Privacy Policy
Last updated: August 21, 2026
Pensyve ("we", "us", "our") operates the pensyve.com website and the Pensyve managed memory service. This Privacy Policy explains how we collect, use, and protect your information when you use our services.
1. Data We Store
When you use the Pensyve managed service, we may store:
- Memory content — text, code, or other content you store as memories
- Embeddings — vector representations generated from your memory content for similarity search
- Metadata — tags, namespaces, entity associations, importance scores, and other structured fields
- Access timestamps — when memories were created, last accessed, and last modified
- Account information — email address, name, and authentication provider details
2. How Memory Data Is Processed
Pensyve offers two deployment modes with different data handling:
- Local engine (open source) — all memory content is stored locally in SQLite on your device. No data is sent to our servers. Processing happens entirely on your machine.
- Managed service — memory content is stored in our cloud infrastructure (AWS). Data is encrypted in transit (TLS 1.2+) and at rest. Embeddings are generated server-side and stored alongside your memories.
3. Your Rights (GDPR)
If you are in the European Economic Area, you have the following rights under GDPR:
- Right of access — request a copy of all personal data we hold about you
- Right to erasure — request deletion of your account and all associated memories, embeddings, and metadata
- Right to export — download your memory data in a portable format (JSON)
- Right to portability — receive your data in a structured, machine-readable format for transfer to another service
- Right to rectification — update or correct your personal data at any time
To exercise any of these rights, contact us at support@major7apps.com. We will respond within 30 days.
4. Data Retention
Memories persist until you explicitly delete them or submit a GDPR erasure request. When you delete a memory, it is removed from our database and associated embeddings are permanently deleted. Account deletion removes all associated data within 30 days.
5. Third-Party Processors
We use the following third-party services to operate Pensyve:
- Amazon Web Services (AWS) — cloud infrastructure, compute, and storage
- Stripe — payment processing and billing
- Neon — managed PostgreSQL database
- Google Analytics — aggregate website usage analytics
- Ahrefs — cookie-free aggregate website analytics using page URLs, referrers, browser and device details, language, and city-level location; raw IP addresses are discarded
Each processor is bound by data processing agreements and processes data only as necessary to provide their respective services. Website analytics are disabled on sign-in, account, dashboard, admin, checkout, and OAuth routes.
6. Cookies
Pensyve uses Auth.js session cookies to maintain your login state. Google Analytics uses first-party cookies for aggregate usage statistics. Ahrefs Web Analytics is cookie-free by default and does not store raw IP addresses or persistent identifiers. We do not use advertising cookies.
7. Contact
For privacy-related inquiries, data requests, or concerns, contact us at support@major7apps.com.