Guide · 5 min read
AI memory privacy checklist
A checklist for storing what users tell an AI agent: purpose, consent, isolation between users, deletion, sensitive data and defence against memory poisoning.
Memory means keeping what people tell a machine. That brings duties a stateless chatbot does not have. This is general information, not legal advice; use it to prepare the conversation with whoever advises you.
Before you store anything
- Purpose. You can state in one sentence why the product remembers, and the memory definition matches it.
- Notice. Users are told that the agent remembers, in plain words, before it starts.
- Choice. Memory can be switched off, and there is a way to have a conversation that is not remembered.
- Minimum. The extractor keeps only what the purpose needs.
Isolation
- Every read and write is filtered by user or tenant in the query itself, not afterwards in application code.
- Shared memories (team, account) inherit the permissions of the system they came from.
- There is a test that tries to recall user A’s memory as user B, and it runs on every release.
What must never be stored
- Passwords, card numbers, one-time codes, API keys. Filter them before extraction.
- Sensitive categories, such as health, religion or sexual orientation, unless the product needs them, the user has clearly agreed and you have taken advice.
- Inferences about a person. Store statements, not guesses.
Control for the user
- A page that shows what is remembered, in readable form.
- Edit and delete for a single memory.
- Delete everything, and export everything.
- “Forget that” in conversation works and is confirmed.
Deletion that is real
- Deleting a note also removes its embedding and anything summarised from it.
- Backups and logs holding memories have a stated lifetime.
- Memories are not used to train models unless the user has agreed to that separately.
Security
- Encrypted in transit and at rest.
- Poisoning. Text from web pages, files and tool results is not written to memory as if the user had said it. Record the source of every memory.
- Injection on recall. Recalled memories are placed in the prompt as data, clearly marked, and the model is told not to follow instructions found inside them.
- Access by staff is logged.
A quick test
Ask someone outside the team to read their own memory page. If anything there surprises or unsettles them, the rules for what to keep are too loose.