how your memory is protected

You decide what enters, what shows, and what gets used.

AI Passport holds a small, reviewable version of you and carries it to the AIs you allow. It is built so that carrying your context across apps never means giving up control over how that context is assembled, read, or removed.

What we can and cannot see

What we hold

  • The memories you bring in or approve, so an AI can recall them.
  • The sources you link and the passes you grant, so recall knows what is allowed.
  • A content-free record of each decision: what happened and when, never the memory text or the query.

What we never do

  • We never sell your memory.
  • We never share it with third parties for their own use.
  • We never use it to train models.
  • We never keep raw chat logs, whole inboxes, or whole calendars when a short memory will do.

Access is exact, and you can take it back

Connecting a source grants no app anything by itself. When an AI asks to read part of your Passport, it gets a pass that is exact: one app, one category, one purpose, one duration. A pass never widens on its own, and you can revoke any of them at any time. Approving a memory is a separate decision from letting an app read it.

Credentials stay sealed

Your session is sealed with AES-256-GCM and lives only in an encrypted, server-side cookie. The app talks to its own backend on your behalf. Your linked sources are held in credential isolation, so the tokens for your calendar or email are never handed to the apps that read through your Passport. Your daily memory is archived encrypted, and you can export it yourself.

The AI runs on our side

Ask your Passport a question and the answer comes from an open model running on GPUs we control, inside a container that cannot reach the internet, with the weights baked in. No third-party AI provider ever sees your prompts, so there is nobody else to retain them. The models that turn your activity into memories run the same way. Chat history is encrypted at rest with a separate key per conversation, and private vault turns are never stored at all.

Keys, not settings

Turn on Memory Lock and your memory stores are sealed with keys derived from your own passkey. Every category gets its own key, so a pass for one category physically cannot decrypt another. Apps read through short-lived leases that renew only while the pass stands, revoking a pass cuts access on its next request, and deleting your data shreds the keys themselves. Sealing is optional, and only you hold the way back in.

Nothing is remembered until you approve it

When an AI saves something, it becomes a proposal in your private inbox, not a memory an app can read. It stays a proposal until you approve it. You are always the editor of what becomes true about you.

A poisoned memory cannot approve itself

Approving a memory or granting a pass requires your own signed-in browser session, which a connected AI never holds. So an AI that has been fed a malicious instruction cannot quietly save a false memory and grant itself access. The approval step happens out of band, where only you can reach it.

Questions

Reach us at privacy@ego.ist. Our full privacy policy and terms describe how the service runs, including the named providers we use to run it and how long we keep each kind of data.