Privacy
last updated · june 2026
No tracking
This marketing site uses no tracking cookies, no analytics, and no third-party trackers, and collects no personal data. See Cookies & browser storage below for the small amount of functional storage the optional Brain Cloud app uses.
Local-first by default
By default, all memory data is stored locally in ~/.brain/ on your machine and never leaves it. Syncing is always opt-in: the /brain:sync feature can push your memories to a Git remote of your choosing, to a single encrypted export file, or to the optional hosted Brain Cloud (below). If you never enable a sync provider, nothing is ever sent to external servers.
Brain Cloud & the Claude connector
Brain Cloud (the optional hosted sync hub) and the Claude connector (a remote MCP server that lets Claude apps recall and write your memories) are entirely optional. When you choose to use them:
- What we store: only the brain you sync (your Markdown memory files and their index) and the minimum account identity needed to sign you in — your Google account, via Firebase authentication. We do not collect your Claude conversations, chat history, prompts, or other files. The
brain_memorizetool stores only the specific content you ask to remember — never the whole conversation. - Encrypted at rest. Brains in Brain Cloud are encrypted on disk with AES-256-GCM using a per-user key that is wrapped by Google Cloud KMS (the key is hosted in the EU). The connector keeps your working copy on an in-memory (RAM-backed) store and purges it after a period of inactivity, so it is not retained on the connector's disk.
- Encrypted in transit. All traffic to Brain Cloud and the connector is HTTPS/TLS.
- Strict isolation. Every request is authorized against the signed-in account; one account can never read or write another's brain.
- Revocable access. Sessions use rotating tokens with reuse detection; you can log out one device or all devices, and revoke the connector's access from your Claude account, at any time.
Because recall runs server-side, this is server-side encryption at rest, not end-to-end encryption — the service necessarily processes your memories in memory to score them. If you require that no server ever sees your memories in plaintext, keep your brain local-only (the default) or use Git/export sync with a passphrase.
Where your data lives & who processes it
Brain Cloud is hosted in the European Union, and your synced brains are stored and backed up within the EU. We rely on a small set of sub-processors, solely to operate the Service:
- Contabo (Germany, EU) — server hosting for Brain Cloud and the connector.
- Cloudflare — TLS/CDN and encrypted off-site backups (Cloudflare R2, EU-jurisdiction bucket). Backups contain only ciphertext.
- Google Cloud KMS (EU) — manages the keys that encrypt your brains at rest; key material never leaves KMS.
- Google Firebase Authentication — sign-in (your Google account identity only).
- Stripe — payment processing for paid subscriptions. We never see or store your full card details.
Firebase and Stripe are global providers that may process limited data (your account identity; billing details) outside the EU. Where that happens, those transfers rely on the providers' standard safeguards, such as the EU Standard Contractual Clauses and applicable adequacy decisions. We use no third-party advertising or analytics processors.
Cookies & browser storage
The marketing site (brainmemory.ai) sets no cookies and runs no analytics; the only thing it stores in your browser is a small local flag remembering that you dismissed the privacy notice.
The Brain Cloud dashboard uses only strictly necessary browser storage to work — your sign-in session (via Firebase) and your theme preference. None of it is used for tracking, advertising, or cross-site profiling, so no cookie-consent banner is required. We run no third-party analytics or tracking cookies anywhere.
Retention, export & deletion
Your memories are yours. You can export your entire brain to a single (optionally encrypted) file at any time with /brain:sync export, archive or forensically erase individual memories with /brain:forget, and delete a synced brain or your whole account from the Brain Cloud dashboard — which removes the stored brain from our systems. Deleting locally never requires the cloud, and deleting from the cloud never touches your local copy.
We keep your synced brain for as long as your account is active. When you delete a brain or your account, it is removed from our live systems right away and purged from our encrypted backups within 30 days (our backup-retention window). We may retain limited billing and account records longer where the law requires it (for example, tax and accounting obligations).
No telemetry
The brain-memory npm package collects no telemetry, usage data, or analytics. It operates entirely offline using local file I/O.
Who's responsible & your rights (GDPR)
Omelas (omelas.tech), a sole proprietorship (eenmanszaak) established in the Netherlands (KvK 98455303, VAT NL005331814B35), is the data controller for the personal data processed by Brain Cloud and the connector. We process that data to provide the Service you asked for (to perform our contract with you), and on the basis of your consent where that applies. We do not sell your data and do not use it to train models.
Registered address: Petrus Dondersstraat 80, 5614 AJ Eindhoven, The Netherlands.
If you are in the EU/EEA, the GDPR gives you the right to:
- access the personal data we hold about you and receive a copy;
- have inaccurate data corrected;
- have your data erased (the “right to be forgotten”);
- restrict or object to certain processing;
- receive your data in a portable format — the
/brain:sync exportcommand does exactly this on demand; and - withdraw consent at any time, without affecting processing already carried out.
You can exercise most of these yourself at any time — export your brain, /brain:forget a memory, or delete your brain or whole account from the Brain Cloud dashboard — or email us at support@omelas.tech and we will respond within 30 days. If you believe we have mishandled your data, you may also lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens.