Skip to main content
Memini AI
Blog

Sub-processor List

Controller: Artem Pecheriukin (NIF Z0774077V), Madrid, Spain. Postal address: see the Legal Notice. Last updated: 2026-07-07 Keeping this list current: we update this list when our sub-processors change; the date above shows the current version. Any AI provider we use is barred from training on your content; retention is zero or limited to a short abuse-monitoring window, as shown per provider below.


Active sub-processors

Sub-processor Purpose Personal data shared Location / jurisdiction Transfer mechanism (for EU/UK)
OpenRouter Gateway for speech-to-text and image/document text-extraction only (your dictated audio and uploaded files); routes only to no-retention providers (data_collection: "deny" set on every request). Not used for Google user data: content imported from Google APIs never routes through OpenRouter, and chat/embeddings do not use it Dictated/uploaded audio; uploaded images and scanned documents US gateway, routes to US/EEA inference providers Zero data retention + no training enforced per request; SCCs (their ToS, EU law) + TIA
Novita Managed chat-model inference for all tiers, including deep reflection modes and nightly memory consolidation (open-weight LLM; specific model may change); reached directly, no gateway. Chat processor for memory content, including imported Google Calendar content Chat messages + memory context (only structured IDs masked; may include imported calendar events) US-incorporated (San Francisco); distributed multi-cloud processing Zero data retention + no training in their Terms of Use (binding); SCCs (their Privacy Policy) + TIA
OpenAI (direct) Text embeddings for memory indexing (may include imported calendar content) + failover chat inference when the primary chat provider is unavailable Memory text for embeddings; chat messages + memory context during failover US No training on API content (API default); requests retained at most 30 days for abuse monitoring, then deleted; DPF or SCCs + TIA
Google — Gemini (via OpenRouter) Image and scanned-document OCR User-uploaded images and documents (may contain arbitrary PII) US DPF or SCCs + TIA
Cloudflare (R2 + reverse proxy) Media object storage; CDN/proxy fronting the API Uploaded audio/images; IP/traffic metadata EU (R2 bucket in EU region) Data at rest in EU; SCCs + TIA for US-parent access
RevenueCat Subscription entitlement source of truth User UUID, transaction/product IDs, entitlement status (no card data) US DPF or SCCs + TIA
Google — Firebase Cloud Messaging Push notifications Device push tokens + notification payloads US DPF or SCCs + TIA
Brevo (Sendinblue) Transactional email (verification, reset, security notices) Email address + message body EU (France) EEA — no transfer
Railway Application, database, and cache hosting All runtime data in transit and at rest EU Data at rest in EU; SCCs + TIA for US-parent access
Apple / Google Sign-In Identity (ID-token sign-in) ID token → email/name US DPF or SCCs
SearXNG (self-hosted) Web search during chat tool-calling; federates to upstream search engines Search queries derived from chat self-hosted → upstream engines per upstream engine
Sentry Crash and error monitoring / app stability Crash reports, error events, device/OS/app version, technical context (may include IP + user ID) US / EU data region DPF or SCCs + TIA
Aptabase Privacy-preserving product analytics Anonymous, aggregated usage events (no PII, no persistent device IDs, no cross-app tracking) EU region EEA — no/limited transfer

Integration sub-processors (only if you connect them)

Sub-processor Purpose Data shared
Google (Calendar) Import calendar events into your memory Event subject, location, attendees, times
Notion Import Notion pages into your memory Page titles and block content

Note on imported data: when you connect an integration, Memini may process personal data about third parties (calendar attendees, Notion collaborators). For that data Memini acts as an independent controller under a documented legitimate-interest assessment.

Bring-your-own-key (BYOK) providers — not Memini sub-processors

These providers are available for bring-your-own-key inference. When you supply your own API key, they process your data under your account and terms, not as Memini sub-processors. Review each provider’s terms before use.

Provider Training default Jurisdiction
OpenAI No training by default (API); verify your account settings US
Anthropic No training by default (API); verify your account settings US
Google (AI Studio) Free tier may use data for product improvement; paid / Vertex: no training Global
Groq States no training; formal retention terms weaker Undisclosed

Managed vs BYOK: for Memini-managed AI processing (our key), the sub-processor table above applies, with the no-training and retention terms shown per provider. BYOK is a separate path: your key, your provider, your terms, your risk.

  • Privacy
  • Terms
  • Sub-processors
  • Support
  • Delete account
  • Legal Notice
  • Accessibility
  • Cookies
  • Report illegal content

This site uses only strictly necessary cookies. No analytics, advertising, or tracking cookies are set.

© 2026 Memini AI. All rights reserved.