Legal

Privacy Policy

Mneme HQ is an open-source developer tool. This policy covers the mnemehq.com website, direct contact, and the hosted Architecture Protection Audit. We keep data collection minimal, we never sell personal data, and repository material submitted to the Audit is handled as described in our Security & data handling page.

Version 2 · Last updated: 10 September 2026

🔒 Submitting a repository to the Architecture Audit?

Repository material is processed deterministically by Mneme's open-source engine, is never sent to an external AI model provider, and original files are deleted when the audit completes. The technical details — inputs, processing locations, retention, deletion — are documented here:

Security & data handling →

Who is responsible (controller)

Superposition Insights OÜ, operating as Mneme HQ, is the controller for personal data described in this policy. Contact for all privacy matters: [email protected].

What we collect

Depending on how you interact with Mneme, the following categories of data are processed:

  • Website analytics (mnemehq.com): pages visited and time on page, referring URL, general geographic region (country/city level), browser type and device category — collected via Google Tag Manager and Google Analytics.
  • Contact and pilot requests: when you email us or submit the pilot request form, we process the details you provide (name, email, company, role, team context, and anything you choose to tell us).
  • Audit-related identifiers: when you run the hosted Architecture Audit, the repository URL you submit (public GitHub URL, or an anonymised "upload" marker for ZIP submissions) and the resulting audit record. See Security & data handling for exactly what an audit record contains.
  • Support communications: email correspondence with us.

We do not collect payment or billing information.

What we do not collect

  • No account registration or login — Mneme HQ has no user accounts
  • No payment or billing information
  • No telemetry from the Mneme CLI unless you explicitly opt in (currently not implemented)

The open-source CLI and enforcement engine run entirely on your machine or CI and do not send your code anywhere.

Repository material and the hosted Audit

Repository material submitted to the hosted Audit (source files, ADRs, agent instructions, configuration) is classified and processed separately from ordinary personal data: it is not used for marketing, profiling, or advertising, and it is not shared with third parties except the infrastructure providers listed below. Original repository files are transient — extracted to a temporary working directory for analysis and deleted when the audit completes. The audit result (discovered decisions, classifications, proposed guardrails) is retained as described on the data-handling page.

AI and model processing

Mneme does not use customer source code to train models, and repository material submitted to the hosted Audit is never sent to any external AI model provider. The Audit analysis is deterministic (no machine learning, no inference calls). There is no training pipeline in Mneme. If this ever changes, this policy and the data-handling page will be updated first, and the change will be stated explicitly.

Why we process data (purposes and legal basis)

  • Operating the website and the hosted Audit — legitimate interest / contract
  • Providing the Audit and, where agreed, supporting pilots — contract
  • Responding to enquiries and supporting design partners — contract / legitimate interest
  • Website analytics to improve the site — legitimate interest, with an opt-out (see Cookies below)
  • Security, service integrity and legal obligations — legitimate interest / legal obligation

Third-party services and infrastructure providers

ProviderServiceDataLocation
Google (Ireland Ltd / LLC)Google Tag Manager, Google AnalyticsWebsite analyticsUS and EU
Google CloudCloud Run + Cloud SQL (hosted Audit)Repository material during processing; audit resultsus-central1 (US)
GitHubPublic repository clone source; open-source hostingPublic repository contentGlobal
CloudflareCDN / edge for mnemehq.comWebsite trafficGlobal edge
FormspreePilot request form deliveryContact details you submitUS

We use no other third-party tracking services. We previously used a visitor-identification service (RB2B, operated by GetEmails, LLC) which, with consent, associated visits from some US-based visitors with company and professional contact details. That service was removed on 7 August 2026 and is no longer loaded on any page. Any cookies it set previously may still need clearing through that provider or your browser.

Cookies and changing your choices

Google Analytics runs on a legitimate-interest basis under Google's Consent Mode; analytics storage is granted by default. You can opt out at any time using Google's Analytics opt-out browser add-on, or block cookies in your browser settings. A first-party cookie preference control is planned.

International transfers

Website analytics and the hosted Audit may process data in the United States (Google Analytics; Google Cloud Run and Cloud SQL in region us-central1; Formspree). Where personal data is transferred outside the UK/EEA, we rely on the provider's standard contractual clauses or equivalent safeguards. Repository material submitted to the Audit is processed in the United States as described on the data-handling page.

US state privacy rights

We do not sell or share personal information as those terms are used in the California Consumer Privacy Act or comparable US state privacy laws. To exercise any privacy right, email [email protected] with "Your Privacy Choices" in the subject.

Data retention

  • Website analytics: 14 months in Google Analytics (the platform default)
  • Email correspondence: for as long as relevant to the conversation
  • Pilot request submissions: for as long as relevant to evaluating and running the pilot
  • Audit records: retained until deletion is requested — see retention and deletion

Your rights

You can request access to, correction of, or deletion of any data we hold about you by emailing [email protected]. You may also object to processing based on legitimate interest, request restriction, or request portability of data you have provided to us. You have the right to lodge a complaint with a supervisory authority — in Estonia (our establishment), the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee), or the supervisory authority of your usual place of residence or work. For anonymous analytics data, we have no way to identify you in the dataset.

Changes to this policy

This policy is versioned (see the version and date at the top). If we make material changes, we will update the version and date at the top of this page, and state what changed. Continued use of the site after changes constitutes acceptance of the updated policy.

Contact

Questions about this policy or any privacy request: [email protected].