1. The landing site collects almost nothing. The marketing site (this page, /pricing, the demo pages) sets no cookies, runs no analytics SDK, and uses no advertising or tracking pixels. The site's "live fleet" counter fetches public aggregate counts (agents under management, memos served) from the control plane; those counts contain no personal data. The pilot inquiry form opens a pre-filled email to hello@airmemo.com on your own device; the message is sent by your mail client, and no form data is transmitted to us in the background.
2. The Service (console) collects what it must. When you enroll an org and devices, AirMemo processes: account and billing data (email, org name, billing identifiers via Stripe); memo content and metadata (author, scope, priority, expiry); device/agent identifiers and platform type; delivery receipts (proof hashes, timestamps, injection points); and audit events (actor, action, target, timestamp). This data is processed solely to provide the Service — queueing, scoping, delivering memos into agent session context, receipt generation, audit, quota enforcement, billing, and support — and only on documented instructions from your org. Full categories, roles, and retention are in the Data Processing Addendum.
3. Storage and location. AirMemo's cloud runs on Railway compute and
Neon Postgres. As of this version, processing is split between US East
(us-east-1, Postgres) and US West (us-west2, compute) — it is not
co-located, and selecting an eu region claim in the console records a
contractual commitment to migrate, not a current storage fact. See the
Security & Trust Whitepaper for the exact posture.
4. Retention and erasure. Memos are live for 90 days, then archived; receipts and audit events are append-only. On offboarding you can export your audit trail, receipts, and memo content, after which org rows and queues are hard-deleted within 30 days. Export-before-delete: we never delete without offering the export first. Details in DPA §6.
5. Telemetry. Telemetry capture is opt-in per OTel convention and off by default. Receipts (hash proofs) are the metric of record and are never derived from telemetry.
6. What we do not do. We do not sell, rent, or share personal data. We do not use it for advertising or profiling. We do not process personal data for any purpose other than providing the Service, except where law requires.
7. Security incidents. We notify affected orgs without undue delay after becoming aware of a security incident affecting their data, provide available details and a timeline for updates, and cooperate with investigation. Notification is not an admission of liability.
8. Your rights. Your org controls its data: who may push, which scopes, revocation of devices, export, and erasure, all through the Service's tooling. If you have a request we cannot fulfill through the console, contact hello@airmemo.com and we will assist within a reasonable time.
9. Changes. We will notify you by email or in-product before this policy changes in a material way. Continued use after notice constitutes acceptance; material changes to data handling follow the DPA process.
10. Contact. AirMemo — hello@airmemo.com.