Privacy

How private your memories are depends on which mode you're in, so this page is organized by mode rather than as one sweeping promise. Most people will only ever use the first one.

Two things are true in every mode: your memories are never used to train any model, ours or anyone else's, and there is no usage tracking or analytics in the product.

Mode 1 · Local
the default

Everything on your own computer

No account exists, so we hold no record that you use the product at all. We cannot read your memories, cannot delete them, and cannot produce them if someone asks us to, because we never have them.

we store about you: nothing
we can read: nothing
you are identified by: nothing
Mode 2 · Managed backup
opt-in, paid

We hold a copy we can't read

Your backup is encrypted on your computer before it's uploaded, and we don't hold the key. What we do hold is real and worth naming: an account, an email address, billing records, and the size and timing of your snapshots.

we store: encrypted blobs,
account + billing, snapshot sizes
we can read: none of the contents
Mode 3 · Server / team
opt-in · not built

Memories live on a server, in readable form

To search a shared collection and serve it to a team, the server has to hold those memories in a form it can actually search. That means the operator of the server — us, on the hosted tier — is technically able to read what's stored there. Saying otherwise would be untrue.

we store: the shared memories,
account, billing, service logs
we can read: yes, technically

What that means for the server tier, said plainly

Turning on the server tier is a decision to hand specific memories to a service. It is never the default, it is separately paid, and nothing is moved there because a tier ran out of space — the choice is yours, per collection.

Anything marked private, or local-only, is removed from the set of things eligible to move to a server before any placement decision is made. Privacy is a filter, not a factor weighed against storage cost.

A shared memory is visible to whoever the collection is shared with. The rules for who may see what within a team are designed but unbuilt, and the tier will not ship before they exist.

Your local memories stay local and keep working whether or not you ever switch this on, and continue working if you cancel. The server is an addition, never a migration.

Does it leave your computer?

What you're doing
Leaves?
Saving, recalling or deleting a memory
No
Working out what a note means (embeddings)
No — your CPU
Reading a folder of documents you approved
No
Usage tracking, analytics, crash reports
None exist
Managed backup (paid)
Encrypted first
Server / team collection (paid, unbuilt)
Yes, readable
Sending text to an outside model for processing
Off by default

On the first row: ModelBrain itself never sends a memory anywhere when saving, recalling, or deleting it. Once your assistant has that memory, what it does next is governed by that assistant's own policies, not ours (see "things we'd rather you knew," right). Note on the last row: the option to send text to an outside model exists only as an unused interface in the first release. Nothing calls it, and it stays off unless you enable it and supply your own key.

Things we'd rather you knew

ModelBrain does not encrypt your vault. Reading memories quickly depends on the files being readable as-is. Turn on your computer's own disk encryption — FileVault on a Mac, BitLocker on Windows, LUKS on Linux — which protects the same files at no cost if the machine is stolen.

Don't put your vault inside Dropbox, iCloud Drive, OneDrive or Google Drive. Those apps would copy it to someone else's servers, and disk encryption doesn't stop them. ModelBrain checks for this when it starts and refuses to run rather than let it happen quietly.

The file format isn't a security measure. It's a custom format for speed, not secrecy. Anyone with your files and enough determination can read them, which is the real reason to use disk encryption.

Your assistant is a third party. Whatever you discuss with Claude, Cursor or anything else is subject to that company's terms, not ours. ModelBrain controls what's stored on your disk, not what your assistant does with a memory after we hand it over.