A useful private agent needs durable context, but sending an entire personal model to a backend defeats the premise. The problem is selective recall: enough relevant memory to help, no ambient plaintext collection, and an honest erase path.
Select a minimal, query-relevant memory card locally; decrypt it only for the owner’s current session; and attach enough provenance for an answer to explain its grounding without exporting a private corpus.
Retrieval quality improves when a system has more context. Privacy usually improves when it has less. Treating that as a budgeted systems problem makes the trade-off explicit.
The web vault holds its AES-256-GCM key and owner token in memory only and clears them on identity change, expiry, or lock. Portable, query-selective memory retrieval is active work, not a complete product claim.
Primary source: Personal World Model research
Prototype a local relevance gate with a fixed context budget, then measure answer quality, leakage surface, and failure behavior against a deliberately over-broad baseline.
The companion essay is written for a broader technical audience. The repository and developer community are the places to turn a claim into a contribution.
One is made by Hushh Technologies Corporation: private, sovereign AI that runs on what you own.