Mementom FAQ

Why. What. How.

Mementom lets a site recognize and authorize the same person without ever requiring that person to identify themselves.

Why

Participation should not require identity.

Most sites use an email address, phone number, or shared identity provider to recognize a returning person. Mementom gives sites another option: ask for private proof and receive only the scoped result.

What problem does Mementom solve?

It separates recognition from identity across devices and technology. You can use the same key ring from a phone, tablet, Mac, Windows PC, or another supported browser. A company can know that the same authorized relationship has returned without receiving your name, email address, phone number, key image, or private phrase from Mementom.

Is Mementom just another login?

No. Mementom can establish an anonymous returning session, but it can also authorize one exact action—such as approving home entry—without granting open-ended access to anything else.

What

A private key ring made from memory.

One memkey is one image plus one private phrase. The same image or the same phrase can be reused separately; only an identical image-and-phrase pair is blocked on the same key ring.

What is a memkey?

A memkey begins with one image you recognize and one phrase that image means to you. Your browser turns the image into a cryptographically derived numeric key specific to that image, and Mementom stores that numeric key with protected phrase values—not the original image. The key ring must contain at least two active memkeys.

Does Mementom know who I am?

No. Mementom does not know who you are, and that is by design. It does not request or store personal information that identifies you, such as your name, email address, phone number, or identity profile. Opaque service records let your key ring, sessions, and authorized company relationships work without revealing who they belong to.

What does a connected company receive?

It receives its own opaque customer relationship and the result of its own scoped request. It does not receive your key images, phrases, key-ring password, or access to the protected Mementom window.

How

Proof stays inside Mementom.

The company describes the exact right it needs checked. Mementom opens a separately served protected window, verifies the memkey there, and returns only an opaque, scoped result.

How does a protected action work?

The company creates a short-lived challenge. Inside the protected Mementom window, Mementom presents a phrase from the key ring and the person supplies the matching original image. The browser derives its numeric key again, Mementom checks that key with the phrase, and the original image is not uploaded. The company then retrieves and consumes one signed decision for that exact challenge.

Where do I add, replace, remove, or share a key?

Start on My key ring. The regular page shows key count and privacy-safe activity. Any image, phrase, password, encoding, decoding, or key change happens only in the protected Mementom window.

What is a shared key?

It is an ordinary key on your ring that you choose to share. Its image is encrypted in the sender’s browser and made available through a one-time pickup link for no more than ten minutes. The recipient needs the separately shared phrase to decrypt it in their browser. Limits on the key itself remain visible and manageable from My key ring.

Privacy

Mementom does not know who you are.

That is by design. Mementom does not ask you for a name, email address, phone number, or identity profile to create or use a key ring.

Mementom keeps random service IDs, key status and limits, short-lived session and request records, and the time and result of key-ring and company-request actions. These records let the service work without naming you.

A company also sends the action details shown in the protected window, such as an order summary or appointment address. Mementom stores those details with that request so your proof can be bound to the exact action. Those details come from the company, not from your key ring.

For ordinary successful use, Mementom does not store your raw IP address. After a failed login, it stores a one-way code made from the IP address for up to 24 hours to slow repeated attacks. AWS and network providers still process the connection details needed to deliver the site.

Read the Mementom privacy policy