Skip to the page
Kept Mems Kept Mems
Home Sign in Privacy Terms

Privacy

Privacy policy

Kept Mems is a private collection of memories.

Describes the product as of 29 September 2026. This is a plain account of how it works, not a lawyer’s review.

Who to write to

The contact already published for Kept Mems is karna.jani@gmail.com.

Signing in

Sign-in is Google. Signing in lets you read your private collection in the browser. Signing in does not, by itself, connect ChatGPT.

The sign-in request asks Google for openid, email, and profile. From Google’s reply, Kept Mems keeps two fields:

  • the email address
  • the Google account subject (sub), stored as google_sub

Kept Mems checks that Google marks the email verified, and refuses the sign-in when Google says it is not. The verified flag itself is not stored. Google’s name and picture are not stored. The Google access token used for that one read is not stored.

The first sign-in opens an empty private collection for that Google account. Nothing is copied in from another account. The account row stores an id, a short name taken from the part of the email before the @ sign, the email, the Google subject, the time it was created, and a status value set to trial. A payment-customer field is on that row and is left empty. Kept Mems does not take payment or card details.

After sign-in, the browser gets a cookie named cw_session. It lasts 7 days, is HttpOnly, and is SameSite=Lax. It holds the Kept Mems account id, the email, an expiry, and a signature. It is not a Google token. Sign out clears that cookie. Signing out leaves the collection, keys, and any connected assistant in place.

While Google’s page is open, a second cookie named cw_oauth_state lasts 10 minutes. It holds a random value, the page to open after sign-in, an expiry, and a signature.

What stays in your account

Memories, files, and links stay in that person’s account. They are stored apart from every other account.

A memory can hold a title, the prose, an attribution, an event date, whether it is marked as fiction, a status such as active or archived, and the times it was saved or changed. Earlier wording is kept as versions, with the reason recorded for a change. A stable idempotency key can be stored with a save so a retry does not create a second copy.

A file attached to a memory stores the file name, content type, size, caption, and the file itself, under that account’s own prefix. A link between two memories stores which memories, a written explanation, and an optional short label.

Archiving hides a memory and keeps it stored. Permanent deletion, when you ask for it and confirm with the words “permanently delete”, removes that memory’s prose, earlier versions, files, links, and published copy. A short deletion record can remain: the memory id, the title, and the time. Removing one file or one link can leave a similar short record (the id, the file name or the explanation, and the time) so a repeated request is not treated as a missing item.

Publishing

Publishing is optional. A published copy is separate from the private memory. It stores its own English and Gujarati wording, whether it is marked as fiction, an event date, an adaptation note, and the files and captions selected for that copy. Later edits to the private memory do not change the published copy until it is published again. Withdrawing the copy hides it. The private memory stays.

On this site, the list of published copies is shown to the signed-in account that published them. Someone who is not signed in sees an empty page. The page does not list anyone else’s collection.

ChatGPT, Cursor, and Claude

Signing in on Kept Mems does not add ChatGPT. ChatGPT connects by adding the Kept Mems plugin: https://chatgpt.com/plugins/plugins_6abb041c87f481918cbee31a52d48dff.

Cursor uses a personal access key against https://keptmems.com/mcp. You make that key on the account page after you sign in. The key is shown once. Kept Mems stores a hash of the key, the first characters, an optional name you give it, and the times it was made or revoked. The key itself is not stored again. Revoking a key stops that assistant from connecting with it.

A Claude plugin is planned, not launched.

An assistant you connect can read and change that same private collection, within the tools that connection has. A Cursor key can use the full set, including archive and earlier versions. The ChatGPT connection can list, search, read, save, correct, and permanently delete memories, link and unlink them, attach and remove files, and publish or unpublish. Archive and the version-history tools are not on that ChatGPT connection. A connected assistant can also see the account id, the email, and the short account name. The name sent to that assistant is the email address.

Connecting through that assistant door stores the client’s name and redirect addresses, and hashed access and refresh tokens for the connection. An access token lasts one hour. A refresh token lasts 30 days and is replaced when it is used. Those tokens are created when the assistant connects. Google sign-in alone does not create them.

Where it runs

Kept Mems runs as a Cloudflare Worker. Account records are in a Cloudflare database. Each account’s memories are in that account’s store, and files are in Cloudflare object storage under that account’s prefix. Cloudflare’s own Worker logs are turned on. These pages do not set an analytics cookie.

Private by default. Your collection is yours. A published copy is separate from the private memory.

Privacy Terms
Kept Mems