Aegis

Privacy policy

Privacy Policy · last updated 2026-10-06

Privacy Policy

Effective 6 October 2026

Aegis checks whether your email addresses and passwords have turned up in known data breaches, and tells you what to do about it. Aegis is operated by Memriq Holdings, Inc. ("Memriq", "we"), which is the controller of the personal information described here.

What Aegis keeps

  • Your account — your name and email address, and a password or your Google sign-in. One Memriq account signs you in to every Memriq service; being let in to Aegis is decided separately, by invitation.
  • The email addresses you check — your sign-in address, and any other address you showed is yours by opening the link Aegis sent to it. Aegis never checks an address you have not shown you own.
  • Your checks — what each check looked at and what it found: the breaches an address appeared in, or how many times a password has been seen in breaches.
  • Your settings — how much Aegis does on its own, and which addresses you asked it to keep watching.
  • Support conversations — what you write to Aegis's support chat.

Your passwords are never kept

When you check a password, Aegis scrambles it and sends only the first five characters of the scrambled form to the breach service, with padding so the request reveals nothing. The password itself is never stored, logged, sent anywhere or shown back to you.

How it is protected

Everything Aegis stores about you is encrypted under your own account, including every address you check and every result. The address is also kept as a one-way keyed fingerprint so Aegis can find it again, which cannot be turned back into the address. Only random record identifiers, timestamps and whether an address is being watched are stored unencrypted, so someone who obtained Aegis's stored data without your account's key could not tell who any of it belongs to.

What Aegis never does

Aegis never signs in to, changes, recovers or closes any of your accounts, never asks you for a password in chat, and never contacts a site, a bank or anyone else for you. It gives you the steps, most urgent first, and you do them. How much Aegis does on its own is your setting, and Aegis tells you what a setting allows before you choose it.

We do not sell or share your personal information, and have not in the past twelve months.

Where your information goes outside Aegis

  • Have I Been Pwned — when you check an email address, Aegis sends that address to Have I Been Pwned to look it up; when you check a password, only the first five characters of its scrambled form. Until Aegis's email check is connected, it says so and sends nothing.
  • Helm — if you ask Aegis to keep watching an address, a weekly reminder to re-check it is written into your Helm account.
  • Billing — Memriq's billing service sees only your account id and which Aegis feature was used.
  • AI models — the steps Aegis shows you are written with the help of a language model. It reads a breach's public facts, or the name of an account and the problem you describe — never your email address or a password.

Services that process it for us

  • Railway — runs Aegis's servers.
  • MongoDB Atlas — stores Aegis's records, encrypted as described above, in the United States.
  • Have I Been Pwned — the breach data Aegis checks against.
  • OpenAI — the language model Aegis uses to write the steps to fix a breach or protect an account.
  • Resend — delivers the emails Memriq sends you, through Memriq's one sender: the link that confirms an address is yours, and an alert when a watched address appears in a new breach.
  • Google — signs you in, if you choose Google.

How long it is kept

Aegis keeps your addresses, checks and settings until you delete them. Your account and everything Aegis holds for you are deleted within 30 days of your account closing. Support messages are kept for 2 years, server logs for 90 days, and billing records, if you ever have any, for 7 years. Backups can hold deleted data for up to 35 days before it is gone from them too.

Removing an address, deleting it, or getting a copy

You can remove an address you added, or stop watching one, from Aegis's Check my exposure page at any time. Closing your Memriq account, getting a copy of what we hold, or correcting it: write to privacy@memriq.ai, or ask Aegis's support chat to pass you to a person — we acknowledge within 5 business days and finish within 30 days.

If you are in the EU or UK

We rely on the contract with you to run Aegis, on our legitimate interests to keep it working and secure, and on your consent for anything else. Your information is processed in the United States under Standard Contractual Clauses. You may complain to your local data protection authority.

Changes and contact

If this policy changes, the new version is published here with its date before it takes effect. Privacy questions: privacy@memriq.ai. Anything else: hi@memriq.ai.