Privacy Policy
This policy explains what information is collected when you use sepiace, how it is used, whom it is shared with, and how it is deleted. In this policy, the operator means [Operator name], which runs sepiace.
Effective September 28, 2026.
1. Information we collect
To provide sepiace, the operator collects the following information.
Account
Your email address, when you signed up, and whether your email address has been verified. You sign in with a code or a link sent to that address. The code is stored in hashed form and expires after 10 minutes.
Sign-in sessions
When you sign in, a session is stored with your IP address and your browser’s user agent at that time, along with its expiry.
Connected clients
When you connect an MCP client such as Claude Code, the information the client registers, such as its name and redirect URLs, is stored. The access tokens and refresh tokens issued to it, their expiry, and the permissions you approved are stored as well.
Requests
These are the natural-language sentences your agent sends to the memory tool. The whole sentence is used to process the request, but the sentence itself is not stored. Only the parts cut out as memory text are stored.
Memories
For each memory, the following are stored: a Key that serves as its heading, the text cut from your requests, values that record how well the memory has settled, and the dates it was created, updated, and last recalled.
Vectors for search
So that related memories can be found, each memory’s Key is converted into a numeric vector and stored.
Looked-up terms
When sepiace is unsure while saving or tidying up memories, it may look up terms on the web. The terms and the excerpts found are stored separately for each user.
Logs
For each request to the service, the time, path, method, response status, and processing time are recorded. For memory requests, the operations that were chosen are recorded too. The daily tidy-up records your user ID and the number of memories it changed. Logs do not include the text of your requests or memories.
This website
This website does not ask you to register and does not use cookies. The website and the service are delivered by Cloudflare, which handles your IP address and similar access information to deliver them.
Memories contain what you or your agent send. Do not send information you do not want stored, such as passwords, or sensitive personal information about other people.
2. How we use information
The information collected is used for the following purposes.
- To let you sign in, and to connect and authorize MCP clients.
- To send sign-in codes and links to your email address.
- To save, recall, search, and forget memories as your requests ask, and to tidy up memories once a day.
- To prevent abuse, for example by limiting how often sign-in emails are sent to each email address and from each IP address.
- To investigate failures, keep the service secure, and improve it.
- To respond to your inquiries and to the requests described below.
- To notify you of important changes to the service, this policy, or the Terms of Service.
The operator does not use the information to train machine learning models. The operator does not sell it or use it for advertising.
How the external services in the next section treat the information they receive, including whether they use it for training, depends on each service’s own policies.
3. External services and where data is stored
The operator does not provide your personal information to third parties, except in the cases below, where required by law, or with your consent. To run sepiace, information is sent to the following services.
Cloudflare
Cloudflare, Inc. runs this website and the service. Accounts, sessions, connected clients, memories, and looked-up terms are stored in Cloudflare D1, and vectors in Cloudflare Vectorize. Cloudflare Workers AI converts the text of each request and each memory Key into vectors. Sign-in emails are sent through Cloudflare and contain your email address, the code, and the link. Your email address and IP address are used to limit how often sign-in emails are sent. The logs described above are recorded in Cloudflare.
OpenRouter
OpenRouter, Inc. runs the model that judges each request. For each request, it receives the text of the request, the Keys and text of your memories, the current date, and any excerpts of looked-up terms. It receives up to 120 memories, and up to 24,000 characters of Keys and text combined. During the daily tidy-up, it receives the Keys and text of up to 500 of your memories. OpenRouter passes this information to the provider that serves the model.
Exa
Exa Labs, Inc. provides web search. When sepiace is unsure while saving or tidying up memories, it may send up to three words or names written in Latin letters at a time, taken from the request or the memory text. Only those words are sent, not whole sentences or information that identifies you. The results are stored for each user so that the same term is not looked up again and again.
Google Fonts
Google LLC provides Google Fonts. When you view this website, your browser loads fonts from Google’s servers, and Google receives your IP address and browser information.
Google Analytics
Google LLC provides Google Analytics. When you view this website, it receives information about the pages you view, your IP address, and your browser information through cookies. The operator uses it only to understand how this website is used.
These companies are based in the United States, and the information may be handled in the United States and other countries. The operator sends information to them only as far as needed to provide the service, under their terms and policies. Information about the personal information protection systems of the United States and other countries is available on the website of Japan’s Personal Information Protection Commission. On request, the operator will explain the measures these companies take to protect personal information.
4. How long information is kept, and deletion
- Your account, memories, vectors, and looked-up terms are kept until your account is deleted.
- Sign-in codes expire after 10 minutes. Sessions and tokens also expire, and expired ones can no longer be used.
- When you ask sepiace to forget part of a memory, it removes the named sentences from the memory text.
- When you ask sepiace to forget a whole memory, it weakens the memory instead of deleting it. A weakened memory stops appearing sooner when unused, but it stays stored.
- A memory that goes unused stops appearing in recall and search once its score falls below a set level, but it stays stored.
- Once a day, sepiace tidies up memories by moving sentences between them without rewriting them. A memory left with no sentences is deleted along with its vector.
- The service has no screen for deleting your account. To delete your account or all of your memories, contact the operator at the address below. The operator will delete your account, memories, vectors, looked-up terms, sessions, and connected clients.
- Logs are deleted when Cloudflare’s retention period ends.
5. Your requests
You can ask the operator to disclose, correct, add to, or delete the personal information it holds about you, or to stop using it or providing it to third parties. You can also ask for disclosure of records of providing it to third parties. To make a request, contact the operator at the address below.
To confirm that a request comes from you, the operator will contact you at the email address registered to your account. The operator responds without delay, as required by law.
You can recall and change memories yourself with the memory tool, but recall returns only the memories most relevant to your request. To receive all of your memories, contact the operator.
6. Security
The operator takes the following measures to protect personal information.
- Every database query and every vector search includes the signed-in user’s ID as a condition, so memories are kept separate for each user.
- Using the memory tool requires an access token with an expiry, issued through OAuth.
- Sign-in codes are stored in hashed form, and the number of sign-in emails is limited for each email address and each IP address.
- The text of requests and memories is not written to logs.
- API keys for external services are stored encrypted.
- Communication with this website and the service is encrypted with HTTPS.
7. Cookies
This website uses Google Analytics to understand how it is used. Google Analytics sets cookies in your browser and sends Google information such as the pages you view, your IP address, and your browser information. Advertising uses of these cookies are off unless you accept them in the cookie notice. You can change your choice at any time from Cookie settings at the bottom of each page.
The sign-in pages of the service use a cookie to keep you signed in. If you block this cookie, you cannot sign in.
While you sign in, your browser’s local storage temporarily keeps your email address and the state of the authorization, so that the link in the email can continue it. They are removed when the link is opened.
8. Changes to this policy
The operator may revise this policy when the service or the law changes. The revised policy is posted on this page with its effective date. Important changes are announced on this website or by email before they take effect.
9. Contact
sepiace is operated by [Operator name].
For questions about how personal information is handled, and for the requests described above, contact [Contact address].