Engram is a memory product, so trust is the product. This page says exactly how your data is handled — including the tradeoffs. We'd rather you know than assume.
Every brain has a storage mode, picked by you:
You can mix modes across brains, and the choice is per brain — not a one-way door for the account.
In either mode, your memories are yours. We don't train models on them, sell them, or share them. Support access to your account only ever happens with your explicit, per-request consent. Whichever AI assistant you connect (Claude, ChatGPT, and others), it reaches your brain through the same connector with the same guarantees.
Your assistant understands your brain only through connector tools (search / recall / traverse) — never by reading raw files. There's no folder to grep, so "load the whole thing" is structurally impossible, and every access goes through one enforced path.
For on-device brains, the only thing our servers receive is a structure snapshot — which concepts and nodes exist and how they link — so your console can draw the brain map. It carries no bodies, and people-profiles never leave the device (a person node syncs as its existence + concept only; never the name or notes). Embeddings for local brains are computed on your device too — local means local compute, not just local disk.
Delete a memory and it disappears immediately — hidden from every list, and never returned by recall again — then it's permanently erased within 90 days. Delete your account and your content goes with it — the only record kept is that your email accepted the Terms (which version, and when), as evidence of the agreement; nothing else. When a fact is updated rather than deleted, the old version is kept with a validity window so your history stays honest — you can always ask "what did we believe back then".
For Cloud Hosted brains, memory content is encrypted at rest (AES-256-GCM) under a key derived per account from a master secret — so one account's key can never read another's data, and a stolen database file or leaked backup yields only ciphertext, not your memories. Sealed: memory bodies and summaries, tags, and commitments (including who they're with). In the clear by design: titles and the concept graph (the "shape"), so retrieval and the brain map keep working. For Locally stored brains, content lives on your own device, so your disk protection is the boundary there (we don't add a second lock to a file only you can reach). Vector embeddings are stored as opaque numeric vectors, not recoverable back into text.
Your benefit ledger (what Engram did for you — skills fired, tokens saved) stays entirely inside your own account and never leaves. Separately, anonymous improvement signals carry your role, grouped with others so you're never singled out, and a generic description of the problem — never your memory content, names, or numbers, with your identity one-way scrambled. Signals are on by default and can be switched off in Settings at any time.
Sign in with Google or with a one-time email code — there is no password to steal, reuse, or leak in either path. We receive only your name and email. Your console session is an httpOnly cookie (not readable by page scripts). Your connector uses a separate, revocable key issued to your account — rotate it any time from Settings.
This is an early product, and this page changes when the product does. Locally stored brains are one-device-per-brain for now (no cross-device sync). We label sample data, and we don't claim capabilities we haven't built. The legal side of these commitments lives in the Terms & Conditions.
Home · Solutions · Compare · Terms · Privacy · GitHub
© 2026 ROOTCAUSE S.R.L. All rights reserved. Engram and its underlying methods are proprietary.