Sheet 01 · Legal

Privacy Policy

This policy covers www.mnemos.ai, the Mnemos web application, and the Mnemos Shopify app. It is written to be read, not to be survived.

Rev. — last updated March 1, 2026
01

The short version

Mnemos connects to systems you already use and reads them so it can answer questions about your operation. It requests read-only access. It does not sell your data, does not use it to advertise to you or anyone else, and does not use your commerce data to train models for other customers. When you disconnect a system or uninstall the app, we stop reading it and delete what we hold.

02

Who we are

Mnemos provides a commerce-operations agent for merchants. For questions about this policy, or to make a request about your data, write to support@mnemos.ai. We answer data requests from a person, not a queue.

03

Account data we collect

To run an account, we collect and store:

  • Your name and email address, from Shopify at install or from you at signup.
  • Your workspace name, and which other people you have invited into it.
  • Authentication records — a session identifier, and an identity-provider user id if you sign in with Google, Microsoft, or a password.
  • Billing records: plan, subscription status, credit balance and usage. Card details are held by our payment processor or by Shopify, never by us.
  • Ordinary service logs: request timestamps, IP address, browser and error traces, kept for security and debugging.
04

Shopify data we access

When you install the Shopify app or connect a store, Mnemos is granted read-only scopes and reads the following from your store, on an ongoing basis, so answers reflect the current state of the business:

  • Orders and line items, including historical orders beyond the default 60-day window.
  • Products, variants, prices and publication status.
  • Inventory levels, per variant and per location.
  • Locations and their fulfillment roles.
  • Fulfillments and tracking events.
  • Returns and their reasons.
  • Customer records attached to orders — name, email, and the order history that joins to them.
  • Shipping methods and rates.

Mnemos holds no write scopes. It cannot change a product, an order, an inventory level, a price, or a customer record, and it cannot message your customers. Where you connect other systems — an ERP, an accounting tool, a help desk, a warehouse or a documentation site — the same rule applies: read-only credentials, stored encrypted, used only to answer questions inside your workspace.

05

How we use it

We use the data described above only to:

  • Run the initial census and keep your workspace's picture of the operation current.
  • Answer the questions you and your team ask, and show the records behind each answer.
  • Watch for changes you asked to be told about, and run the weekly review.
  • Remember facts and decisions your team tells the agent, scoped to your workspace.
  • Operate, secure, support and bill the service.

Answering a question involves sending the relevant records to an AI model provider acting on our behalf under contract. Your commerce data is not used to train general models, and it is never used to answer another customer's question.

06

Who else sees it

We do not sell personal information, and we do not share it for advertising. We use a small number of subprocessors to run the service — cloud hosting and infrastructure providers, and AI model providers — each under contract, each limited to processing data on our instructions. We also share billing information with Shopify or our payment processor as needed to charge you. Beyond that, we disclose data only when the law requires it, and we will tell you unless we are legally barred from doing so.

07

How long we keep it

Commerce data is kept while your workspace is active, because the product's value is continuity — a review is only useful next to last quarter's. If you disconnect a system, we stop syncing it and delete the data derived from it within 30 days.

If you uninstall the Shopify app, access ends immediately: the connection is disabled and the offline token is discarded. Shopify then sends a mandatory shop/redact request, and on receiving it we delete that shop's commerce data and stored credentials. A customers/redact request deletes the records for the named customer. A customers/data_request is answered with what we hold for that customer. Backups age out on their own schedule, within 90 days.

08

Your rights

Depending on where you live, you may have the right to access, correct, export or delete personal data we hold about you, and to object to or restrict some processing. Write to support@mnemos.ai and we will act on it. Where we process store data on a merchant's behalf, we act on the merchant's instructions and will refer an end-customer request to them.

09

Security

Credentials are encrypted at rest and are never shown back to you or to us in plain text. Data is isolated per workspace at the database level, so one workspace's query cannot read another's rows. Access to production is limited and logged. No system is perfect; if we ever have a breach affecting your data, we will tell you promptly and plainly.

10

Children

Mnemos is a business tool and is not directed to anyone under 16. We do not knowingly collect personal information from children.

11

Changes to this policy

If this policy changes materially, we will update the date at the top and notify workspace owners by email before the change takes effect. Continuing to use Mnemos after that means the new version applies.

Sheet 03 · Close