AideMemo Connector privacy

Effective date: September 26, 2026.

This notice covers the AideMemo Connector service only. It is not a privacy notice for every feature of the AideMemo app.

A relay, not a store

When an assistant uses a connector, this service sends a wake-up notification to your iPhone, holds the assistant's request in memory until AideMemo on the iPhone collects it, and returns AideMemo's answer to the assistant. Search words, memory text and your iPhone's push token pass through only while that request is handled, for at most about 25 seconds, and are then discarded. The service has no accounts, cookies or analytics, and it keeps no memories.

Connector tokens

A connector URL or token contains your iPhone's push token and a connector credential, encrypted with a key only this service holds. The assistant you give it to keeps it; AideMemo does not store a copy. Pausing or removing the connector in AideMemo on your iPhone stops it from working.

Connecting from an assistant

When you connect AideMemo from an assistant's sign-in page, there is no account: you approve the request in AideMemo on your iPhone. Until the connection is finished, this service keeps the pending request: which assistant asked, the type of browser and device it came from, an approximate location (city, region and country) derived from the network address, and a salted one-way hash of that network address, used only to check whether your iPhone approved from the same network. The address itself is not kept. A request nobody approves is deleted after 5 minutes, and an approved one 10 minutes after approval. The assistant then holds an encrypted connector token as described above, and the service still stores nothing about you.

Logs

Request logs, invocation logs, tracing and log export are turned off in this service's deployment configuration, and the code logs nothing.

Apple Push Notification service

Apple delivers the wake-up notification. It carries only a random request identifier and a one-time code, never your search words or memories. Apple processes it under its own policies.

Assistants

What an assistant reads is kept by that assistant's provider under the provider's own policy. AideMemo cannot see or delete it. Share only what you are comfortable sharing with that provider.

Hosting and abuse protection

Cloudflare hosts this service and may process infrastructure metadata, such as IP addresses, under its own policies. Turning off application logs does not mean that no infrastructure metadata is processed. Rate limiters keep temporary aggregate counts keyed by a fixed name or a one-way hash of the connector credential, never by IP address.