FishMem

Privacy Policy

This policy explains how FishMem collects, uses, discloses, and protects personal information when you use the website, dashboard, APIs, and related services.

Effective: August 12, 2026Last updated: August 12, 2026Service operator and contracting entity: BLENDDUCK LLC

1. Who is responsible

BLENDDUCK LLC operates the hosted service and is responsible for the account, billing, website, and service-operation data described here. A customer remains responsible for deciding what its application sends to FishMem, which people it covers, and the notices, permissions, and legal basis required for that content.

2. Account and commercial information

We collect information you provide directly, including email address, name or username, authentication profile, organization and project settings, support messages, invitation state, and billing metadata returned by our payment processor. We do not receive full payment-card numbers.

3. Memory and document content

The service processes memory inputs, extracted records, metadata, source documents, search queries, retrieved results, feedback, and operation state that you or your application submit. This content may contain personal data selected by the customer. Scope identifiers and project boundaries are used to isolate it within the service.

4. Usage and security data

When you use FishMem, we may process IP address, browser and device information, timestamps, request identifiers, API-key metadata, event status, credit usage, error and security logs, and cookie or analytics signals needed to operate, measure, troubleshoot, and protect the service.

5. Information from other services

Identity providers may return a name, email address, profile image, and provider account identifier according to your authorization. Payment providers return subscription, invoice, payment-status, tax, fraud, and dispute metadata. Model, infrastructure, email, and analytics providers process only the data needed for their configured role.

6. Purposes and legal bases

We use personal information to perform the service contract; authenticate users; run projects, memories, documents, events, API keys, billing, and support; protect the service and prevent abuse; comply with law; and improve reliability. Where required, we rely on consent for optional analytics or marketing and on legitimate interests for proportionate security, debugging, and product measurement.

7. AI and model providers

Inference-enabled requests may send the submitted content and necessary context to the model provider configured for the hosted project. Provider terms and retention rules apply to that processing. Verbatim writes do not invoke memory inference. We do not use customer memory or document content to train public models unless the customer separately and explicitly opts in.

8. Sharing and sale

We do not sell personal information or use customer content for targeted advertising. We disclose information to processors that operate hosting, storage, model inference, identity, email, analytics, support, and payments; to professional advisers; when legally required; to protect users and the service; during a corporate transaction; or when you direct or consent to the disclosure.

9. International processing

Our providers may process information outside your country. Where applicable law requires it, we use an approved transfer mechanism or another recognized safeguard. Local laws in the destination may differ from those where you live.

10. Retention, export, and deletion

Memory and document content remains until the customer deletes it, the account or project is deleted, or an agreed retention rule applies. Exporting content does not delete it. Operational, security, tax, payment, dispute, and backup records may remain for a limited period needed for integrity, fraud prevention, legal compliance, or disaster recovery. Deletion from active systems may not immediately remove encrypted backup copies, which are removed or overwritten on the backup lifecycle.

11. Security

We use HTTPS, scoped credentials, one-time display of API-key secrets, hashed stored key material, tenant and project boundaries, and operational logging designed to avoid secret values. These controls reduce risk but cannot make transmission or storage completely secure. Customers must protect credentials, choose appropriate content, and rotate a key whenever exposure is suspected.

12. Your rights and choices

Depending on your location, you may have rights to access, correct, delete, export, restrict, object to, or withdraw consent for eligible personal information, and to appeal a denied request or complain to a regulator. Account owners can use service controls for project content; other requests can be sent to support@fishmem.com. We may verify identity and retain information where an exception applies.

13. Children

FishMem is not directed to children under 18, and we do not knowingly collect their personal information through consumer accounts. Customers must not submit children's data unless they have a lawful basis, appropriate notices and consent, and a written service arrangement that permits it.

14. Changes to this policy

We may update this Privacy Policy from time to time. The updated version will be posted on this page with a revised last updated date. Significant changes may be notified by email or in-service notice.

15. Contact

Privacy questions and rights requests can be sent to support@fishmem.com. Include the relevant account or organization without sending an API key, password, or other secret.