Plain-language summary
Mementom does not know who you are, and that is by design.
Mementom does not ask you to identify yourself. It uses random IDs and key-ring records to operate the service without learning who those records belong to. A connected company may send the details you need to review for one action, and Mementom stores those details with that request.
The important image rule
Your image is not stored as your key.
When you create or use a memkey, your browser turns the original image into a cryptographically derived numeric key specific to that image. Mementom stores and checks that derived numeric key with your phrase. The original image stays on your device and is not uploaded or kept as part of your Mementom key.
A company receives its result—not your key.
A connected company can receive an opaque relationship, request context it supplied, and a signed result for its own scoped challenge. It cannot see the protected Mementom window or receive the key image, phrase, readable key-ring password, or proof details.
Sharing is the only temporary image transfer.
When you share a key, Mementom offers a secure way to transfer the image portion of that key. The sender’s browser encrypts the image before upload. Mementom holds only that encrypted copy between sharing and pickup, for no more than ten minutes, then deletes it after accepted pickup or timeout. It never becomes the stored image for the memkey.
1. Scope and roles
This policy covers the Mementom website, key-ring service, protected authorization window, partner API, My key ring view, and temporary shared-key pickup.
Mementom does not know who you are, and that is by design. It does not ask you for a name, email address, phone number, or identity profile to create or use a key ring. Mementom still keeps the random service records needed to operate and protect the service.
A site or app that uses Mementom remains responsible for its own data practices. Mementom does not control information you give directly to that company outside the protected Mementom window. The company may include action details in a Mementom request so you can review exactly what you are authorizing. Mementom stores those details with that request, but they come from the company rather than your key ring. For example, if nCent uses Mementom for anonymous continuity, Mementom governs the private proof exchange while nCent’s own privacy policy governs information collected by nCent.
3. Why Mementom uses this information
- To create, verify, recover, and manage a private key ring.
- To establish an opaque relationship between one key ring and one participating company.
- To issue and enforce a result for one exact, time-limited request.
- To show key count, health, limits, and privacy-safe activity in My key ring.
- To prevent replay, fraud, unauthorized mutation, and abuse; investigate incidents; and maintain service reliability.
- To comply with applicable legal obligations and enforce the service’s terms and security boundaries.
4. Cookies and browser storage
Mementom uses strictly necessary, secure session cookies so a browser can remain connected to My key ring and so recent key proof can be recognized for a limited time. Protected session cookies are HTTP-only and are restricted by same-site and secure transport controls where HTTPS is used.
The current Mementom site does not use third-party advertising cookies. Browser-local state may be used to complete an active flow, protect a popup return, or present an explicitly requested download; it is not a substitute for server authorization.
5. What Mementom discloses
To a connected company
Mementom discloses only that company’s opaque relationship, the request identifiers and context needed to match its own request, and the scoped result it is authorized to retrieve. Mementom does not disclose your original key images, private phrases, readable key-ring password, another company’s relationship, or the contents of the protected Mementom window.
To infrastructure providers
Mementom uses service providers, including cloud hosting and database infrastructure, to run and secure the service. Those providers process operational data on Mementom’s behalf according to their service agreements and applicable law.
For legal and security reasons
Mementom may preserve or disclose records when reasonably necessary to comply with law, respond to valid legal process, protect the service or its users, investigate abuse, or address a security incident. Data minimization limits what Mementom has available to disclose.
6. Temporary shared-key transfer
Ordinary key creation and use do not upload the original image. Sharing is different only because Mementom provides a short-lived delivery path for the image portion of the key. The key remains an ordinary key on your ring with the limits you selected:
- The original image is encrypted in the sender’s browser before upload.
- Mementom temporarily holds the encrypted copy, integrity values, and short-lived pickup state—not a plaintext image or a permanent image attached to the memkey.
- The pickup URL carries a separate browser-side secret, and the phrase is meant to be sent separately.
- The transfer works once, expires in no more than ten minutes, and the encrypted image is deleted after accepted pickup or timeout.
- The recipient decrypts and downloads the original image in their browser.
7. Retention
Mementom keeps active key-ring records until they are replaced, removed, expired by a limit, or otherwise no longer needed to provide the service. Public My key ring sessions currently last up to 30 minutes; reusable recent-proof entries last up to 15 minutes without sliding; individual management and challenge ceremonies use shorter expirations.
Temporary shared-key ciphertext lasts no more than ten minutes and is deleted after successful pickup or expiration. Security, activity, relationship, and transaction records are retained only for the time reasonably needed to operate the product, preserve an accurate user-visible history, meet contractual or legal requirements, and investigate security events. Retention periods may differ by record type because those purposes differ.
8. Security
Mementom separates the public site, participating company, and protected authorization origin. It uses encrypted transport, protected session cookies, short-lived and one-use request material, scoped partner credentials, replay controls, encryption for protected stored values, and audit records. No security system can guarantee absolute protection, but the service is designed to reduce both the amount and usefulness of exposed information.
9. Your choices and requests
- Use My key ring to review active-key count, limits, and privacy-safe activity.
- Add, replace, remove, share, or limit a key through the protected Mementom window.
- Sign out of My key ring on that browser.
- Do not complete a partner request, or cancel before authorization completes.
- Contact Mementom to ask a privacy question or request access, correction, deletion, restriction, or another right available under applicable law. Because Mementom does not collect ordinary identity or recovery contact information for a key ring, Mementom may require key-based proof before disclosing or changing account-linked records.
10. Children
Mementom is not directed to children under 13, and Mementom does not knowingly ask children under 13 to create a key ring. A participating company is responsible for the age requirements and consent rules that apply to its own service.
11. Changes to this policy
Mementom will update this page when its product or data practices materially change. The effective date at the top identifies the current version. Material changes should be reflected here before or when the new processing begins.