What it can see.
What it can never see.

An agent that knows you is only a good idea if you can see exactly how it knows, and take it back whenever you want. This page is the whole picture, including the parts that are less flattering.

Last updated 12 August 2026

The shape of the thing

Most assistants are a service you send your life to. This one is not built that way, for a reason that is more practical than principled: there is no server to send it to. You run the agent on your own computer, using your own keys. It runs there. Nobody sells you storage, because nobody is storing anything.

That single fact decides almost everything else on this page.

What it can see

  • Messages you send it, in the app you chose
  • Calendars you connect
  • The mailbox you connect, if you connect one
  • Files in the folders you point it at
  • Accounts you deliberately connect — shops, subscriptions, notes, whatever you pick
  • Spends you tell it about, and bank-statement CSV files you drop in its files folder — kept as one plain CSV on your machine, owner-only at every trust level, never learned from, never in the memory file
  • The journal, if you switch it on — its own file, owner-only, never learned from; entries imported from another journal app live under exactly the same rules
  • Preferences it has learned, which you can read and delete

What it can never see

  • Anything you haven’t connected — there is no "discover my accounts" step
  • Your bank account. There are deliberately no bank logins: reading a live account is Open Banking, a regulated activity this product is not licensed for. It reads the CSV export you hand it, locally, and nothing ever connects to a bank
  • Other conversations in your messaging app
  • Your camera, microphone, location or screen
  • Other apps on your phone
  • Your card details — it never handles payment
  • Passwords. If something asks it for one, that is not it

Your rights, as things you can type

Privacy that lives in a settings screen you never open is not privacy. These work as ordinary messages, in the same chat you use for everything else, and they take effect immediately.

Type thisAnd it
WHAT DO YOU KNOW Lists everything it has learned about you and where each thing came from — whether you told it, or it worked it out, and from which account.
FORGET <thing> Deletes that preference and stops acting on it. Nothing is kept "for quality".
FORGET EVERYTHING Wipes the memory file back to empty. It keeps working; it just no longer knows you.
DISCONNECT <service> Drops the connection and the access that came with it. It cannot read that service again unless you reconnect it.
EXPORT Sends you the whole memory file as it actually is. No summary, no redaction.
PRIVATE Maximum-privacy mode: it keeps helping but stops remembering anything new. Existing memory is untouched. Say LEARN to switch it back on.
KEEP <name/topic> PRIVATE Precise privacy — one contact or subject only. It never looks at, learns from, or mentions it; the runtime filters it out of your email digest, your daily brief and memory, and forgets anything it already knew about it. WATCH <it> lifts it; PRIVATE LIST shows what’s off-limits.
PERMISSIONS Shows exactly what it can reach, whether learning is on, and a timestamped log of every access you’ve granted or revoked.
PAUSE Stops it acting on anything. It stays quiet until you say RESUME.
STOP The panic switch. It halts mid-task, does nothing further, and tells you what it had already done.
Why these are commands and not buttons. The agent lives in a chat window. Anything important enough to need in a hurry — STOP especially — should be reachable in the place you already are, at the speed you can type, without finding a settings page while something is going wrong.

How it learns, and how you check its working

It learns two ways, and it always records which. Things you told it are taken as fact. Things it worked out are stored as guesses, with the evidence attached — "nine of your last eleven orders chose an evening slot".

A guess has to be confirmed before it can spend money or message another person. So the first time it matters, it asks: you seem to always take evening deliveries — shall I default to that? Ask it how it knows something and it will show you the evidence, because the evidence is stored alongside the guess rather than thrown away.

This is also the honest answer to the creepiest failure of personalised software: being confidently wrong about you, with no way to see why or correct it.

What it will not do on its own

When you hand your phone to someone else

Your agent lives in your messenger, so to it every message looks like you. The moment you say "someone else is using my phone" that changes: your email, files, money and connected accounts lock, and a separate memory starts for whoever is holding it — their preferences never mix with yours, and neither of you can read the other’s. Name a family member you trust and they can help with the shared calendar and reminders, and nothing else that’s yours. Coming back to your own world takes your passcode.

The honest part, because it’s the whole point: this is a declared handoff, not biometrics. The agent cannot tell who is holding the phone from how they type, and it never pretends to. Voice and face "recognition" on other assistants can be fooled in minutes; we’d rather do the thing that’s actually true — you tell it, it acts, and your private world stays shut until your passcode opens it.

This website

The honest limits

Every claim above is one this product actually keeps. These are the ones it does not.

It does not watch what you do on your phone

It cannot see which apps you open, how long you use them, or what you tap — a program that lives in your messenger has no way to read that, and we would not build it if it could. It gets to know you from two honest places: what you tell it, and what you connect (a calendar, a shop’s order history, a feed). That’s the whole input. "Figuring out who you are" means noticing patterns in those — not surveilling your device. Say PERMISSIONS to see every source, and PRIVATE to stop it learning at all.

Your accounts are only as safe as their keys

The agent runs on your own computer with your API keys. That is what keeps your data out of anyone else’s hands, and it also means the security of the whole thing is the security of that account. Turn on two-factor authentication there. If someone gets into it, they get everything the agent can reach.

The dashboard passcode hides, it does not encrypt

Setting an owner passcode stops someone glancing at your revenue over your shoulder. It is not encryption. The real secret is the published spreadsheet link the dashboard reads — anyone with that link can read the figures without ever seeing the dashboard. Keep that link private and never share your dashboard URL.

Model providers see what you send them

Understanding your messages means sending them to an AI provider under your own key. Nothing routes through us, but it does reach them, under their terms and their retention policy. If a subject is too sensitive for that, do not send it — and read your provider’s data policy, which governs this, not us.

Messaging apps have their own rules

WhatsApp, Telegram, Slack, Discord, Messenger and SMS each carry their own privacy terms and their own metadata. A message to your agent is still a message on their network. End-to-end encryption between you and a business account does not mean the business end is invisible — that end is you.

This is software, sold as-is

It is careful by design and it asks before anything it cannot undo, but it is not supervised, insured, or a substitute for checking things that genuinely matter. Read the receipts. That is what they are for.

Found a security problem?

Report it and it gets fixed — no legal threats, no arguing. Contact details are in /.well-known/security.txt. Please give a reasonable window before making it public, and do not test against anyone else’s installation.