Privacy & retention

Memory deserves clear boundaries.

Effective October 4, 2026. This notice describes Temri’s admin-managed pilot and its data handling boundaries.

What is stored

Temri stores workspace identity links, memberships and roles, invitations, namespace grants, memory revisions, evidence excerpts and source locators, verification and correction records, and content-free operation receipts. Bounded usage records identify product, workspace and operation dimensions. Billing is deferred.

For an invitation, Temri stores its role, expiry, status, the namespace access it grants, an optional email restriction and a SHA-256 hash of the link token. The token itself is not stored.

Who can access it

Clerk authenticates accounts. Temri links identities by issuer and subject, then checks current membership and namespace capabilities. Signing in, using a matching email or belonging to another application’s organization does not grant a workspace. Treat granted read access as permission to copy returned content.

Workspace owners and admins add people by invitation and can remove them. Members of a workspace can see each other’s names, email addresses and profile images. Temri reads these from Clerk when the member list is shown and does not store them. To check an invitation’s email restriction, Temri compares it with your verified addresses at Clerk at that moment and stores none of them.

Services involved

  • Cloudflare hosts the service, workspace directory, temporal ledger and private evidence storage; when automatic maintenance is enabled, Workers AI processes the configured prompt and a bounded selection of authorized memory and evidence
  • Clerk processes account authentication and session information
  • When hybrid search is enabled, turbopuffer processes the rebuildable search projection and embedding processing is part of the search path; hybrid search is disabled in the initial development configuration
  • Your agent or application receives content you authorize it to retrieve, under that provider’s separate terms

Automatic maintenance

Maintenance is off until an authorized administrator enables it. Its behavior prompt is private namespace configuration. Enabled maintenance applies supported memory changes automatically under current grants, evidence checks and spending limits. AI Gateway logs and response caching are disabled; Workflow checkpoints contain identifiers, counts and status rather than private prompt or completion text. Disabling maintenance fences late writes but cannot recall a request already sent for inference.

Retention and deletion

Memory and evidence remain available until an authorized deletion or an explicitly configured retention policy applies. No universal automatic retention period is promised in this pilot. A correction preserves revision history; it is not deletion.

Deletion suppresses affected content from current and historical online reads first. The operation receipt tracks cleanup of ledger payloads, evidence storage and search sinks. Pending cleanup is shown as pending, not complete. Receipts retain no deleted private text.

Temri cannot erase copies already exported to an agent, product, source repository or external backup. Source and backup retention are separate from online sink cleanup. A removed Git file does not prove historical blob erasure. Confirm those retention obligations with your pilot administrator before storing sensitive information.

Public site and private workspace

Customer memories and evidence are excluded from public documentation, SEO jobs, social images and readiness screenshots. The private workspace uses no session replay or acquisition analytics carrying private identifiers. Signing out or switching accounts clears displayed private state.

Pilot requests and changes

Ask an owner or admin of your workspace, or the pilot administrator who enrolled it, about membership, data access, retention or deletion. Do not publish private data in public issues. This pilot does not promise a compliance certification, data residency commitment, perfect erasure or uninterrupted availability. Material policy changes will update this notice before broader enrollment.