Meko Connector and Skills Privacy Policy

Last Updated: August 13, 2026

This Privacy Policy explains what data the Meko MCP connector, the skills, and the Claude plugin distributed in the meko-skills repository (“the Connector”) collect, how that data is used and stored, when it is shared, how long it is retained, and how to contact us. It is published by YugabyteDB, Inc. (“Yugabyte”, “we”, “us”), the maker of Meko.

This policy covers data sent through the Connector to the hosted Meko service at https://mcp.mekodata.ai/mcp. It supplements the Yugabyte Privacy Notice, which governs our websites, marketing, and account relationships but does not cover content you store in Meko through the Connector. Where you use Meko under a commercial agreement with Yugabyte, that agreement controls if it conflicts with this policy.

What the Connector does

Meko is a memory, knowledge, and observability layer for AI agents. The Connector exists to store data you choose to persist: memories, conversation history, shared knowledge, and usage traces. Storing your data, at your direction, is the product — not a side effect.

Data collection

Account and authentication data. Connecting to the hosted Meko service requires a Meko account. The Connector leverages OAuth 2.0 for authentication; usernames and passwords are not collected for authentication purposes. We associate stored content with your Meko user ID, the calling agent’s identifier (agent_id), and the active workspace (datapack_id).

Content you or your agent store. Meko stores what is explicitly sent to it through MCP tool calls, including memories (memory_add), conversation turns — user prompts, assistant responses, and reasoning or tool-call summaries — posted via conversation_add_message, artifacts, and knowledge-base documents uploaded through the Meko Cloud UI. When the optional Claude Code plugin hooks are installed, session lifecycle events (SessionStart, PreCompact, SessionEnd, and a periodic checkpoint) automatically capture conversation turns and send them to Meko. The Meko service extracts durable memories from captured user turns.

In addition to the content described above, captured turns and tool calls may include limited operational metadata necessary to provide the Meko service: working directory, git branch, session ID, timestamps, conversation and datapack identifiers, and token-usage counts. This metadata is collected solely to power the observability, auditing, and tracing features you access in your Meko Cloud account and is not collected for background logging or any purpose unrelated to the service.

What we do not collect. The Connector only transmits data needed to perform the tool call you or your agent invoked. It does not read your files, browsing history, or other applications, and does not capture conversation content outside the turns explicitly posted to it. The Connector does not query or extract data from Claude’s memory, chat history, conversation summaries, or user-generated or uploaded files.

Choosing not to capture. Automatic capture requires installing the plugin hooks. If you install only the skill files (or nothing), Meko stores data only when you or your agent explicitly call a Meko tool. You can also instruct your agent not to store specific content, and the skills direct agents to disclose saves and skip sensitive material on request.

Usage and storage

We use stored content solely to provide the Meko service: persisting and retrieving memories, extracting durable memories from captured conversations, generating embeddings for semantic search, powering shared knowledge bases, and providing observability and audit views. We do not use your stored content to train foundation models, and we do not serve advertising.

Data is stored in the Meko Cloud service, scoped to your account and datapack. Personal memories are visible only to you; content becomes visible to other members of a datapack only when it is uploaded to the shared knowledge base or when you promote a memory to shared knowledge. Data is encrypted in transit (HTTPS/TLS) and at rest.

Our role and legal basis

For content you or your agent store in Meko (memories, conversation turns, knowledge-base documents), we act as a processor or service provider, processing that content on your behalf and at your direction. For account, authentication, and operational metadata we collect to run the service, we act as a controller and process it on the basis of our contract with you (performance of a contract) and our legitimate interests in operating, securing, and improving the Meko service.

Third-party sharing

We do not sell your data. We share it only with:

  • Service providers (subprocessors) that host and operate the Meko service, such as cloud infrastructure providers and AI model providers used for memory extraction and embedding generation. These providers process data only to provide the service and are bound by contractual confidentiality and data-protection obligations. A current list of sub processors is available at https://www.yugabyte.com/yugabytedb-aeon-subprocessors/ We update this list when subprocessors change and will notify you of material changes through the Meko documentation or Cloud UI.
  • Your team, for content you or your datapack administrators deliberately place in a shared knowledge base or promote to shared knowledge.
  • Legal authorities, where required by law, legal process, or to protect rights, safety, or the integrity of the service.

International data transfers

Yugabyte and its subprocessors may process your data in the United States and other countries that may have data-protection laws different from those of your country of residence. Where required by applicable law, we rely on appropriate safeguards for cross-border transfers, such as the European Commission’s Standard Contractual Clauses. For more information, see the International Data Transfers section of the Yugabyte Privacy Notice.

Data retention

You can delete individual memories, conversations, datapacks, and knowledge-base content at any time through the Meko MCP tools (e.g. memory_delete_by_id, conversation_delete, datapack_delete, etc.) or the Meko Cloud UI, where your role permits. When you close your Meko account, associated stored content is deleted or de-identified within 90 days, except where retention is required by law or an applicable customer agreement specifies a different period. You may request deletion of all of your stored content at any time by submitting a support ticket using our support website, which can be referenced at https://support.yugabyte.com/hc/en-us

Your choices and rights

You control what is stored: capture is opt-in by installation choice, all stored content is inspectable in the Meko Cloud UI, and deletion tools are exposed both in the Meko Cloud UI and as MCP tools. Depending on your jurisdiction, you may have additional rights regarding your personal information, including the right to access, correct, delete, object, restrict, or port (move) your personal data. You may also have the right to withdraw consent at any time without affecting prior processing, and to lodge a complaint with your local data protection authority. If you are a California resident, you may also request to know, delete, or correct your personal information, opt out of any sale or sharing of personal information, and limit the use of sensitive personal information; we will not discriminate against you for exercising these rights. To exercise any right, contact privacy@yugabyte.com.

Children

The Connector and the Meko service are not directed to children under 13 (or such higher age as may be required by applicable law in your jurisdiction), and we do not knowingly collect personal information from them.

Changes to this policy

We will update this policy from time to time and revise the “Last Updated” date above. Material changes will be announced through the repository, the Meko documentation, and the Meko Cloud UI.

Contact Information

YugabyteDB, Inc., 100 Mathilda Place, Suite 250, Sunnyvale, CA 94086, USA