Privacy Policy
Updated September 6, 2026
Ikelos provides a memory layer for the AI tools you already use. This Privacy Policy describes how Ikelos collects, uses, and discloses Personal Data when you use the website at ikelos.ai, the API at api.ikelos.ai, the ikelos-connect command line tool and the hooks it installs, the connectors for third-party AI tools, the Ikelos GitHub App, and the other products and services Ikelos offers that link to this policy (together, the “Services”).
“Personal Data” means information that identifies, relates to, or could reasonably be linked with you.
This policy covers individuals who use the Services in the United States. If you use Ikelos through a team or organization account, that organization’s agreement with Ikelos may also govern how Personal Data in that account is handled. Where this policy and that agreement conflict, the agreement controls for the organization’s account.
1. Personal Data Ikelos collects
Ikelos collects Personal Data in three ways: you provide it, Ikelos receives it from your use of the Services, and Ikelos receives it from other sources.
Personal Data You Provide
Account Information. When you create an account, Ikelos collects your email address and the identifier assigned to you by its login provider. Sign-in credentials, such as a password, a one-time code, or a third-party sign-in, are handled by the login provider, WorkOS, and Ikelos does not store your password. Ikelos also keeps account records such as your plan, entitlement status, and the date your account was created. If you subscribe to a paid plan, the payment processor collects your payment details directly. Ikelos keeps only references such as a customer identifier, a subscription identifier, and subscription status. Ikelos does not store full payment card numbers.
User Content. Ikelos is a memory service, so most of the Personal Data it holds is the content you choose to have it remember (“Content”). Content may include:
- Conversations captured from the AI tools you connect, such as your prompts and the assistant’s replies, along with the session identifier the tool assigns.
- Messages you send in Ikelos chat, including the memory chat, the behavior chat, and project chat, and the responses generated for you.
- Memories Ikelos extracts from your conversations, such as decisions and the reasons behind them, lessons, goals, tasks, facts, dated events and timelines, and the people, projects, tools, and organizations you work with, together with the relationships between them.
- Corrections, confirmations, ratings, and other feedback you give about what Ikelos remembers or serves.
- Skills you write or import, pins and instructions you attach to parts of your memory, project roadmaps, and standing instructions for chat.
- Code knowledge, when you enroll a repository or install the Ikelos GitHub App: repository names and remote URLs, branch names, commit messages and authors, the paths of changed files, and symbol names, structure, and descriptions from the files Ikelos indexes. Ikelos runs a secret filter on your machine before code leaves it and again when it arrives, honors your ignore rules, and applies size limits and a file type allowlist.
- Files and documents you ingest, and anything else you ask Ikelos to remember.
Content often includes information about other people, such as colleagues, clients, or contacts you mention. You are responsible for having the right to store that information in Ikelos. Please do not include sensitive information you do not want stored, such as health, financial, or government identification details.
Communication Information. If you contact Ikelos by email or another channel, Ikelos collects your name, your contact details, the contents of your message, and any attachments.
Contact Data. If you join the waitlist, Ikelos collects your email address and the page or source you joined from.
Other Information You Provide. This may include:
- Your Anthropic API key, which Ikelos asks for when you join and runs all of its model work on, and any other provider keys, such as OpenAI or Google, that you choose to add for chat. Ikelos does not run models for your account without your own key. Stored keys are encrypted at rest and are never included in exports.
- Information you provide when you connect an integration, such as the repositories you grant the Ikelos GitHub App.
- Answers to project interviews, surveys, or other prompts within the Services.
Personal Data Ikelos Receives from Your Use of the Services
Log Data. When you use the Services, Ikelos servers record information such as your IP address, the endpoint or page requested, the date and time of the request, the type of browser or client making the request, and whether the request was authenticated. Ikelos also keeps an audit log of account actions such as key rotation, data export, and account deletion, and a log of failed authentication attempts.
Usage Data. Ikelos collects information about how you use the Services, such as:
- The AI tools and devices you connect, whether capture is on or off for each, the version of the ikelos-connect tool, and when each connection was last verified.
- The features you use, the models you select in chat, and the number of tokens and the estimated cost of each model call, which Ikelos itemizes for you on the Usage page.
- Retrieval telemetry: which memories were served to your tools, where they ranked, the route the request took, how long it took, and the usefulness ratings your tools report back. This telemetry may include vector representations of the queries your tools sent. It does not include the text of your Content.
Device Information. Ikelos receives the name you give a connected device, the platform it runs (for example Claude Code, Codex, Cursor, or a web connector), and general information about your browser when you use the website.
Location Information. Ikelos may infer your general location from your IP address to operate and secure the Services. Ikelos does not collect precise geolocation.
Cookies and Similar Technologies. Ikelos uses a session cookie set by its login provider to keep you signed in, and may use browser storage to remember preferences such as a selected tab or model. Ikelos does not currently use third-party analytics or advertising cookies. If analytics are added in the future, this policy will be updated. You can control cookies through your browser settings, though the Services may not work without the session cookie.
Information Ikelos Receives from Other Sources
- Login provider. WorkOS provides Ikelos with your identifier, your email address, and your email verification status.
- GitHub. If you install the Ikelos GitHub App, GitHub sends Ikelos the installation identifier, the repositories you granted, and push events for those repositories, including commit messages, commit authors, and changed file paths. During enrollment Ikelos also reads the contents and history of the granted repositories to index them.
- Connected AI tools. When you connect a tool such as Claude, ChatGPT, Gemini, or another connector, Ikelos receives the queries that tool sends on your behalf, the tool’s identity, and the memories it reports as useful.
- Payment processor. Stripe sends Ikelos subscription lifecycle events such as payment success, cancellation, and period end.
- Other users. If another user shares a project or a memory scope with you, Ikelos receives the information they chose to share.
- Publicly available information. Ikelos may use public information to describe entities in your memory, such as a tool or company you mention.
2. How Ikelos uses Personal Data
Ikelos uses Personal Data for the following purposes:
- To provide, operate, and maintain the Services. This includes storing your Content, extracting durable knowledge from captured conversations, building and maintaining your memory graph, resolving dates and relationships, describing the entities in your memory, serving context back to your tools, orienting new sessions, routing your skills, and answering in chat. Ikelos uses AI models from third-party providers to perform much of this processing (see “Disclosure of Personal Data”).
- To personalize the Services for you. Ikelos adapts retrieval to your account based on your ratings, corrections, and usage. This adaptation uses only your own data and affects only your account.
- To improve and develop the Services. Ikelos analyzes usage and retrieval telemetry to measure quality, find failures, and make the Services faster and more useful. Improvement work that reaches beyond your account uses content-free telemetry (ranks, routes, latencies, counts, spend) or aggregated or de-identified information. The text of your Content stays inside your account.
- To communicate with you. This includes in-product notifications, service announcements, responses to your requests, and, if you joined the waitlist, the invitation to use the Services.
- To process payments and manage your plan. This includes itemizing model spend, enforcing plan limits, and handling subscription events.
- To prevent fraud, abuse, and security incidents. This includes monitoring authentication failures, detecting misuse, scrubbing secrets, and protecting the Services and Ikelos users.
- To comply with legal obligations and protect rights. This includes responding to lawful requests and enforcing the Ikelos terms.
Model training. Ikelos does not use your Content to train AI models that serve other users. Your memory personalizes your own account and nothing else. If Ikelos ever offers a program that uses Content to improve models for others, it will be opt-in, off by default, and described in an update to this policy. The third-party model providers Ikelos uses process your Content under API terms that do not permit training on API inputs and outputs unless you opt in with that provider. When you bring your own API key, your agreement with that provider governs how that provider handles the data sent with your key.
Aggregated or De-Identified Information. Ikelos may aggregate or de-identify Personal Data so that it can no longer identify you, and use that information to analyze the effectiveness of the Services, improve features, conduct research, and for similar purposes. Ikelos maintains and uses de-identified information in de-identified form and does not attempt to re-identify it, except to test whether its de-identification works.
3. Disclosure of Personal Data
Ikelos discloses Personal Data in the following circumstances.
Vendors and Service Providers. Ikelos shares Personal Data with vendors that help operate the Services. They may access Personal Data only to perform services for Ikelos and are bound by obligations to protect it. Current vendors include:
- Hosting and infrastructure: Railway, which hosts the Ikelos application and database.
- Authentication: WorkOS, which provides sign-in and session management.
- AI model providers: Anthropic, whose models Ikelos runs under your own API key to extract knowledge from your conversations, describe entities, and answer in chat, and OpenAI, whose models Ikelos uses under its own account to generate the embeddings that make your memory searchable. If you add a key for OpenAI or Google, Ikelos sends the relevant Content to that provider under your key when you use their models in chat.
- Payment processing: Stripe, for paid plans.
- Key management: Amazon Web Services, which Ikelos may use to protect encryption keys.
- Code hosting: GitHub, when you install the Ikelos GitHub App or enroll a repository.
Ikelos may add or replace vendors from time to time. Vendors of these kinds may also include email delivery, error monitoring, and analytics services.
Business Transfers. If Ikelos is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of its business, Personal Data may be disclosed as part of that transaction, subject to this policy.
Government Authorities or Other Third Parties. Ikelos may disclose Personal Data to government authorities, law enforcement, or other third parties if required by law, or if Ikelos believes in good faith that disclosure is necessary to comply with a legal obligation, protect the rights, property, or safety of Ikelos, its users, or others, detect or prevent fraud or security issues, or enforce its terms.
Affiliates. Ikelos may share Personal Data with affiliates, meaning entities that control, are controlled by, or are under common control with Ikelos, who will use it consistent with this policy.
Business Account Administrators. If you use Ikelos through a team or organization account, the administrators of that account may access and manage the account and the Content within its scope.
Other Users and Third Parties You Interact or Share Information With. When you share a project or memory scope with other users, they can see what you share. When you connect a third-party AI tool, the memories that tool requests are sent to that tool and processed by its provider under that provider’s terms. Ikelos does not control how those tools use the information once they receive it.
4. Retention
Ikelos keeps Personal Data only as long as needed for the purposes described in this policy. How long depends on the type of data, why it was collected, and legal obligations.
Information Ikelos retains until you delete it. Your account, Content, memories, code knowledge, skills, pins, projects, stored API keys, and connections stay in Ikelos until you remove them. Deleting a memory removes it from your graph along with the connections that referenced it. Corrections keep the old value as history unless you delete it. Deleting your account removes all of your data immediately and irreversibly.
Information Ikelos deletes automatically. Short-lived items such as setup tokens, one-time authorization codes, and sign-in state expire on their own. Vector representations and other derived data are removed with the Content they were derived from.
Information Ikelos retains for longer for legitimate security, safety, or legal reasons. After you delete your account, Ikelos retains de-identified service telemetry such as request latencies, counts, routes, and spend totals, with all links to you and all Content removed in the same transaction. Ikelos keeps a record that an export or a deletion happened, holding no user data. Ikelos retains logs of failed authentication attempts, including IP addresses, for a limited period to detect and investigate abuse. Copies of data may persist in encrypted backups for a limited time before they are overwritten. Ikelos may also retain information where required by law, to resolve disputes, or to enforce its agreements. Your sign-in record at the login provider is separate from your Ikelos account and can be deleted with them.
5. Data controls
You have direct control over what Ikelos captures and keeps:
- Capture. Capture is opt-in per tool, and you can turn it off at any time from the Connect page or by disabling the hooks on your machine. Web tools only receive memory on request and cannot capture.
- Memories. You can correct a memory or delete it from within your tools or from Ikelos chat. Deletion removes the memory and its references.
- Export. You can download a copy of your data from Settings, under Account. The export includes every table that holds your data, excluding credentials and derived vectors.
- Account deletion. You can delete your account from Settings, under Account. Deletion is immediate and cannot be undone.
- API keys and devices. You can add or remove stored provider keys, rotate your Ikelos key, and revoke connected devices and connectors from Settings and the Connect page.
- GitHub. You can change the repositories the Ikelos GitHub App can access, or uninstall it, from your GitHub settings. Uninstalling stops new capture.
- Sharing. You control which projects and scopes, if any, you share with other users.
Retrieval telemetry that contains no Content is part of operating the Services and cannot be turned off separately. Retrieval personalization for your account can be turned off on request.
6. Your rights
Depending on where you live, you may have rights regarding your Personal Data, including the right to:
- Access your Personal Data and information about how it is processed.
- Delete your Personal Data.
- Correct or update your Personal Data.
- Receive a copy of your Personal Data in a portable format.
- Restrict or object to how your Personal Data is processed.
- Withdraw consent where processing is based on consent, without affecting processing that already occurred.
- Lodge a complaint with a supervisory authority or your state attorney general.
You can exercise most of these rights yourself through the controls described above. For anything else, contact Ikelos at the address in “How to contact Ikelos.” Ikelos will verify your request using your signed-in session or your account email, and may ask for additional information. Ikelos will respond within the time required by applicable law and will not discriminate against you for exercising your rights.
Because Content may include information about other people, someone who is not a user may ask Ikelos about information stored in another user’s memory. In that case Ikelos may refer the request to the user who stored it, and will assist as the law requires.
7. Children
The Services are not directed to children under 13, and Ikelos does not knowingly collect Personal Data from children under 13. You must be at least 16 years old to create an account. If you believe a child has provided Personal Data to Ikelos, contact Ikelos and it will be deleted.
8. Security
Ikelos takes reasonable technical and organizational measures to protect Personal Data, including:
- Encryption in transit for all connections to the Services.
- Encryption at rest for stored provider API keys, and hashing of Ikelos API keys and device keys, so the keys themselves are never stored.
- Isolation of each account’s data at the database layer, so that queries for one account cannot read another’s.
- A secret filter that runs on your machine before Content leaves it and again when Content arrives, so that credentials that appear in conversations or code are redacted before storage.
- Signed webhooks, short-lived tokens, rate limits, and audit logging of account actions.
- Staff access to production data limited to operating the Services, troubleshooting, and responding to your requests, with access logged.
No method of transmission or storage is secure in every case, and Ikelos cannot guarantee absolute security. If you discover a security issue, please report it to the address below.
9. Additional U.S. state disclosures
The following disclosures supplement this policy for residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and other U.S. states with comprehensive privacy laws.
Categories of Personal Data. In the preceding 12 months Ikelos has collected the following categories of Personal Data. The sources, purposes, and recipients are described in sections 1 through 3.
| Category | Examples | Disclosed to |
|---|---|---|
| Identifiers | Email address, account and login identifiers, IP address, device identifiers | Vendors and service providers; login provider; payment processor |
| Customer records | Email address, plan and subscription references | Vendors and service providers; payment processor |
| Commercial information | Plan, subscription status, model spend | Vendors and service providers; payment processor |
| Internet or network activity | Log data, usage data, retrieval telemetry, connected tools | Vendors and service providers |
| Geolocation data | General location inferred from IP address | Vendors and service providers |
| Professional or employment-related information | Projects, colleagues, and work details that appear in Content | AI model providers; connected tools you use; other users you share with |
| Content and communications | Captured conversations, chat messages, extracted memories, code knowledge, skills, messages to Ikelos | AI model providers; connected tools you use; other users you share with |
| Inferences | Descriptions of entities, relationships, and timelines that Ikelos derives from your Content | AI model providers; connected tools you use |
| Sensitive Personal Data | Stored provider API keys; any sensitive information you choose to include in Content | AI model providers (Content only, when processed on your behalf) |
Sale and sharing. Ikelos does not sell Personal Data, and does not share Personal Data for cross-context behavioral advertising. Ikelos does not use Personal Data for targeted advertising. Ikelos has no actual knowledge that it sells or shares Personal Data of consumers under 16.
Sensitive Personal Data. Ikelos uses sensitive Personal Data only to provide the Services you request, to maintain security, and as otherwise permitted by law. Ikelos does not use it to infer characteristics about you.
Your Opt-Out Rights. Because Ikelos does not sell or share Personal Data, and does not use it for targeted advertising or for profiling that produces legal or similarly significant effects, there is nothing to opt out of. If that changes, Ikelos will provide an opt-out mechanism and honor opt-out preference signals such as Global Privacy Control.
Your Other Rights. Residents of these states may have the right to know what Personal Data Ikelos collects and how it is used and disclosed, to access, correct, and delete Personal Data, to obtain a portable copy, to limit the use of sensitive Personal Data, and to be free from discrimination for exercising these rights. California residents may also request information about disclosures to third parties for their direct marketing purposes; Ikelos makes no such disclosures.
Verification. Ikelos verifies requests using your signed-in session or a confirmation sent to your account email, and may ask for additional information if it cannot verify you.
Authorized Agents. You may designate an authorized agent to make a request on your behalf. Ikelos may require proof of the agent’s authority and may still verify your identity directly.
Appeals. If Ikelos declines a request, you may appeal by contacting the address below and stating that you are appealing. Ikelos will respond in writing within the time required by law. If your appeal is denied, you may contact your state attorney general.
10. Changes to the privacy policy
Ikelos may update this policy from time to time. When it does, the updated version will be posted and the date at the top will change. If a change materially affects how Personal Data is handled, Ikelos will notify you by email or within the Services before it takes effect. Your continued use of the Services after a change means you accept the updated policy.
11. Data controller
Ikelos is the controller of the Personal Data processed under this policy.
[Legal entity name][Mailing address]
12. How to contact Ikelos
If you have questions about this policy or about how Ikelos handles Personal Data, contact privacy@ikelos.ai. You can also manage most of your data directly from Settings within the Services.
13. Useful resources
- Terms of Service
- Connect page: what gets installed, the capture switch for each tool, and connector setup.
- Settings, under Account: export your data and delete your account.
- Usage page: itemized model spend.
- GitHub App installations: permissions and installation settings.
- Privacy policies of Ikelos vendors: WorkOS, Railway, Anthropic, OpenAI, Google, Stripe, Amazon Web Services, and GitHub.