Mnemor

Security

Last updated: 29 July 2026

Mnemor aggregates your mail, messages, calendar and code activity into one place. That concentration is exactly why its security model starts from a simple premise: keep the data on the device, and give you the controls.

Architecture in one line. There is no Mnemor account, no user database and no server-side copy of your content. The app talks directly to the services you connect; our only server hands out an AI key and completes OAuth handshakes.

Data at rest

Data in transit

Access control on the device

AI controls

For the step-by-step version — every workflow in the app, each step labelled with whether it runs on rules, on-device, from cache or in the cloud, plus a complete list of every AI call the app can make — see how it works.

Auditability

The in-app Activity log records every AI request — when it ran, whether it stayed on-device or went to a named provider, and roughly how much text was sent — plus security-relevant actions such as replies sent, exports, key changes and disconnections. It never records message content. You can review the last 3, 7 or 30 days.

Your data rights, self-serve

Sub-processors

Mnemor uses a deliberately short list of third parties, and only for the features described:

ProviderPurposeData involved
Anthropic Drafting replies, summarising threads, meeting notes Text excerpts only, when cloud AI is enabled. No training on your data.
OpenAI Same, if configured as the provider Text excerpts only. No training on your data.
Google Cloud (hosting) Serving this website and the key-vending endpoint No user content. Request logs contain no message bodies.
Apple App distribution and subscription billing Payment is handled entirely by Apple; we never see card details.

The services you connect — Google, Microsoft, Slack, GitHub — are your own accounts, accessed with your authorisation, not sub-processors acting for us.

This website

This site is static. It sets no cookies, runs no analytics, loads no third-party scripts or fonts, and contains no trackers — which is why you will not see a cookie banner here. It is served over HTTPS with HSTS and a strict Content Security Policy.

Reporting a vulnerability

Please report security issues privately to @saysereze on X rather than disclosing them publicly. We aim to acknowledge within two business days and will keep you updated through to a fix. We do not currently run a paid bounty programme, but we credit reporters who want it.

What we do not claim

Being straight with you: Mnemor is an independently built product. It does not currently hold SOC 2 or ISO 27001 certification, and there is no admin console, SSO or centrally managed deployment. If your organisation requires those, tell us what you need — but do not assume them.