Skip to content Mpalo Logo Spiral

Privacy Policy

Memory Is Not Inventory

Effective August 26, 2026. This policy follows memory through collection, transformation, access, export and deletion. It names the representations created from what you provide because the raw text is not the whole privacy object.

Version history

We keep every published version of this policy on this site.

Current: Version 1.1, effective August 26, 2026.

Previous: Version 1.0, effective August 26, 2026. This revision adds the Protected Memory Data definition, derived-data rights, lineage-aware deletion, and the consumer and commercial role distinction.

Purpose and roles

Mpalo Inc. builds systems for preserving, representing and using memory across time. Memory can contain some of the most intimate information a person creates. This policy explains what we process, what we create from it, why each category exists, how long it lasts, who may access it, and what happens when you ask us to delete it.

Mpalo Inc. is a Delaware Public Benefit Corporation. Our charter states that Mpalo exists to pursue, with honesty and precision, the question of what it means to preserve, represent, and augment a human mind. A representation is not the person. Greater technical understanding of a person does not give Mpalo greater moral authority over them.

When you use the Mind Platform directly, Mpalo ordinarily determines the purposes and means of processing and acts as the controller or equivalent responsible business under applicable law. When an organization uses the Palo Bloom API under its instructions, Mpalo ordinarily acts as that organization's processor or service provider for that data. The organization remains responsible for its notice, permissions and instructions. A Data Processing Addendum applies when one is agreed for that use.

Privacy questions and requests: privacy@mpalo.com. Operational support runs through the support desk.

What we do not do

  • We do not sell user memory data.
  • We do not use Protected Memory Data for advertising or behavioral profiling.
  • We do not make a new optional research or shared-model training purpose part of ordinary service operation without the additional notice and authorization required by the Privacy Policy.
  • We do not transfer user memory data to an acquirer under the Open Decay Protocol.

Protected Memory Data

Protected Memory Data means memory you provide and representations Mpalo creates from it while they remain associated with you, your account, your workspace, or an identifiable person.

  • Source memory. Conversations, notes, recollections, files, images, recordings where supported, and related metadata.
  • Portable representations. Embeddings or other representations intentionally made available for export or independent use.
  • Generated representations. Summaries, reconstructions, temporal information, episode relationships, labels, relevance or confidence signals, and other derived context where a feature creates them.
  • Internal representations. Semantic and episodic latent states, retrieval indexes, caches, graph data and other technical states needed to operate memory. Calling a representation internal, derived, pseudonymous or latent does not remove it from these protections while Mpalo can reasonably associate it with a person.
  • Future sensitive inputs. If a specific product or research study supports neural signals, health-related information or another especially sensitive category, that feature receives a separate notice and eligibility or consent flow before collection begins.

Other information we process

  • Account and authentication. Email address, optional profile and recovery details, password verifier, OAuth provider identifier, passkey public key, MFA material and recovery-code hashes.
  • Billing. Plan state and payment-provider identifiers. Payment-card information is handled by the payment provider and does not pass through Mpalo's ordinary application storage.
  • Support and communications. Ticket text, attachments, replies, transactional email records and security notices.
  • Security and diagnostics. Login outcomes, sessions, device and IP information, rate-limiting values, revoked-token identifiers, error records and optional diagnostics. These exist to operate and protect the service.
  • Connections you configure. Provider keys and requests sent to an inference or storage provider you choose. That provider may process what you direct to it under its own terms.

Why we process information

We process information to provide the service you request, create and retrieve memories, maintain security and integrity, answer support and privacy requests, manage billing, meet legal obligations, and operate features you enable. Where applicable law requires a lawful basis, the basis depends on the purpose. Core service processing may be necessary to perform our contract. Security and narrowly defined operational processing may rely on legal obligations or legitimate interests. Optional processing is identified separately.

Consent is a condition of operation for material memory and cognition processing under Mpalo's charter. That internal principle is broader than any one statutory legal basis. Accepting general terms does not, by itself, authorize a new category of cognitive representation, research study, neural collection or materially different use. We provide an additional notice and an affirmative choice where our doctrine or applicable law requires one. Declining optional processing does not disable unrelated service functions.

Training and research

The Mind Platform exposes a training-use preference. That preference is the operative choice for eligible conversation content. When it is disabled, we do not enroll newly processed eligible content in that use. Turning it off stops new enrollment going forward. We do not describe deletion from a completed training run or model as fully reversible unless we can verify it. Any new training purpose or materially broader category receives a separate notice and authorization where required.

Product operation and research are different purposes. Participation in a research study involving Protected Memory Data requires a study-specific notice describing the purpose, risks, data categories, retention, publication rules and withdrawal process. Neural, dream, cognitive-influence and other highly intimate human-subject research is not authorized by an ordinary product account.

Human access

Mpalo does not provide employees with unrestricted access to Protected Memory Data. Staff may access information when necessary for a defined purpose such as a support request you initiated, a security or abuse investigation, a technical incident, a legal obligation or separately authorized research. Access is limited by role, subject to confidentiality obligations, and logged where the relevant system supports access logging. Exceptional access receives additional review.

Service providers and transfers

As of this revision, Mpalo uses Cloudflare for hosting, storage, compute and bot defense; Stripe for payments; Resend for transactional email; and Twilio Lookup for one-time phone validation. We may use other providers for authentication, security, communications or infrastructure. We require providers engaged by Mpalo to process information only for the service purposes and instructions established in their agreements. We publish material provider and processing-region changes through the relevant service documentation.

If you independently configure a third-party inference or storage provider, it is a user-directed connection, not an Mpalo subprocessor. We show the connection before activation. Information sent through it may also be governed by that provider's privacy terms.

When personal information is transferred internationally, Mpalo uses a transfer mechanism required by applicable law, which may include an adequacy decision, approved contractual clauses or another lawful mechanism.

Export and access

You can request access to, correction of or deletion of your personal information. We provide these processes to all users, subject to account security, the rights of other people and legally required retention.

A standard memory export includes source memories, available metadata, user-facing summaries, Portable Representations intentionally created for independent use, and a machine-readable manifest describing formats and representation versions. Some proprietary internal Bloom states are not exposed as raw model artifacts. That does not limit an access right that applicable law gives you. We respond to requests for derived information in a form consistent with applicable law while protecting other people's rights, system security and legitimate trade secrets.

Memories can concern people who never created an Mpalo account. We may limit export or access where necessary to protect another person's legal rights or safety.

Deletion and retention

Deleting a memory is a request to remove more than its visible source record. Mpalo treats deletion as a request to remove the source memory and the reconstructive representations derived from it, including Portable Representations retained by Mpalo, internal semantic and episodic representations, generated summaries, graph relationships, retrieval indexes and caches. Where a derived object also depends on memories you kept, we delete the contribution attributable to the deleted memory or recompute the object without it.

Active deletion begins after the request is authenticated. We retain only the minimum operational record needed to complete and verify the request. Backups expire on their normal schedule, and recovery procedures are designed not to reintroduce records deleted before restoration. Where the product exposes a deletion status or backup deadline, that status is the operative record.

Verification codes expire in minutes. Security counters, anti-forgery values and similar short-lived records expire within hours. Revoked tokens age out naturally. Support records are retained for the account or issue lifecycle and then reviewed for deletion. Account deletion ends the subscription relationship and starts removal of stored content from active systems.

We may retain narrowly limited information when law requires it. Such information is isolated from ordinary product, research and training use and is deleted when the obligation ends.

Open Decay Protocol

Mpalo's charter commitment is exact: if Mpalo is ever acquired or changes ownership, all user memory data is automatically deleted. It is not transferred to any acquiring entity. You cannot acquire Mpalo and receive its users' memories.

For this policy, user memory data includes Protected Memory Data and the linked source, portable, internal, graph, summary, index, cache and training representations Mpalo holds. A successor does not receive an independent license to use that data for a product, advertising, training or other commercial purpose. Information that Mpalo is legally prohibited from deleting remains isolated and is used only for the legally required purpose until the restriction ends.

Your choices

In Mind Platform settings you can manage location metadata, training use and anonymous diagnostics. You can view and delete memories, export available data, rotate credentials and end sessions remotely. You can also withdraw an optional consent by using the control that collected it or by writing to privacy@mpalo.com. We do not discriminate against you for exercising a privacy right.

Cookies

At the effective date, the site uses functional cookies and local storage only. We do not use advertising cookies, cross-site pixels or behavioral analytics.

NamePurposeLifetime
authToken / refreshTokenKeeping you signed in.Session to months, depending on your sign-in choice.
__Host-csrf-tokenCross-site request forgery defense.One hour.
themeRemembering light or dark preference.Until site data is cleared.

Security and incidents

We use measures appropriate to the sensitivity, volume and purpose of the information we process. They include encryption, identity and access controls, security logging, secrets management, vulnerability management, incident response, backup protection and review of privileged access. Current implementation details and certifications are described separately on our Safety & Security page. We do not imply a certification we do not hold.

We notify regulators, customers and affected people when applicable law requires notification. Where we can provide additional information without increasing security risk, compromising an investigation or violating law, we publish what occurred and what we changed.

Government requests

We disclose Protected Memory Data only when required by applicable law or valid legal process, or in a narrowly defined emergency where disclosure is legally permitted and necessary to address an imminent threat. We review requests for validity and scope and seek to narrow or challenge overbroad requests where legally permitted. We notify affected users before disclosure unless law prohibits notice or an emergency makes prior notice impracticable.

Changes to this policy

We preserve every published version of this policy. Material changes receive a new version, a summary and notice inside the product for signed-in users. If a change materially expands how existing Protected Memory Data may be used, continued use alone does not authorize a new optional purpose that requires consent. That processing begins only after the required authorization.

Contact and complaints

Mpalo Inc., Attn: Privacy.
Privacy requests and questions: privacy@mpalo.com