1. Scope and responsible entity
This Policy applies to the Mory website, including its public pages, account center, order and subscription pages; the Mory browser extension and its internal pages; and the identity, payment, email and support services that enable them (together, the “Mory Services”). The website is Mory's web and official service entry point, while the extension is the browser-installed tool. They are parts of the same product and use the same Mory account, subscription and entitlement system.
For account, website access, order, subscription, entitlement and support data whose purposes and means are determined by Mory, the responsible entity is the Mory service provider (also called a controller, business or equivalent term in some jurisdictions). Its registration details will be identified on the official Mory website or purchase page. You control chat content that remains only in your browser and is never transmitted to Mory; the Mory service provider cannot access that content from its servers.
This Policy does not govern how third-party AI services such as ChatGPT, Claude, Gemini, DeepSeek, Grok, ChatGLM, Kimi, Qwen, Doubao, Yuanbao, Perplexity or Copilot process original conversations, or how a destination you choose processes exported data. Please review those third parties' privacy notices as well.
2. Principles and legal bases
- Purpose limitation and minimization: we process only what is needed to provide requested features, fulfill orders and protect accounts and services.
- Surface-aware and local first: the website handles data needed for online services; chat reading, organization, saving and export that can be completed locally remain in the extension.
- User initiated: reading an AI page, exporting, sharing and third-party sync follow your action or explicit setting.
- Transparency: material changes to purposes, data categories, retention or recipients will be disclosed, with renewed consent where required.
- No training on chat content: Mory does not use your AI chat content to train, fine-tune, label or evaluate AI models.
Depending on your location and use, our legal bases may include performing a contract or taking pre-contract steps at your request, your consent, compliance with legal obligations, and legitimate interests that do not override your rights, such as account security, fraud prevention, service maintenance and troubleshooting. You may withdraw consent at any time without affecting processing that was lawful before withdrawal.
3. Data we process
This table reflects the current product and the account, payment and extension scenarios already contemplated. If a feature is unavailable or unused, we do not process data merely because that feature appears here.
| Context | Data involved | Purpose and method | Retention approach |
|---|---|---|---|
| Visiting the website | Request time, IP address, browser and device type, requested and referring pages, and necessary server or security logs | Deliver pages, prevent abuse, secure the service and troubleshoot | The shortest period necessary on our servers or hosting systems |
| Consented website analytics | Pages and sources, browser and device type, approximate region, registration, login and checkout events, and pseudonymous client and session identifiers. A completed payment also includes the transaction number, plan, amount, currency and payment provider | Use Google Analytics to understand acquisition, page use and the purchase funnel and improve Mory. We do not send names, email addresses, Mory user IDs or AI chat content, or use this data for advertising profiles | Processed only after consent. The choice is stored for 180 days, Analytics cookies for up to about 395 days, and Google Analytics user- and event-level data is configured for 14 months |
| Registration, login and account security | Name or display name, email, profile image, account and identity-provider identifiers, locale, verification status, protected passwords or authorization credentials, session identifiers, IP address and user agent | Create and identify one Mory account; sign in through email and password, email verification codes or Google as currently shown; maintain sessions, reset passwords, secure the account and restore entitlements across web and extension | For the life of the account; sessions usually last up to 30 days and may refresh or end earlier |
| Extension sign-in, trials, entitlements and quota checks | Account ID, membership tier, trial start and end, plans and entitlements, feature capabilities, quota groups and used or reserved counts, policy version, operation ID and completion or release status | Identify the account across web and extension, grant trial or paid capabilities, enforce feature quotas, and handle retries or reconciliation. These requests do not include chat text, reasoning, attachments, the local library, conversation titles or source links | For the account or membership relationship and the shortest period needed for quota periods, reconciliation, security and disputes |
| Consented extension daily usage analytics | On Mory's account side: internal user ID, consent version and time, first or latest sign-in and active time, daily activity, extension version and browser family. The anonymous events sent to Google Analytics contain only a resettable random client ID, sign-in or active event, time, extension version and browser family | Only after you enable it under “Settings → Data & Privacy,” calculate account-level acquisition, DAU and D1, D7 and D30 retention, and understand extension use through anonymous aggregates. We do not send names, email addresses, Mory user IDs, visited pages, page titles, chat text, attachments or the local library | The local consent state remains until you disable it. Disabling stops new events and resets the anonymous client ID. Account-level and daily analytics records are retained for up to 14 months from the latest relevant activity, and Google Analytics user- and event-level data is configured for 14 months |
| Extension uninstall feedback | One or more uninstall reasons you select, text entered when choosing “Other reason,” extension version, browser family, interface language and submission time | Understand why people stop using Mory and improve the product. The survey does not require sign-in and does not store a Mory user ID, email address, AI conversation content, visited pages or browsing history | Up to 14 months from submission |
| Verification and service email | Email, verification or reset tokens, message content and necessary delivery status | Send verification, password reset, security or transaction messages through an email provider when configured | Tokens are removed after expiry or completion; delivery records are kept only as needed |
| Orders, subscriptions and entitlements | Order number, product, plan, amount, currency, billing period, payment channel, transaction or subscription ID, status, timestamps, account email and entitlement status | Create checkout, confirm payment, grant or restore entitlements, manage subscriptions, refunds, reconciliation, fraud and disputes. We do not request payment passwords or directly store full card numbers | For the service and support term, plus tax, accounting, audit, fraud and dispute periods |
| Discover submissions and likes | Account ID, author name and account avatar, title, body, re-encoded image and media metadata such as dimensions and digest, submission and review state, rights confirmation, publication time and like count. Guest-like deduplication uses a hash derived from a signed browser identifier | Store, review, publicly display, rank and delete submissions at your direction, provide one like per browser and prevent abuse. The like table does not store the raw cookie identifier or IP address | Submissions remain until you or an administrator deletes them. Public display stops when deletion begins, and the database record is removed after object-storage cleanup. The signed browser cookie lasts up to one year; the like hash is removed when the like is canceled or the post is deleted |
| Reading, saving and exporting AI conversations | Selected prompts, answers, reasoning, titles, roles, timestamps, source links, platform identifiers, citations, attachments, generated images or files, highlights, tags, favorites, folders, custom titles and export settings | Read, organize, display, search, create share cards and generate files locally in the current browser; currently not uploaded to Mory servers or used for model training | In your browser for the period you choose in the extension; deletable at any time |
| Third-party sync or export | Content you select, target workspace, database, vault, folder or file information, and client registration, authorization tokens, connection keys and sync state | Send at your direction to Notion, the Obsidian Bridge on your device, the clipboard, files or another clearly identified destination. Chat content is not relayed through Mory servers | Authorization or connection data remains in the extension until disconnection or revocation, with sensitive tokens protected through browser cryptography. Destination copies follow that destination's settings |
| Support, customer chat or rights requests | Contact details, request text, relevant account or order information and attachments you provide. Online support may also process transcripts, support-cookie identifiers, IP address, browser and device type, referral source, the page where chat began and page activity during the chat | Verify identity, respond, provide support and resolve complaints or disputes. The Olark widget loads only after your explicit permission | As needed to resolve the request and meet legal obligations. Copies in Olark follow support-dashboard retention settings and applicable deletion requests |
4. How AI chat data is handled
4.1 The website does not read your AI conversations
Visiting the Mory website, creating an account, signing in, viewing an order or purchasing an entitlement does not let the website read chats on third-party AI sites or automatically upload your extension library.
4.2 The extension is local by default
When you actively use Mory on a supported AI site, the extension reads only the current-page content needed for that action and performs formatting, preview, saving and file generation in the current browser. Mory does not silently collect your entire browsing history.
4.3 A shared account syncs identity, entitlements and quotas only
The website and extension may synchronize your Mory identity, membership or trial status, plan, subscription, entitlements, feature capabilities, quota usage, policy version, operation IDs and completion status. Chat text, reasoning, attachments, the local chat library, conversation titles and source links are not login, order, entitlement or quota verification parameters.
4.4 No training or sale
Mory does not use AI chat content for model training, fine-tuning, human labeling, model evaluation, advertising profiles or personalized ads, and does not sell it. Content enters a third-party destination only when you choose to export, copy, share or sync it.
4.5 Browser extension store data-use commitment
Mory collects, uses and transmits user data only to provide the single purpose described in this Policy and related account security, entitlement and quota checks, and feature reliability. It is not used for personalized advertising, cross-site profiling, data brokerage, credit assessment or sale. Mory does not permit humans to read user data unless you explicitly authorize access for a specific support issue or access is necessary for a security investigation or legal obligation.
6. Browser extension permissions
Mory may request browser permissions whose labels vary by browser:
- Active tab and script execution to recognize supported AI pages and read conversations you choose to process;
- Local storage for your library, settings, long messages, previews, export drafts, authorization state, retry queues and functional data;
- Clipboard writing and file delivery to write to the clipboard when you click copy and generate or deliver files in the page when you request an export;
- Identity, the active tab and navigation events for Mory login, identifying a supported page you actively use, Notion authorization callbacks and third-party connections;
- Side panel, scheduled background tasks and offscreen documents to display the local library, maintain account and quota state, and generate images or PDFs at your request;
- Supported-site and resource access to run the toolbar only on listed AI sites, read content you actively process, and read images already present in a conversation for export; and
- Optional site access only when you enable a Notion connection or the local Obsidian Bridge.
You can review or revoke permissions in your browser's extension manager. Revoking a required permission may disable the related feature without affecting unrelated local features.
Mory does not run in private browsing windows. Firefox data permissions for online services, accounts, and third-party sync are optional. Refusing or revoking them does not affect local saving, highlighting, or local export, but stops the related online transmission.
7. Providers, third parties and disclosures
We do not sell personal data. Necessary data may be handled by:
- Hosting, content delivery and database providers that deliver the website, hold online account and transaction records, and protect availability;
- Identity and email providers: Google supplies identity information when you select it, and configured email services, currently potentially including Resend, send verification codes, password resets and service notices;
- Payment providers that run checkout, refunds and subscriptions; current adapters may include Creem and ZPay, with the actual provider shown at checkout;
- Analytics provider: Google Analytics processes the relevant pseudonymous website, conversion or extension usage events only after you separately consent to website analytics or extension daily usage analytics. Google may process data outside your country or region; see the Google Privacy Policy;
- Customer support provider: only after you explicitly allow support chat, Olark (Habla, Inc.) processes messages and contact details you choose to send, the visitor and session information needed to provide support, and stored chat transcripts. Data may be processed outside your country or region; see the Olark Privacy Policy;
- Destinations you choose, such as Notion, the Obsidian Bridge on your device, your file system or clipboard. The extension sends selected content directly to the destination rather than relaying it through Mory servers; and
- Authorities or protected parties where disclosure is lawfully required or necessary to protect safety and rights.
Processors acting for Mory must handle data only for the agreed purpose, duration and scope with appropriate safeguards. Independent third parties apply their own notices. Third-party AI sites independently govern original conversations; Mory does not represent or control their existing processing.
8. Location, retention and deletion
- Local chat content: remains in the current browser for your selected retention period and may become unrecoverable after deletion, expiry, uninstall or clearing browser data.
- Accounts and sessions: account data remains while the account exists; sessions usually last up to 30 days, may refresh with continued use, and may end earlier after sign-out, revocation or a security event.
- Extension account and third-party authorization: Mory account and Notion access or refresh tokens follow their expiry periods and are removed or no longer used after sign-out, disconnection, revocation or expiry. Sensitive tokens stored by the extension are protected through browser cryptography.
- Orders, subscriptions and entitlements: kept for contract, support, tax, accounting, audit, fraud and dispute requirements.
- Website and security logs: kept for the shortest period needed to prevent abuse, troubleshoot and meet legal duties.
- Website analytics: the consent choice remains in the current browser for 180 days, Google Analytics user- and event-level data is configured for 14 months, and first-party Analytics cookies last up to about 395 days. No new analytics events are created after consent is withdrawn.
- Extension daily usage analytics: the local consent state remains until disabled. Account-level and daily analytics records are retained for up to 14 months from the latest relevant activity, and Google Analytics user- and event-level data is configured for 14 months. Disabling stops new events and resets the anonymous client ID.
- Third-party copies: are managed and deleted in the destination you selected.
When a purpose is complete or no longer necessary, a retention period expires, consent is withdrawn, an account is closed, or applicable law otherwise requires, we delete or anonymize the relevant personal data. If law requires continued storage or deletion is temporarily infeasible, processing is limited to storage and necessary protection.
9. Security
We use technical and organizational measures proportionate to risk, including local-first design, least-privilege access, encryption in transit, access control, credential protection, rate limiting and incident response. Please secure your device, browser profile and Mory account.
The extension protects locally stored sensitive Mory account and Notion tokens with browser Web Crypto and keeps access tokens in session storage where supported. Local data and authorized destinations may still be exposed if another person controls your device or browser profile.
No system is absolutely secure. If personal data is or may be compromised, we will take remedial action and notify authorities and affected users where applicable law requires.
10. Your privacy rights
Depending on applicable law, you may have rights to know or confirm processing; access, copy, correct, supplement, delete or port data; restrict or object to processing; withdraw consent; close an account; and opt out of sale, sharing, targeted advertising or solely automated decisions with significant effects.
- View, export or delete local chat content in Mory's extension library or data settings.
- Revoke browser or optional site permissions in the extension manager.
- Withdraw website analytics consent at any time through “Cookie settings” in the footer.
- Enable or disable extension daily usage analytics at any time under “Settings → Data & Privacy.”
- Disconnect third-party integrations and manage previously synced copies at the destination.
- Contact us for account, order or other requests unavailable in the interface.
Mory currently does not sell personal data or use it for cross-context behavioral or targeted advertising, and will not discriminate against you for exercising legal rights. We may verify identity before acting. If local chat content was never transmitted to Mory, we cannot retrieve or delete it from our servers for you.
11. International transfers
Mory does not transfer chat content internationally merely because the extension stores it locally. Third-party AI sites and identity, email, payment or sync providers you choose may process data outside your country under their own notices.
Where Mory or a provider transfers account, entitlement or payment-verification data internationally, we use safeguards required by applicable law, such as adequacy decisions, standard contractual clauses, certifications or contractual measures, recognized legal exceptions, and supplemental technical or organizational protections where appropriate.
12. Children
Mory is not directed to children below the minimum age at which they may independently consent to online services or personal-data processing where they live. A parent or legal guardian should review and consent where required. If we learn that we processed a child's data without valid consent, we will delete it or take other required steps.
13. Changes to this Policy
We may update this Policy as Mory features, processing or legal requirements change. Material changes will be highlighted before they take effect through the website, extension, account notice or another appropriate channel. We will request renewed consent where a change to purpose, method or data category legally requires it.
14. Contact us
Responsible entity: Mory service provider, with registration details identified on the official Mory website or purchase page.
Contact email: support@moryext.com
Use this channel for privacy requests, account or order questions, complaints and feedback. We may request the minimum information needed to verify identity. Never send a payment password or full card number.