Skip to content

Last updated 17 September 2026

Privacy notice

NetworkMemory is a personal networking CRM. It collects only the information needed to exchange contact details, remember relationship context, and manage follow-up. It does not use advertising trackers, precise visitor location, or device fingerprinting.

Who we are

The data controller for NetworkMemory is Marius Miclau, trading as VoxAutomated. For any question about this notice, or to exercise any of the rights described below, contact privacy@networkmemory.io.

What we collect

  • Account details: your email address, name, and the profile fields you complete, such as job title, company, and timezone.
  • Your digital card: the fields you explicitly choose to publish. Every optional field starts private.
  • Your private CRM content: contacts you store, meeting notes, typed context, tasks, and tags. This content is visible only to you.
  • Contact exchange submissions: when a visitor submits their details to an account holder, we store the submitted fields together with the exact consent statement shown, its version, and the time of consent.
  • Voice recordings: short recordings you choose to make, held temporarily for transcription as described below.
  • Billing records: if you subscribe to the AI plan, we store your Stripe customer and subscription identifiers, your plan status, and the end of the current billing period. Stripe handles your payment details; we never receive or store full card numbers. We also keep a count of the AI notes your account has used, which persists for the lifetime of the account even after a note is deleted, because the free allowance is a lifetime allowance.
  • Operational records: security and audit events that reference opaque identifiers only. Abuse prevention and view counting use keyed one-way digests of network addresses; we do not store raw IP addresses for these purposes.

We use only essential cookies needed to keep you signed in. There are no advertising or third-party analytics cookies.

Voice notes and AI

Voice recordings are limited to a few minutes and are stored privately and temporarily. Audio is deleted on successful transcription, and failed uploads become eligible for deletion within about an hour.

AI assistance is disabled by default. When an external AI provider is enabled, content is sent to it only when a signed-in account holder requests transcription, extraction, or a message draft, and every AI suggestion requires human review before it changes a contact. We instruct the provider not to store or train on submitted content, and any enabled provider is listed in the subprocessor list below.

Where your data lives

The application runs in London (Vercel) and the database and file storage run in AWS eu-west-2, London (Supabase). Data is processed in the UK/EU. No transfer outside the UK/EU takes place unless an external AI provider is enabled, in which case the transfer and its safeguards will be disclosed here first. Payment processing is the one exception: when you subscribe to the AI plan, Stripe processes your payment and billing details under its own privacy notice and international transfer safeguards.

Current subprocessors: Vercel (application hosting, London region), Supabase (database, authentication, and storage, AWS eu-west-2), Resend (email delivery and receiving for this domain, processed in the EU), and Stripe (payment processing, subscription billing, VAT calculation, and the billing portal, engaged only when you subscribe to the AI plan). No external AI provider is currently enabled.

How long we keep data

  • Successful voice recordings: deleted on transcription.
  • Failed or abandoned voice uploads: eligible for deletion within about an hour.
  • Card view records: 90 days.
  • Abuse-prevention digests: at most 24 hours.
  • Security and audit events: 12 months.
  • Your CRM content, card, and exchange records: kept until you delete them or your account is deleted.
  • Billing records and the AI note count: kept until your account is deleted. Stripe keeps transaction records for as long as tax and accounting law requires.

Legal bases

We process contact exchange submissions on the basis of the visitor's consent. We provide the service itself, including your CRM content and the AI features you invoke, on the basis of our contract with you. Billing for the AI plan is processed on the basis of that contract, and transaction records are kept to meet our legal obligations for tax and accounting. We operate abuse prevention, privacy-preserving view counting, and security logging on the basis of legitimate interests.

Your rights

Under UK GDPR you can request access to, correction of, export of, or deletion of your personal data, and you can object to or ask us to restrict certain processing. Account holders can export their data directly from the account page and can edit or delete their content at any time. Account deletion requests are currently fulfilled manually by the controller; submit one from the account page or by email and we will confirm completion. You can also complain to the Information Commissioner's Office (ico.org.uk).

If someone stored your details

If you shared your details with a NetworkMemory account holder and want them corrected or removed, you can ask that person directly or contact us at privacy@networkmemory.io and we will help.

Changes to this notice

We will update this page when our processing changes, and the date at the top reflects the latest revision. Significant changes to the consent language shown to visitors are versioned, and historical consent records keep the exact text that was agreed to.