Privacy Notice
Last updated: 23 August 2026
This notice explains what happens to personal data in Mnemia, who decides the processing, and the choices and rights available to coaches, clients, and visitors. It is information, not a contract that a client is asked to accept.
Mnemia is operated from Zürich, Switzerland by Christophe Kurkdjian and Yacine Brahmi while the intended Swiss company is being incorporated. Full operator details are in the Impressum. Privacy questions can be sent to privacy@mnemia.ch.
1. Current service boundary
The early-access service is for independent coaches established in Switzerland and their adult clients in voluntary, one-to-one, non-clinical coaching. It is not currently approved for psychotherapy, healthcare or clinical records, minors, couples, groups, emergency use, or employer-directed assessment and reporting. Those settings can involve different professional-secrecy, health-law, employment, retention, and consent duties and require a separate review before use.
2. Who is responsible
For a client relationship and its coaching records, the independent coach or the practice identified by the coach is the controller: it decides why the record exists, the lawful basis, what is written, how long it is kept, and how client rights are answered. Mnemia is its processor and handles that information under the Data Processing Agreement. Ask your coach for the identity and contact details of that controller.
Mnemia is a controller for its own account administration, authentication, service security, legal evidence, support, billing, public-site analytics, and direct business communications. If Mnemia and a coach ever determine a purpose jointly, the role and information will be updated before that processing begins.
3. Data we handle
- Account and controller data: name, email, role, authentication data, practice/controller identity, authority to accept agreements, and account preferences.
- Relationship data: client name or display label, optional email until an invitation is sent, engagement type, expected rhythm, portal status, and session dates.
- Manual records: notes, recaps, homework, and other text deliberately saved by a coach. Storing these digitally is personal-data processing even when AI is off.
- Selected source material: live audio or authorised imported audio, transcript, text, document, or image content submitted for a permitted AI action.
- Draft and approved output: transcripts, recaps, key moments, continuity context, suggested homework, and private coach reflection produced from selected material.
- Legal and permission evidence: document and notice versions, choices, method, scope, time, relationship or session reference, withdrawals, and deletion events.
- Technical and security data: limited request, device, error, access, and operational data needed to deliver and protect the service.
- Public-site analytics: a short-lived pseudonymous identifier, sanitised page path, language, broad browser/device category, landing version, selected call-to-action source, and anonymous account-creation step status.
- Direct business conversations:business contact details, founder-entered context and objectives, a consented recording or transcript or a founder's typed recollection, and AI-assisted preparation, follow-up drafts, and founder coaching notes.
Coaching records may incidentally reveal health, intimate-sphere, beliefs, affiliations, or other sensitive or special-category data. Mnemia does not require those details. Coaches should minimise them and must determine the legal basis and any additional condition that applies to their practice. A normal service contract alone does not automatically satisfy GDPR Article 9 where it applies.
4. Manual mode
A coach can create a relationship and keep encrypted manual records in Mnemia without AI processing and without recording. Mnemia does not add an AI or recording consent gate to that mode. The controller must still give the client the required privacy information and have a lawful justification for the digital record and any sensitive data it contains.
5. AI permission
Identifiable client material is not intentionally sent to the AI provider until an active, versioned AI permission exists for that named relationship. The request appears when a coach first tries to use an AI feature, rather than during invitation or account entry. It explains the sources, purpose, recipients, locations, retention, manual alternative, and withdrawal route. Declining leaves manual mode available.
AI permission applies prospectively by default. Earlier manual records are excluded unless the client separately chooses to include records up to a stated date and the coach then deliberately selects relevant earlier material. Mnemia does not silently analyse the whole history. Withdrawal stops new AI processing; it does not by itself rewrite or erase a record already lawfully created, which is handled through the controller's rights process.
6. Recording
Recording has a separate standing authorisation for future one-to-one sessions between the named coach and client. It is not selected by default and cannot be created by a coach on the client's behalf. Before every live recording, the coach must tell the client that recording is about to start and ask whether it is still acceptable that day. The coach then records that current confirmation with one action before microphone access begins. A clear recording indicator and pause and stop controls remain available.
The client may decline any session or withdraw the standing authorisation. A new direct choice is required after withdrawal, a material purpose or provider change, a new relationship, or any additional participant. Couples, groups, guests, and covert recording are unsupported.
7. Imported material and general reflections
Before importing material, the coach confirms its source, authority to use it, and that it concerns only the named one-to-one relationship. Existing audio also requires the coach to record when and how all participants agreed to the original recording. A transcript does not remove that underlying responsibility. Material that contains another participant is not supported.
A Quick Capture must be attached to a named client and follow that client's AI gate, or be marked as a general practice reflection containing no identifiable client information. The unattached route must not be used to bypass a client's choice.
8. Accountless exploration
A coach can prepare a provisional relationship without creating a client account or sending an email. When accountless exploration is enabled, a client who is offered AI or recording for one exploration session receives a protected client-facing handover on the coach's device or a one-time link and makes the session-only choice directly. It is never silently converted into an ongoing permission. The client can take a receipt and exercise rights without creating an account.
9. Why data is processed
For processing where Mnemia is controller, the usual grounds are:
- performing the account and service contract;
- legitimate interests in delivering, securing, supporting, and improving the service;
- complying with legal duties and establishing or defending legal claims; and
- consent where the law or the feature specifically requires it.
For client coaching records, the coach/controller determines and documents the applicable basis under Swiss law and, if relevant, GDPR Articles 6 and 9. The in-product AI and recording permissions are additional safeguards and evidence; they are not a promise that consent is the controller's only or sufficient legal basis for every part of the record.
10. Direct business and research conversations
Mnemia is the controller when a founder speaks directly with a prospective customer or research participant. A call is recorded only after every participant gives clear prior agreement and is told that the material may be transcribed and analysed for follow-up, product learning, and private founder coaching. A typed recollection can be used where the person was informed about follow-up and AI processing. The material is not used for lead scoring, employment decisions, cross-prospect profiling, or automatic message sending.
Encrypted source transcripts are scheduled for deletion 90 days after successful review. The remaining prospect record is scheduled for deletion after 12 months without an interaction unless a founder records a justified extension. It can be exported, corrected, or deleted sooner on request.
11. AI provider and automated decisions
Permitted source material is sent to Microsoft Azure OpenAI for transcription or analysis in the configured Switzerland and EU deployments. Microsoft states that prompts, outputs, and training data supplied to its Azure service are not used to train foundation models without permission. Azure's abuse-monitoring and deployment configuration can affect transient provider retention and exact processing location; Mnemia therefore records these settings as operational release controls and describes the confirmed state on the Sub-processors page.
Mnemia does not sell coaching content, use it to train public or shared models, score clients for employers, or make solely automated decisions with legal or similarly significant effects. AI output remains subject to coach review.
12. Providers and locations
The primary database and sensitive Supabase Edge Function execution are configured in Zürich. Vercel dynamic functions are configured in Frankfurt, while Azure transcription and analysis use the stated Switzerland/EU deployments. Vercel also hosts the application, Resend sends service emails, and PostHog EU receives only the limited public-site analytics described here. The live list, purposes, data, locations, and important configuration qualifications appear on our Sub-processors page.
Where access or transfer reaches a country without an applicable Swiss or EU adequacy decision, the responsible party uses a lawful transfer mechanism and appropriate safeguards, such as recognised standard contractual clauses and supplementary measures. No provider location removes a coach's separate professional-secrecy obligations.
13. Security
Stored session content is field-encrypted and access is separated by role and relationship. Original audio and uploaded file bytes are processed transiently rather than retained as the durable coaching record. Access controls, row-level database policies, permission gates, audit evidence, encrypted transport, backups, security testing, and incident procedures are used according to risk. No online system can promise absolute security.
14. Retention
- Original audio, image, and document bytes are not intentionally persisted as product records after processing.
- A temporary full transcript or extracted text used for review is deleted no later than seven days after coach review and, in all cases, no later than 30 days after successful processing. Failed or incomplete sources are deleted after seven days. The coach can delete a source sooner.
- Coach-authored manual records and coach-reviewed outputs follow the relationship's normal retention and the controller's lawful instructions.
- A provisional relationship that does not continue is deleted 30 days after its exploration session, unless the controller records a lawful retention reason and date.
- A content-free accountability receipt for an accountless permission and deletion event may be retained for up to three years, then deleted.
- Account, security, agreement, and billing evidence is kept only as long as needed for the service, security, legal duties, or legal claims. Deleted production data may remain in access-restricted backups until the normal backup cycle expires.
15. Your rights and choices
Depending on the applicable law and circumstances, you may have rights to information, access, correction, erasure, restriction, objection, portability, and withdrawal of consent. You may also complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, where applicable, another competent supervisory authority.
For a coaching record, contact the coach/controller first. Mnemia will assist that controller. A client without an account can use the reference on their receipt. If the controller is unavailable, or for data controlled by Mnemia, email privacy@mnemia.ch. Identity may need to be verified, but creating an account is not required to make a request.
16. Cookies and product measurement
Essential first-party cookies keep users signed in, protect the service, and remember the selected language. On the public site and account-creation pages, PostHog EU receives only manually defined, cookieless events with sanitised paths and pseudonymous, short-lived identifiers. Names, emails, invitation tokens, query strings, free text, client data, session content, automatic capture, replay, heatmaps, and advertising tracking are excluded.
Inside the authenticated product, policy and journey health is measured from content-free events in Mnemia's own database. Operational views show aggregate outcomes and decision identifiers, not transcripts, notes, permission text, or client identities.
17. Changes
A material change receives a new notice version. We will present or notify that version in an appropriate channel and request a fresh optional permission where the earlier permission no longer covers the changed purpose, recipient, or processing.
Notice version 2026-08-23-review-v1. This production review text is prepared for Swiss counsel. It records the intended release controls; the operational policy gate keeps an optional processing path unavailable when its required control is not satisfied.