Unibase
    • Memory
    • BitAgent
    • UB Bridge
    • Membase
    • AIP
    • Unibase Pay
    • Unibase DA
    • Explorer
    • Docs
    • GitHub
    • Twitter
    • Telegram
    • Unibase Dev Group
Unibase

© 2026 Unibase

Products
MemoryBitAgentUB Bridge
Developer
MembaseAIPUnibase PayUnibase DAExplorerDocs
Community
GitHubTwitterTelegramUnibase Dev Group
Home/Products/Unibase Memory/Privacy Policy

Privacy Policy

Unibase Memory (Chrome Extension)

Last updated: June 11, 2026

Unibase Memory captures your ChatGPT and Claude conversations into a single, private, searchable memory. Your conversations stay in your browser by default, and anything you sync leaves your device only as ciphertext encrypted with a key only you hold. We collect a limited amount of anonymous usage data to improve the product — never your conversation content.

On this page

  1. 1. Who this policy covers
  2. 2. What the extension handles
  3. 3. Optional encrypted sync
  4. 4. On-device AI tagging
  5. 5. Usage analytics
  6. 6. What we do NOT do
  7. 7. Third-party services
  8. 8. Your controls
  9. 9. Children
  10. 10. Changes
  11. 11. Contact

1. Who this policy covers

This policy applies to the "Unibase Memory" Chrome extension (the "Extension") published by Unibase. It does not cover third-party websites you visit (such as ChatGPT or Claude), which are governed by their own policies.

2. What the extension handles, and where it lives

Stored locally on your device (always)

  • Conversation content — the text of the ChatGPT and Claude chats you view or import, read from the page as it is rendered, plus titles and timestamps.
  • Your organization data — tags, stars, highlights, saved snippets, and settings.

This data is stored in your browser's local storage (IndexedDB and chrome.storage.local) on your own device. By default it is never transmitted anywhere.

Account & encryption material (only if you sign in)

  • Email address — if you sign in with Google, X, or email via our authentication provider, your email may be stored locally to show which account is active.
  • Wallet address — the public address of the wallet used to derive your encryption key.
  • Wallet signature— a one-time signature over a fixed, app-specific message. It is hashed on your device into an encryption key. The signature is cached locally so you don't have to sign again on every use. It is not a session token and cannot be used to act as your wallet elsewhere.

3. Optional encrypted sync

Sync is off by default. If you turn it on:

  • Your conversations are encrypted on your device (Fernet: AES-128-CBC + HMAC-SHA256) using a key derived from your wallet signature.
  • Only the resulting ciphertext is uploaded to Membase, Unibase's decentralized storage layer, stored under your own wallet address.
  • The encryption key never leaves your browser. There is no key escrow and no copy of your key on any server. Membase and the Unibase Explorer only ever see encrypted blobs — never your plaintext conversations.
  • Signing in with the same identity on another device re-derives the same key, so your data decrypts locally there. Same wallet, same key, your data.

4. Optional on-device AI tagging

You may optionally enable AI tag suggestions. The model runs entirely locally inside your browser. On first use, the extension downloads the model weights (data files) from Hugging Face and caches them in the browser. Your conversation text is never sent to any server for tagging — all inference happens on your device.

5. Usage analytics

To understand how the Extension is used and improve it, we collect a limited amount of anonymous product-usage data through Google Analytics 4 (sent directly to Google's Measurement Protocol endpoint; no third-party tracking scripts are loaded).

What we collect

  • Feature-usage events — for example, that the side panel was opened, a sync ran, or sign-in completed, along with basic session information (session start/duration).
  • A random installation identifier — a per-install UUID generated on your device to distinguish sessions and approximate active-user counts. It is not your name, email, or wallet address.
  • Google may additionally process standard technical data such as approximate location (derived from IP address) and device/browser type, per Google Analytics' own handling.

What we do NOT collect through analytics

  • We never send your conversation content, titles, tags, highlights, email, wallet address, wallet signature, or any backup data to analytics.
  • Analytics events describe that a feature was used, never what was in your conversations.

This usage data is used solely to measure adoption and improve the Extension. See Google's Analytics privacy information for how Google processes it.

6. What we do NOT do

  • We do not sell your data, and we do not transfer your data to third parties except the service providers listed in Section 7, acting on our behalf.
  • We do not use or transfer your data for purposes unrelated to the extension's single purpose.
  • We do not use your data to determine creditworthiness or for lending purposes.
  • We do not send your conversation content, or any backup data, to analytics or any advertising service. We do not show ads.

7. Third-party services

  • Privy — handles sign-in (Google / X / email / wallet) and wallet provisioning. Subject to Privy's privacy policy.
  • Membase / Unibase — decentralized storage that holds your end-to-end-encrypted backups (ciphertext only). Encrypted entries can be viewed by you on the Unibase Explorer.
  • Hugging Face — serves the on-device AI model weights (data files) when you enable AI tagging. No conversation content is sent there.
  • Google Analytics — receives the anonymous product-usage events described in Section 5. No conversation content or account identifiers are sent.

8. Data retention and your controls

Export

Download a full JSON copy of your data at any time.

Delete

Remove conversations, tags, or highlights. Uninstalling clears all local data, including the analytics installation identifier.

Disable sync

Turn sync off so nothing leaves your device.

Sign out

Clears the cached signature and derived key from your browser.

Encrypted backups already uploaded to Membase remain associated with your wallet address until removed; because they are decentralized-storage entries, contact us if you need help managing them.

9. Children

Unibase Memory is not directed to children under 13 (or the minimum age in your jurisdiction) and we do not knowingly collect their data.

10. Changes to this policy

We may update this policy as the extension evolves. Material changes will be reflected here with a new "Last updated" date at https://www.unibase.com/memory/privacy.

11. Contact

Questions about this policy or your data? Contact us at support@unibase.com or visit www.unibase.com.

Unibase Memory keeps your conversations local by default, end-to-end encrypts anything you choose to sync, and collects only anonymous usage data to improve the product. You own your memory.