated when the website is accessed are not analytics cookies. They are processed only to provide, protect and troubleshoot the website. Further information about Google's processing is available in the Google Privacy Policy.

Article 11

Application stores and platform providers

If memTITAN® is downloaded through application stores or platforms, those providers may process their own data, such as account, device, payment, download or diagnostic information. That processing is governed by the privacy terms of the respective platform provider.

Application-store data safety and privacy label information must be kept aligned with this Privacy Policy and the actual technical implementation before any store publication. A public user-facing summary is available in the Data Safety Summary.

Article 12

External services and device-based actions

memTITAN® may prepare device actions such as email drafts, messaging drafts, calendar entries, map routes or meeting reminders.

memTITAN® does not send such contents automatically. The relevant application is opened as a draft, link or system action. The user decides whether to send a message, save an event or open a route.

If external applications or services are used, such as messaging applications, email providers, map services or calendar services, their own privacy terms apply.

Article 13

Research, news and external sources

For research or news features, memTITAN® may retrieve public sources, websites or feeds. External sources may see technical access data such as IP address, timestamp and requested URL of the requesting device or server.

Automatically found research content is not added to usable personal memory without user approval.

Article 14

Legal bases and purposes

Processing is carried out in particular for the following purposes:

  • providing the website and product information
  • handling Early Access, support and contact requests
  • providing and operating the personal Core and the mobile connection
  • technical operation of the official relay
  • technical security, troubleshooting and abuse prevention
  • managing the Early Access list and sending Early Access, launch and availability-related messages after double-opt-in consent, and providing private downloads
  • measuring and improving website use with GA4 after consent
  • preparing device-based actions at the user's request

Where the GDPR applies, processing is based in particular on Art. 6(1)(b) GDPR where processing is necessary to provide application functions or perform pre-contractual measures, Art. 6(1)(f) GDPR where processing is necessary for security, stability, abuse prevention and technical operation, and Art. 6(1)(a) GDPR where consent is required for optional functions. Where the GDPR applies, Early Access communications are based on consent pursuant to Art. 6(1)(a) GDPR. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Where Swiss data protection law applies, personal data is processed in accordance with the Swiss Federal Act on Data Protection (FADP), including the applicable principles of lawfulness, transparency, purpose limitation, proportionality, data security and data protection by design and by default. Where the GDPR applies pursuant to its territorial scope, personal data is additionally processed in accordance with the GDPR.

Article 15

Switzerland, EU and international transfers

The current website and controller email infrastructure are operated in Switzerland. Website fonts are hosted locally and do not disclose visitor data to an external font provider.

memTITAN® is based in Switzerland. The European Commission recognizes Switzerland as providing an adequate level of data protection, which generally allows personal data to flow from the EU/EEA to Switzerland without additional transfer safeguards.

If the user consents to GA4, analytics data is disclosed to Google Ireland Limited and may also be processed by Google group companies and service providers in the United States and other locations in which Google or its subprocessors operate. Google states that Google LLC and its covered United States subsidiaries participate in the Swiss–U.S. and EU–U.S. Data Privacy Frameworks and that Standard Contractual Clauses may be used for transfers not covered by an applicable adequacy framework. Further information is available in Google's information on international data transfers for advertising and analytics products.

Where memTITAN® offers goods or services to persons in the EU/EEA or monitors their behavior within the territorial scope of the GDPR, the GDPR applies to the relevant processing in addition to Swiss data protection law. Where an EU representative or another contact arrangement is legally required, the corresponding details will be published before the relevant processing begins.

If a user deliberately follows an external link, uses an external application or sends an email through their own provider, that third party may process data in another country under its own privacy terms. Any future disclosure by memTITAN® to a recipient abroad will be identified together with the destination country and, where required, the applicable safeguard before the relevant processing begins.

Article 16

Retention and deletion

Local data remains on the user's device until it is deleted, the application is uninstalled, the Core is reset or the local data area is removed.

The official memTITAN® relay creates limited technical relay logs for security, abuse prevention, reliability and troubleshooting. Ordinary technical relay logs are retained for a maximum of 7 days unless longer retention is legally required or necessary for security investigation.

Technical website hosting logs are normally deleted after 7 days. Website or relay logs may be retained for longer only where this is legally required or necessary to investigate a specific security incident.

Confirmed Early Access registration data is retained until consent is withdrawn or until 12 months after the Early Access programme ends, whichever occurs first. If the contact becomes a customer, any further retention is governed by the purposes and periods applicable to the customer relationship.

Unconfirmed Early Access registrations are not added to the active mailing list and do not receive Early Access or launch communications. Data relating to an unconfirmed registration is retained by the newsletter service only for as long as necessary to complete and document the double-opt-in process, prevent abuse, or comply with applicable legal obligations, and is deleted when it is no longer required for those purposes. Infomaniak's publicly available Newsletter documentation and Privacy Policy do not state a more specific technical deletion period for unconfirmed registrations.

Article 17

Recipients and service providers

Depending on use, the following service providers or categories of service providers may be involved:

  • Swiss hosting, DNS and email infrastructure providers
  • Swiss infrastructure providers used for the official relay
  • Google Ireland Limited and associated Google processors for GA4, but only after analytics consent
  • Infomaniak Network SA, Switzerland, as processor for the Early Access form, double-opt-in confirmation and subscriber-list management
  • email providers involved when a user sends a support or other direct email
  • application store and platform providers, where the application is provided through stores or platforms
  • external applications and services if users perform a corresponding device-based action

Once the planned hosted checkout is activated, the selected payment provider will be added to this list before payment processing begins.

Data is disclosed only to the extent required for operation, communication, security or legal obligations and, after activation of the hosted checkout, for payment processing requested by the user.

Article 18

Data security

memTITAN® follows a local-first approach. Personal memory content should remain in the private Core. Technical safeguards may include access keys, secure operating system storage, local storage, restricted download provision, encryption and separate processing of content data and technical connection data.

memTITAN® does not use website, relay or support data to make automated decisions that produce legal or similarly significant effects for individuals.

Users should protect computers and mobile devices with a device PIN, password or biometric lock, keep pairing codes confidential, use memTITAN® only on trusted devices and reset connections if a device is lost or compromised.

Despite technical and organizational safeguards, complete security cannot be guaranteed.

Article 19

Rights of data subjects

Individuals may exercise the data protection rights available to them under applicable law, including, where applicable, access, rectification, deletion, restriction of processing, data portability, objection and withdrawal of consent.

Because most memTITAN® data is stored locally on the user's own device, many rights can be exercised directly by viewing, changing or deleting local data.

For data actually processed by memTITAN®, such as website or relay metadata, requests can be sent to info@memtitan.ai.

Individuals protected by the Swiss FADP may contact the Swiss Federal Data Protection and Information Commissioner (FDPIC). Where the GDPR applies, individuals may lodge a complaint with the competent supervisory authority in the relevant EEA Member State. Individuals in other jurisdictions may exercise the rights and remedies provided by the data protection laws applicable to them.