Hippocampus
Privacy notice
Hippocampus keeps shared memory for your AI agents in a private GitHub repository that you own. This notice says what this service processes to do that, who can see it, and how to make it go away.
Who runs this service
[Operator: your name or organization, and where you're based.]
What it processes
- Your GitHub identity. When you sign in with GitHub, the service keeps your GitHub user id and login. It doesn't keep your password or a lasting GitHub token: the sign-in token is used once to learn who you are, then dropped.
- Your access request. The note you write when asking for access, for the admins who approve accounts.
- Your vault repository. Through the GitHub App you install on the repository you select, the service reads and writes that repository's files to answer your agents and to save what they remember. It can't see repositories you didn't select.
- A search index and cache of your vault. Kept per vault in Cloudflare, so search and reads are fast. They hold your notes' text; secret values stay encrypted (see below).
- Keys. Only a hash of each agent or curator key, with its label, scopes and when it was last used. The key itself is shown to you once and never stored.
- Connected apps. For connectors such as Claude.ai or ChatGPT: which app, which agent it acts as, and its permissions.
- Operational logs. Route names, status codes and timings, for keeping the service running. No vault content.
There are no third-party analytics, ads or tracking cookies. Signing in sets a session cookie (and a short-lived one while the sign-in is under way). Your browser keeps a copy of recently viewed pages for this tab and your display preferences; signing out clears the copy.
Your agents and your curator
Agents you connect read and write your vault within what their key or connection allows, and they run under their own providers' terms. The curator you choose reads every new memory in full while curating, secret values included, before they're encrypted. Give the curator key only to an agent, and an AI provider, you trust with that.
Secret facts
If you made a secrets key during setup, it was made in your browser, and only its public half reached this service. Secret values (passport numbers, account numbers, passwords) are encrypted to it with age and stored in your repository. Without your key file nobody can read them: not the operator, and not you.
Where it lives
The service runs on Cloudflare (Workers, D1, Durable Objects, KV); your vault lives on GitHub. Each provider decides where it stores data.[Operator: add the regions and any other processors your setup uses.]
How long it's kept, and deleting it
Everything above is kept while your account exists. To delete your account, open Setup → Account and confirm with your GitHub login. Right away:
- every key stops working and connected apps are signed out;
- the GitHub App is uninstalled from your repository;
- your account, keys, and your vault's search index and cache are erased from this service.
A minimal record (your GitHub id and login, marked deleted) stays so the deletion holds; you can sign up again later. Your repository stays on GitHub, untouched: your memory is yoursthe campaign is yours, so delete the repository on GitHub if you want it gone too. Uninstalling the app on GitHub disconnects your vault without deleting your account. Operational logs expire on their own.[Operator: state the log retention.]
Your choices
Your memory is already in your hands: clone the repository to export it, edit any note to correct it, and delete the account (above) to remove what this service holds. For anything else, contact the operator.
Contact
[Operator: a contact address for privacy questions.]
Changes
Changes to this notice are posted here with a date. Status: draft, not yet in effect.