Guide · 5 min read

AI memory privacy checklist

A checklist for storing what users tell an AI agent: purpose, consent, isolation between users, deletion, sensitive data and defence against memory poisoning.

Memory means keeping what people tell a machine. That brings duties a stateless chatbot does not have. This is general information, not legal advice; use it to prepare the conversation with whoever advises you.

Before you store anything

  • Purpose. You can state in one sentence why the product remembers, and the memory definition matches it.
  • Notice. Users are told that the agent remembers, in plain words, before it starts.
  • Choice. Memory can be switched off, and there is a way to have a conversation that is not remembered.
  • Minimum. The extractor keeps only what the purpose needs.

Isolation

  • Every read and write is filtered by user or tenant in the query itself, not afterwards in application code.
  • Shared memories (team, account) inherit the permissions of the system they came from.
  • There is a test that tries to recall user A’s memory as user B, and it runs on every release.

What must never be stored

  • Passwords, card numbers, one-time codes, API keys. Filter them before extraction.
  • Sensitive categories, such as health, religion or sexual orientation, unless the product needs them, the user has clearly agreed and you have taken advice.
  • Inferences about a person. Store statements, not guesses.

Control for the user

  • A page that shows what is remembered, in readable form.
  • Edit and delete for a single memory.
  • Delete everything, and export everything.
  • “Forget that” in conversation works and is confirmed.

Deletion that is real

  • Deleting a note also removes its embedding and anything summarised from it.
  • Backups and logs holding memories have a stated lifetime.
  • Memories are not used to train models unless the user has agreed to that separately.

Security

  • Encrypted in transit and at rest.
  • Poisoning. Text from web pages, files and tool results is not written to memory as if the user had said it. Record the source of every memory.
  • Injection on recall. Recalled memories are placed in the prompt as data, clearly marked, and the model is told not to follow instructions found inside them.
  • Access by staff is logged.

A quick test

Ask someone outside the team to read their own memory page. If anything there surprises or unsettles them, the rules for what to keep are too loose.

Quick answers

Is AI agent memory personal data?

Usually yes. Facts about an identifiable person are personal data under laws such as GDPR, wherever they are stored. Take legal advice for the countries you operate in.

How do I delete a memory completely?

Remove the note, its embedding, any summary derived from it and any cached prompt that contains it, and make sure backups expire on a stated schedule.

What is memory poisoning?

An attack in which text from a web page, document or message tricks an agent into saving a false or harmful instruction as a memory, which then affects later sessions.

Read next

Pack the doko. Ask it anything.

Nine memories, one question, no account. See which facts an agent would carry into its next answer.