Last updated: July 15, 2026
Who We Are
Pearl(TM) is operated by Maple Brain Healthcare Inc. For privacy questions, access requests, correction requests, or complaints, contact admin@pearlmemory.ca.
This policy is written for Canada. We aim to follow Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws where they apply.
Information We Collect
- Account details such as name, email address, organization, password hash, role, package, and entitlement state.
- Billing and transaction records, while full payment card details are handled by payment providers when enabled.
- Support information such as ticket messages, support category, issue details, and support desk metadata.
- Download, security, audit, device, API token, and session records needed to operate and protect the service.
- Vault metadata and encrypted object records where vault features are enabled. The service is designed so private vault plaintext is not available to administrators by default.
- Website and technical data such as IP address, browser type, pages visited, timestamps, and error or security logs.
- If you connect PEARL to ChatGPT or another approved MCP client: OAuth client and consent metadata, hashed access credentials, requested permissions, bounded handoff purpose and status, and the exact short-lived capsule export you separately approve in PEARL Desktop.
ChatGPT And The Public MCP Bridge
The public PEARL MCP service is a broker, not your canonical archive. It cannot browse your Windows or macOS filesystem. Your local .pearl archive remains authoritative. Account and project tools read bounded cloud metadata only. A memory capsule is sent to ChatGPT only after you connect your account, request the capsule, and separately approve the exact export in PEARL Desktop.
OAuth authorization codes expire within five minutes. Access tokens normally expire within one hour. Rotating refresh tokens normally expire within 30 days and never later than 90 days under the service configuration. An approved capsule is encrypted at rest and available only until its request expires, never longer than 60 minutes; its encrypted payload is then erased. MCP request metadata is retained for up to 30 days after expiry, and MCP security audit records for up to 12 months unless a longer period is reasonably required for an investigation or legal obligation.
When you invoke the connected plugin, the requested tool output and any capsule you approve are disclosed to OpenAI/ChatGPT as the recipient you selected. Hosting, security, and backup providers may process limited service data on our behalf. We do not sell MCP or capsule data and do not ask for full conversation history.
You can deny any Desktop request, let it expire, revoke the connection, or stop using the plugin. You may also contact us to request access, correction, or deletion, subject to identity verification and lawful retention requirements.
How We Use Information
- To create and manage accounts, authentication, package access, downloads, billing status, support, and vault-related controls.
- To respond to support requests and communicate about the service.
- To secure the site, investigate abuse, prevent fraud, maintain audit records, and protect service integrity.
- To meet legal, tax, accounting, compliance, and dispute-resolution obligations.
- To improve reliability, usability, support quality, and product planning.
Consent And Choices
We collect, use, and disclose personal information with consent, or as otherwise permitted or required by law. Consent may be express or implied depending on the context and the sensitivity of the information.
You may choose not to provide certain information, but some information is required to create an account, provide downloads, process billing, or answer support requests.
Sharing And Service Providers
We do not sell personal information. We may share limited information with service providers that help operate hosting, security, email, support desk, payment processing, analytics, backups, and customer operations. We may also disclose information if required by law, to enforce terms, to protect rights or safety, or as part of a business transaction.
Some providers may process information outside your province or outside Canada. In those cases, information may be subject to the laws of the place where it is processed.
Security And Retention
We use administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including access controls, hashed credentials, audit records, and protected storage patterns. No online service can guarantee absolute security.
We keep personal information only as long as needed for the purposes described in this policy, unless a longer retention period is required or permitted by law. When information is no longer needed, we delete it, anonymize it, or restrict it according to operational and legal needs.
Cookies And Similar Technologies
We use essential cookies and session storage for sign-in, administration, security, and site operation. If optional analytics or marketing tools are added later, they should be identified and controlled in a clear consent flow where required.
Access, Correction, And Complaints
You may request access to your personal information, ask us to correct inaccurate information, or make a privacy complaint by emailing admin@pearlmemory.ca. We may need to verify your identity before responding.
If a privacy complaint is not resolved, you may have the right to contact the Office of the Privacy Commissioner of Canada or an applicable provincial privacy regulator.
Children
The service is not directed to children. Do not create an account or submit personal information if you are not old enough to consent to these terms and this policy under the laws that apply to you.
Changes
We may update this policy as the service, legal requirements, or operational practices change. The posted version is the version currently in effect.