1. Introduction
Binary Leap OÜ ("LeapMemory", "we", "us", or "our"), a company registered in Estonia (registry code 16040964, Harju maakond, Tallinn, Lasnamäe linnaosa, Sepapaja tn 6, 15551, Estonia), operates the LeapMemory platform, a long-term memory service for AI assistants and applications. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use our website, application, APIs, connectors, and related services (collectively, the "Service").
By accessing or using the Service, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy.
2. Information we collect
We collect the following categories of information:
Account information. When you create an account, we collect your email address and a cryptographic hash of your password (we never store passwords in plain text). We generate and store API keys and connector credentials associated with your account. API keys are hashed before storage.
Memory Data. The core function of the Service is to store memories on your behalf. When you or an application you have connected submits conversation content to the Service, we process that content to extract and store structured memories: facts, statements, and the relationships between them. Memory Data includes the submitted conversation text, the extracted memories, and the associated knowledge graph. Memory Data is addressed in detail in Sections 5 and 6.
Usage data. We collect information about how you interact with the Service, including API requests made, ingestion and recall operations performed, and timestamps of these activities. This information is used for billing, plan limits, and service operation.
Technical data. We automatically collect your IP address, request headers, and connection metadata when you access the Service. This information is used for rate limiting, abuse prevention, and security monitoring.
Payment information. Payment processing is handled entirely by Paddle.com Market Limited ("Paddle"), our Merchant of Record. We do not collect, store, or process credit card numbers, bank account details, or other payment instrument data. Paddle provides us with your billing email, transaction identifiers, and subscription status.
3. How we use your information
We use the information we collect for the following purposes: (a) to provide, operate, and maintain the Service, including extracting, storing, indexing, and recalling memories on your behalf; (b) to authenticate your identity and authorize access to your resources; (c) to process transactions and manage your subscription or prepaid credits through Paddle; (d) to enforce plan limits, rate limits, detect abuse, and protect the security of the Service and its users; (e) to monitor and improve the performance and reliability of the Service; (f) to respond to your support requests and communicate with you about the Service; (g) to comply with applicable legal obligations.
We do not use your personal information for advertising, profiling, or automated decision-making that produces legal effects. We do not sell your personal information to third parties. We do not use Memory Data to train machine learning models.
4. Legal basis for processing (GDPR)
If you are located in the European Economic Area (EEA), we process your personal data under the following legal bases as defined by the General Data Protection Regulation (GDPR):
Performance of a contract. Processing your account information, Memory Data, and usage data is necessary to provide the Service as agreed under our Terms of Service.
Legitimate interests. Processing technical data for security monitoring, abuse prevention, and service improvement is necessary for our legitimate interest in operating a secure and reliable platform, provided that these interests are not overridden by your data protection rights.
Legal obligation. We may process your information where necessary to comply with applicable law, regulation, or legal process.
Consent. Where required by applicable law, we will obtain your consent before processing your personal information for purposes not covered by the bases above. You may withdraw consent at any time by contacting us at support@leapmemory.com.
5. Memory Data and your role
How we process Memory Data depends on how you use the Service:
Personal use. If you use the Service directly, for example by connecting it to an AI assistant so that it remembers your conversations, the Memory Data stored in your account relates to you. We process it solely to provide the Service to you: to extract memories from the content you submit, store them, and return them when you or your connected applications recall them.
Developer use. If you integrate the Service into your own application, the conversation content and memories you submit may relate to your end users. In that case, you are the data controller for that data and we act solely as a data processor on your instructions. You are responsible for ensuring that your collection and processing of end user data through the Service complies with all applicable data protection laws, including providing appropriate notice to your end users.
In both cases, we do not access, analyze, sell, or share Memory Data except as necessary to operate the Service (for example, to extract memories, execute recall queries, maintain search indexes, or perform backups).
6. AI processing of submitted content
To convert submitted conversation content into structured memories, the Service sends that content to a third-party large language model provider for extraction. We currently use Anthropic PBC models, accessed via OpenRouter, Inc. These providers process the content solely to return extraction results to us, acting as our sub-processors, and do not use the content to train their models.
Recall (searching and retrieving your stored memories) is performed entirely on our own infrastructure and does not involve sending your Memory Data to third-party model providers.
7. Data storage and infrastructure
The Service runs on infrastructure we operate across two locations. Primary data servers, where memory stores, search indexes, and message queues live, are dedicated physical servers hosted in our primary EMEA data center facility, a professional, access-controlled facility located outside the European Economic Area. API and edge servers, which route traffic to the primary servers, are cloud servers located in the European Union (Germany). Each account's memory store is isolated at the database level: no shared tables, no shared credentials, no shared connection strings.
Backups are stored in encrypted form on Amazon Web Services (AWS) S3 storage located in the EU (Frankfurt region).
8. Sub-processors
We engage the following categories of third-party sub-processors to provide the Service:
Data center and hosting providers (EMEA region, including the European Union). Physical server hosting and cloud infrastructure. These providers act only as infrastructure providers and do not access the content of your memory stores.
Amazon Web Services EMEA SARL (Luxembourg). S3 object storage for encrypted backups. AWS processes backup data only as a storage provider.
AI model providers (United States). Large language model processing for memory extraction, as described in Section 6.
Paddle.com Market Limited (United Kingdom). Payment processing, invoicing, and tax compliance. Paddle processes your billing information as Merchant of Record. Paddle's privacy policy is available at paddle.com/privacy.
All sub-processors are bound by data processing agreements that require them to protect your data in accordance with applicable data protection laws.
9. Data transfers
Your account information and stored Memory Data are held on our primary servers in our EMEA data center facility, located outside the European Economic Area, with API traffic routed through edge servers in the European Union (Germany). Backups are stored in encrypted form in the EU (Frankfurt). Where the GDPR applies to your data, we protect processing outside the EEA with appropriate safeguards, including encryption of data in transit and at rest, database-level isolation, and contractual commitments consistent with GDPR requirements.
During memory extraction, submitted conversation content is transmitted to AI model providers in the United States, as described in Section 6. These transfers are made under appropriate safeguards as required by the GDPR, including standard contractual clauses or an applicable adequacy framework. Extraction is transient processing: the content is sent, the extraction result is returned, and long-term storage of your Memory Data remains on our own servers.
Paddle, as a UK-based entity, processes billing data under the UK GDPR framework and the EU-UK adequacy decision.
10. Data retention
Account information. Retained for the duration of your account. Upon account termination, all data is retained for 30 days to allow recovery, after which it is permanently deleted.
Memory Data. Retained for the duration of your account; permanence is the purpose of the Service. You may delete individual memories or your entire memory store at any time, and deleted memories are removed from the primary stores and search indexes. Upon account termination, all Memory Data is permanently deleted after the 30-day grace period.
Backups. Retained according to the automated backup schedule. Deleted data may persist in encrypted backups until those backups expire under the schedule. Upon account termination, all backups are permanently deleted after the 30-day grace period.
Technical data (IP addresses, rate limit records). Retained for a maximum of 30 days for security purposes, after which it is automatically purged.
Inactive free accounts. We may terminate Free tier accounts with no activity for 12 consecutive months, subject to 30 days prior notice by email.
11. Data security
We implement the following security measures to protect your information: (a) all connections to the Service are encrypted using TLS; (b) passwords are stored using bcrypt cryptographic hashing, and we never store passwords in plain text; (c) API keys are hashed before storage; (d) backups are encrypted at rest; (e) rate limiting and IP-based abuse detection are enforced at the API layer; (f) each account's memory store is isolated at the database level from every other account.
While we implement commercially reasonable security measures to protect your data, no method of electronic storage or transmission is completely secure, and we cannot guarantee absolute security.
12. Your rights
If you are located in the European Economic Area, you have the following rights under the GDPR:
Right of access. You may request a copy of the personal data we hold about you.
Right to rectification. You may request correction of inaccurate personal data.
Right to erasure. You may request deletion of your personal data, subject to our legal obligations and the retention periods described above. You can also delete individual memories or your entire memory store directly through the Service at any time.
Right to restriction. You may request restriction of processing of your personal data under certain circumstances.
Right to data portability. You may request your personal data in a structured, commonly used, machine-readable format.
Right to object. You may object to processing based on legitimate interests.
Right to withdraw consent. Where processing is based on consent, you may withdraw consent at any time.
To exercise any of these rights, contact us at support@leapmemory.com. We will respond within 30 days of receiving your request. We may request additional information to verify your identity before processing your request.
If you believe that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or your local supervisory authority.
13. Cookies
The LeapMemory marketing website (leapmemory.com) uses only essential cookies required for basic site functionality. We do not use advertising cookies, tracking cookies, or third-party analytics services on our marketing site.
The LeapMemory application (app.leapmemory.com) uses only the cookies and local storage necessary to keep you signed in and operate the application. API access is authenticated via API keys in request headers and does not use cookies.
14. Children's privacy
The Service is not directed at individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal data from a child under 16 without parental consent, we will take steps to delete that information promptly. If you believe that we have collected information from a child under 16, please contact us at support@leapmemory.com.
15. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email to your registered address at least 30 days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated Privacy Policy.
16. Contact information
For questions about this Privacy Policy or to exercise your data protection rights, contact us at:
Harju maakond, Tallinn, Lasnamäe linnaosa, Sepapaja tn 6, 15551, Estonia
Email: support@leapmemory.com
Andmekaitse Inspektsioon
Tatari 39, 10134 Tallinn, Estonia
info@aki.ee