A widely misunderstood implementation detail with real architectural consequences: Anthropic's memory tool "operates entirely client-side through tool calls. Developers manage the storage backend" (source). The model emits create/read/update/delete calls against a memory directory; your infrastructure is what actually stores them.
So it is a protocol for an agent to manage files, not a hosted memory service. What follows: nothing is persisted unless you build the persistence; retention, encryption, deletion and residency are your problems; and — the part that is genuinely useful — the memory is plain files you can read. You can inspect what the agent decided to keep, which is not true of an extraction layer that writes embeddings.
The cost is the same as the benefit: the model chose what to write, with no human in that loop. If it wrote down the wrong thing confidently, that is now durable, and it will be retrieved with the same confidence next session.