Skip to content

Privacy

Privacy policy

Last updated:

This policy covers three things: the website totalmemory.dev, the open-source software total-agent-memory (TAM), and paid services such as pilots and support. The controller for the website and the services is Vitalii Cherepanov. Questions: vitalii@vbcherepanov.com.

1. The website

Cookies, analytics and tracking

Requests to other services

Without your consent, pages on this site make no requests to other services: everything your browser loads comes from totalmemory.dev. If you accept analytics, your browser also loads Google Analytics from googletagmanager.com and sends events to google-analytics.com. The GitHub star count in the header is fetched once when the site is built, not by your browser, and the Product Hunt badge is a copy stored on this site.

Links to other sites (GitHub, npm, PyPI, X, PayPal, Product Hunt and others) only contact those sites if you click them.

Server logs

The web server (nginx) writes a standard access log. For each request it records the IP address, the time, the requested URL and method, the response status and size, the referring page and the browser's user agent. Errors are written to an error log. These logs are used to run the site and investigate problems, not to profile visitors. No retention period is configured in the site's code; logs are kept according to the hosting server's log rotation. The site sits behind a reverse proxy (Traefik) whose logging is configured on the host, not in the site's code.

Email

Contact links on the site open your own email program. If you write, your message and email address are kept in the mailbox so the conversation can be answered and continued. They are not added to any mailing list and not shared.

2. The software

TAM is local-first. There is no account and no telemetry. All memory is stored on the user's own machine (by default in ~/.tam) or, for the team server, on a server the company runs itself. The author receives none of it.

The software makes outbound connections only in these cases:

The repository also contains optional scripts that are never started by any installer or by the server, and that you would have to run and configure yourself (for example a Telegram digest and web-search helpers). They are not part of normal use.

The team server

The team server is installed and operated by the company that uses it. That company is the controller of the data stored on it and decides who has access, which model providers are used and how long data is kept. The author has no access to it. The team dashboard loads all of its scripts and styles from the company's own server.

3. Pilots and support

When a customer buys a pilot, installation or support, work is done remotely. Access to the customer's systems and data happens only as agreed in the statement of work or data processing agreement for that engagement, and only for that engagement. Customer data is never copied for other purposes, never used to train or benchmark anything, and never shared.

4. Legal basis, processors and your rights

Legal basis. Website analytics runs on your consent (GDPR Art. 6(1)(a) and Art. 5(3) of the ePrivacy Directive, and the equivalent rules of UK GDPR, the Swiss FADP and the Serbian Law on Personal Data Protection). Server logs rely on legitimate interest in running and securing the site (Art. 6(1)(f)). You can withdraw consent at any time; this does not affect earlier processing.

Processors and transfers. Analytics is processed by Google Ireland Limited for visitors from the EEA, the UK and Switzerland and by Google LLC elsewhere, under Google's data processing terms. Data may be transferred to the USA; Google LLC is certified under the EU–US Data Privacy Framework and its UK and Swiss extensions and also relies on Standard Contractual Clauses. Analytics event data is kept for 14 months at most.

EEA, UK, Switzerland, Serbia: you can ask for access, rectification, erasure, restriction, portability, object to processing, withdraw consent and complain to your data protection authority (in Serbia: the Commissioner for Information of Public Importance and Personal Data Protection).

US states (California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon and others): you can know, access, correct and delete your personal information and opt out of its sale, sharing for cross-context behavioural advertising and targeted advertising. We do not sell or share personal information and do not use it for targeted advertising. Global Privacy Control is honoured as an opt-out. We do not process sensitive personal information and do not discriminate against anyone for using these rights; an authorised agent may act for you.

Other countries (Canada, Brazil, Australia, Japan, South Korea, India and others): comparable rights of access, correction, deletion and withdrawal of consent apply.

To use any right, or to ask what data about you is held (for example an email conversation), write to vitalii@vbcherepanov.com. The controller is Vitalii Cherepanov. Requests are answered within 30 days, or sooner where your law requires.

5. Changes to this policy

If this policy changes, the new version is published on this page with a new "Last updated" date.