MYREE
·

Privacy Policy

Last updated: 5 October 2026

MYREE stores your memory and uses the OpenAI API to think over it. Here is exactly what we collect, where it lives, and how you stay in control of it.

01 · Who we are

MYREE is a service of Cuadro S.r.l., Via Toscana 45/1, 43123 Parma, Italy, VAT number 03104310341, certified email cuadrosrl@pec.it. Aclas is a brand of Cuadro S.r.l.

Cuadro S.r.l. is the data controller of your personal data. For any privacy question or request write to admin@cuadrogroup.com.

This policy explains what data we collect, why we use it and the rights you have.

02 · Data we collect

Account data: your email address, a hashed (one-way encrypted) version of your password, your display name and, if you upload one, your profile photo. If you sign in with Google, we receive your email address and an account identifier to recognise you — we never receive your Google password.

Content you create: notes, decisions, memory atoms, conversations with the assistant, content pieces and drafts, diary entries, your Identity Card and your settings. This is the data you deliberately put into the app.

In your browser we store only a session cookie (to keep you signed in) and your theme and language preferences. The session cookie is HttpOnly, meaning it cannot be read by JavaScript running on the page. We use no advertising cookies and no third-party tracking or analytics.

Technical data: for each sign-in we keep the IP address and browser type of the session, so that you can see it and revoke it. If you connect Claude or ChatGPT we keep the connection token, which assistant it is and when it was last used. We also keep a count of each account's actions (saves, recalls, messages, voice characters) without their content, to apply usage limits and to understand how the service is used.

What you write is free text: it can contain information about other people, or sensitive data, if you choose to put it there. The names of people and things mentioned in a memory are stored with it. We do not ask the model to infer your mood or your emotions.

MYREE in beta is for adults only and for personal use only. Do not enter data about clients, colleagues or employees, or confidential information of your company. If you write about other people, do so only within the limits of personal use.

03 · Why we use your data

We use your data only for these purposes:

• To give you the service (account, memory, search, summaries, connectors): this is the performance of our contract with you (Art. 6(1)(b) GDPR).

• To process the sensitive data you choose to write, for example about health, political opinions, religion or sex life: only with your explicit consent (Art. 9(2)(a) GDPR), which you give at sign-up and can withdraw at any time.

• To protect the service and apply usage limits (sessions, IP address, counts): this is our legitimate interest in security (Art. 6(1)(f) GDPR).

• To comply with the law, when a rule requires it (Art. 6(1)(c) GDPR).

We do not use your data for advertising or profiling, and we make no automated decisions that produce legal effects on you.

04 · Where your data lives

Your notes, atoms, conversations and settings live in MYREE's own PostgreSQL database, on the server this instance runs on, scoped to your account. They are never shared with other users.

The server is hosted by Hostinger in Frankfurt, Germany (European Union). An encrypted backup copy of the database is made every night, kept on the same server for 7 days and then deleted. Hostinger also keeps weekly copies of the whole server, for up to two weeks, in its data centre in Vilnius, Lithuania (European Union). Overall, every backup is deleted after 14 days at most.

05 · AI processing

Chat replies, content generation and atom extraction are produced by OpenAI's API (gpt-4o-mini and text-embedding-3-small). For each request, only the text it needs — your message and the relevant memory — is sent to OpenAI to produce the response.

OpenAI processes this data on our behalf, as a data processor, under a Data Processing Addendum. Our account is set so that content is not shared with OpenAI to train its models. Your full database is never uploaded anywhere: only what a given request needs ever leaves the server.

OpenAI processes these requests outside the European Union as well, including in the United States. The transfer is based on the standard contractual clauses approved by the European Commission, which are part of our agreement with OpenAI. According to its documentation, OpenAI may keep the content of requests for up to 30 days in its abuse-monitoring logs, after which it is deleted. In addition, every night the summaries of the day's memories are sent to OpenAI to produce one short summary of the day.

06 · Using MYREE with Claude or ChatGPT

You can connect MYREE to Claude (Anthropic) or ChatGPT (OpenAI) as a connector. The connection is made only after you sign in to MYREE and explicitly allow it, and it gives the assistant access to your memory only: recalling what you saved and saving new memories.

When the assistant saves a memory, the text reaches MYREE, is stored in our database and is sent to OpenAI's API to be organised into memories, as described above. When the assistant recalls a memory, the question reaches MYREE and the relevant memories are returned to the assistant: from that moment that text is part of your conversation with Claude or ChatGPT and is subject to the terms and privacy settings of your own account with Anthropic or OpenAI, not to this policy.

The assistant can save automatically: when you share something worth remembering (a decision, a plan, a preference), it can save it into MYREE without asking your permission each time. It confirms this in the conversation.

You can disconnect an assistant at any time from Settings → Connectors: the connection stops working at once. To prevent abuse and runaway costs, saves and recalls have a daily limit per account.

07 · Third parties

We share data only with the providers needed to run the service, who process it on our behalf: Hostinger (server in Frankfurt and sending of service email, such as account verification and password resets; European Union), OpenAI (AI processing; United States, with standard contractual clauses) and, only if you turn on read-aloud for replies, ElevenLabs, which receives the text of the reply to be spoken (United States). We do not sell your data and we do not use it for advertising.

If you sign in with Google, authentication is handled by Google under their privacy policy. We use Google sign-in only to verify your identity; we do not read or store any other data from your Google account unless you explicitly connect a service such as Google Calendar (see the dedicated section).

08 · How MYREE accesses, uses, stores and shares Google user data

This section is our complete disclosure of how we handle Google user data. MYREE requests a single sensitive Google scope, “https://www.googleapis.com/auth/calendar.events”, and only if you choose to connect Google Calendar from Settings → Connectors. If you never connect it, MYREE accesses no Google user data beyond the email address and account identifier used to sign you in.

DATA WE ACCESS. With that scope, our application accesses the events on your primary Google Calendar: the title, the start and end date and time, and the link to the event. We do not access Gmail, Drive, Contacts, Photos or any other Google service, and we request no other scopes.

HOW WE USE THIS DATA. We use your calendar data solely to provide and improve the app features you asked for: showing your commitments alongside your memories in the Calendar tab, and creating, changing or deleting the events you explicitly ask us to. Every write is shown to you as a proposal first and happens only after you confirm it. We do not use Google user data for advertising, profiling, market research, resale, or to train artificial intelligence models, whether ours or anyone else's. In particular, we do not use data obtained through Google Workspace APIs (including Google Calendar) to develop, improve, or train non-personalized or generalized artificial intelligence (AI) and/or machine learning (ML) models.

HOW WE STORE IT. Calendar events are NOT stored. They are fetched from Google live, only for the date range you are looking at, shown on screen and then discarded: they are never written to our database, never become memories or atoms, and are never indexed for search. The only information we retain to keep the connection working is the email address of the connected Google account and an OAuth refresh token, which is encrypted at rest.

HOW WE SHARE IT. We do not share Google user data with anyone. In particular, your calendar data is never sent to OpenAI or to any other provider or third party, is never sold, and is not transferred except where required by law or where you explicitly ask us to.

RETENTION AND DELETION. You may revoke this access at any time, without losing any other feature of the app. Disconnecting the calendar from Settings → Connectors immediately deletes the refresh token from our database and revokes the access at Google; you can also revoke it from Google's “Third-party apps with account access” page (myaccount.google.com/permissions). Because we store no events, no calendar data remains to be deleted.

LIMITED USE. MYREE's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

09 · Data protection and security

Security procedures are in place to protect the confidentiality of your data. We use encryption to protect your information, including sensitive data such as Google access tokens and account credentials.

In concrete terms: all traffic between your browser and MYREE is encrypted in transit over HTTPS/TLS; the Google refresh token is encrypted at rest in the database and is never exposed to the browser; passwords are stored only as one-way hashes (bcrypt) and are never readable, including by us; the session lives in an HttpOnly cookie, so it cannot be reached by JavaScript on the page; requests that change data require an anti-CSRF header; and a Content Security Policy with a per-request nonce blocks unauthorised scripts.

Every row of data is scoped to its own account, and isolation between users is enforced in the database query itself, not only in the interface: another user's data is not reachable even if its identifier is known. Access is limited to the personnel who need it to operate the service. You can end a session on any device, or on all of them, from Settings.

No system is perfectly secure. If we became aware of a breach affecting your data, we would notify you without undue delay.

10 · Retention & deletion

We retain your personal information for the length of time needed to fulfil the purposes outlined in this privacy policy — that is, for as long as your account is active — unless a longer retention period is required or permitted by law. When the retention period expires for a given type of data, we delete it.

You can export everything as a JSON archive at any time from Settings → Data. From the same place you can erase all your content while keeping the account (“Delete all my data”), or delete the account (“Delete my account”). Deleting the account immediately and permanently removes from the database the account and everything linked to it: memories, pages, conversations, settings, sessions, the Claude, ChatGPT and Google connections, and the usage counts. You may also request deletion by writing to admin@cuadrogroup.com.

After a deletion, data can remain in our encrypted backup copies for up to 7 days, in the weekly server copies kept by Hostinger for up to two weeks, and in OpenAI's logs for up to 30 days, as described above. Anything a connected assistant already received inside one of your conversations stays with that service, under its own terms.

11 · Your rights

You have the right to:

• access your data and receive a copy;

• have it corrected;

• have it deleted;

• restrict or object to its processing;

• receive it in a format another service can read (portability);

• withdraw your consent for sensitive data at any time, by deleting that content or your account, or by writing to us. Withdrawal does not affect what was done before.

Export and deletion are available directly in Settings → Data, or from the buttons at the bottom of the Connectors page. For everything else write to admin@cuadrogroup.com: we reply within one month.

If you believe the processing of your data breaks the law, you can lodge a complaint with the Italian data protection authority, Garante per la protezione dei dati personali (www.garanteprivacy.it).

12 · Changes to this policy

If we update this policy we will change the “Last updated” date above. If we change how MYREE uses Google user data, we will notify you before the change takes effect, by email to the address on your account and with a notice in the app. Other material changes will be announced in the app.

13 · Contact

Cuadro S.r.l., Via Toscana 45/1, 43123 Parma, Italy. Email: admin@cuadrogroup.com. Certified email: cuadrosrl@pec.it.

← Back to MYREE/privacy/terms