Security and Trust
Security boundaries for the native Memrov app and its connected services.
Last updated September 9, 2026
- Native app records use device storage and private iCloud synchronization.
- Provider credentials use the device Keychain.
- Sending content to a provider makes that provider's processing rules relevant.
- The current native app requires iOS or iPadOS 27. It does not require a Memrov account or offer a Memrov subscription. OpenRouter and connected services have their own accounts, terms, availability, and charges. OpenRouter requires users to be at least 18 to use its service, including the account used for Memrov chat.
- Conversations, selected attachments, profile answers, and profile documents are stored on your device. Memrov uses your private iCloud database to synchronize supported app records when iCloud is available. Apple operates iCloud under your Apple Account and iCloud settings.
- When you send a chat request, the conversation context, relevant profile context, selected images or extracted document text, and any integration results included in that request go to OpenRouter and the model provider used for the response. These requests go directly from the app to OpenRouter.
- OpenRouter processes chat content and request metadata, including the model, token usage, timing, and identifiers used to associate requests with your provider account and conversation. Retention and training depend on your OpenRouter settings and the provider or endpoint that serves the request. Memrov does not enforce a universal zero-retention setting.
- When Web search is enabled in Chat, OpenRouter can process search queries and return web results through its search tool. Relevant conversation context and search results may be included in the model request.
- Optional integrations connect through Composio. Composio and the services you authorize process connection information, tool requests, arguments, and results needed for the integration. This can include content from a connected service, such as messages or documents, depending on the permissions and action you choose. Results used in chat are also sent to the AI provider.
- OpenRouter and Composio authorization credentials are kept in the device Keychain using device-only protection. Connecting a provider requires its authorization flow. Disconnecting locally does not delete your provider account or guarantee revocation of every permission at that provider.
Review provider permissions before connecting an integration. Keep your device and Apple Account secure. To report a Memrov security issue, contact admin@memrov.com without including passwords, access tokens, or unnecessary private content.
- AI Help sends the relevant conversation and available OpenRouter call diagnostics to OpenRouter and the serving model provider to help investigate an issue. The provider controls described above also apply to Help requests.
- In the current native app, Email Support prepares a report on your device. It contains the conversation messages and timestamps, Help analysis, available OpenRouter call details, app and build versions, OS version, locale, time zone, and conversation identifier. Review the report before opening the email composer. If Apple Mail is not configured, you can share the report with another email app.
- The report is not sent to Memrov until you send the email. Your email provider handles delivery. Memrov receives your sender address, the report, and any note you include and uses them to respond and investigate your support request. Do not include passwords, provider tokens, or unnecessary private information.
- Earlier TestFlight builds could send support reports through an authenticated Memrov AWS endpoint when an Apple-derived session already existed. That path uses Amazon Simple Email Service to deliver the report and the authenticated account identifier, with account email when available, to Memrov Support.
- Deleting data inside the app does not delete a support email already sent to Memrov or copies held by your email provider. Contact admin@memrov.com for access or deletion requests concerning support information Memrov holds.
The sections below describe the Memrov web service, including Auth0 accounts, web imports, Safe AI, and Stripe billing where available. They were last updated May 25, 2026. Those account and billing workflows do not describe the current native iOS launch. General company, rights, acceptable-use, and legal-contact provisions still apply where relevant.
- Users authenticate through Auth0 Universal Login and supported social connections.
- Frontend requests are proxied through Vercel functions and scoped to the authenticated Auth0 subject.
- Backend APIs validate tokens, scopes, and ownership before returning user data.
- Long-lived cloud credentials are not exposed to the browser.
- Raw imports are source evidence, not runtime connector context.
- Connector profiles are compact, field-based, and scoped.
- Sensitive, unclear, conflicting, malformed, and source-only data can be held away from connectors.
- SQL/business access is a deeper path that requires explicit scope and audit logging.
- Memrov uses managed cloud services with encryption in transit and at rest where available.
- Access is designed around per-user ownership, service roles, scoped tokens, and audit records.
- Deletion jobs remove active product data from the authoritative stores and retain only minimal hashed receipts where needed.
- Connector access logs record who or what requested data, what scopes were used, what was returned, and whether access was denied.
- Import, review, correction, approval, deletion, billing, and connector flows are treated as auditable events.
- Security events may be retained to protect accounts, investigate abuse, and satisfy legal obligations.
Send vulnerability reports or security concerns to admin@memrov.com with the subject line Security Report. Include affected URLs, steps to reproduce, impact, and your contact information.
Memrov, Inc.
admin@memrov.com
Registered agent
Legalinc Corporate Services Inc.
131 Continental Dr
Suite 305
Newark, DE 19713
United States
