Privacy Policy
Last updated July 9, 2026
B3dmar ApS, trading as 3ngram, is the controller for account, website, support, and billing data used to operate the hosted service. When a business customer submits personal data about other people as customer content, that customer is generally the controller and B3dmar ApS acts as its processor under the applicable agreement.
This policy covers the hosted service and website. A self-hosted deployment is controlled by its operator and does not send data to B3dmar ApS unless that operator configures a third-party service or contacts us.
Data we collect
Information you provide
- Account data: email address, password hash, verification status, and account settings.
- Customer content: memories and their type, topic, content, scope, project, tags, lifecycle, lineage, and related audit metadata.
- Billing data: plan and subscription state, Stripe customer and subscription identifiers, invoice status, and subscription lifecycle dates.
- Communications: support, security, privacy, legal, and feedback messages.
Information collected when you use the service
- Security and operational metadata: request time, route, status, bounded identifiers or hashes, client and event type, duration, and error class. Application policy prohibits memory content in logs, traces, and metrics.
- Website analytics: anonymous page paths, referrer, coarse location, browser, device, custom product events, and performance measurements through Vercel Web Analytics and Speed Insights.
- Network data: hosting and security providers may process IP addresses and request headers to deliver traffic, prevent abuse, and diagnose failures.
What v1 does not collect
3ngram does not passively read AI conversations, repositories, documents, calendars, project systems, email, or chat services. Source-system sync, messaging bots, and outbound digests are not live v1 features.
How we use data
- authenticate accounts and connected MCP clients;
- store, retrieve, brief, revise, resolve, export, and hand off typed memories;
- generate vector embeddings needed for semantic search;
- operate subscriptions, checkout, invoices, customer portal, and access state;
- send transactional account and billing messages;
- secure, monitor, debug, and improve service reliability;
- respond to support, security, legal, and privacy requests;
- comply with law and enforce our agreements.
We do not sell personal data, use customer content for advertising, or use customer content to train a foundation model. Hosted semantic search submits the minimum required text to OpenAI's API to generate an embedding. OpenAI's API data controls, including its abuse-monitoring retention, apply to that request.
Legal bases
We process data as necessary to perform the service contract, to comply with legal obligations, and for legitimate interests such as security, fraud prevention, service reliability, and privacy-preserving website measurement. Where consent is legally required, we rely on consent and you may withdraw it prospectively.
Service providers and sharing
We share data with providers only for the operating purposes listed above. The current named providers and their data categories are published on our subprocessor page. We may also disclose information when legally required, to protect users or the service, or in a business transaction subject to appropriate safeguards and notice.
Retention and deletion
- Account data and customer content remain while the account is active, unless erased earlier through an available control or request.
- Hosted session tokens expire no later than 30 days; OAuth access tokens live no longer than one hour and refresh tokens no longer than 30 days.
- Billing and accounting records are retained as required for subscription administration, tax, fraud prevention, and legal obligations.
- Operational and security records are kept only for their configured diagnostic, abuse-prevention, or compliance period.
Account deletion erases the user's identity and memory content in place and revokes active sessions, API keys, OAuth grants, reset tokens, and verification tokens. Content-free audit and structural tombstones may remain to preserve security and append-only integrity. Deleted data may remain in encrypted backups until overwritten under the normal backup lifecycle and is not used for ordinary product access.
Your choices and rights
Depending on applicable law, you may have rights to:
- access personal data and receive information about processing;
- correct inaccurate account or customer data;
- export account data through
GET /api/v1/exportor available dashboard controls; - erase an account and revoke credentials;
- object to or restrict certain processing;
- withdraw consent where processing relies on consent;
- receive portable data where applicable;
- complain to Datatilsynet or another competent supervisory authority.
Contact privacy@3ngram.ai to exercise a right. We may need to verify your identity before fulfilling the request.
International transfers
Some providers may process data outside the EEA. Where GDPR requires a transfer mechanism, we rely on applicable safeguards such as the EU Standard Contractual Clauses or an adequacy framework. Provider-specific roles are listed on the subprocessor page.
Cookies and browser storage
The marketing site uses local storage for the theme and cookie-free Vercel Web Analytics. The hosted application and OAuth flow use essential security cookies. Details are in the Cookie Policy.
Security
Security measures include TLS, managed encryption at rest, Postgres row-level tenant isolation, credential revocation, content-free telemetry, and an append-and-supersede memory model. See the security page for the public technical summary.
Children
The hosted service is not directed to people under 18, and we do not knowingly create accounts for children. Contact us if you believe a child has provided personal data.
Changes
We will post updates here and change the date above. Material changes will also be announced by email or a prominent service notice where required.
Privacy questions: privacy@3ngram.ai. Legal and DPA requests: legal@3ngram.ai.