Privacy & Trust
The questions people and agents actually ask, answered directly. 'Sovereign' is the philosophy; these are the facts — starting with the boundary in one picture.
Updated 2026-10-03. English reference · Overview in five languages · Machine-readable guide. What the * means.
The data boundary, in sixty seconds
The arrows above are the main routes named by the code and our deployment records, not an inventory read from the running service. One more sits behind them: image and scanned-page turns go to Google's Gemini, which also answers when the text model fails. Other routes are configurable or follow what you connect: other model and speech providers, the search engines the deployment's SearXNG queries, your connected mailboxes, notification services, telephone calls, and assistants you connect through Sathi's MCP door when it is turned on. What each of those parties can observe is still being inventoried. The same facts in three tenses (today / next / best available), with reasons, live on /principles.
Current processing routes and terms
The maintained implementation entries are on Trust. The text adapter defaults to DeepSeek’s hosted API; its endpoint is configurable. Google hosts Gemini processing, with Vertex AI and Gemini API client routes supported by configuration. An OpenAI-family voice model is reached through OpenRouter; the model name alone does not identify its actual upstream host. This website pass has not verified live routing or account-specific retention settings.
For Google processing, consult the terms for the configured service: Google Cloud data governance or Gemini API terms. For voice routing, OpenRouter’s data handling also depends on the selected provider. These links are not a claim that zero-retention settings have been enabled for Sathi.
What is encrypted?
User files and generated documents: encrypted at rest with authenticated encryption. Cached document text: stored no more readably than the file it came from. Nightly backups: encrypted by restic before they leave the node, then stored off-site in Google Drive. Transport: HTTPS everywhere with HSTS. Database rows (claims, messages) are protected by disk, access control, and audit rather than per-row encryption — stated so the next answer can be honest.
What would a server compromise expose?
Assume an attacker with application-level access could read what the application can read — that is the honest baseline for any hosted system, including this one. What limits the damage: at-rest encryption on files, short-lived scoped tokens, quotas and rate limits, tamper-evident audit logs, and a single small attack surface instead of a fleet of integrations. What we refuse to do is pretend the risk is zero; the mitigation roadmap (cryptographic operator separation) is public on /security.
What happens if Sathi disappears?
Your life does not disappear with it. Export is a sealed, signed, self-describing archive in readable formats — designed so a fresh compatible Sathi can be rebuilt from it.* Paired devices are repointable by design, and neither action depends on our permission. Exportability is not a convenience feature here; it is existential infrastructure, built before it was needed.
What does Sathi know about me?
What you gave it: conversations, documents you keep, connected calendar and mailboxes, imports you ran — and the understanding derived from them as claims, each with provenance and confidence. The memory panel shows every claim and why it is believed.*
Where is it stored?
Today, on one Sathi-operated server, in its own Postgres database and disk. User files are encrypted at rest. Nightly encrypted backups are kept in a separate Google Drive repository; on 2 September 2026 we restored the database, uploads, music, vault, and production keys from that copy and verified their integrity. A home node is experimental, hybrid/local placement is direction, and dedicated or fully independent deployments are future offerings.
Can Sathi forget something?
The deletion path removes live records and their derived understanding. Encrypted backup snapshots expire separately; downstream processors may retain copies under their own terms. What a deletion keeps depends on the operation: leaving keeps the words you already sent into shared conversations with their other members, while erasing removes them too; neither reaches an organization's workspace records, the admin audit log, guest logs, feedback sent through the public form or an in-app report, or the usage (unlinked from you), purchase and mail-relay records kept to run the service. Leaving issues a signed receipt, which authenticates the recorded operation and is not proof that every copy is gone; erasing issues none. See the current deletion entry.
Can I export everything? Can I leave?
Not everything yet. Export covers your supported records and files: a sealed, cryptographically signed archive of your profile, memories, conversations, documents, notes, lists, tasks and reminders, in readable formats (a JSON record, or a ZIP that also carries your files). Derived search embeddings are left out, an organization's workspace records stay with the organization, and an archive past the fixed size limits is refused rather than cut short. The front door restores supported sections onto a fresh account; notes and lists are export-only records that restore does not import. Leaving issues a signed receipt of what was destroyed and of the account records that remain, with their operational retention reasons. Its category notice is not a complete inventory of copies or a legal-basis assessment. The receipt does not establish that backup or downstream copies have already expired.
Can the operator read my data?
During the beta, yes by default: operator support access starts on for each account so problems can be found and fixed, unless its owner switches it off — shown in your account as a beta default rather than something you granted, and one tap to switch off. It becomes opt-in, granted only from your own account and recorded on the relationship graph, once Sathi runs reliably without us looking. Every admin request lands in a tamper-evident audit log. Honest limit: this is application-level enforcement, audited but not yet cryptographic — the operator still runs the database.
Does Sathi use OpenAI?
Sathi is not affiliated with OpenAI or Meta. The models and serving providers depend on the configured route and task, including direct APIs and intermediaries such as OpenRouter. A model family’s name is not proof of who receives the request. Relevant context, images, audio and reply text can leave Sathi for processing. See the provider and processing account.
What stays stored with Sathi, and what is processed outside?
Sathi stores the archive and derived understanding on its operated node. Relevant excerpts, document/image content, audio or reply text may still be sent to external processors for a task. Storage custody is different from processing. Web search uses the deployment's SearXNG instance; search requests still reach the search engines it queries.
Is a Private chat the same as guest chat?
No. Signed in, a Private chat still uses what Sathi knows about you, but saves no conversation and no trace; usage is metered without content. Guest chat needs no account and uses nothing personal, and its conversations are logged for testing, as the next answer says. Choose Private before your first message, from the rings icon at the top of a new chat or the Private button under the greeting.
What about guests?
Guest chat requires no account. Nothing a guest says becomes memory. Guest conversations, with the reply and identifiers derived from the network address and session, are logged for testing and feedback, and a nightly job deletes them after the number of days an operator setting sets (30 by default; an operator can also set no limit, and which maximum to promise is an open decision). Deleting an account does not reach these logs, because they belong to no account.
Is my data the product?
No. There is no advertising, no engagement optimization, no data sale, or advertiser access. External processors do receive the task data described above. Sathi should know you because you chose to let it know you — that is the founding rule.
The three verbs
See it — the memory panel lists every claim with sources and confidence.* Change it — corrections teach it; rejected hypotheses stay rejected. Take it — export of your supported records and files, verified return, and a signed receipt when you leave. All three are live today.