Privacy
Browser-first does not mean nobody sees the request.
Memoir normally sends a queried public address from the user's browser directly to the public sources needed for that investigation. This avoids pooling routine address lookups behind a Memoir data server, but each contacted provider can still observe the address, public IP, request metadata, and timing.
Who receives an investigated address?
| Recipient | Normal behavior | Boundary |
|---|---|---|
| Cloudflare Pages | Serves Memoir's public site and workspace shell. | Like an ordinary web host, it can process the public IP, requested URL—including an address in an /address/0x… path—browser and network metadata, timing, and security signals. Memoir does not install third-party product analytics on address pages. |
| Public history and intelligence sources | The browser requests admitted source endpoints directly. | Those services can observe normal network metadata and the address included in their request. |
| Memoir server | Does not receive routine browser-direct address history. | An optional deployment can expose a history fallback; the address is sent to it only after the user explicitly chooses that fallback. |
| OpenSanctions | No per-address runtime request. A compact dated EVM subset ships with the app and is matched locally. | The browser downloads the static dataset from the Memoir origin; freshness and separate data licensing still apply. |
| User-selected AI provider | Receives the selected evidence, address, limitations, credential, and normal request metadata directly from the browser. | The provider's own retention, training, and privacy terms apply. |
What stays on this device?
- Reports are stored in this site's IndexedDB, including the result, selected evidence snapshot, signals, and contemporaneous limitations.
- Address observations keep bounded current-state checkpoints for comparison; they are not continuous tracking.
- AI configuration and credentials are stored in this origin's localStorage until the user chooses Forget key or clears site data.
- Downloaded dossiers and PDFs are created for the user; Memoir does not upload them to a document service.
Scripts running on the same origin can read localStorage. Clear credentials before using Memoir on a shared or untrusted device.
What Memoir does not ask for
Rate limits and shared networks
Browser-direct requests reduce centralized Memoir quota pressure, but rate limits are often applied to a public IP. People on the same NAT, corporate network, VPN, or relay may still share an upstream quota. Memoir coordinates requests across its tabs and reports rate limits or source failures instead of translating them into a clear result.
Public addresses and sensitive conclusions
Blockchain records are public, but analysis can still affect privacy and reputation. Memoir does not infer sensitive personal traits, physical location, criminal intent, or a verified real-world identity from behavioral resemblance. Public labels retain their source and uncertainty.
See methodology for the attribution rules and sources for provider-specific disclosure.