Alfred Memory Privacy Policy
Effective date: September 3, 2026
Alfred Memory is an external, self-hostable memory service published by AlfredLabs. It is not ChatGPT's native Memory feature.
Information we process
- Memory content that you explicitly ask Alfred to create, search, read, update, or delete.
- Memory metadata such as type, namespace, tags, source, timestamps, project identifiers, confidence, and optional expiration dates.
- OAuth authorization data required to connect ChatGPT to your Alfred tenant. Authorization codes, access tokens, refresh tokens, API keys, and client secrets are stored only as cryptographic hashes where persistence is required.
- Limited request metadata used for security, troubleshooting, and rate limiting, such as endpoint, method, result, timestamp, and credential hash. Hosting infrastructure may also process IP addresses and standard network logs.
How we use information
We use this information only to provide Alfred Memory, authenticate users, return requested memories, perform user-requested changes, enforce tenant isolation and scopes, prevent abuse, and diagnose service failures. We do not sell personal information or use memory content for advertising.
ChatGPT and service providers
When you invoke an Alfred Action, the request and response needed to complete that Action pass between ChatGPT and the Alfred Memory API. OpenAI processes that data under its own terms and privacy policy. Infrastructure providers may process encrypted or operational data solely to host and secure the service.
Retention and deletion
Memories remain until you delete them or an optional expiration date is reached. OAuth artifacts expire or are revoked according to the service configuration. You can review and delete memories through the Alfred Memory Custom GPT or Alfred console. Deleting a tenant removes its associated Alfred Memory data subject to operational backup retention.
Security and choices
Alfred uses scoped OAuth access, exact redirect URI matching, tenant isolation, hashed credentials, short-lived authorization codes, rotating refresh tokens, and rate limits. Do not store secrets, passwords, API keys, private keys, raw transcripts, or sensitive personal data as memories. You may revoke access by disconnecting the Action or rotating your Alfred API key.
Children
Alfred Memory is not directed to children under 13, and we do not knowingly collect their personal information.
Changes and contact
Material changes will be reflected on this page with a new effective date. For privacy questions or deletion assistance, email alfred.support@alfredlabs.org.