Ask a privacy question

Privacy & stewardship

Your work creates memory. You remain in control of it.

This statement covers mnera.online and the controlled Mnera web, Android, and iOS pilot. It explains the current product behavior in plain language.

Effective 3 August 2026Controlled pilot

01

Our operating principle

Mnera is a steward of work memory, never its owner. We request the narrowest useful access, explain what a connection can read and retain, keep consequential actions under human control, and make revocation visible.

We do not sell personal information, use it for advertising, or design notifications simply to bring people back.

02

Information Mnera may handle

  • Account and tenant information: name, verified email address, tenant identifier, roles, sign-in events, and the status of any request for a personal Mnera account.
  • Reading continuity: the publication, saved page, reading mode, and update time for a bookmark you choose to synchronize. Anonymous bookmarks remain only on that browser or device.
  • Access and beta requests: the adult confirmation, policy version, owner decision, and audit information for a personal-account request; and, only if you separately opt into testing, the official Google or Apple account email needed to deliver a private beta invitation. For person-to-person communication, Mnera also records the accepted communication-safety policy version and time.
  • Connected work sources: only the source, workspace, conversation, or time window shown in a consent preview. The present pilot supports a bounded, read-only Mnera Mail connection and documents a person deliberately selects for upload. Selecting a document does not give Mnera broad access to the device or its other files.
  • Consent-first Meeting Notes: an optional meeting title, the recording and transcription consent attestation, temporary foreground audio used to service a transcription request, an encrypted short-lived retry copy of the machine transcript shown for review, and only the reviewed transcript a person explicitly saves as Work Memory.
  • Persistent human chat: messages deliberately addressed to another verified person, their sender and recipient details, message body, and the Work Story permission that governs how long the conversation is kept.
  • Two-person live meetings: meeting title, fixed verified-email roster, voice or video choice, each participant's recording and transcription decisions, and limited connection events. Microphone use is optional for a meeting; camera use is optional and requested only for video.
  • Communication-safety records: a participant's block state and explicit block or unblock confirmation; a report's selected chat message, meeting participant, or meeting target; the selected safety reason; bounded context needed for review; rate-limit state; moderator review status; and an auditable resolution reason. Mnera does not reveal which person created a block to the other participant.
  • Work memory: source-linked events, proposed decisions or commitments, human corrections, verification state, visibility, and provenance.
  • Website participation: an optional name and email address, a private thought, or an email address used to follow meaningful development updates.
  • Security and service records: timestamps, request identifiers, source health, audit events, and limited network information needed to protect and operate the pilot.

Mobile sign-in tokens are kept in protected device storage. Mnera does not ask the app to store your account password.

03

How information is used

We use information to authenticate people, preserve the permission-filtered story of work, propose source-linked memory for review, deliver addressed human chat, connect a chosen live meeting, require the current acceptable-use choice, enforce a confirmed communication block, route a concern to an authorized human moderator, limit abuse and spam, show what changed, protect the service, respond to private feedback, and send development updates people requested.

AI may propose relationships, summaries, decisions, or commitments. Those proposals are not authoritative memory until a person verifies them. Mnera’s controlled model infrastructure is used for the current pilot; connected work is not used to train a public advertising model.

04

Consent, retention, and deletion

Before a work source is connected, Mnera shows its purpose, scope, data categories, model route, and retention period. The controlled mail pilot currently uses a 30-day source-retention window unless its approved consent preview states otherwise.

Controlled-pilot document uploads are limited to 8 MiB per file and to the supported text, image, and PDF formats shown by the product. A selected file is accepted only for one bounded request, checked before admission, and then read either by the native text extractor or the isolated OCR service. If validation or scanning does not pass, the file is not admitted.

Mnera discards its submitted copy as soon as scanning and extraction finish, before returning success, and also discards rejected or failed submissions. It retains the extracted representation, page references, provenance, and source-linked chunks only for the period approved in the consent grant. The current document consent uses a 30-day period for that source-derived representation, not for the original upload. Mnera shows: “Original discarded after Mnera finished reading it.”

Meeting Note is optional and uses a separate, meeting-scoped consent preview. Nothing starts automatically. Before the microphone permission is requested, the person operating Mnera must confirm that everyone present was informed and agreed to recording and transcription. Listening is visibly active only while the Meeting Note screen is in the foreground and stops when the app leaves the foreground.

Meeting Note divides audio into bounded temporary AAC chunks and sends them through Mnera Core to Mnera’s private transcription service. Raw audio is transient request material: a local chunk is deleted after successful transcription or when the Meeting Note is discarded, the transcription service removes its transient request copy, and Core does not retain a raw-audio record. A machine transcript is only a review draft, not Work Memory. Core encrypts a retry copy so an interrupted request can be reconciled safely for up to 24 hours. After that cutoff it cannot be replayed, and bounded cleanup physically removes the encrypted row. It is removed sooner when the note is saved or discarded, or when the meeting consent is revoked, forgotten, or erased with the account. Only the transcript a person reviews and explicitly saves becomes source-linked user content under the meeting consent and retention period shown before capture.

Human chat is part of the governed Work Story, not a separate public feed. A message is retained under the shown story grant and is visible only to its authorized sender and addressed participant. A participant invited only for chat or a meeting does not thereby gain access to the owner's private source timeline, candidates, decisions, or commitments. Revocation, expiry, Selective Forget, and account erasure remove governed chat content according to the same permission boundary.

A live meeting in this beta has exactly two authenticated participants: one host and one invited participant. This is a controlled-pilot limit, not a statement that future Mnera work is limited to two people. Voice and video are carried by Mnera's LiveKit service only while the meeting is active. Live media is transient and is not kept for durable recording or playback. Without microphone permission a person can remain listen-only; without camera permission a video room remains audio-only or listen-only. Declining transcription does not prevent the meeting from working. A participant who accepted can stop transcription of their own microphone while the meeting remains connected; that choice does not change the other participant's media or consent, and cannot be reversed until a new governed meeting session.

When a participant accepts live-meeting transcription, Mnera may route only that participant's microphone track to its private, CPU-only Faster-Whisper service. A declined track is excluded, and the meeting remains usable. When a participant stops their own transcription, Core confirms that participant's temporary Egress has stopped and prevents a new Egress for the rest of the session. Speaker labels come from the authenticated meeting roster and track identity, not voice recognition. Transcription audio is reserved only in a dedicated memory-backed temporary area, is capped and fail-closed, expires after at most two hours, and is deleted sooner when processing completes or the service restarts. It is never offered as a durable recording. Core may keep the machine transcript encrypted for review for up to 24 hours and removes it sooner on review, discard, revocation, Forget, or account erasure. The draft is not Work Memory; only text a person reviews and explicitly saves becomes Work Memory under the retention and visibility shown before saving.

OCR can misread a page. Extracted text is source-derived evidence, not verified truth, and any summary, relationship, decision, or commitment inferred from it remains a candidate for human review. Discarding Mnera’s submitted copy does not delete the original a person keeps on a device. Likewise, forgetting information copied from a connected service does not delete the authoritative original still held by that external provider.

Selective Forget first shows the source and derived records that will be affected. After explicit confirmation, Mnera commits an immediate retrieval fence and redacts the governed extracted text, chunks, lineage, and dependent projections. The preview counts only vector entries that were actually indexed and identifies downstream offline purge obligations. Those obligations do not mean the current native apps already keep offline tombstone records; encrypted offline storage and tombstone handling remain future native integration work. Mnera also keeps a keyed suppression marker with no readable forgotten content so the same source is not relearned automatically.

“Immediate” means the forgotten material is no longer available through live Mnera retrieval once that transaction commits. It does not mean every physical storage block is overwritten at the same instant. Database dead tuples, write-ahead logs, backups, content-free audit proof, and records of actions already carried out follow the documented retention and restore-erasure process. Restores must reapply committed fences before serving data. Revoking an entire source follows the same permission-first principle for records governed by that grant.

Update subscriptions remain until a person asks to unsubscribe. Private website feedback remains while it is being reviewed or used to improve the pilot. A signed-in reader can replace or delete synchronized reading progress, withdraw a beta request, and initiate account deletion from the account area.

Communication-policy acceptance and an active block remain while needed to enforce the person's active choices. An open safety report remains while the concern is assessed. After a report is resolved or dismissed, its identifying references are scheduled for minimization after 180 days. After a block is removed, its identifying references are scheduled for minimization after 30 days. A valid legal-preservation hold pauses that scheduled minimization; when the hold is lifted, an overdue record is processed by the next bounded cleanup. Content-free audit proof may remain under its governing audit schedule. Report records do not copy chat or transcript content. Authorized moderators can request only the smallest available governed source excerpt needed for review, with every access audited. A block removal does not erase an existing report, and a block is not a substitute for source revocation, Selective Forget, or account deletion.

An account-deletion request first revokes active sessions and app access, then initiates removal of the reader identity, personal tenant, synchronized reading progress, and governed source-derived data. A minimal decision and security record may remain where necessary to demonstrate the request, prevent unauthorized reactivation, and protect the service. To unsubscribe, request correction, or ask a question about deletion, use the dedicated Mnera support route or email support@mnera.online from an address where you can receive a reply.

05

Sharing and protection

Mnera does not make a person’s work memory public. Information is shared only with authorized members of the relevant tenant and, for addressed chat or a rostered live meeting, only with the specifically authorized participant, authorized moderators who need narrow report context, infrastructure providers needed to operate the service, or when disclosure is required to protect people, the service, or comply with a valid legal obligation.

The pilot uses encrypted transport, tenant- and actor-scoped authorization, source-level permissions, protected mobile storage, audit records, and isolated service roles. No security system is absolute, so the pilot deliberately begins with narrow workspaces and limited access.

06

Your choices

  • Review a permission preview before connecting a source.
  • Accept, edit, reject, or correct proposed memory.
  • Send or reply to a persistent message only inside an authorized Work Story.
  • Choose voice or video for a two-person meeting; keep the camera off, decline or stop transcription of your own microphone, or leave without creating a recording.
  • Accept the current communication-safety policy before using person-to-person chat or meetings; a material new version is a new choice.
  • Report a specific chat message, meeting participant, or meeting; preview and confirm a block; explicitly unblock later; or ask for a moderation decision to be reviewed.
  • Pause or revoke a connected source.
  • Delete one uploaded document, or revoke document-upload permission and remove all files governed by it.
  • Keep a bookmark only on your device, synchronize it to a reader identity, or delete the synchronized copy.
  • Request a personal Mnera account and see whether it is pending, approved, rejected, provisioned, or suspended.
  • Join Android, iOS, or both private betas through a separate consent, and withdraw that request at any time.
  • Native push is not enabled in the current pilot; notification controls will be presented before it is introduced.
  • Request access, correction, export, or deletion.
  • Unsubscribe from development updates at any time.

07

Questions and changes

Mnera is not directed to children. The controlled pilot is for invited adults participating through an approved workspace.

The current Communication Safety & Acceptable Use policy explains prohibited conduct, reporting, blocking, moderation, and review in plain language.

Material changes to this statement will be dated here and communicated to pilot participants before they take effect where fresh consent is required.

The responsible operator for the controlled Mnera pilot is Jose Arnold San Diego Bagabaldo, operating Mnera in the Philippines. Contact support@mnera.online or use the dedicated Mnera support route for privacy, support, correction, access, or deletion requests.

Ask a question or make a privacy request