Security
How we protect your account and data, and what we do not promise.
Connections
All connections between the app, this website and our servers use HTTPS, and the connection to the database uses TLS.
Signing in
- Passwords are stored as Argon2id hashes, never as text.
- Your email address is verified with a 6-digit code.
- Access tokens are short-lived (15 minutes). Refresh tokens last up to 30 days, are stored on the server only as a keyed hash, are replaced each time they are used, and reusing an old one ends that sign-in chain.
Your data on our servers
- Photos are kept in private storage, reachable only through signed links that expire after 5 minutes.
- Every request is checked against the account the data belongs to.
- The content of emails we send you is stored encrypted until it is sent, then removed.
- The app holds no AI provider key; every AI request goes through our servers.
- We keep operational logs to what is needed to run and protect the service.
On your phone
Your reminders and saved information are kept in an encrypted file for your account, and your sign-in session in the iOS Keychain. Contact links stay on the phone only.
Our team
Our staff console requires two-factor authentication, and administrative actions are recorded in an audit log.
What we do not promise
MemoSeek is not end-to-end encrypted. Data is encrypted in transit, but our servers can read what you save so that the service can work, which is why we keep as little as we can.
Reporting a vulnerability
If you find a security issue, write to [email protected] with the steps to reproduce it. Please do not access other people’s data or disrupt the service while testing, and give us reasonable time to fix it before disclosing it.