Memo
Legal

Privacy Policy

1. Who we are

Memo Technologies Oy (“Memo”, “we”, “us”) is a company registered in Finland, Business ID 3602819-5. We provide the Memo service at app.sentmemo.com, in Slack, through our browser extension (section 4), and through the integrations described below.

For any question about this policy or about your data, write to henri@sentmemo.com.

2. The two roles we act in

Which rights apply, and who you should ask, depends on why we hold the data.

We are the controller

— for data about the people who visit this website, evaluate Memo, or administer an account: your name, work email, sign-in identity, and how you use the product. We decide why and how that data is processed.

We are a processor

— for the working data inside a customer’s Memo workspace: meeting notes, chat messages, CRM records, calendar events, emails and transcripts. That data belongs to the customer organisation, which is the controller. We process it only on that organisation’s instructions and under our agreement with them. If you are an employee of a Memo customer and want your data corrected or erased, ask your organisation first — we act on their instruction.

3. What we process

Account and identity data

Your name, work email address, profile picture and Google account identifier (we use Google sign-in), the organisation you belong to, your role and permissions, your timezone and language preference.

Content you give Memo directly

Meeting notes and messages you write in the web app or send to the Slack bot, voice notes you record, instructions you give Memo, and the corrections you make to what Memo proposes.

Data from the systems you connect

Memo only reads a connected system after someone in your organisation explicitly authorises it, and only within the permissions granted at that moment. Depending on what you connect, that can include:

You can disconnect any of these at any time in Settings. Disconnecting stops all further reading immediately.

Usage and technical data

Pages viewed, features used, approximate location derived from IP address, browser and device type, and application logs (including errors and the timing of requests). We also record sessions in the web application to diagnose faults and understand how it is used; these recordings include content entered into the app, though never passwords, which are always masked. They are stored in the EU, retained for a limited period (see section 9), and we can exclude your account on request.

4. The browser extension

Memo offers an optional browser extension. It is an accessory to a Memo account: it does nothing until you connect one, and it can be disconnected or uninstalled at any time. It runs on two sites and nowhere else — Google Calendar and LinkedIn — and has no access to any other page you visit.

What it reads

Google Calendar. When you open an event, the extension reads the identifier of that one event so it can ask Memo for the meeting prep belonging to it. It does not read your calendar, other events, event contents or attendee lists from the page, and it never writes to your calendar.

LinkedIn. When you click Log to Memo on a conversation, the extension reads the messages of that one open conversation, together with the name, headline and profile link of the person you are talking to, and sends them to your Memo account. It reads nothing until you click. It does not open, browse, search or crawl LinkedIn on its own, and it never sends messages or connection requests on your behalf.

Where that data goes

Only to Memo’s own servers, over HTTPS, authenticated as your Memo seat. No third party receives data from the extension. A conversation you log is handled exactly like a note you type into Memo yourself: Memo reads it and proposes CRM records for you to approve, and nothing is written to your CRM without that approval. The AI processing and sub-processors described in sections 6 and 7 apply unchanged to anything the extension sends.

What it stores in your browser

Clicking Disconnect in the extension’s settings deletes all of the above and revokes the access token on our side. Uninstalling the extension removes it too. You can also revoke a connected browser from Settings → Browser extension in the web app.

Notifications

If you enable it, the extension shows a notification a few minutes before a meeting, carrying that meeting’s prep. You choose whether it appears and how far ahead. It stays silent when Memo has no context for the meeting.

Usage analytics

The extension reports a small, fixed set of usage events: that a prep panel was shown, that it was clicked, and that a notification was shown, clicked or deliberately suppressed. Events carry your workspace identifier and whether a meeting was a first meeting or a follow-up. They never carry meeting titles, meeting identifiers, contact names, deal data or message contents — our servers drop those fields even if a client sends them.

What the extension never does

5. Why we process it, and on what legal basis

Where we rely on legitimate interest, we have weighed it against your rights and you may object at any time (section 10).

6. How AI is used

Memo sends the content it is working on — your notes, relevant CRM records, calendar and email context — to large language models in order to produce summaries, proposed CRM changes and drafted messages. The models we use are operated by Anthropic and, as a fallback, OpenAI. Voice notes are transcribed by ElevenLabs, with OpenAI as a fallback.

AI output is a proposal, not a decision. Memo is built so that changes to your CRM, emails and calendar are presented to a person for approval before they take effect, and you can edit or reject any of them. AI output can be wrong or incomplete and should be reviewed. We do not use AI to make decisions that produce legal effects concerning you or similarly significantly affect you within the meaning of GDPR Article 22.

7. The systems we rely on

These are our sub-processors — the providers that host or process data on our behalf in order to run Memo.

They are Google Cloud (database, secrets, logging), Vercel (hosting), Anthropic and OpenAI (language models), ElevenLabs (voice transcription), PostHog (analytics and session recordings) and Slack (message delivery, if you connect it). The full list — what each one does, the data it can reach and where it runs — is maintained on its own page so it stays current.

Your CRM, Google Workspace and meeting note-taker are not our sub-processors. They are your own systems; Memo reads from and writes to them at your direction, and your relationship with those providers is governed by your own agreement with them.

How we handle changes to that list is set out in our Data Processing Agreement.

8. Where your data is stored, and international transfers

Memo’s database, application servers and analytics all run in the European Union. Data at rest is encrypted, and the database is not reachable from the public internet.

The AI providers listed above process data in the United States. Those transfers are made under the European Commission’s Standard Contractual Clauses together with the providers’ own supplementary safeguards. Content is sent for the duration of the request and is not retained by them for training.

9. How long we keep it

10. Your rights

Under the GDPR you may request access to your personal data, correction of it, erasure, restriction of processing, portability, and you may object to processing based on legitimate interest. You may also withdraw consent where processing rests on consent.

Send any request to henri@sentmemo.com. We answer within one month. If the data sits inside a customer’s workspace, we will forward your request to that customer, who is the controller.

If you believe we have handled your data unlawfully, you may complain to your local supervisory authority. In Finland that is the Office of the Data Protection Ombudsman (tietosuoja.fi).

11. Security

We keep data in the European Union, encrypted at rest and in transit. Every customer’s data is isolated at the database level, so one customer’s workspace cannot read another’s. Access to production systems is limited to the people who need it, credentials are held in a managed secret store rather than in code, and the production database is reachable only over a private connection.

No system is perfectly secure. If a breach affects your personal data we will notify the relevant supervisory authority and, where the law requires it, you, without undue delay.

12. Cookies and similar technologies

We use a small number of cookies and equivalent browser storage: one to keep you signed in, and analytics identifiers used by our analytics provider to recognise a returning session. We do not run advertising cookies and we do not share data with ad networks. You can clear or block cookies in your browser, though the sign-in cookie is required for the app to work.

13. Children

Memo is a business tool. It is not directed at children and we do not knowingly collect data from anyone under 16.

14. Changes to this policy

We may update this policy as the product changes. The effective date at the top always reflects the current version. If a change materially affects how we handle personal data, we will tell account administrators before it takes effect.