Trust
UltraMemory is operated by LogicLabsAI, LLC · © 2026 LogicLabsAI, LLC. This page summarizes our data practices; the Privacy Policy and Sub-processors pages govern.
Founded by James Lindsay.
Data location
We maintain a single production environment hosted on Amazon Web Services in region us-east-1 (United States). AWS hosts all customer data at rest, and our primary processing takes place in the United States (AWS us-east-1).
Sub-processors
Of all the parties we engage, only AWS (which hosts all data at rest) and Voyage AI (which receives Memory Content text to compute embeddings) ever process Memory Content. We give at least 30 days’ prior notice of any new or replacement sub-processor. The full list is on the Sub-processors page.
Retention & deletion
On termination of a customer’s subscription the customer may export its Memory Content, and UltraMemory deletes Memory Content within 30 days of termination, except for copies required to be retained by law and copies in tamper-evident audit logs or backups, which cycle out on their normal schedule. To exercise your privacy rights, email privacy@ultramemory.us or use your account in the customer app.
No training on your data
We do not use your Memory Content (including the embeddings and any consolidated memories derived from it) to train, retrain, or fine-tune any artificial-intelligence or machine-learning model — neither our own models nor any third party’s. Memory Content text is transmitted to our embedding sub-processor (Voyage AI) only to compute the vectors used for your own semantic recall, and not for any model-training purpose.
Security contact
Report security issues to security@ultramemory.us. Our disclosure details live at /.well-known/security.txt.
How UltraMemory is secured
A summary of controls that are live today. The legal pages govern; this page summarizes.
Access. No SSH anywhere; administration is via AWS Systems Manager only. No public IP addresses on compute or data. Humans use single sign-on with temporary credentials; workloads use IAM roles with zero static keys. Deploys run through keyless OIDC CI/CD.
Encryption. TLS 1.2+ in transit with HSTS. Customer-managed KMS keys at rest, with rotation.
Tenant isolation. Every request passes one tenant chokepoint, and PostgreSQL row-level security (FORCE RLS) enforces isolation at the database layer as a second belt.
Monitoring. CloudTrail audit logging (KMS-encrypted, 365-day retention, log-file validation), GuardDuty threat detection, and AWS WAF at the edge, each wired to alerting.
Application audit trail. Administrative and data actions are recorded with actor attribution.
Backups and resilience. Multi-AZ database, 35-day point-in-time recovery, nightly backups with cross-region copies, and backup-failure alerting.
Admin protection. Admin surfaces require MFA (AAL2) behind Cloudflare Access; customers can opt in to MFA on their own accounts.
Secrets and content hygiene. Secrets live in AWS Secrets Manager (never on disk, never in logs), and stored conversation content passes a secret-redaction pipeline before it is written.
UltraMemory does not currently hold SOC 2 or ISO 27001 certification. Our DPA, sub-processor list, and privacy policy describe our commitments in full.