Last updated: 2026-08-21
The default myAI configuration makes zero outbound network calls. Memory is a local database and a folder of markdown you can walk away with (myai memory export). We are not a processor of your context because it is never transmitted to us. There is no telemetry and no silent upload.
If you create an account on our hosted service or subscribe to a paid tier, we collect only:
We do not collect your agent memory, code, repositories, prompts, or task history — those stay on your machine.
The software you self-host contacts an external service only when you supply the corresponding credential in your own .env. These are your integrations under your own accounts, not data we share:
None of these receive your memory corpus. Each provider's own privacy policy governs the data you send it.
We do not sell personal data, and we do not use your account data to train models.
Because your context lives on your hardware, deletion is largely in your hands: stop the stack, remove the database volume, and it is gone. For hosted account data, we retain it while your account is active and delete or anonymise it within 30 days of account closure, except where we must keep billing records to meet legal and tax obligations. To request access or deletion of hosted account data, contact us (Section 8).
Account credentials are hashed, API keys are stored SHA-256 hashed and compared in constant time, and the local stack ships loopback-bound by default. Full detail is on the Security & Data Locality page.
Questions or data requests: open a private thread via the repository or email the maintainer listed in the repo profile. We will post any material change to this policy on this page and update the “Last updated” date above.
This document is a plain-language policy, not legal advice; adapt it to your jurisdiction before relying on it commercially.