Security · 2026-09-24 · 1:50

The memory that knows you is the memory that exposes you

One of the fastest-rising open-source AI projects of the year, around 40,000 stars in seven months, sells memory. Connect your accounts and every twenty minutes it pulls inbox, calendar, repositories, documents and chats into a local knowledge graph, so an orchestra of agents has full context from day one. The README says it in three words: it becomes you.

In favour
  • Local-first is the right instinct: the memory lives encrypted on your device, secrets go to the OS keyring, and there is an approval gate and a one-switch privacy mode.
  • Serious engineering rather than a wrapper, open to inspection, and a real alternative to assistants that ship everything to someone else's cloud.
Worth watching
  • The more complete the memory, the more valuable the target. One searchable store also holds whatever passed through it: a password someone emailed you, an API key pasted into a chat, a contract.
  • This is the risk class, not one project. Agent memories record by design, rarely know what they should not keep, and this one is still early beta.
Our takeFour boring questions for any agent memory: what exactly is ingested and can you exclude sources; are secrets redacted before storage rather than after; where do the copies live, counting index, backups and logs; and can you really delete something. Local-first answers where your memory lives, not what it should remember.

Source: OpenHuman, ανοιχτού κώδικα πλαίσιο agents με τοπική μνήμη (GitHub, GPL-3.0)

← All Focus posts