The shape of the thing
Most assistants are a service you send your life to. This one is not built that way, for a reason that is more practical than principled: there is no server to send it to. You run the agent on your own computer, using your own keys. It runs there. Nobody sells you storage, because nobody is storing anything.
That single fact decides almost everything else on this page.
✓ What it can see
- Messages you send it, in the app you chose
- Calendars you connect
- The mailbox you connect, if you connect one
- Files in the folders you point it at
- Accounts you deliberately connect — shops, subscriptions, notes, whatever you pick
- Spends you tell it about, and bank-statement CSV files you drop in its files folder — kept as one plain CSV on your machine, owner-only at every trust level, never learned from, never in the memory file
- The journal, if you switch it on — its own file, owner-only, never learned from; entries imported from another journal app live under exactly the same rules
- Preferences it has learned, which you can read and delete
✕ What it can never see
- Anything you haven’t connected — there is no "discover my accounts" step
- Your bank account. There are deliberately no bank logins: reading a live account is Open Banking, a regulated activity this product is not licensed for. It reads the CSV export you hand it, locally, and nothing ever connects to a bank
- Other conversations in your messaging app
- Your camera, microphone, location or screen
- Other apps on your phone
- Your card details — it never handles payment
- Passwords. If something asks it for one, that is not it
Your rights, as things you can type
Privacy that lives in a settings screen you never open is not privacy. These work as ordinary messages, in the same chat you use for everything else, and they take effect immediately.
| Type this | And it |
|---|---|
WHAT DO YOU KNOW |
Lists everything it has learned about you and where each thing came from — whether you told it, or it worked it out, and from which account. |
FORGET <thing> |
Deletes that preference and stops acting on it. Nothing is kept "for quality". |
FORGET EVERYTHING |
Wipes the memory file back to empty. It keeps working; it just no longer knows you. |
DISCONNECT <service> |
Drops the connection and the access that came with it. It cannot read that service again unless you reconnect it. |
EXPORT |
Sends you the whole memory file as it actually is. No summary, no redaction. |
PRIVATE |
Maximum-privacy mode: it keeps helping but stops remembering anything new. Existing memory is untouched. Say LEARN to switch it back on. |
KEEP <name/topic> PRIVATE |
Precise privacy — one contact or subject only. It never looks at, learns from, or mentions it; the runtime filters it out of your email digest, your daily brief and memory, and forgets anything it already knew about it. WATCH <it> lifts it; PRIVATE LIST shows what’s off-limits. |
PERMISSIONS |
Shows exactly what it can reach, whether learning is on, and a timestamped log of every access you’ve granted or revoked. |
PAUSE |
Stops it acting on anything. It stays quiet until you say RESUME. |
STOP |
The panic switch. It halts mid-task, does nothing further, and tells you what it had already done. |
STOP especially — should be reachable
in the place you already are, at the speed you can type, without finding a settings page
while something is going wrong.
How it learns, and how you check its working
It learns two ways, and it always records which. Things you told it are taken as fact. Things it worked out are stored as guesses, with the evidence attached — "nine of your last eleven orders chose an evening slot".
A guess has to be confirmed before it can spend money or message another person. So the first time it matters, it asks: you seem to always take evening deliveries — shall I default to that? Ask it how it knows something and it will show you the evidence, because the evidence is stored alongside the guess rather than thrown away.
This is also the honest answer to the creepiest failure of personalised software: being confidently wrong about you, with no way to see why or correct it.
What it will not do on its own
- Spend money. It can fill a basket and hold a booking. Paying is always yours.
- Delete permanently. Deletions go to the bin, so you can get them back.
- Message someone new. Contacting anyone outside your approved list needs your yes.
- Sign anything. Contracts and agreements come back to you.
- Hide a mistake. Every action leaves a one-line receipt, and a failure is reported as a failure. It is built never to invent a success.
When you hand your phone to someone else
Your agent lives in your messenger, so to it every message looks like you. The moment you say "someone else is using my phone" that changes: your email, files, money and connected accounts lock, and a separate memory starts for whoever is holding it — their preferences never mix with yours, and neither of you can read the other’s. Name a family member you trust and they can help with the shared calendar and reminders, and nothing else that’s yours. Coming back to your own world takes your passcode.
The honest part, because it’s the whole point: this is a declared handoff, not biometrics. The agent cannot tell who is holding the phone from how they type, and it never pretends to. Voice and face "recognition" on other assistants can be fooled in minutes; we’d rather do the thing that’s actually true — you tell it, it acts, and your private world stays shut until your passcode opens it.
This website
- No analytics. No tracking script, no pixel, no fingerprinting, no cookie banner — because there are no cookies to consent to.
- No accounts. There is nothing to sign up for and no password to lose.
- The demo is local. What you type on the front page is handled in your browser and never sent anywhere. Reload and it is gone.
- Sharing is local too. A photo shared into the app is handled on your device and cleared once shown.
- Local storage holds four things: your theme choice, your setup-wizard progress, whether you dismissed the install prompt, and — if you use the dashboard — its passcode, stored in plain text. Clearing site data removes all four.
- Checkout is not us. Buying hands you to a payment company. Card details go to them and never touch this site.
The honest limits
Every claim above is one this product actually keeps. These are the ones it does not.
It does not watch what you do on your phone
It cannot see which apps you open, how long you use them, or what you tap — a program that
lives in your messenger has no way to read that, and we would not build it if it could. It
gets to know you from two honest places: what you tell it, and what you
connect (a calendar, a shop’s order history, a feed). That’s the whole
input. "Figuring out who you are" means noticing patterns in those — not
surveilling your device. Say PERMISSIONS to see every source, and
PRIVATE to stop it learning at all.
Your accounts are only as safe as their keys
The agent runs on your own computer with your API keys. That is what keeps your data out of anyone else’s hands, and it also means the security of the whole thing is the security of that account. Turn on two-factor authentication there. If someone gets into it, they get everything the agent can reach.
The dashboard passcode hides, it does not encrypt
Setting an owner passcode stops someone glancing at your revenue over your shoulder. It is not encryption. The real secret is the published spreadsheet link the dashboard reads — anyone with that link can read the figures without ever seeing the dashboard. Keep that link private and never share your dashboard URL.
Model providers see what you send them
Understanding your messages means sending them to an AI provider under your own key. Nothing routes through us, but it does reach them, under their terms and their retention policy. If a subject is too sensitive for that, do not send it — and read your provider’s data policy, which governs this, not us.
Messaging apps have their own rules
WhatsApp, Telegram, Slack, Discord, Messenger and SMS each carry their own privacy terms and their own metadata. A message to your agent is still a message on their network. End-to-end encryption between you and a business account does not mean the business end is invisible — that end is you.
This is software, sold as-is
It is careful by design and it asks before anything it cannot undo, but it is not supervised, insured, or a substitute for checking things that genuinely matter. Read the receipts. That is what they are for.
Found a security problem?
Report it and it gets fixed — no legal threats, no arguing. Contact details are in
/.well-known/security.txt. Please give
a reasonable window before making it public, and do not test against anyone else’s
installation.