What we hold, and how.
adja is in private beta. This page describes what we collect today and the controls you have. It will be replaced with a finalised policy before general availability. Until then, treat this as a working agreement, not a finished legal document.
Your memories are yours. We hold them so your agents can read them back. We don't sell them, mine them for ads, or train models on them. You can delete your tenant - and everything in it - by mailing hello@adja.ai.
Four buckets.
- Account
Email, first/last name, location, date of birth.
To create your tenant and address you correctly.
- Memories
Whatever your AI agent stores via the MCP API - text, tags, kinds, source, embeddings.
This is the product. Your memories are the service.
- Session
An HttpOnly cookie (adja_session) holding your access token; IP and user-agent on each request.
To keep you signed in and to throttle abuse.
- Email events
Send/delivery status of invite + login emails.
To diagnose deliverability problems.
Only to run the service.
- - Authentication, tenant provisioning, billing.
- - Diagnostics: rate limits, error logs, abuse detection.
- - Email delivery for invites and login links.
- - Not for advertising, profiling, or third-party data sales.
- - Not for training models. Your memories don't leave your tenant.
Who else touches the data.
- Cloudflare
Hosting (Workers, KV, Access). Edge in your region.
- Resend
Transactional email (invites, login links).
- adja memory_api
First-party upstream that stores the actual memory graph. Operated by us, not a third party.
Take it back.
- - Access: sign in to /me to see what adja currently holds about you.
- - Export: request a JSON dump of your memory graph by emailing hello@adja.ai.
- - Delete: we'll wipe your tenant - memories, session, waitlist record - on request. Usually within one business day.
Questions, requests, breach notifications: hello@adja.ai.
Effective: this draft, while in private beta. Final policy lands before public launch.