Privacy Policy
1. Who We Are
Miller is owned and operated by Memento AI Inc., a Delaware corporation. Memento AI is the data controller responsible for your personal information and is the company you contract with when you use Miller.
We use service providers to help run Miller, including our engineering subsidiary and the third-party providers listed in Section 4. All of them process your information only on our instructions, under data processing terms, and are bound by the access rules in Section 4.4.
Additional provisions that apply only in certain countries or states are in the Appendix at the end of this Policy.
Note: Miller was previously called M24. References to Miller mean the same service.
2. What We Collect
2.1 Screen text
What
Details
On-screen text
Text extracted from your active screen and supported applications
Application context
Name and type of the active application
Browser context
Page title and full URL of the active browser tab, including any parameters in the URL
Timestamps
When each extraction happened
This is optional, and it runs continuously while it's on. We collect screen text only if you grant screen access permission. While the permission is on, Miller reads your screen in the background as you work, not only when you ask it something. You can turn it off at any time.
Text only. We extract text. No screenshots, no video, no images. Visual content from your other applications is never captured or transmitted.
Where it goes. Extracted text is sent to and stored on our servers so Miller can build your working context and provide features like proactive summaries, smart suggestions, and automated recaps. Parts of it may be processed by the AI providers listed in Section 4 solely to generate responses and summaries for you, under the no-training commitments in Section 8. If you need your screen text to stay on your device, do not grant screen access permission.
What we exclude automatically, and what we can't. Password fields and secure input areas marked as such by your operating system or application are automatically excluded. Identifiers with a fixed, verifiable format, such as national ID numbers and payment card numbers, are detected and masked on your device before any screen text is sent to us. But automatic exclusion cannot catch every kind of sensitive information that appears as ordinary text on screen, such as an account number or a verification code displayed in a document or webpage. It also does not filter URLs: we collect the full address of the active tab, which can include search terms and other parameters. For apps and sites where you routinely view sensitive information, such as banking, health, or legal services, use the exclusion controls below to exclude the whole app or domain.
What you control:
·
Exclusions. Exclude collection for a single page, an entire application, or an entire web domain in settings. Excluded scopes are never extracted or transmitted.
·
Rollback. Delete already-collected screen text for a time range you pick, such as the last few minutes, hours, a day, or your entire history.
·
Turn it off. Revoke screen access permission any time in app or device settings. Context-aware features will be limited.
Deletion. When you delete screen text, whether by rollback or by deleting your account, it is removed from our live systems and not restored. See Section 7 for how backups work.
Who can see it. Miller staff and contractors access your screen text only in the limited cases described in Section 4.4, each of which is subject to the approval, scope, and logging requirements in that section.
We never sell it, never use it for advertising, and never use it to train AI models (Section 8).
2.2 Account information
What
How we get it
Required
Email address
OAuth sign-in (e.g., Google)
Yes
Nickname
OAuth sign-in
No
Profile image URL
OAuth sign-in
No
Provider account identifier
OAuth sign-in
Yes
2.3 Voice and transcription
What
Details
Transcribed text
Text converted from audio
Recording times
When a recording started and ended
Speaker separation data
Labels indicating which audio source (your microphone or your computer's audio output) each part of a recording came from
Audio files
The original audio recorded through Miller
When we record. Miller records only while you are using meeting notes. When you start meeting notes, Miller captures your microphone and your computer's audio output so it can transcribe both sides of a conversation. It does not record at other times.
Other people's voices. Because Miller captures your computer's audio output, recordings include the voices of other people in the meeting or call. You are responsible for following recording laws that apply to you, including laws requiring notice to or consent from everyone in a conversation. See Section 4 of the Terms of Service.
Where it goes. Audio files are sent to and stored on our servers so Miller can record, transcribe, and summarize. Audio and transcribed text may be processed by the speech and AI providers in Section 4 solely to deliver those features, under the no-training commitments in Section 8.
Speaker separation. Speaker separation is based on audio source: input from your microphone is labeled as you, and your computer's audio output is labeled as other participants. We do not analyze voice characteristics, create voiceprints, build a profile of anyone's voice, or attempt to identify who a speaker is. This data is deleted together with the transcript it belongs to.
Who can see it. The rules in Section 4.4 apply to audio, transcripts, and speaker separation data.
2.4 Calendar
What
Details
Calendar name and description
Basic information about connected calendars
Event title and description
Event details
Event times
Start and end times
Attendees
Name, email, participation type
Read-write, only when you ask. Miller reads your calendar to provide assistant features, and can create, update, and delete events and respond to invitations, but only when you ask it to and confirm the change Miller proposes. Changes you direct are made in your real calendar and may be visible to attendees and organizers. Miller never changes your calendar without your direction.
2.5 Notes
What
Details
Note title and content
What you write
Timestamps
When you created or changed it
2.6 Chats with the assistant
What
Details
Conversation content
Your conversations with the AI assistant
Timestamps
When each interaction happened
2.7 Country
What
Details
Country or region
Derived from your connection, not from GPS
We record which country you're connecting from so we can keep the service working and apply the right regional rules. We don't collect GPS coordinates, movement history, step counts, or activity data.
2.8 Gmail (optional)
What
Details
Email metadata
Sender, recipients, subject, timestamps, thread and label identifiers
Email body
Plain-text body of messages
Contacts and profile details (optional)
Names, email addresses, and phone numbers from your Google contacts and "other contacts," and the language, addresses, birthday, phone numbers, and email addresses on your Google account, if you grant those permissions. Used to help you address and draft email and recognize people in your work
Opt-in only. We collect email information only if you connect your Google account through "Connect Gmail" and grant the Gmail permissions listed in Section 5.1.
Read-write, only when you ask. Miller reads your messages in the background to provide the features below. When you ask and confirm, it can also draft and send messages from your address and create and manage labels in your mailbox. Anything Miller sends goes out from your address and is visible to its recipients. Miller does not delete your messages, and it never sends messages or changes your mailbox without your direction.
How it works. After you connect Gmail, Miller periodically retrieves your recent messages in the background so it can organize meeting-related communications, surface relevant emails in summaries, and answer your questions about past communications. Miller reads messages only as needed for those features. Spam and explicitly excluded categories may be omitted depending on how the Google API behaves.
What you control. Disconnect Gmail any time in Settings, Integrations, or revoke access at https://myaccount.google.com/permissions.
Retention. Kept on our servers only while the integration is active. Deleted when you disconnect or delete your account.
2.9 Google Drive and Docs (optional)
What
Details
File metadata
File name, MIME type, last modified time, owner, file ID
Document body
Text or markdown content of Google Docs files read in response to your requests
Opt-in only. We collect document information only if you connect your Google account through "Connect Google Drive" and grant the Drive and Docs permissions listed in Section 5.1.
Read-write, only when you ask. Miller reads your files in response to your requests. When you ask and confirm, it can also create and edit files in your Drive, limited to the files and content you asked about. Miller does not change sharing permissions or disclose your Drive files to other users unless you direct it to. Document content may be processed by the service providers described in Sections 4 and 5 solely to provide Miller's features. Miller never creates, changes, moves, or deletes anything in your Drive without your direction.
Only when you ask. Miller reads from or writes to Drive only when you ask the assistant something that involves your documents, at the moment you ask.
What you control. Disconnect Google Drive any time in Settings, Integrations, or revoke access at https://myaccount.google.com/permissions. You can also avoid Drive access entirely by not asking the assistant about your documents.
Retention. File metadata and document content read on your behalf are kept only while the integration is active. Deleted when you disconnect or delete your account.
2.10 Slack, Notion, Outlook, Linear, and Granola (optional)
What
Details
Slack
Messages, channel and thread information, files and file metadata, and search results from the workspaces and channels you connect
Notion
Page and database content, titles, comments, and metadata from the pages you connect, and workspace member names and email addresses
Outlook
Email metadata, message bodies, calendar events, contacts, and attachment metadata from the account you connect
Linear
Issues, comments, projects, and workspace metadata from the workspace you connect
GitHub
Profile and email information, repositories, issues, pull requests, branches, files, commits, Gists, notifications, Projects v2, Actions workflows, Codespaces, and related metadata from the GitHub account you connect
Granola
Basic account profile information, such as name, email, and profile image
Opt-in only. We collect this information only if you connect the service yourself through in-app Settings, Integrations, and grant access through that service's own authorization flow. If you don't connect a service, this section doesn't apply to you.
Reading and acting. Miller reads from these services to provide the features described here. Where an integration supports actions, Miller can also act on your behalf, but only when you ask and confirm: in Slack, send messages, upload files, and add reactions, pins, and reminders; in Notion, edit pages, create content, and write comments; in Outlook, send email, create and change calendar events, and manage contacts; in Linear, create and update issues and write comments; and in GitHub, create and update issues and comments, create branches, create or modify files through commits, create pull requests, submit pull request reviews, request reviewers, create, update, and delete Gists, mark notifications as read, dispatch, cancel, or rerun Actions workflows, and start or stop Codespaces. Granola is read-only. Miller never acts in a connected service without your direction.
GitHub permissions. If you connect GitHub, Miller requests the following GitHub OAuth scopes: repo, user, gist, notifications, project, workflow, and codespace. These permissions are used only to provide the GitHub features described above. Some scopes, including repo, provide technical access to a broad range of information and actions within your connected GitHub account. Miller uses that access only as needed to provide the features you request.
Why. So the assistant can find, recall, and summarize your work across the tools you already use, answer questions about it when you ask, and carry out the actions you ask for in those tools.
Where it goes. This content is stored on our servers and may be processed by the AI providers in Section 4 solely to answer your requests, under the no-training commitments in Section 8.
What you control. Disconnect any service at any time in Settings, Integrations, or revoke access in that service's own settings. When you disconnect, the content we hold from it is deleted.
Retention. Kept only while the integration is active. Deleted when you disconnect or delete your account.
2.11 Handing work to tools on your computer (optional)
Miller can pass what it already knows about your work to a coding tool running on your own computer, such as Claude Code or Codex, when you ask it to. This only happens for the scope you point it at.
What we send. The context Miller has already collected and that is relevant to what you asked for, such as screen text and notes. Miller does not read your files, write to your disk, or run commands itself.
Where it goes from there. The tool runs on your computer under your own account with its provider. Once Miller hands the context over, that tool's own terms and privacy policy govern what happens next, including anything it does with your files and anything it sends to its provider. That part is outside this Policy and outside our control.
What you control. This only runs when you ask for it. If you don't use the feature, Miller never sends anything to those tools.
2.12 Technical information
What
Details
IP address
Collected when you use the service
Device information
Device and service type
Access logs
Request URL, HTTP method, response time
We use these for security, fraud prevention, troubleshooting, performance monitoring, and keeping the service running.
3. How We Use Your Information
We use your information only for the purposes below.
What
Details
Running your account
Account information, technical information, and the country you connect from
Providing Miller's features
Screen text, voice and transcription, calendar, notes, chats, and data from connected services (Gmail, Drive, Slack, Notion, Outlook, Linear, GitHub, Granola), used to deliver transcription, summarization, search, recall, and assistant responses, and to take actions you ask Miller to take in a connected service, such as creating an event, sending an email or message, editing a document or page, creating an issue, or creating a pull request
Keeping Miller secure
Technical information, access logs, and account information, used to prevent fraud and abuse
Improving Miller
Aggregated statistics and non-identifiable in-app usage analytics as described in Sections 8 and 11; limited review of service data under the controls in Section 4.4, case 6; and specific content you explicitly agree to share with us for this purpose
Supporting you
Account information and anything you send us when you contact support
4. Who We Share It With
We don't sell your personal information, and we don't share it for advertising. We share it only with the service providers below, who process it on our instructions to run Miller, or when the law requires it.
4.1 Service providers
Provider
Where data is processed
What they do
What they receive
How long they keep it
OpenAI
United States
Speech-to-text, summarization, assistant responses
Screen text relevant to a request, audio and transcripts, notes, chats, calendar, email content, document content
Under our data processing terms; not used for training; kept only as those terms permit
Anthropic
United States
Summarization, assistant responses
Screen text relevant to a request, transcripts, notes, chats, calendar, email content, document content
Under our data processing terms; not used for training; kept only as those terms permit
United States
Speech-to-text, calendar, Gmail, and Drive integrations
Audio sent for transcription, calendar data, email metadata and body, document metadata and body
Audio sent for transcription is deleted after processing; integration data is held until you disconnect or delete your account
Fireworks.ai
United States
Speech-to-text
Audio sent for transcription
Under our data processing terms; deleted after processing
Assembly.ai
United States
Speech-to-text
Audio sent for transcription
Under our data processing terms; deleted after processing
Portkey.ai
United States
AI request routing and monitoring
Request content transits its systems on the way to an AI provider, along with operational metadata
Under our data processing terms; kept only as those terms permit
Amazon Web Services
United States and Republic of Korea
Cloud infrastructure and storage
All service data
Until you delete your account, subject to the backup cycle in Section 7
Google Analytics
United States
Website analytics for our marketing site, such as download counts
Visits to our website. Not linked to your Miller account or to anything inside the app
Under Google's own retention settings
Mixpanel
United States
Usage analytics
Non-identifiable usage events and device information. Not linked to your account, your identity, or your content
Under Mixpanel's own retention settings
Soniox
United States
Speech-to-text
Audio sent for transcription
Under our data processing terms; deleted after processing
Memory Labs Inc. (engineering subsidiary)
Republic of Korea
Development, operation, and support
Access to service data only as permitted under Section 4.4
For as long as it supports the service
Each provider above processes your data under data processing terms covering confidentiality, retention limits, and no use of your data for model training. A summary is available on request at contact@trymiller.com.
This list is current as of the date at the top of this Policy. We may add or replace a provider within one of the categories above (cloud hosting, speech-to-text, AI inference, analytics) with one bound by equivalent terms. When we do, we update this list, and that update on its own is not a material change under Section 13. Adding a new category of provider, or a provider that receives a new category of your data, is a material change.
4.2 Legal requests
We disclose personal information to government or law enforcement only when we receive valid legal process under the law that applies to the requesting authority. We review every request for legal sufficiency and scope, disclose only what is specifically required, and, where the law allows, tell you before or promptly after we disclose. This applies to requests from any country, including requests made to our engineering subsidiary.
We may also disclose information when you have asked us to, or in an emergency where disclosure is necessary to protect someone's life or safety.
4.3 Business transfers
If Miller is acquired or merged, your information may transfer to the acquiring company. Section 18 of the Terms of Service sets out what we commit to in that case, including advance notice and your right to leave and have your data deleted instead.
4.4 Who at Miller can see your data
Miller staff and contractors, including employees of our engineering subsidiary, do not read, view, or otherwise access your personal information, including Google data, screen text, audio, transcripts, and speaker separation data, except when:
1.
You ask us to, for example when you send a support request and authorize us to look at specific data, or when you explicitly agree to share specific content with us so we can improve Miller;
2.
We are investigating abuse, fraud, or a security incident affecting Miller or other users;
3.
The law, a court order, or a lawful government request requires it;
4.
The data has been aggregated and de-identified so that it cannot be connected to any individual;
5.
Access is technically necessary to operate, maintain, or support Miller, such as diagnosing a failure or restoring service. Access under this case is limited to what the task requires, is logged, and is not used to read your content for any other purpose. Where a task can be done without viewing your content, we do it that way. This case does not apply to Google user data, which we access only under cases 1 through 4; or
6.
Access is necessary to evaluate and improve how Miller works, such as reviewing a limited sample of screen text, transcripts, summaries, or assistant responses to diagnose why a feature produced a poor result, to measure output quality, or to understand how a feature is failing in practice. This case does not apply to Google user data, which we access only under cases 1 through 4.
Controls that apply to this access. For cases 2, 3, 5, and 6, we require:
·
Named approval. Access is approved by our privacy lead or a designated security lead. Where the situation allows, we get that approval before the access; during an active incident it may follow afterwards. For case 6, approval is always obtained in advance.
·
Minimum scope. Access is limited to the smallest set of data needed for the stated reason. Where a task can be done on aggregated statistics instead of your content, we do it that way.
·
A record of every access. We log who accessed the data, when, for what stated purpose, and what scope of data was accessed. These staff access records are separate from the service access logs in Section 6, and are retained for our own audit purposes.
·
Purpose limitation. Data accessed under one case is not used for a different purpose. Content reviewed under case 6 is not used to train, fine-tune, or evaluate any AI model (Section 8), is not disclosed outside the people performing that review, and is not used to make decisions about individual users.
What case 6 does not cover. Case 6 does not permit browsing your data out of curiosity, monitoring an individual user, reviewing your content to enforce these policies (that is case 2), or accessing Google user data for any purpose.
How case 1 and case 6 differ. Case 1 covers content you specifically choose to send us, for example when you attach a transcript to a support request or opt in under Section 8. Case 6 covers samples we select ourselves, under the controls above. You do not need to opt in for case 6.
We do not routinely read your content. Most of our product work runs on aggregated statistics and on the non-identifiable in-app analytics described in Section 11. Case 6 exists because some quality problems, such as a transcript that came out wrong or a summary that missed the point, cannot be diagnosed from counts alone.
5. Google User Data
Miller uses Google OAuth for sign-in and accesses Google user data through the Google Calendar, Gmail, People, and Drive and Docs APIs.
The Gmail integration and the Drive and Docs integration are optional and opt-in. If you don't enable an integration, its provisions don't apply to you. You can enable or disable each one independently in Settings, Integrations.
5.1 What we access
Data
What
Why
OAuth scope
When
Sign-in
Email, name, profile image
Registration and identity verification
openid, email, profile
You sign in
Calendar
Event title, description, time, attendees
Assistant features, and creating, updating, and deleting events and responding to invitations when you ask and confirm
calendar, calendar.events
You connect your calendar; periodic sync for reading. Write actions happen only when you ask and confirm
Gmail
Email metadata, body, attachment metadata
Email organization, recall, summarization, and drafting and sending messages and managing labels when you ask and confirm
gmail.readonly, gmail.compose, gmail.labels
You connect Gmail; periodic background sync for reading. Write actions happen only when you ask and confirm
Drive and Docs
File metadata, Google Docs body
Retrieving and referencing documents you ask about, and creating and editing files when you ask and confirm
drive.readonly, documents.readonly
Only when you ask the assistant about your documents. Write actions happen only when you ask and confirm
Contacts and profile (optional)
Contact names, email addresses, and phone numbers; account language, addresses, birthday, phone numbers, and email addresses
Helping you address and draft email and recognize people in your work
contacts.readonly, contacts.other.readonly, profile.language.read, user.addresses.read, user.birthday.read, user.emails.read, user.phonenumbers.read, profile.emails.read
You grant the permissions. Read-only
Write actions. Where the table above says Miller can create, change, send, or delete something, those actions happen only at your explicit direction in a conversation with the assistant, are limited to the scope of what you asked, and require your confirmation of the specific action before Miller carries it out. Miller never acts in your Google account without your direction.
5.2 Who receives it
We don't share, transfer, or disclose Google user data to anyone beyond the providers below, except as required by law under Section 5.4.
Recipient
Where
Why
What
OpenAI
United States
Summarization, analysis, assistant responses
Calendar, email content, document content, contact names and email addresses
Anthropic
United States
Summarization, analysis, assistant responses
Calendar, email content, document content, contact names and email addresses
Portkey.ai
United States
Routing AI requests
Google user data contained in a request transits Portkey on its way to an AI provider, under our data processing terms
Amazon Web Services
United States and Republic of Korea
Storage and hosting
Google user data
5.3 Limited Use commitments
Miller's handling of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements.
1.
You ask us to, for example when you send a support request and authorize us to look at specific data, or when you explicitly agree to share specific content with us so we can improve Miller;
2.
We are investigating abuse, fraud, or a security incident affecting Miller or other users;
3.
The law, a court order, or a lawful government request requires it;
4.
The data has been aggregated and de-identified so that it cannot be connected to any individual;
5.
Access is technically necessary to operate, maintain, or support Miller, such as diagnosing a failure or restoring service. Access under this case is limited to what the task requires, is logged, and is not used to read your content for any other purpose. Where a task can be done without viewing your content, we do it that way. This case does not apply to Google user data, which we access only under cases 1 through 4; or
6.
Access is necessary to evaluate and improve how Miller works, such as reviewing a limited sample of screen text, transcripts, summaries, or assistant responses to diagnose why a feature produced a poor result, to measure output quality, or to understand how a feature is failing in practice. This case does not apply to Google user data, which we access only under cases 1 through 4.
5.4 Legal disclosure of Google data
Google user data may be disclosed only under a court order or lawful legal process, a lawful request from investigative authorities, or in an emergency necessary to protect life, body, or property. Where the law allows, we will tell you before or after.
5.5 Disconnecting and deletion
·
Disconnect any Google integration any time in Settings, Integrations.
·
When you disconnect Calendar, all calendar data on our servers is promptly and permanently deleted.
·
When you disconnect Gmail, all email metadata and body data, and any contacts and profile details we hold, are promptly and permanently deleted from our servers.
·
When you disconnect Drive, all file metadata and document content read on your behalf is promptly and permanently deleted.
·
Deletion on disconnect removes the data from our live systems; backup copies expire on the cycle described in Section 7 and are never restored.
·
When you delete your account, all Google-related data is permanently deleted on the schedule in Section 7, subject only to the legal retention requirements in Section 6.
·
You can also revoke Miller's access directly at https://myaccount.google.com/permissions.
6. How Long We Keep Your Information
Category
What
How long
Account information
Email, nickname, profile image
Until you delete your account, or three years after your last sign-in (see below)
Screen text
On-screen text, app and browser context, timestamps
Until you delete it by rollback or delete your account
Voice and transcription
Transcripts, timestamps, speaker separation data
Until you delete them or delete your account
Audio files
Original recordings
Until you delete them or delete your account
Calendar
Events, attendees
Until you disconnect your calendar or delete your account
Notes
Titles and content
Until you delete them or delete your account
Chats
Assistant conversations
Until you delete them or delete your account
Country
Country or region of connection
Until you delete your account
Access logs
IP address, access records
At least 12 months as a security measure, and longer where applicable security regulations require. These are not deleted on request
Staff access records
Records of internal access under Section 4.4
At least 12 months, and longer where applicable security regulations require. These are records about our staff, not about you, and are not deleted on request
Gmail data
Metadata, body, and contacts and profile details
Until you disconnect Gmail or delete your account
Drive data
File metadata, document content read for you
Until you disconnect Drive or delete your account
Slack, Notion, Outlook, Linear, GitHub, Granola data
Content and metadata from connected workspaces and accounts
Until you disconnect the service or delete your account
When you delete your account. We begin deletion without undue delay. If you want a copy of your data first, tell us when you delete your account and we will hold it for up to 30 days so you can request one. See Section 7.
Where a row above says "delete your account," the same applies if we delete your account under Section 10 of the Terms of Service or after a period of inactivity.
If your account goes inactive. Before we delete anything for inactivity, we will tell you at least 30 days in advance by email. The notice includes a one-click option to keep your account active and instructions for requesting a copy of your data first.
When the law requires longer. Where applicable law requires us to keep certain records, such as transaction records for tax or consumer protection or security logs, we keep them for the period the law requires and delete them promptly afterwards. Country-specific periods are in the Appendix.
7. Deleting Your Data
We delete personal information from our live systems without undue delay once its retention period ends or the purpose for keeping it is met.
Backups. Encrypted backups may still contain copies for a limited period after deletion, until they expire on our documented backup cycle. Deleted data is not restored to live systems, and backup copies are subject to the same access rules as everything else in Section 4.4.
When you delete your account, deletion begins without undue delay. If you ask us to hold your data so you can request a copy first (see Section 11 of the Terms of Service), we keep it for up to 30 days, or until we have delivered the copy, and then delete it. Data held during that period stays subject to every protection in this Policy, including the access rules in Section 4.4.
How we delete. Electronic files are deleted using methods that make them unrecoverable from our live systems, subject to the backup cycle above. This includes data you delete yourself through rollback, exclusions, or account deletion.
8. AI Processing and Model Training
We don't use your personal data to train AI models, and we don't let our providers do it either.
·
We don't train, fine-tune, or evaluate any AI model, including our own, on your content.
·
Every AI provider processes your data under terms that prohibit using it to train models.
·
Your data is processed only to deliver Miller's features, subject to each provider's retention terms in Section 4.1.
·
Training exclusion options offered by AI APIs are enabled.
This applies to everything, including content reviewed internally. Content our staff review under Section 4.4, case 6, to diagnose a quality problem is not used to train, fine-tune, or evaluate any model. Human review to understand why an output was wrong is a different thing from training a model on your data, and we do not do the latter.
Improving Miller with your permission. If you explicitly agree, we may look at specific content you choose to share with us so we can diagnose a problem or improve how Miller works. This is always opt-in, limited to what you agree to share, and you can withdraw it at any time. Even then, we do not use that content to train, fine-tune, or evaluate any AI model.
Aggregated data. We use aggregated statistics to improve Miller, for example how often each feature is used, how often a request fails, and how long things take. These are counts and measurements, not your content, and we don't use them to train models.
9. Your Rights and Choices
You can:
·
See the personal information we hold about you
·
Correct information that's wrong
·
Delete your information, in whole or in part. Security and access logs, and the staff access records described in Section 6, are kept for a fixed period and can't be deleted on request
·
Get a copy of your information in a common, machine-readable format, by emailing contact@trymiller.com
·
Limit what we collect, using the exclusion and permission controls described in Section 2
·
Withdraw consent for any optional collection
How to ask. Email contact@trymiller.com or use in-app settings. We respond within the time applicable law requires, and in any event without undue delay.
If you're in the United States, additional state-law rights are in the Appendix.
10. Security
Independent assessments. As of the date at the top of this Policy, we have completed Google's Cloud Application Security Assessment (CASA) for the Google integrations described in Section 5, and Miller has been tested by an independent penetration testing firm. We are currently undergoing a SOC 2 Type II audit; the observation period is under way and the report has not yet been issued. Summaries of the completed assessments can be requested at contact@trymiller.com.
We protect your information with:
·
Encryption in transit and at rest, using industry-standard methods. Miller processes your data on our servers to provide its features, so encryption does not prevent that processing; who can see your data is governed by Section 4.4
·
Secure storage and access records
·
Industry-standard network protections
·
Access controls limiting who can see your data, as described in Section 4.4
Reporting a vulnerability. We welcome responsible security research. If you think you've found a vulnerability, email contact@trymiller.com. We'll acknowledge it and work with you in good faith.
If there's a breach. If a security breach results in unauthorized access to your personal information, we will tell affected users without undue delay after we discover it, and in any case within the time applicable law requires. Our notice will describe what happened, what data was involved, what we've done, and what you can do. We will also notify regulators where the law requires.
11. Analytics
We use Mixpanel to understand how Miller is used and improve it. It collects non-identifiable usage events and device information that are not linked to your account or your identity. Separately, we use Google Analytics on our marketing website to count visits and downloads; that is website analytics and is not connected to your Miller account.
What it never sees. Mixpanel observes interactions inside the Miller app only, such as which features you use and how you move through Miller's own screens. Screen text from your other applications, audio, transcripts, email content, and document content are never sent to it.
Your choice. Where the law requires consent, analytics stay off until you give it. You can opt out of analytics any time in app or device settings. Core features keep working.
12. Age Requirement
Miller is for adults. You must be 18 or older to use it, or older still where local law sets a higher age of majority (see Appendix). We don't knowingly collect personal information from anyone under 18, and if we find that we have, we delete it promptly.
We don't sell or share personal information about anyone, including anyone under 16, so no opt-in consent for sale or sharing is required or sought.
13. Changes to This Policy
We'll post any change to this Policy when it takes effect.
For material changes, we'll give at least 14 days' notice by in-app notification or email. Material changes include any change to the categories of information we collect, why we process it, who receives it (including a transfer under Section 18 of the Terms of Service), how long we keep it, or the removal or significant narrowing of a protection stated in this Policy.
If you keep using Miller after a change takes effect, that means you accept it. If you don't agree with a change, you can delete your account before it takes effect.
14. Contact Us
Everything, including privacy requests and security reports: contact@trymiller.com
If you're not a Miller user but believe your information was captured through someone else's use of Miller, please email contact@trymiller.com and we'll look into it and take appropriate action, consistent with the access rules in Section 4.4.
Mailing address: Memento AI Inc. 8 The Green, STE B #24308, Dover, DE 19901, USA
Appendix: Region-Specific Provisions
These provisions apply only to users in the places named. Where an Appendix provision conflicts with the main Policy, the Appendix controls for users in that place.
A. United States
The rights below apply to the extent a U.S. state privacy law, such as the California Consumer Privacy Act as amended, applies to our processing of your personal information.
·
Know and access the categories and specific pieces of personal information we've collected, the sources, purposes, and categories of recipients
·
Delete personal information, subject to legal exceptions
·
Correct inaccurate personal information
·
Opt out of sale or sharing. We don't sell personal information and don't share it for cross-context behavioral advertising
·
Non-discrimination for exercising these rights
Opt-out preference signals. Where the law requires us to recognize opt-out preference signals, we treat a Global Privacy Control (GPC) signal from your browser as a valid opt-out request for that browser. Because we don't sell or share personal information, honoring the signal doesn't change our practices, but we record and respect it.
To exercise these rights, email contact@trymiller.com or use in-app settings. We verify your identity before fulfilling requests and respond within the time the law requires.
You may also contact your state Attorney General or, where applicable, the California Privacy Protection Agency.
B. Republic of Korea
These provisions apply to users located in the Republic of Korea. For these users, this Policy is provided under Article 30 of the Personal Information Protection Act (PIPA). Memento AI Inc. is the personal information controller, and operational processing is performed by its Korean subsidiary.
Where PIPA requires disclosure, this Policy addresses it as follows:
PIPA Article 30 requirement
Where it appears
Purposes of processing
Section 3
Categories and items of personal information processed
Section 2
Retention and use periods
Section 6, and the table below
Provision to third parties
Sections 4.1, 4.2, 5.2
Outsourcing of processing
Section 4.1
Cross-border transfer
Section 4.1, and the cross-border transfer note below
Destruction procedures and methods
Section 7
Rights of data subjects and how to exercise them
Section 9
Security measures
Section 10, and the breach notification note below
Automatic collection tools
Section 11
Privacy officer and contact
Below
Remedies for infringement
Below
Changes to this Policy
Section 13
Statutory retention periods. Where Korean law requires retention:
Category
Period
Basis
Records on contracts or withdrawal of subscription
5 years
Act on Consumer Protection in Electronic Commerce
Records on consumer complaints or dispute resolution
3 years
Act on Consumer Protection in Electronic Commerce
Access logs
At least 3 months
Protection of Communications Secrets Act
Response time. Requests under Section 9 are answered within 10 days, subject to legal limitations.
Cross-border transfer. Your information is transferred to and processed by the providers listed in Section 4.1, in the countries stated there, for the purposes, items, and retention periods stated there. Transfers happen over encrypted network connections as part of running the Service. You can refuse this transfer by not using Miller or by deleting your account; because the transfer is necessary to run the Service, refusing means the Service cannot be provided. Questions about a transfer can be sent to contact@trymiller.com.
Internal review for product improvement. The access described in Section 4.4, case 6, is carried out under Article 15(3) of PIPA as processing reasonably related to the purpose for which we collected your information. Diagnosing why a transcript or summary came out wrong is part of providing the service you signed up for, not a new purpose. We disclose it in this Policy so it is foreseeable, we do not use it to make decisions about you or disclose it outside the people performing the review, and we apply the approval, minimum scope, logging, and purpose limitation controls in Section 4.4.
Breach notification. If a breach affects users in the Republic of Korea, we will notify affected users within 72 hours of becoming aware of it, and report to the Personal Information Protection Commission within the same period where Korean law requires such a report.
Consent to changes. For users in the Republic of Korea, continued use is not treated as consent to processing beyond the purposes described in this Policy. If we ever want to collect or use your information beyond those purposes, we will ask for your separate consent first.
Notice of changes. For users in the Republic of Korea, we give at least 7 days' notice before any change to this Policy takes effect, and at least 14 days' notice for material changes, by in-app notification or email.
Destruction. Personal information is destroyed without delay once the retention period ends or the purpose of processing is achieved, as described in Section 7. Where you have asked us to hold your data so you can request a copy, we destroy it once the copy has been delivered or the holding period ends, whichever comes first.
Minimum age. Users in the Republic of Korea must be at least 19, the age of majority under the Korean Civil Act.
Privacy officer. Jisan Kim, Chief Executive Officer and Chief Privacy Officer. Contact: contact@trymiller.com
Dispute resolution. In addition to contacting us, users in Korea may contact:
·
Korea Internet & Security Agency (KISA): 118
·
Personal Information Dispute Mediation Committee: 1833-6972
·
Supreme Prosecutors' Office Cyber Bureau: 1301
·
National Police Agency Cyber Bureau: 182
C. European Union and United Kingdom
Miller is not directed at residents of the European Union or the United Kingdom. We don't market or offer it there, and this Policy doesn't provide the disclosures those regions require. If you're in the EU or UK, please don't use Miller.
Change History
Date
Summary
December 1, 2025
First version (under the previous name M24)
April 29, 2026
Renamed M24 to Miller. Added Gmail and Google Drive integrations, Limited Use commitments, and access rules for staff.