How private your memories are depends on which mode you're in, so this page is organized by mode rather than as one sweeping promise. Most people will only ever use the first one.
Two things are true in every mode: your memories are never used to train any model, ours or anyone else's, and there is no usage tracking or analytics in the product.
No account exists, so we hold no record that you use the product at all. We cannot read your memories, cannot delete them, and cannot produce them if someone asks us to, because we never have them.
Your backup is encrypted on your computer before it's uploaded, and we don't hold the key. What we do hold is real and worth naming: an account, an email address, billing records, and the size and timing of your snapshots.
To search a shared collection and serve it to a team, the server has to hold those memories in a form it can actually search. That means the operator of the server — us, on the hosted tier — is technically able to read what's stored there. Saying otherwise would be untrue.
Turning on the server tier is a decision to hand specific memories to a service. It is never the default, it is separately paid, and nothing is moved there because a tier ran out of space — the choice is yours, per collection.
Anything marked private, or local-only, is removed from the set of things eligible to move to a server before any placement decision is made. Privacy is a filter, not a factor weighed against storage cost.
A shared memory is visible to whoever the collection is shared with. The rules for who may see what within a team are designed but unbuilt, and the tier will not ship before they exist.
Your local memories stay local and keep working whether or not you ever switch this on, and continue working if you cancel. The server is an addition, never a migration.
On the first row: ModelBrain itself never sends a memory anywhere when saving, recalling, or deleting it. Once your assistant has that memory, what it does next is governed by that assistant's own policies, not ours (see "things we'd rather you knew," right). Note on the last row: the option to send text to an outside model exists only as an unused interface in the first release. Nothing calls it, and it stays off unless you enable it and supply your own key.
ModelBrain does not encrypt your vault. Reading memories quickly depends on the files being readable as-is. Turn on your computer's own disk encryption — FileVault on a Mac, BitLocker on Windows, LUKS on Linux — which protects the same files at no cost if the machine is stolen.
Don't put your vault inside Dropbox, iCloud Drive, OneDrive or Google Drive. Those apps would copy it to someone else's servers, and disk encryption doesn't stop them. ModelBrain checks for this when it starts and refuses to run rather than let it happen quietly.
The file format isn't a security measure. It's a custom format for speed, not secrecy. Anyone with your files and enough determination can read them, which is the real reason to use disk encryption.
Your assistant is a third party. Whatever you discuss with Claude, Cursor or anything else is subject to that company's terms, not ours. ModelBrain controls what's stored on your disk, not what your assistant does with a memory after we hand it over.