1. Separate memory from conversation history. Store task state, formatting preferences and decisions in known fields. Avoid retaining entire conversations by default. Write down the purpose and authorized readers of each field; exclude fields that have no defined purpose.
2. Set expiry and isolation rules. Associate every record with the correct user or project, decide when it expires and provide a removal path. Confirm that ownership filtering happens before retrieval. An identifier in a prompt cannot replace database access control.
3. Process memory both when storing and when retrieving it. Summaries may include names, contacts and document details. Assemble the minimum useful context and send it through the selected privacy policy. Do not reconstruct identities from placeholders by searching another database.
4. Verify using two fictional users. Have each store a preference, remove a detail and resume a task. Confirm that answers retain allowed preferences, do not retrieve deleted data and never mix users' memories. Record the results before expanding deployment.