Privacy & Trust

The questions people and agents actually ask, answered directly. 'Sovereign' is the philosophy; these are the facts — starting with the whole boundary in one picture.

This layer is kept in English so it stays current; the full story lives at /principles in Nepali, English, Japanese, and Hindi. Machine map: /llms.txt. Everything here is true as of 2026-08-20; plans are labeled as plans.

The data boundary, in sixty seconds

your lifeyour Sathione server the operator ownsthe archiveunderstandingmessages & callsfiles & vaultweb search (own SearXNG)encrypted at rest · deletion provablestays: archive · understanding · messagestext model — open-weightsthe reply's context (DeepSeek)embeddings — Google, todaytext chunks, for retrievalspeech — Google, todayvoice audio, when you speakemail — Resendverification & reset mails onlyOpenAI · Meta · advertisersnothing, ever

Every arrow above is the complete list — there is no fifth flow. The same facts in three tenses (today / next / best available), with reasons, live on /principles.

What is encrypted?

User files and generated documents: encrypted at rest with authenticated encryption. Cached document text: stored no more readably than the file it came from. Backups: on-server today. Transport: HTTPS everywhere with HSTS. Database rows (claims, messages) are protected by disk, access control, and audit rather than per-row encryption — stated so the next answer can be honest.

What would a server compromise expose?

Assume an attacker with application-level access could read what the application can read — that is the honest baseline for any hosted system, including this one. What limits the damage: at-rest encryption on files, short-lived scoped tokens, quotas and rate limits, tamper-evident audit logs, and a single small attack surface instead of a fleet of integrations. What we refuse to do is pretend the risk is zero; the mitigation roadmap (cryptographic operator separation) is public on /security.

What happens if Sathi disappears?

Your life does not disappear with it. Export is a sealed, signed, self-describing archive in readable formats — designed so a fresh Sathi, run by you or anyone, can be rebuilt from it. Paired devices are repointable by design, and the architecture Sathi implements is an open framework anyone may run. Exportability is not a convenience feature here; it is existential infrastructure, built before it was needed.

What does Sathi know about me?

What you gave it: conversations, documents you keep, connected calendar and mailboxes, imports you ran — and the understanding derived from them as claims, each with provenance and confidence. The memory panel shows every claim and why it is believed.

Where is it stored?

On a single server the operator owns, in its own Postgres database and disk. User files are encrypted at rest. Backups are on-server today; off-site backups are not currently protecting this deployment.

Can Sathi forget something?

Yes, and it is the strongest rule in the system: user deletion beats archive immutability, provably. Deleted means gone from the archive, the understanding, and every surface.

Can I export everything? Can I leave?

Export is total: a sealed, cryptographically signed archive of your memories, history, and files, in readable formats. The front door accepts it back onto a fresh account, and leaving issues a signed receipt of what was destroyed and what remains, with the consent basis for each retention.

Can the operator read my data?

Only after you grant support access from your own account — a revocable consent recorded on the relationship graph. Without it, your content is invisible to the admin panel, and every admin request lands in a tamper-evident audit log. Honest limit: this is application-level enforcement, audited but not yet cryptographic — the operator still runs the database.

Does Sathi use OpenAI?

No. OpenAI and Meta receive nothing. Text reasoning runs on open-weights models via a hosted API (DeepSeek today — chosen because the exit was engineered before the entrance); speech and embeddings transit Google today, stated plainly, with self-hosting as the named direction. The full three-tense disclosure table is on /principles.

What never leaves the infrastructure?

The archive, the understanding, documents, family messages and calls. Web search runs through the deployment's own SearXNG instance, not a third-party search API.

What about guests?

Guest chat requires no account and is not remembered — nothing a guest says becomes memory.

Is my data the product?

No. There is no advertising, no engagement optimization, no data sale, and no third party with read access. Sathi should know you because you chose to let it know you — that is the founding rule, not a policy that could quietly change.

The three verbs

See it — the memory panel lists every claim with sources and confidence. Change it — corrections teach it; rejected hypotheses stay rejected. Take it — total export, verified return, signed deletion receipt. All three are live today.