Legal
This Policy explains how LeadHash LLC ("LeadHash," "we," "us"), a Virginia limited liability company, handles information in Nuramem (the "Service"). Read it with our Terms & Conditions. If you don't agree with it, don't use the Service.
Beta notice. Nuramem is in beta. The data flows and providers described here are current as of the effective date and may change; we update this Policy and its date when they do.
Nuramem stores the memory records you write and makes them available to the AI tools you connect. We host that content, and our systems and the AI providers we use read it in plaintext. That's what makes the product work.
We don't sell it, train models on it, or show ads. You can download your memory at any time. Deleting a single record retires it; deleting your account erases your personal data for real — Section 8 explains the difference honestly.
If you use email capture, other people's words end up in your memory, though not their contact details (Section 3.4). Section 9.5 is for non-users who want their information out.
LeadHash LLC is the data controller for everything processed through the Service: your account identity, the memory records made through your use of it (including from email you capture), usage and security logs, and support messages. Content you contribute to a shared project, we process for that project and its members under its access settings.
We need your account email to give you an account; everything else you write is up to you.
LeadHash LLC, Attn: PrivacyNuramem isn't built for special-category data — health, biometrics, precise location. Please don't store sensitive information you wouldn't want persisted. Email capture is the exception to "you control what goes in," because other people wrote some of it.
Every account can be issued a private address like nura-…@in.nuramem.ai. Mail that reaches it is captured: send or forward a message there, or leave the address on a thread and we capture the later replies too, until you take it off or rotate it.
What lands in your memory. Our models read the message and turn it into records in your private memory, including what other people wrote. Attachments aren't read into extraction. Captured mail can carry the contents of communications, which California treats as sensitive personal information; we use it to provide the Service and nothing else.
Substance without identity. What we keep about someone else is what they said and the name they wrote under. Email addresses, phone numbers and contact handles are removed before anything reads the message, and again from every record before it is stored; their employer domain isn't kept either. Your own addresses are the exception — the Service has to know which are yours. Our mail provider's copy is not covered: Resend stores the message as it arrived and currently can't delete it, so that copy can outlive records you delete here.
Our legal basis. Your own personal data: our contract with you. Other people's: legitimate interests (Art. 6(1)(f) GDPR / UK GDPR) — your interest in a reliable memory of correspondence you lawfully received, and ours in providing it. Ask us for a summary of that assessment.
What protects it, and what doesn't. We screen inbound mail for forged senders, spam and viruses and discard what fails, though no screen is airtight; you can block a sender or rotate the address at any time. Anyone holding that address can save to your memory and ask questions; receipts go to your account email or an address you registered as yours, which we don't verify.
Your responsibility. Capture only mail you took part in or were entitled to receive; in some places, keeping or disclosing a conversation without the other participants' knowledge is restricted by law. Not a user? Section 9.5.
Your information is held in the United States, in databases we operate on Google Cloud, with a short-lived cache of your self-model so assistants can load it quickly. Some of it sits with providers instead: sign-in credentials with Auth0 (Okta), card details with Stripe, inbound mail with Resend and Amazon SES. Backups are encrypted and expire after seven days.
We do not train AI models on your memory, and we do not sell or share your personal information. We don't make automated decisions about you that produce legal or similarly significant effects.
Nuramem works by having AI models read your content. Two providers do that for us:
What reaches them. The text you type to Nura on any surface; the text you capture, including captured email with identifiers removed first (Section 3.4); the records being synthesized or indexed; and, when Nura answers you, the parts of your memory relevant to the question. Nothing else: not your account details, not your device, sign-in, or payment information.
On what terms. Both process your content under their commercial API terms, which prohibit using it to train their models and bind them to confidentiality and security obligations that protect your content no less than this Policy does. They hold it only briefly, to process the request and for their own abuse-and-safety checks, and never for their own purposes. They are listed, with what each one touches, at nuramem.ai/subprocessors.
Your permission. In the mobile app we ask for your permission in the app, before anything is sent, and you can withdraw it at any time in Settings → AI processing, which turns chat off until you allow it again. On every other surface, the acceptance line you pass at sign-in binds your use of the Service to this Policy. Legal basis: contract (this processing is the product); in the mobile app, also your consent.
We share only as described here, and we do not sell your personal information or share it for cross-context behavioral advertising, as the CCPA/CPRA defines those terms.
Your data is stored in the United States, so using the Service from elsewhere means transferring your information here. Where we move personal data out of the EEA, UK, or Switzerland to a provider in another country, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the equivalent UK and Swiss mechanisms. Email privacy@nuramem.ai to ask which safeguards apply to a particular provider, and we'll send you a copy.
How long we keep things. Memory records and everything derived from them: until you delete them or close your account — we set no time limit of our own. Account and identity data: until you delete your account. Email-capture receipt context: 180 days. Logs: a limited period appropriate to security and debugging. Shared-project content you contributed stays with the project when you leave, because it belongs to its other members too. We may keep limited information longer where the law requires it.
What deletion does. We'd rather be precise than flattering.
GET /v1/account/export — no ticket, no waiting. For the rest of what we hold — shared-project content you contributed, email-capture settings, connected accounts, account details — email privacy@nuramem.ai and we'll send it.Access to your personal data, correction, erasure, a portable copy, restriction of how we use it, and objection to anything we base on legitimate interests, including email capture (Art. 21 GDPR) — ask, and we'll send you a summary of the assessment behind it. Where we rely on consent, you can withdraw it. You'll never be treated worse for asking.
Which of these you can enforce depends on your law. We offer them to everyone.
Email privacy@nuramem.ai. We'll verify it's you, usually by confirming you control the account email, and respond within the time the law allows — generally 30 days under GDPR and 45 under US state laws, extendable where those laws permit and we tell you why.
A Nuramem user may have captured an email you took part in, so what you wrote can sit in their private memory. What we may hold is what the message says: your words, your name, your role, and facts stated about you. We don't hold your email address or phone number: both are removed before anything is stored.
We don't write to you when this happens: we have no address to write to, we usually don't know you were on the message, and contacting everyone named in someone else's correspondence would collect more information than the capture did. This section makes the information available instead.
Email privacy@nuramem.ai to ask what we hold about you, to correct it, to stop us using it, or to have it removed — including by objecting under Art. 21 GDPR. We'll act whether or not you have an account, and you don't have to tell us who captured the message. We hold no address for you, so give us your name and enough about the correspondence to find it. Two honest limits: where a full answer would disclose someone else's private content, or where we can't tell your records from a namesake's, we'll say what we can and can't do; and our mail provider's copy of the original email is outside our ability to delete.
Traffic between you and Nuramem is encrypted in transit, and everything we store is encrypted at rest with Google-managed keys. Our services run on infrastructure we operate inside a private network.
Your memory is isolated from every other user's, and the database enforces that isolation itself rather than leaving it to our code, so a coding mistake can't hand your records to someone else. Search runs through an access-controlled path that fails closed if it can't identify you. Our services hold only the access they need, credentials live in a managed secret store, backups are encrypted, and administrative access is limited.
Two things we won't dress up: mail arriving over SMTP is encrypted only if the sending server negotiates it, which is outside our control; and no system is perfectly secure. You're responsible for your own credentials and for the AI tools you connect.
The Service isn't for children. You must be at least 16 to use it, and we don't knowingly collect personal information from anyone under 16 — or, in the United States, under 13. If you think a child's information has reached us, email privacy@nuramem.ai and we'll delete it.
We'll update this Policy as the product changes. When a change is material we'll move the "Last updated" date and give you notice by email or in the product. How you accept changes to the agreement itself is set out in Section 14 of the Terms.
Questions, requests, or complaints: privacy@nuramem.ai, or the postal address in Section 2.
This document describes how Nuramem actually handles your information. It is not legal advice.