Idle

Hold space and talk

Privacy

Version 2026-09-15.1 · last updated 15 September 2026

Memoe is in beta. You are early. The app changes often, so this page changes with it — what is written here is what today’s Moe does, and we will say so at the top when it changes. If you find something that does not match, tell us; that feedback is what keeps this page honest.

This policy is from Yisrael Gottlieb, a sole proprietor in New Jersey, United States, who makes Memoe (“we”, “us”). Write to hello@moebot.app about anything on this page.

The short version

Who Memoe is for

You must be 18 or older to use Memoe. We do not knowingly hold anything about anyone younger; if you believe we do, write to us and we will delete it.

What stays on your Mac

What leaves your Mac, and when

Mail you connect

Connecting a mailbox is optional and off until you do it. Moe reads Gmail over IMAP with an app password you create yourself at myaccount.google.com/apppasswords — for mail there is no Google sign-in and no key to your account held anywhere but your own Keychain. You can connect as many mailboxes as you like, personal and work.

The one place mail does travel, and it is your choice. The brief is part of what Moe tells your connected AI when you ask it something, so the senders and subjects in it go to the provider you chose — from your Mac, directly, under their terms. Ask about a particular message and the part needed to answer goes too. If you connected a local model, nothing leaves your Mac. Turn the mailbox off and none of it is gathered in the first place.

The deep read is separate, and it asks first. Moe can also read back over up to a year of your inbox and sent mail to learn how you write and who matters to you — once, and after that only what is new, once a day. It reads nothing without your yes for that mailbox: the first-run screen lists what is connected with each one ticked, and nothing is read until you save it (untick a mailbox to leave it alone); a mailbox you connect later is asked about on its own; and Settings › Background turns it off again. Each pass sends the text it read to your connected AI to be distilled; the raw text is written to ~/.moe/context/crawl, readable only by your account, and deleted as soon as the distilling is done. What survives is a digest you can read and delete in ~/.moe/memory/profile.

Taking it back. Revoke the app password at myaccount.google.com/apppasswords and Moe cannot reach that mailbox again, from that moment, whatever else is on your Mac. To clear what is on your Mac, use Disconnect on the mailbox in Settings › Connections, which removes both the saved password and the account entry; then delete the files under ~/.moe/context and ~/.moe/memory/profile — they are ordinary files, and deleting them is the deletion.

What Moe reads from your mail is never sold or shared with anyone for their own purposes, never used for advertising, and never used to train models — we have none. On the free tier it is never sent to us. If you upgrade to Away, what Moe has learned from it moves to your cloud computer with the rest of Moe’s memory.

Sending mail

Moe can also send mail from a connected mailbox, over SMTP with TLS, using the same app password. Nothing is ever sent without your explicit approval. A dialog shows the recipients, the sending address, the subject and the message before anything leaves your Mac, and nothing is preselected — Escape cancels it. If a message is long enough that the dialog cannot show all of it, it tells you exactly how many characters it is not showing.

Google Docs and Sheets

This is optional and off until you set it up. It uses Google’s drive.file permission, which Google classes as non-sensitive: Moe can only see the documents you personally pick in Google’s own file chooser, and nothing else in your Drive — not the files you did not pick, and not new ones.

As with mail, the contents of a document you asked about travel to the AI provider you chose, from your Mac, under their terms.

Your calendar, contacts and files

Calendar events, contacts, reminders and notes are read from the apps already on your Mac, so Google calendars you have added to Calendar work with no sign-in of any kind. Files in Google Drive are read from the folder Google’s own Drive for Desktop app syncs to your Mac, if you have it — again with no sign-in to us. Chrome browsing history is off unless you switch it on, and when on it records page titles and sites, never the query strings in an address.

Signing in with Google

Signing in is optional. It asks Google for your email address and nothing else — not your name, not your contacts, your Drive or your calendar. What we keep is that address and the account number Google gives us for you, in a Memoe account on our server. We send one welcome email when you first sign in.

Signing in uploads nothing from your Mac. The account exists so that connections made through Composio belong to you and nobody else, so a problem report has somewhere to send the reply, and so a subscription belongs to somebody. Signing in means you agree to the Terms and this policy. Moe records that agreement on our side when it can: it is signed on your Mac and sent right away, with the date and the versions of both.

How an agreement is recorded. Only Moe on your Mac can record that you agreed. Each agreement is signed by a key that only the Memoe app can use, and we record which versions you agreed to and when. If a key for agreeing is set up on another Mac, or the one on your Mac is replaced, we email you.

Apps connected through Composio

Some apps in Settings › Connections are connected through Composio, a service that holds the sign-in to that app and carries Moe’s requests to it. When you connect one, we create a Composio project that is yours alone, so the key your Mac holds can reach your connected accounts and nobody else’s. Composio holds the sign-ins for those apps; what Moe asks of them passes through Composio to the app and back. Our Composio account can administer your project — that is how it is made and how it is deleted — and that is covered by the no-look rule like everything else of yours we hold.

Away: your own computer in the cloud

Away is a paid upgrade. Before it starts, Moe shows you what is about to happen and asks you to agree, and we record the agreement with the date and the versions of these documents. Agreeing does not start the copying: copying starts once your plan is active. If you agree and then leave the payment page, nothing leaves your Mac.

What moves. Your memories and the conversations you’ve had; what Moe knows about you and how you like things done; the apps and accounts you’ve connected; the ways you message Moe; and your AI sign-in. Your own Telegram and WhatsApp come too, in the one way they can: your cloud computer becomes one of their devices, so it can read and send there — your Mac lets it into your Telegram by itself, and WhatsApp asks you to type a code on your phone. It shows among each app’s linked devices, and you can remove it there; Moe does not add it back by itself. From then on, what Moe learns on either side is kept in step.

Where it goes. To a computer rented from Fly.io in Ashburn, Virginia, United States, which runs only your Moe. Our own server — which also runs on Fly.io in Virginia, with its database at Neon in the same region — carries things between your Mac and that computer.

How it is protected, precisely.

What our server does read. Not everything we hold is locked away from us. Our server can read: your email address; your problem reports; the tokens for messaging channels you connect for Away (a Telegram bot’s token, for example), so it can receive and send on your behalf; the name and chat of anyone who messages your bot before you’ve let them in, so you can decide; the key to your Composio project, which it stores encrypted with a key of its own and can open; your tier, your usage against its allowance, your agreements, and Stripe’s identifiers; and messages crossing a channel, in transit (see below).

The one step where you trust us. When you start Away, our server introduces your cloud computer to your Mac, and your Mac then encrypts your keys to the computer it was introduced to. That introduction is the one step where you trust us rather than the maths: an honest server introduces your computer, and ours does.

The no-look rule. Our staff open your cloud computer only to fix something you asked us about, with your yes on the ticket, and we note it on that ticket. We do not browse it, sample it, or read it to improve Moe.

Stopping it. Settings › Privacy has Keep a copy in the cloud. Turn it off and your Mac stops copying anything new; while Away is paid, that means the cloud Moe stops learning anything new, and Moe tells you so before it happens. Turning it off does not delete the copy already on your cloud computer. To remove that, cancel Away (it is deleted after the retention period below) or delete your account (it is removed straight away).

Messaging Moe through a channel

If you reach Moe through a messaging channel that runs through our server — a Telegram bot set up for Away, for example — each message crosses our server readable in transit, because our server has to see it to deliver it to your Moe. If your Moe cannot take it right away, it is stored encrypted so only your cloud computer can read it, until it can. The messaging service itself (Telegram, WhatsApp and so on) receives what you send under its own terms.

Cloud voice

Cloud voice is included on both paid plans. You can turn it on for a faster, more natural voice. With it on, your Mac streams what you say to AssemblyAI to be turned into text, and sends the words Moe is about to say to Inworld to be spoken. Your Mac talks to them directly, with short-lived passes our server issues; our server counts how much you used against your allowance and never hears the audio. Turn Cloud voice off and your voice stays on your Mac again.

Problem reports

When you tell Moe something is broken, it can send a report to the Memoe team. Nothing is sent until you turn on Let Moe send problem reports in Settings › Privacy, which is off until you do. While it is off, Moe writes no report and keeps nothing of one on your Mac — not the conversation, not its description, not even a title — and tells you where the switch is; once you have turned it on, ask again and the report is written then. After that, a report you ask for goes straight through. Turn the switch off and reports stop, and we record that you turned it off.

Paying

Payments are handled by Stripe, who process what you type into their form. Your card number never reaches us. What we keep is which tier you are on, whether it is paid, and Stripe’s identifiers for you as a customer and for the subscription, so the app knows what you are entitled to. Stripe’s privacy policy covers what they hold, and Stripe keeps its own invoices for as long as tax law requires.

This website

The playground

The playground is a demonstration, not the app, and it does not run on your Mac.

Who else handles your data: sub-processors

These are the companies that process personal data on our behalf, what for, and where. Services you connect yourself — your AI provider, your mail, your Google account, your messaging apps — are yours, under your agreement with them, and are not on this list.

CompanyWhat forWhere
Fly.ioRuns our server, and your cloud computer if you have AwayUnited States (Ashburn, Virginia)
NeonOur server’s database; the playground’s daily countersUnited States (Virginia)
VercelHosts this website and the playgroundUnited States
StripePaymentsUnited States
ResendSends our emails: welcome, problem reports, receiptsUnited States
ComposioHolds sign-ins for apps connected through it, and carries Moe’s requests to themUnited States
GoogleSign in with GoogleUnited States
AssemblyAICloud voice: turning speech into text (paid tiers, when on)United States
InworldCloud voice: speaking Moe’s replies (paid tiers, when on); the playground’s voiceUnited States
GroqThe playground’s replies and listeningUnited States
OpenRouter, CerebrasThe playground’s replies, when routed thereUnited States
DeepgramThe playground’s voice, only if Inworld is not set upUnited States
GitHubProblem reports, as issues in our private repositoryUnited States
TelegramNotifying our team of a problem reportWorldwide (Telegram’s own servers)
AnthropicClaude Code, the coding assistant that reads problem reportsUnited States
Nous ResearchOne-click Telegram bot setup, only if you choose itUnited States
jsDelivr, Hugging FaceThe playground’s in-browser voice model, downloaded only if your browser can run itWorldwide (content delivery networks)

Our server and these services are in the United States. If you live elsewhere, using the parts of Memoe that involve us means your data is processed there.

How long we keep things

Your rights

Wherever you live, you can ask us to:

Use the buttons in Settings › Privacy, or write to hello@moebot.app. We answer within 30 days, and we will not treat you any differently for asking. We may need to check that the request comes from the account’s owner, which usually means asking you to sign in with the same Google account.

If you are in the EU, the EEA or the UK, these are your rights under the GDPR and the UK GDPR. We rely on providing the service you asked for as the basis for most of what is on this page, on your consent for problem reports (withdraw it at any time by turning the switch off) and for Away’s copying to the cloud (turning off Keep a copy in the cloud stops new copying; cancelling or deleting your account removes the copy), and on our legitimate interest in keeping the service secure and counting visits to this website. You can also complain to your data protection authority.

If you are in California, these are your rights under the CCPA, including the right to know, to delete, to correct, and not to be discriminated against for using them. We do not sell personal information and we do not share it for cross-context behavioural advertising.

Changes and versions

This policy is versioned; the version is at the top of the page. A small edit changes the date only. A material change gets a new version, and Moe asks you to agree to it again in the app — your service is not cut off while it waits. The current version always lives at memoe.app/privacy.

What changed in 2026-09-15.1: a problem report sent without saying who you are is not tied to your account, so deleting your account does not delete it (see reports sent without saying who you are). If you agreed to the previous version, Moe asks you to agree to this one.

This page is written against what Memoe actually does, and it has not yet been reviewed by a lawyer; that review happens before paid plans are generally available, and any change it brings will come with a new version.

Questions

Write to hello@moebot.app. If this page and the app ever disagree, tell us; the app is the truth and this page will be corrected.

Memoe runs on your Mac. What leaves it, and when. Beta. Expect a few rough edges — tell us what breaks. Home Pricing Docs Privacy Terms Licences