Privacy Policy
Incord Memory keeps your notes, conversations, and code summaries on your own machine, and searches them there. This policy explains exactly what stays local, the few things that can leave your device, and what our hosted API collects if you use it.
Last updated: August 2026
1.Which Product This Covers
Incord is two products with very different data models, and this policy covers both. Read the section that applies to what you are using — conflating them is the fastest way to misunderstand where your data lives.
Incord Memory (desktop app)
A memory and recall tool that runs on your own machine. Your conversations, code summaries, saved facts, and the knowledge graph built from them are stored locally and are not uploaded to us. Sections 2 through 6 describe it.
Incord knowledge API (hosted service)
Our hosted, account-based API. Sections 7 onward describe it. If you only use the desktop app and never create an account, the account sections do not apply to you.
2.What the Desktop App Stores on Your Device
Incord Memory keeps its data in a local database under your home directory, at ~/.incord (configurable with the INCORD_HOME environment variable). Nothing in this list is transmitted to us as part of normal use.
- Conversation messages captured from your agent sessions, for recall and search
- Summaries of code files you have indexed — a description of the file, not its source
- Facts, decisions, preferences, and tasks you explicitly ask the app to remember
- A knowledge graph linking those items to projects, folders, and each other
- Vector embeddings of the above, which is what makes semantic search work
- A local record of tool calls and their results, used to avoid repeating work
What the app does not do
The desktop app collects no analytics, no telemetry, no advertising identifiers, and no location data. It does not phone home to report how you use it.
3.Microphone and Voice Input (Desktop App)
The app includes an optional dictation control that types spoken words into a terminal or message box. It is worth being precise about how it behaves, because always-listening software deserves scrutiny.
When the microphone is open
- Dictation starts only when you press the microphone button. There is no voice-activity detection and nothing begins listening on its own.
- While listening, the button turns amber and shows a pulsing ring for as long as the microphone is open, so a live microphone is never something you have to infer.
- Pressing the same button stops it immediately and releases the microphone. Closing or navigating away from the view also stops it.
- Recognition continues across natural pauses within a session you started; it does not survive you turning it off.
- Recognised words are typed in and never submitted for you — you press Enter. A misheard word cannot run a command on its own.
Where the audio goes
Speech recognition is performed by your operating system's or browser engine's own speech recogniser — the app does not run its own transcription and does not send audio to us or to any AI provider under our account. On some platforms that built-in recogniser transmits audio to the platform vendor to be transcribed, which means your speech can leave your device. That is the platform's behaviour and is governed by the platform vendor's privacy policy. The app discloses this on the dictation control itself rather than burying it here.
What is kept
The app writes no audio files to disk and retains no recordings. Only the resulting text is kept, stored locally like anything else you type. If you decline the microphone permission, every other feature continues to work normally.
4.Optional Features That Send Data Off Your Device
The features below are the only ones that can send your content anywhere, and each is off or unconfigured until you deliberately turn it on.
Semantic search embeddings — local by default
Embeddings are generated by a model running on your own machine (embed.mode = local, the shipped default). Nothing is sent anywhere to be indexed. If you switch this to api, the text being indexed is sent to the embeddings provider you configure.
Background jobs — off by default
Automatic conversation titling and rollup summaries run in one of three modes. off is the shipped default and sends nothing. local runs summaries through an agent CLI already installed on your machine. service sends conversation content to a model endpoint that you configure. We do not select a provider for you.
Code auditing — off by default
The code auditor is disabled on install and has no folders configured. When you enable it and list folders, it reads files in those folders and sends their contents to the model you have configured for review. It stays idle until you do both.
The proxy and agent assistance
Features that ask a model to review a pending decision send the decision text and relevant memory excerpts to whichever model endpoint you have configured. Which provider that is remains your choice throughout.
5.Team Sync and Notifications (Desktop App)
Synced memory is encrypted before it leaves
If you pair devices or share memory with a team, the content is sealed with your own key on your machine before it is transmitted. Our relay stores and forwards ciphertext; it holds the sealed blob and the routing metadata needed to deliver it, and cannot read the content. Sealing applies once your key is established — on a fresh install being upgraded into a paired setup, content written before that point is not retroactively sealed.
Push notifications are an exception, and we will say so plainly
If you enable push notifications to your phone, the notification text — which can include an excerpt of the item being notified about, such as a title or the first part of a post — is sent to the platform push service in readable form so it can be displayed on your device. This is inherent to how mobile push works: a notification has to be readable to be shown on a lock screen. If that is not acceptable for your content, leave push notifications off.
Metadata
Delivering a sealed message requires knowing where to deliver it. Routing information — which node or team a message is for, and when it was sent — is necessarily visible to the relay even though the content is not.
6.Your Control Over Local Data
Because the desktop app's data is on your own disk, you control it directly and do not need to ask us for it.
- Delete individual memories, messages, or graph nodes using the app's forget functions
- Delete everything by removing the ~/.incord directory — there is no server-side copy of local memory to survive it
- Turn off any optional feature at any time in the app's settings; the change takes effect immediately
- Uninstalling the app does not require us to be involved, and leaves no account behind if you never made one
If you also hold an Incord account, contact privacy@incord.ai to request deletion of data held server-side under that account.
7.Account and API: Information We Collect
The remaining sections describe the hosted Incord account and knowledge API. They do not describe the desktop app's local memory, which is covered above.
Information You Provide
- Account details, name, work email, and company
- API keys you generate
- Billing information, handled by our payment processor
- Messages you send to support
Automatically Collected
- API request metadata, endpoints called, timestamps, and latency
- Usage volume for metering and billing
- IP address, device, and browser for the dashboard
- Cookies used only to keep you signed in
What We Don't Collect
We never sell personal data, and we don't retain the content of the public-data queries you run beyond what's needed to serve and meter the request.
8.How We Use Your Information
- Provide, authenticate, and maintain the API
- Meter usage and process billing
- Improve retrieval relevance, ranking, and reliability
- Detect abuse and secure the network
- Send essential service and account notices
9.How We Share Your Information
- Subprocessors (cloud hosting, payments, analytics) under contract and only as needed
- When required by law or to protect the service
- Never sold to advertisers or data brokers
Node operators in the network only ever see signed, content-hashed facts, never your account details or query payloads beyond what is required to serve a request.
10.Data Security
- Encryption in transit (TLS) and at rest
- ed25519-signed, tamper-evident records validated by consensus
- Scoped API keys you can rotate or revoke at any time
- Least-privilege access and audited controls (SOC 2 / ISO aligned)
11.Your Rights & Choices
- Access, correct, export, or delete your account data
- Rotate or revoke API keys instantly
- Opt out of non-essential email
- Exercise your GDPR / CCPA rights by emailing privacy@incord.ai
12.International Data Transfers
Because Incord runs as a distributed network, data may be processed in the regions where our nodes operate. We rely on standard contractual clauses for cross-border transfers.
13.Children's Privacy
Incord is a developer product not directed to anyone under 16, and we do not knowingly collect their information.
14.Changes to This Policy
We may update this policy and will revise the date above. We'll notify you of material changes before they take effect.
15.Contact Us
Privacy questions: privacy@incord.ai · Support: support@incord.ai