Encrypted at rest and in transit
Your memory, documents and transcripts are encrypted on the Core. Losing the machine does not mean losing control of what's on it.
A system with this much context about a person is only worth building if the controls come first. Here is exactly how they work.
Baseline
Your memory, documents and transcripts are encrypted on the Core. Losing the machine does not mean losing control of what's on it.
Every integration is connected with the narrowest scope that does the job. Alfred never asks for, and never holds, unrestricted credentials to your accounts.
Every consequential action Alfred takes is written to an append-only record you can review line by line — what was done, when, on whose authority, and why.
Answers carry their evidence. If Alfred says you agreed something, it shows you the message, document or transcript where you agreed it.
Onboarding connects everything read-only and starts in observe mode. Authority is granted in stages, by you, and can be withdrawn the same way.
No advertising, no data sale, no training a general model on your life. The business model is a subscription, deliberately.
The boundary
In the default Private Hybrid deployment, routine work — classification, extraction, transcription — happens locally. Heavier reasoning may be routed to an approved external model, and you control that switch.
| Work | Private Local | Private Hybrid |
|---|---|---|
| Memory graph & document vault | On your Core | On your Core |
| Classification & extraction | Local | Local |
| Transcription | Local | Local |
| Heavy reasoning & long-form drafting | Local model | Approved external model |
| Audit ledger | On your Core | On your Core |
| Data used to train anyone's model | Never | Never |
Exact behaviour is documented per integration before it is enabled, and every routed request is written to the ledger.
Your rights
Your memory, documents and ledger export in open formats. No hostage-taking of the thing that makes Alfred valuable.
Deletion removes the data and is recorded as an action, so you can see it happened.
Any integration or autonomy mode can be pulled back to observe-only at any moment, without support tickets.
Note: this page describes the designed security and privacy model of a product in development. It is not a legal commitment or a certification claim. Formal terms, data-processing documentation and the published privacy policy will accompany the first paid installs — see our current privacy policy for how this website itself handles data.
That's the right instinct. Ask them directly — vague answers about security are a bad sign in any product.