Snapshot of the source text at fetch time, not a live mirror of the policy page.
Plain-English summary
This document emphasizes strong security practices, including the encryption of user content during transit and at rest. The company is SOC 2 Type II compliant, indicating ongoing independent audits of its data handling practices. User personal information is explicitly stated to never be sold to third parties. Access to user data for employees is restricted to only those who require it for support, and all internal and user-facing communications are securely encrypted. Account credentials are managed by Google Cloud Platform, preventing the company from accessing or leaking user passwords, and two-factor authentication is offered and required for team members.
90% confidence
Ask Verbaterm
Follow up on findings with grounded answers from this review. Not legal advice.
Risk Flags
Not clearly stated
Critical terms that can lead to significant user harm. These often involve loss of funds, privacy violations, or severely limited rights.
?
Not clearly stated
No cited risk flags — wording is unclear
There were no risk flags identified in the provided text.
Data Use and Privacy
Not clearly stated
How your data is collected, used, shared, and protected.
?
Not clearly stated
No cited data-use findings — wording is unclear
The provided text does not contain concerns regarding data use or privacy practices, such as broad data sharing or retention policies, that would classify as user harm. Instead, the text focuses on protective measures for data, which are captured in the 'Protections' section.
Cancellation and Renewal
Not clearly stated
Terms related to subscription management, including automatic renewals, cancellation processes, and refund policies.
?
Not clearly stated
No cited billing terms — wording is unclear
The provided text does not contain information about cancellation processes, automatic renewals, or refund policies.
Gotchas
Not clearly stated
Potentially unfavorable clauses that may not be immediately obvious, but could lead to inconvenience or unexpected costs.
?
Not clearly stated
No cited gotchas — wording is unclear
No 'gotchas' were identified in the provided text that would categorize as potential user harm, such as hidden fees or broad indemnification clauses.
Protections
8 findings
Explicit commitments and features designed to protect users' rights, privacy, and security.
Protection95% confidence
User content encrypted in transit and at rest
All user content is encrypted while it is being transmitted and when it is stored.
Why it helps: Encrypting user content both in transit and at rest helps protect sensitive personal data from unauthorized access or interception, enhancing the security and privacy of user information.
**We encrypt all user content in transit and at rest.**We encrypt all user content in transit and at rest.
The fundamentals, paragraph 1 · Citation strength: strong
Protection90% confidence
SOC 2 Type II compliant
Mem is compliant with SOC 2 Type II, which is described as an ongoing audit of data handling by independent auditors over an extended period.
Why it helps: SOC 2 Type II compliance provides assurance that the company has established and maintains strong data security and operational integrity controls, verified by independent audits.
SOC 2 Type II is the gold standard for data security and operational integrity. It's not a checkbox—it's an ongoing audit of how we handle your data, conducted by independent auditors over an extended period.
The fundamentals, paragraph 1 · Citation strength: strong
Protection95% confidence
No selling of personal information to third parties
The company commits to never selling user personal information to third parties.
Why it helps: This commitment helps protect user privacy by ensuring that their personal data will not be monetized or shared with unaffiliated entities without explicit consent.
We are committed to protecting your privacy, and we will never sell your personal information with third parties.
Privacy, paragraph 1 · Citation strength: strong
Protection90% confidence
Access to data limited to necessary employees
Only employees who need access to user data to provide support are granted access.
Why it helps: Limiting data access to only those employees with a legitimate need-to-know reduces the risk of internal misuse or unauthorized exposure of personal information.
All Mem employees are responsible for security and we ensure that only those employees who need access to your data in order to provide you with great support can access them.
Secure and encrypted communication channels for staff
All communication within the staff is conducted through securely encrypted channels that use modern, strong encryption.
Why it helps: Using strong encryption for internal communications helps prevent unauthorized interception and access to sensitive information, including potentially user-related data, thereby enhancing overall security.
Lastly, all communication is done through securely encrypted channels that use modern, strong encryption.
Secure, encrypted channels for user-application communication
All communication between users and the application takes place over secure, encrypted channels using 128-bit TLS encryption.
Why it helps: Encrypting all communication between users and the application with TLS encryption protects data in transit from eavesdropping and tampering, safeguarding sensitive information like login credentials and personal data.
All communication between users and the Mem application takes place over secure, encrypted channels with 128-bit TLS encryption.
Account credentials managed by Google Cloud Platform
Mem account credentials are fully managed by Google Cloud Platform, which means the company cannot access or potentially leak user passwords.
Why it helps: Leveraging Google Cloud Platform for credential management means the company does not directly handle user passwords, reducing the risk of password leaks and enhancing account security.
Mem account credentials are completely managed by the Google Cloud Platform. Therefore we can't access or potentially leak your passwords.
Two-factor authentication (2FA) offered and required for teams
The company offers and requires all team members to enable two-factor authentication (2FA) for added account protection.
Why it helps: Two-factor authentication adds an extra layer of security, making it harder for unauthorized individuals to access accounts even if they have a password, thereby protecting user data and accounts.
We offer and require that all team members enable 2FA for added protection on your account.