| Account: email address, password (stored only as a salted PBKDF2 hash), verification status, account creation date. | To create and secure your account, sign you in, and send the emails the service needs (verification, password reset). | Contract |
| Your content: memories, tags, projects, skills, bundles, tasks, tables, artifacts, settings. | To provide the service: store it, make it searchable by meaning, return it to you and the AI tools you connect. | Contract |
| Credentials: API keys, recovery code material, session and sign-in tokens, authorisations you grant to AI clients over MCP. | To let you and your connected tools access your account. | Contract |
| Connections you choose: a Google Drive authorisation (limited to files Muninn creates) and, if you connect GitHub, the GitHub App installation identifier. | To mirror your data into storage you own, only if you connect it. | Contract |
| Teams and sharing: team names, members, the email address of someone you invite, your email shown in that invitation, and a public handle if you claim one. | To share memories with a team and publish pages under your handle. | Contract |
| Subscription and payments: plan, status, renewal date, the subscription, customer and transaction identifiers Paddle gives us, and a record of each payment event (amount, currency and outcome). We never receive your card details. | To give paid accounts their paid features. | Contract; legal obligation (accounting) |
| Technical data: IP address, request logs (time, address, path, status), browser type. | To keep the service running and secure: rate limits, abuse and fraud prevention, debugging. | Legitimate interests (keeping the service available and safe for all users) |
Website analytics on bizat.co: pages viewed, clicks and scrolling, device and approximate location. | To understand which pages are useful and improve the site. | Consent |
| Messages: emails you send us. | To answer you. | Legitimate interests (responding to people who contact us) |