Your systems stay the system of record.
memmoo orchestrates work inside the systems you already run. Cloud co-workers act through your own cloud apps; on-device co-workers process locally and transmit nothing off the machine. What memmoo holds is set out below: the account, the co-worker configuration, the credentials you authorise, and the action log that makes each run auditable.
Where your data lives
Scroll sideways to see the whole diagram →
memmoo orchestrates
The cognitive layer decides what should happen next, then instructs a co-worker to do it in your system of record. The decision travels; the data does not.
Cloud co-workers work inside your apps
Chloe, Max, Alex, Smart Inbox, Marketing Buddy and Billing & Payments Buddy operate inside your QuickBooks, Salesforce or SAP through their APIs, under credentials you authorise and can revoke.
On-device co-workers never transmit
Daily Buddy, TimePal and Inbox Buddy run entirely on your machine, so the content they handle is not transmitted off the device. Suited to personal productivity, local files and private journaling.
Human in command
- Human-in-loop from run one
A person approves each action before it commits. Nothing acts unattended on day one.
- Autonomy is earned, not granted
A co-worker moves to autonomous operation after 50 successful transactions on that workflow — evidence, not optimism.
- Override at any point
Pause a co-worker, revert to human-in-loop, or revoke its access. The control sits with your team, not with memmoo.
- Every action logged
Each co-worker logs every action it takes. The self-reporting layer writes its own accountability, so you always know what happened, why, and what is next.
Failures are visible by design
When a process breaks — an API fails, a document format changes, an approval stalls — memmoo detects it, reroutes automatically, notifies the right person with full context, and resumes the moment it is resolved. Silent failures disappear.
That matters for security as much as for operations: an automation that fails quietly is an automation nobody is governing.
What each plan gives your security team
Governance features are tied to plan, so a security review can start from the published list.
| Capability | Launch | Growth | Transform | Enterprise |
|---|---|---|---|---|
| Audit trails | Standard | Advanced | Advanced | Enterprise |
| Human-in-loop controls | ✓ | ✓ | ✓ | ✓ |
| Workflow scheduling | — | ✓ | ✓ | ✓ |
| SSO / SAML | — | — | ✓ | ✓ |
| Data residency | — | — | — | ✓ |
| On-device / private cloud deployment | — | — | — | ✓ |
| Records stay in your systems | ✓ | ✓ | ✓ | ✓ |
Full plan comparison on the pricing page →
Three places a co-worker can live
On your device
The co-worker runs locally and transmits nothing. Suited to personal productivity, local file handling and anything that must not leave the endpoint.
Enterprise option.
Your private cloud
The co-worker runs in your own cloud tenancy, inside your network boundary and your existing controls, with data residency where you need it.
Enterprise option.
Hybrid
Sensitive steps on-device or in your private cloud, everything else through your cloud apps — one fleet, one cognitive layer, one audit trail.
Enterprise option.
What is held, and for how long
Held to run the service
- Account, user and billing records
- Co-worker configuration and the SOP instructions you provide
- Integration credentials you authorise — revocable at any time
- The action log that makes each run auditable
Not copied into memmoo
- Your business records — invoices, claims, orders, tickets, ledgers
- Anything an on-device co-worker touches
- Copies of documents processed inside your cloud apps
Retention
Personal information is kept only for as long as necessary for the purposes set out in the Privacy Policy, unless a longer retention period is required or permitted by law.
Your privacy rights
In some regions, including the European Economic Area, you can request access and a copy of your personal information, request rectification or erasure, restrict processing, and where applicable data portability.
How long each class of record is kept
These are the periods published in section 6 of the Privacy Policy. Where a longer period is required or permitted by law, the legal requirement governs.
| Class of record | Retention period |
|---|---|
| Transient run content | Deleted at the end of the run, and normally within 24 hours |
| Prompt and output records | Up to 30 days, where this record-keeping is enabled |
| Execution logs | Up to 12 months |
| Security and audit logs | Up to 12 months |
| Voice note audio | 7 days |
| Voice note transcript | 30 days |
| Backups | Up to 35 days |
| Consent records | Up to 7 years |
The Privacy Policy retention clause is the authoritative version of this table. Deletion and access requests go through the privacy request form →
How the models are governed
Your content does not train shared models
Customer content is not used to train shared foundation models. Co-workers are configured with the SOPs you give them; that configuration belongs to your account.
A published sub-processor register
The processors and model providers involved in delivering the service are listed, with role and location, in the sub-processor register.
Human in command, by design
Meaningful human review is required for decisions with legal or similarly significant effects. Co-workers begin human-in-loop and a person can override at any point; every action is logged either way.
Out-of-scope data categories
The service is not intended for special-category personal data, criminal-offence data, HIPAA protected health information, full payment card data or children’s data. No Business Associate Agreement is offered as a standard term.
Stated precisely, not badged
These are the frameworks memmoo’s security programme is aligned to, worded exactly as they appear on the Microsoft commercial marketplace listing. Alignment is not certification and we do not present it as such.
GDPR
EU General Data Protection Regulation. Data processing terms, sub-processor disclosure, transfer mechanisms and data subject request handling are published.
FADP
Swiss Federal Act on Data Protection, covering Swiss-resident data subjects on the same operational controls.
SOC 2
The SOC 2 trust services criteria inform how access control, change management, logging and incident response are run. memmoo does not claim to be SOC 2 certified, compliant or audited.
Security and vulnerability reports
Report a suspected incident or a vulnerability to security@memmoo.com. Include reproduction steps and your disclosure timeline; we will acknowledge and keep you updated through resolution.
Data subject and privacy requests
Access, correction, deletion, portability, restriction and objection requests go to privacy@memmoo.com or through the privacy request form, which records the identifiers we need to verify you.
Who you are dealing with
Two legal entities, one set of published terms. Which one contracts with you depends on your purchase path — all four are set out on the pricing page →
What review teams ask
Bring your security review to the discovery call
Deployment model, governance features, action logging, credential handling — we would rather answer it in the first hour than the fifth week.