Trust

An AI this close to your life is only worth having if the terms are yours. Here they are, in plain facts.

Where Sathi lives

Today Sathi runs as a private deployment we operate. The same architecture is being shaped so execution can move closer to you without creating a second Sathi — or moving its understanding merely because a stronger model is consulted.

Sathi can live with us, live with you, or belong entirely to you.*

Current

Sathi Systems operates your private deployment. Your archive is not stored by the model provider.

Models may change. Your archive and understanding stay with your Sathi.*

What leaves, and to whom

To answer you, Sathi sends the text of that one request to a model provider — open-weights models on a hosted API today. Speech transits Google today. Neither ever receives your archive. OpenAI and Meta receive nothing. Self-hosting both is the named direction, and until it happens this page says so.*

It is yours to take

Export everything as one sealed, signed file whenever you want. Delete anything and it is gone — from the archive, from the understanding, from every surface. Leave, and bring that file back later to a fresh Sathi. Leaving is mechanical here, never a negotiation.*

What we will not do

No advertising. No engagement optimization. Your personal data is never sold, and never pooled with anyone else’s to train anything. Guests are never remembered; guest conversations are kept only briefly for testing and feedback, then deleted.

The honest limits

Sathi is in beta. The operator still runs the database, and during the beta operator support access is on by default — disclosed in the agreements, one tap to switch off — so problems can be found and fixed; it becomes opt-in once Sathi runs reliably without us looking. Every admin request lands in a tamper-evident audit log, but that is application-level enforcement, not yet cryptographic. Nightly backups are encrypted and kept off-site in Google Drive; a full restore was verified on 2 September 2026. There is no third-party security audit yet. When any of this changes, this page changes.

About the asterisk

Our product pages describe the experience we are building toward. An asterisk marks something still being implemented, planned, or awaiting verification. During beta, some functions use external providers. We intend to self-host suitable open models as scale makes that practical. The entries below describe today’s behavior and remaining limitations. Implementation status and independent review are separate questions.

Connected day and continuity

Intended experience
One continuing Sathi connects information, services, people and devices, with grants governing actions across surfaces.
Current behavior
This scene is scripted and uses fictional data. It shows a bedtime request to a screenless speaker, a morning alarm, and a flight-delay notification on the phone. The product has mail, chat, calling surfaces and a speaker prototype; this complete workflow is illustrative.
Remaining work / limits
Reliable email and flight updates, alarm delivery, shared-speaker attribution and timely phone notifications still need end-to-end implementation and testing. Access to personal information and actions must respect the relevant grants.

Last checked against the code and published account: 5 September 2026. Live configuration may differ.

Read the detailed privacy account and provider terms

Transcribe and external processing

Intended experience
Natural mixed-language transcription, with suitable open models self-hosted as scale makes that practical.
Current behavior
The current beta account names Google Gemini for transcription. Audio is sent to Google for processing; Sathi-owned weights are not serving this demo. The request is handled by Sathi’s API.
Remaining work / limits
The transcription backend is configurable. Self-hosted models must pass licensing and quality checks. Do not upload sensitive audio on an assumption of zero provider retention: downstream handling follows the applicable provider terms.

Last checked against the code and published account: 5 September 2026. Live configuration may differ.

Read the detailed privacy account and provider terms

Storage, models and serving providers

Intended experience
Your archive and understanding stay with your Sathi; external capabilities receive the context they need.
Current behavior
Sathi stores the archive on its operated node. The text adapter defaults to DeepSeek’s hosted API; its endpoint is configurable. Google hosts Gemini speech/embedding processing through Vertex AI or the Gemini API. An OpenAI-family voice model is reached through OpenRouter, which routes to an upstream host. Model developer, intermediary and actual host are different roles. Resend handles verification/reset mail. Live routing was not inspected in this website pass.
Remaining work / limits
This is not a promise that no data leaves Sathi or that all connectors will become self-hosted. Provider routing and retention must be read with the processing terms; no independent audit is claimed.

Last checked against the code and published account: 5 September 2026. Live configuration may differ.

Read the detailed privacy account and provider terms

Deletion and receipts

Intended experience
Delete from your Sathi and carry a clear record of what was removed.
Current behavior
The deletion path removes live records. Encrypted restic snapshots are retained in Google Drive and a second Oracle backup location. The retention policy keeps 14 daily, 8 weekly and 12 monthly snapshots.
Remaining work / limits
A signed receipt authenticates the recorded operation; it does not prove every backup or downstream copy is gone. Backup expiration is separate from live deletion. External processors have their own retention obligations.

Last checked against the code and published account: 5 September 2026. Live configuration may differ.

Read the detailed privacy account and provider terms

Independent composition

Intended experience
Different personal and community systems cooperate recursively while retaining their capabilities, identity and legitimate control.
Current behavior
Sathi is the current implementation testbed; an independently reusable generalized framework has not been released.
Remaining work / limits
Preserved capabilities and lower reconfiguration costs are hypotheses to test. Organs may keep their own databases, models and runtimes. Replication should enable an independent cooperating participant, without requiring our brand or control.

Last checked against the code and published account: 5 September 2026. Live configuration may differ.

Read the detailed privacy account and provider terms

Every privacy question, answered

The security posture, with its limits

Company background and disclosed security partnership