1. Introduction
SeKondBrain AI Labs Limited (“we”, “us”, “our”) operates the Kora for Chrome extension and the Kemory memory service (together or separately, the “Service”). Kemory can also be used without the extension — from the Kemory dashboard, or by connecting your own AI tools and agents to it. This policy covers both products and both ways in, and supplements our master Privacy Policy, which applies to all SeKondBrain services; if they conflict in respect of the extension or Kemory, this policy prevails.
Kora captures your own AI chat conversations — on the AI platforms you choose to enable — into a private, searchable memory that you can browse, continue and synchronise to your own Kemory account.
We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. By installing the extension or using the Service, you acknowledge the practices described in this policy. This acknowledgment does not itself constitute consent; where we rely on consent as a legal basis, we obtain it separately, as noted below.
2. Data controller
The data controller is SeKondBrain AI Labs Limited, Company No. 16806279, registered office 2 Peel Court, 24 St. Cuthberts Way, Darlington, England DL1 1GB. Email: privacy@sekondbrain.ai. Website: https://www.sekondbrain.ai. ICO registration: applied for; registration number will be added here once issued. We have not appointed a statutory Data Protection Officer.
Self-hosted Kemory: if you configure Kora to synchronise to a Kemory instance you host yourself, you (or your organisation) are the data controller for the data held on that instance; we act only as the provider of the software.
3. Information we collect
3.1 Account information
When you sign in with your SeKondBrain account we collect your email address and account identifier for identification and service communications. Sign-in happens on SeKondBrain’s own secure pages using OAuth 2.0 with PKCE; your password is never entered into, transmitted through, or stored by the extension.
Signing in to Kora is signing in to Kemory — there is no separate Kora account. On sign-in the extension automatically creates a device-scoped Kemory API key for this browser install (section 3.3), which synchronises your conversations to your Kemory. Signing in is optional for local capture: without an account, conversations are captured to your browser only and nothing is sent to our servers.
3.2 AI conversation content
The extension reads your own conversations on the AI platforms you have enabled, as they are visible in your browser: conversation text (your prompts and the AI’s replies as shown on screen); conversation metadata (title, URL/identifier, source platform); timestamps; and attachments and artefacts exchanged in the conversation — including files you upload to the platform and images generated or shared in the chat — captured as the files themselves, subject to a per-file size cap (currently 5 MB), together with their names, types and sizes.
Scope of collection: Kora only reads conversations on the supported AI platforms — ChatGPT, Claude, Gemini, Perplexity and Manus — and only on the platforms you have switched on. Each platform can be disabled individually. Kora does not access private messages on other sites, content on any other website, or data from platforms you have disabled. History import starts only when you initiate it; once started, it continues and resumes automatically in the background — including after interruptions or platform rate limits — until your history is complete, shows a visible progress banner while running, and can be stopped in Settings.
Prompt enrichment (“Enhance with Kora”): while you compose a prompt on an enabled platform, the extension may send your in-progress draft text to your connected Kemory as a search query, to find your own relevant memories and offer them as context. Draft text is used only to search; it is not stored as a conversation or memory by this feature, and it is sent nowhere other than your connected Kemory. This stops entirely when you turn cross-AI recall off in Settings, and never runs on platforms you have disabled.
Derived memory data: after your conversations synchronise, Kemory automatically derives further records so that recall works: extracted memories (short facts and preferences found in your chats), compressed summaries of related memories and of each namespace, and numeric search representations (embeddings). Derived records are part of your Kemory data and are covered by the same access controls, retention and deletion rules as the content they came from (sections 6 and 10).
3.3 Extension data stored locally
- Captured conversations (local database in your browser);
- Authentication tokens (OAuth) for maintaining your session;
- A per-install Kemory API key, scoped to this browser installation and revocable per device;
- An installation identifier (random UUID) and a device label used to label this install in your Kemory devices list;
- Your preferences: enabled platforms, sync settings, theme, endpoint configuration, onboarding state.
This data remains on your device and is not transmitted to our servers except as described in sections 5 and 7.
3.4 Product telemetry and service records
While signed in, the extension sends us feature-usage events — for example “a conversation was captured on platform X”, counts, durations and error types — to help us understand usage and fix failures. Telemetry events never include conversation content. Your Kemory additionally keeps server-side records needed to operate the service: access and error logs (retention in section 10) and an audit trail of account, agent and API-key actions. These records describe actions, never conversation or memory content.
3.5 Information we do not collect
Kora does not collect or access: browsing history, bookmarks or download history; saved passwords, autofill data or payment information; content on any website other than the supported AI platforms you have enabled; device hardware identifiers or precise geolocation; or cookies set by third-party websites.
4. Legal bases for processing
Under Article 6 UK GDPR we process personal data on the following bases:
- Performance of a contract (Art. 6(1)(b)): capturing, storing, searching and syncing your conversations — the core function of the Service; account sign-in and session management; generating responses when you use Continue or Ask; device management (issuing and revoking per-install keys as part of the service).
- Legitimate interest (Art. 6(1)(f)): security monitoring and abuse prevention; product telemetry and service improvement; service communications such as security alerts.
Legitimate interest assessments. Product telemetry: our interest is understanding which features are used and where they fail; events are feature-level and never contain conversation content; the privacy impact is minimal and proportionate. Security monitoring and abuse prevention: our interest is detecting and preventing misuse, unauthorised access and security threats; per-install keys and device revocation allow us to limit abuse to a single installation without affecting other users; the privacy impact is limited to device-level identifiers and is proportionate to the security benefit. You may object to processing based on legitimate interest at any time (section 11).
5. How we use your information
We use the information we collect to: provide the Service (capture, organise, search and display your AI conversations in the Kora side panel); synchronise your memory to the Kemory you connect so it is available wherever you sign in; authenticate you and maintain a secure session; power Continue and Ask by processing the conversation context you select through AI models at your request; improve the Service using feature-level telemetry (never conversation content); and send service-related notifications.
6. Automated processing and AI
The Service uses AI in two ways: at your request (Continue, Ask, prompt enrichment) and automatically in the background, to organise the memory you have chosen to sync.
At your request — when you use Continue or Ask, the relevant conversation context is sent to the SeKondBrain AI backend, which processes it through a large language model to generate the response you asked for.
Automatically, on your synced memory — once conversations reach your Kemory, background processing organises them so recall works: extracting memories, grouping and compressing related memories into summaries, generating a summary per namespace, computing search embeddings, and suggesting which namespace a chat belongs to. Parts of this pipeline use an LLM. This processing runs only on content you have chosen to sync, serves no purpose other than organising your own memory, and its outputs (section 3.2) are visible and deletable in your Kemory dashboard. It does not profile you for advertising or make any decision about you. Prompt enrichment is different: it sends your draft only to your connected Kemory to retrieve your own context, and does not send your draft to the AI backend.
AI-generated responses are informational only and are not used to make decisions that produce legal or similarly significant effects on any individual. AI models may produce inaccurate or incomplete outputs; review AI-generated content before acting on it. You may object to automated processing or request human review by contacting privacy@sekondbrain.ai. We conduct Data Protection Impact Assessments for our AI processing activities and review them periodically.
We do not use your conversations or memories to train our models. Content processed by our inference providers is used solely to generate your requested output. Our sub-processors, including the categories of inference providers we use, are listed at docs.sekondbrain.ai/subprocessors.
7. Data storage and security
7.1 Local storage. Captured conversations, tokens, keys and preferences are stored locally via the browser’s storage APIs. Local data is removed when you delete conversations, sign out (sign-in-created keys) or uninstall the extension.
7.2 Server-side storage (your Kemory). When you connect a SeKondBrain-hosted Kemory, your conversations synchronise to our infrastructure on Google Cloud — Switzerland for customers in the rest of the world, India for customers in India (section 9). You may additionally opt in to content encryption at rest: your conversation and memory content is encrypted with AES-256-GCM envelope encryption, using data-encryption keys unique to your account, wrapped by a root key held in a cloud key-management service. Enabling encryption is permanent for your account. Encrypted content is decrypted only transiently, in memory, to serve your own requests and the background organisation described in section 6. When your account is deleted, your keys are destroyed, rendering any residual encrypted content permanently unreadable. If you connect a self-hosted Kemory, your data goes to your server, not ours; you are responsible for that instance’s security and compliance.
7.3 Security measures. All communication between the extension and our services uses HTTPS/TLS. Sign-in uses OAuth 2.0 with PKCE on our own pages. Kemory access uses a per-install API key, scoped to one browser installation, revocable per device from the dashboard, and deleted from the browser when you disconnect or sign out. Access to production systems is restricted to authorised personnel on a need-to-know basis.
7.4 Data breaches. Where a breach is notifiable we will notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware (Article 33), and where it is likely to result in a high risk to your rights and freedoms we will notify you directly without undue delay (Article 34).
8. Data sharing and recipients
We do not sell, rent or trade your personal data. We share it only with: AI inference providers (listed at docs.sekondbrain.ai/subprocessors) to generate responses when you use Continue or Ask, with content transmitted solely to generate your requested output; infrastructure providers (Google Cloud — Switzerland and India, section 9) to store and serve your Kemory data and backend services; law enforcement or regulators where required by law and only to the extent legally required; and a successor entity in a merger or acquisition, with equivalent privacy protections maintained and notice to you.
AI tools you connect to your Kemory. Kemory is designed to be one memory shared across your AI tools. When you connect another agent — for example an assistant via MCP, or any tool holding an API key you created — that tool can search and read the memory content your permissions allow, including conversations Kora captured, and content it retrieves is processed by that tool’s AI provider as part of your session with it. You stay in control: each agent gets its own key, permissions are default-deny until granted, and you can revoke any agent from the dashboard at any time.
Organisation and team sharing. If you join a Kemory organisation and share a namespace with teammates, content in that namespace becomes readable by the members authorised by you or your organisation’s admin.
A self-hosted Kemory involves no sharing with us at all: conversation data flows from your browser to your own server.
9. International data transfers
Your personal data is stored on Google Cloud infrastructure in Switzerland (customers in the rest of the world) or India (customers in India). Transfers to Switzerland are covered by UK adequacy regulations. Transfers to India, and any other transfer to a country without UK adequacy (including processing by inference providers in other jurisdictions), are made under the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, with supplementary measures where appropriate. You may request a copy of the relevant safeguards at privacy@sekondbrain.ai.
10. Data retention
We retain personal data only as long as necessary for the purposes collected or as required by law: account data — life of the account plus 30 days after a deletion request; conversations in your hosted Kemory — until you delete them or close your account (deleting a conversation in Kora deletes it from your connected Kemory); local browser data — under your control; product telemetry — 12 months, then deleted or irreversibly aggregated; server access and error logs — 90 days. Records may be kept longer where required by law. Memories and derived data follow the same rule as the content they were derived from: kept until you delete them or close your account — and, if you enabled encryption, account deletion destroys your keys (section 7.2). Data reaching the end of retention is securely deleted or irreversibly anonymised.
11. Your rights under UK GDPR
You may exercise the following rights free of charge by contacting privacy@sekondbrain.ai; we respond within one month, extendable by two further months for complex requests, in which case we will tell you. Most of these you can also exercise directly in the product — view, search, export and delete conversations; disconnect Kemory; sign out.
- Access (Art. 15); rectification (Art. 16); erasure (Art. 17), subject to legal retention; restriction (Art. 18); portability (Art. 20); objection to legitimate-interest processing, including telemetry (Art. 21); human review of solely automated decisions (Art. 22); and withdrawal of consent at any time without affecting prior lawful processing (Art. 7(3)).
You may complain to the Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF · ico.org.uk · 0303 123 1113. We would appreciate the chance to address your concern first.
12. Third-party services
The Kora extension does not integrate third-party analytics, advertising or tracking services. The only network requests the extension makes are to our own backend services (*.apps.s9n.ai), to the AI platforms you are actively using, to your configured Kemory endpoint, and — when you use Continue or Ask — to the AI model provider(s) named in section 8. (Our websites are covered by the master Privacy Policy and Cookie Policy.)
13. Browser permissions
The extension requests the following permissions, each for a specific, limited purpose:
- storage — persist captured conversations, settings and connection state locally;
- tabs — detect which supported AI platform a tab is on (to badge capture state) and open/manage AI-platform tabs only for features you invoke, such as history import; never used to read general browsing activity;
- tabGroups — organise history-import tabs into a labelled group;
- alarms — schedule periodic background sync to your connected Kemory;
- sidePanel — Kora’s main interface lives in the browser side panel;
- activeTab / scripting — inject the capture script and setup overlay only on supported AI platforms you have enabled;
- identity — “Sign in with SeKondBrain” via the browser’s secure sign-in flow; no credentials pass through the extension;
- host permissions (AI platforms) — read your own conversations on ChatGPT, Claude, Gemini, Perplexity and Manus; each can be disabled individually;
- host permissions (
*.apps.s9n.ai) — communicate with your SeKondBrain account and Kemory services; - host permissions (localhost) — support self-hosted local Kemory instances;
- optional host permissions — never requested at install; the permission dialog appears at runtime only when you configure a custom self-hosted Kemory URL, and access is granted to that single origin alone.
14. History import
When you start a history import, the extension opens temporary tabs within your signed-in session to load your past conversations on the platforms you selected, paging through them at a deliberately limited rate and pausing and retrying when a platform applies rate limits. These tabs are placed in a separate labelled tab group and closed when the import completes.
Once you have started an import, it continues and resumes automatically in the background until your history is complete; a progress banner is shown while it runs and you can stop it at any time in Settings. If a platform signs you out mid-import, the import pauses and resumes after you sign back in. Only your conversation content on those platforms is read; no other browsing data is accessed. An import never begins without you initiating it.
15. Children’s privacy
The Service is not directed at, and not intended for use by, anyone under 18, consistent with our Terms of Service. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact privacy@sekondbrain.ai and we will promptly delete it.
16. Changes to this policy
We may update this policy to reflect changes in our practices or the law. For material changes we will update the date above and notify you via the extension or by email where appropriate. Continued use after changes are posted constitutes acceptance, except where further consent is required by law.
17. Contact
SeKondBrain AI Labs Limited · privacy@sekondbrain.ai · 2 Peel Court, 24 St. Cuthberts Way, Darlington, England DL1 1GB · https://www.sekondbrain.ai.