MindSpace · Private by design
Privacy Policy
Effective Date: February 18, 2026 · Last Updated: August 7, 2026
Distilligent ("we," "our," or "us") is an AI memory platform — a place where your AI learns who you are, remembers what matters to you, and grows alongside you. That kind of relationship requires trust. This policy explains what data we collect, why, how we protect it, and your rights. We wrote it to be read, not to be hidden behind legalese.
The covenant, up front: nothing is remembered unless you say so. Every capture is opt-in, every capture is visible in a ledger you can read, and anything captured can be released — by you, at any time. The rest of this policy is the detail; that sentence is the deal.
1. Information We Collect
Account Information
When you sign in with Google, we receive:
- Your name and email address
- Google account identifier (user ID)
- Profile picture URL (if available)
Signing in requests only basic profile scopes. We do not touch your email, calendar, or files unless you separately and explicitly connect those services (see "Connected Services" below) — and you can disconnect them at any time.
Connected Services (Optional)
You can choose to connect Google services so your AI has real context. If you grant them — every grant is shown on Google's own consent screen, where you decide — we access:
- Gmail — message metadata and content of threads, used to surface priority mail, action items, and the people who matter to you
- Google Calendar — your events, used for scheduling awareness and meeting prep
- Google Drive — files you search for or point the AI at, used to answer your questions
Each connection is a separate OAuth grant that you approve on Google's own consent screen. You can revoke any of them at any time from your Google Account settings, and the connection stops working immediately.
Distilligent's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data from Google services is used only to provide features to you — never for advertising, and never sold.
Browser Extension Captures (Opt-In, With a Ledger)
Our browser extension can save things you choose — AI conversations, pages, threads — into your memory. It is built around consent:
- Consent buckets — captures are grouped by category (AI chats, email, shopping, health, school, any page). Every bucket except AI chats starts off; nothing in an off bucket is ever sent to our servers. AI chats start on, paired with ask-first (below), and can be switched off in one tap.
- Ask-first — buckets can be set to "ask me before keeping." You'll see a prompt in the page before anything is ingested. No answer within 20 seconds means it is not captured — silence never becomes consent.
- The ledger — every capture, skip, and release writes a row you can read in the extension popup: when, what, from where. Transparency isn't a request form; it's a running log.
- Local-first — your consent settings and ledger live in your browser's local storage, on your machine. Once you're logged in, your choices are also mirrored to our servers and enforced there, closing the gap a misbehaving client could otherwise exploit.
- Memory boost (context injection) — on supported AI-chat sites, the extension can add your relevant Distilligent memories to the message you send, so the AI you're talking to knows you. To find those memories, text you compose on those sites is sent to our servers as you type and used to look up your own memories. The added context travels inside your message to the AI platform you're using, the same way the rest of your message does. To pause this, disable or remove the extension.
Usage Data
We automatically collect:
- Pages and features you interact with
- Timestamps of your sessions
- Browser type and device information
- IP address (for security and rate limiting)
Your Memories & Content
When you use the platform, we store:
- AI memories — your conversations, context, and the things your AI learns about you
- Canvas artifacts and configurations you create
- Preferences and settings you configure
2. How We Use Your Information
| Purpose | Data Used |
|---|---|
| Authentication & account access | Google profile, email, user ID |
| Providing personalized AI experiences | Your content, preferences, interactions |
| Context from connected services (only if you connect them) | Gmail threads, calendar events, Drive files you point at |
| Improving the platform | Aggregated, anonymized usage data |
| Security & abuse prevention | IP address, session data |
| Customer support | Account info, usage context |
We do not sell your personal data. Ever. We do not use your data for advertising. We do not train AI models on your personal data or memories — your data serves you, not us, and your memories are used only to build your own context. Our business model is the service, not the surveillance.
3. Data Storage & Security
Your data is stored on Google Cloud Platform infrastructure in Montreal, Canada, using PostgreSQL databases with encryption at rest. Active session data is cached in Redis for performance and persisted to PostgreSQL for durability.
How Your Memories Are Stored
Your AI memories flow through a multi-tier architecture designed for both speed and safety:
- Hot layer (Redis) — Active memories cached for fast retrieval during conversations
- Persistent layer (PostgreSQL) — All memories durably stored with encryption at rest
- Per-user isolation — Every user's data is logically isolated. Your memories are never mixed with, accessible to, or visible to other users
Security Measures
- All data transmitted over TLS/HTTPS — no exceptions
- Data encrypted at rest in PostgreSQL
- Once you're logged in, captures are tied to your verified login token, so memories are provably yours
- Once you're logged in, consent is also enforced server-side: a capture from a bucket you switched off is rejected at the door
- Secure session management with HTTP-only, Secure cookies
- Role-based access controls at every layer
- Regular security reviews and monitoring
Your AI memories belong to you. They are never shared with other users, never sold, and never used to train AI models. You can release any memory at any time — from the extension's ledger or the Memory Constellation's "Release" feature. Released memories are recoverable for 10 days in MindSpace (in case you change your mind), then permanently deleted.
4. Third-Party Services
We integrate with the following third-party services:
- Google OAuth 2.0 — For authentication, and for the optional service connections described above. Google's privacy policy applies to data Google collects.
- Google Cloud Platform — Our hosting infrastructure provider (Montreal, Canada region). Subject to Google Cloud's security and privacy practices.
- AI Model Providers (Anthropic, OpenAI, Google) — Conversations may be processed by AI model providers to generate responses. We do not send your personal account information to these providers; only conversation content necessary for generating responses. Separately, if you use the extension's memory boost on a third-party AI chat site, the memories it adds are delivered to that platform inside your own message (see "Browser Extension Captures" above).
We do not embed third-party tracking pixels, analytics scripts, or advertising networks.
5. Cookies, Session Data & Extension Storage
We use essential cookies only — the bare minimum to keep you signed in and safe:
| Cookie | Purpose | Attributes |
|---|---|---|
| Session cookie | Keeps you signed in across pages | HttpOnly, Secure, SameSite=None |
| CSRF token | Prevents cross-site request forgery | Secure |
That's it. No tracking cookies. No third-party cookies. No advertising cookies. No persistent cookies that follow you around the internet.
The browser extension keeps your consent settings, login token, and capture ledger in your browser's local extension storage — on your machine, readable by you, removed when you uninstall the extension.
6. Data Retention
We retain your data as follows:
- Account data — Retained while your account is active
- Content you create — Retained until you delete it or close your account
- Released memories — Held in recovery for 10 days after you release them, then permanently deleted
- Usage logs — Retained for up to 90 days, then anonymized or deleted
- Security logs — Retained for up to 12 months for abuse prevention
When you request account deletion, we remove your personal data within 30 days. Some anonymized, aggregated data may be retained for service improvement.
7. Your Rights
Your data is yours. Full stop. Most privacy policies make you file a request and wait; we built the rights into the product, live by default:
- See — View all personal data we hold about you, including your AI memories and the extension's capture ledger. Not by request — by default.
- Release individual memories — Use the Release button in the extension ledger or the Memory Constellation to remove specific memories. Recoverable for 10 days, then gone.
- Change your mind about capture — Flip any consent bucket off at any time. From that moment, nothing in that category is captured.
- Delete your account — Request complete deletion of your account and all associated data
- Export — Request a machine-readable export of your data
- Correction — Request correction of inaccurate data
- Disconnect services — Revoke Gmail, Calendar, Drive, or sign-in access at any time through your Google Account settings
To exercise any of these rights, use the in-app tools where available, or contact us at the address below.
8. Beta Program
Distilligent is currently in beta. That means features evolve quickly — but the covenant above does not: opt-in capture, the visible ledger, and your right to release are commitments, not features. If a change would materially affect what we collect or how we use it, we will update this policy and tell you before it applies to you. Beta feedback you send us (bug reports, suggestions) may be kept to improve the product.
9. Children's Privacy
Distilligent is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.
10. International Data Transfers
Our services are hosted on Google Cloud in Montreal, Canada. Distilligent is operated by Aina Software USA Inc., a United States company. If you access the platform from outside Canada, your data may be transferred to and processed in Canada (and, for support and operations, in the United States). We take steps to ensure your data is protected in accordance with this policy regardless of where it is processed.
11. Changes to This Policy
We may update this privacy policy from time to time. When we make material changes, we will update the "Last Updated" date at the top and, where appropriate, notify you via email or through the platform. Continued use of the service after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have questions about this privacy policy, your data, or anything else — we're real people and we'll answer.
Distilligent (Aina Software USA Inc.)
Email: info@distilligent.ai
Web: distilligent.xyz
