# Security and privacy

> Where memory is stored, who can read it, how apps are let in, and how forgetting works.

A memory holds what people tell you, so who can read it, and how it is forgotten, matter as much as what it can
do. This is how Geniffy handles both.

## Where memory is stored

Geniffy stores memory in India. Every call to the API, the MCP server and the app travels over HTTPS.

## Who can read a memory

- **Your key reaches your memory, and nothing else.** An API key reaches its owner's memory and the
  [spaces](https://docs.geniffy.com/keys-and-spaces) beneath it, never another account's. Revoke a key in the Geniffy app and it stops
  working at once.
- **Each of your users is separate.** A space is one of your users. What is added to one space is never found
  from another, and your own memory never mixes with theirs.
- **Keys stay on your server.** A key is shown once, when you make it. Keep it out of browsers and mobile apps.

## How AI apps are let in

Claude, ChatGPT, Cursor and the other apps connect through the [MCP server](https://docs.geniffy.com/mcp) with a sign-in, never with a
copied key.

- **You approve each app.** Geniffy shows who is asking and where it will send you back, and nothing is shared
  until you choose **Allow**. You can allow reading only.
- **Access is short-lived.** An app's access lasts an hour and is renewed with a refresh token that works once.
  A refresh token used twice ends that app's access, because only a copied token would be used twice.
- **Tokens are stored as hashes.** Geniffy keeps a one-way hash of each app's tokens, not the tokens themselves.
- **You can disconnect at any time**, in the Geniffy app under **Agents and MCP**.

The details are in [Sign-in](https://docs.geniffy.com/mcp/sign-in).

## Forgetting

- **One memory**, forgotten for good, or marked wrong with what is right saved in its place. See
  [Correct and forget](https://docs.geniffy.com/correct-and-forget).
- **One source**, and every memory only it taught.
- **Everything held for one of your users**, with one call, when they ask to be forgotten.

## A record of every call

Every call gets a request id, and a record of what was asked and what came back that you can search in the
Geniffy app for 30 days. See [Request ids](https://docs.geniffy.com/request-ids).

## Secrets

Don't add passwords, API keys or other secrets to a memory. The memory tools tell AI apps never to save them,
and the [Claude Code plugin](https://docs.geniffy.com/mcp/claude-code) removes them before anything leaves your computer.

## Report a vulnerability

Email **ops@geniffy.com** with what you found and how to reproduce it, and please don't open a public issue. See
the [security policy](https://github.com/Geniffy/.github/blob/main/SECURITY.md).

Source: https://docs.geniffy.com/overview/security
