Privacy Policy
Last updated: July 2026
Draft for review. This document is being finalised and will be checked by legal counsel before paying customers rely on it.
This policy explains how Mnemora, operated by Solven ("we", "us"), handles personal information. It is written to meet the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs), and to align with the European GDPR, UK data protection law, and the California CCPA and CPRA. If you use Mnemora, please read it. Questions go to hello@solven.au.
Who is responsible for your data
Solven is the operator of Mnemora. When your firm uses Mnemora to hold information about your own clients, your firm is the controller of that client information and we act as your processor, handling it on your instructions and only to run the service.
What we collect
- Account details: your email address and a securely hashed password.
- Firm profile: your name, firm name, field of work, and the details you choose to add (services, pricing, terms, tone, tools).
- Client information you enter: your clients' names, contact details, references, notes and the reminders you create.
- Assistant conversations: the messages you send to the assistant.
- Basic technical data needed to run and secure the service.
How we use it
- To provide Mnemora to you: your workspace, clients, reminders and the assistant.
- To keep the service secure and reliable.
- To respond to you when you contact us.
- To meet our legal obligations.
We do not sell your data, and we do not use it for advertising.
Our legal basis (where the GDPR applies)
We process personal data to perform our contract with you, to pursue our legitimate interest in running and securing the service, to meet legal obligations, and, where required, with consent.
Who we share it with
We share data only with the providers that help us run Mnemora, under agreements that require them to protect it. They are:
- Supabase, our database, storage and authentication provider, hosted on Amazon Web Services (Sydney region).
- Vercel, our application hosting provider.
- Anthropic, our AI provider, which powers the assistant. Anthropic does not use data submitted through its API to train its models.
- Resend, our email provider, used only to deliver the reminders you approve.
We may also disclose data where the law requires it. We do not sell personal information.
Where your data is stored and sent
Your data is stored in Australia (Sydney). Some of our providers process data in other countries. Where data is handled outside Australia or the EEA, we rely on providers that offer appropriate safeguards for that transfer, and the data remains encrypted in transit.
How we protect it
Encryption in transit and at rest, strict per-firm isolation, secure authentication, and other measures described on our Security page.
How long we keep it
We keep your data while your account is active. If you close your account or ask us to delete your data, we delete it, except where we must keep some records to meet a legal obligation.
Your rights
Subject to the law that applies to you, you can:
- Ask what personal data we hold about you and get a copy.
- Correct data that is wrong.
- Ask us to delete your data.
- Export your data.
- Object to or restrict certain processing.
To exercise any of these, email hello@solven.au. If your firm is our customer and the request concerns your own clients' data, we will act on your firm's instructions.
If there is a data breach
If a breach is likely to cause serious harm, we will notify affected users and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme without undue delay, and the relevant supervisory authority within 72 hours where the GDPR requires it.
Children
Mnemora is a tool for businesses and is not intended for anyone under 18.
Changes
We may update this policy. If we make a significant change, we will let you know. The date at the top shows when it last changed.
How to contact us or complain
Email hello@solven.au. In Australia, you may also complain to the Office of the Australian Information Commissioner. If the GDPR applies to you, you may complain to your local data protection authority.