Asked, answered.

The long version, on purpose, including the questions most products hope you will not ask: whether you could build this yourself, and who else is trying.

Part one, The basics

What is this?

We compile what you know, and let the people you choose ask it.

Most of what you know you already wrote down or received: policies, agreements, invoices, decisions, years of them. We take that. The rest never got written down, so we ask you for it. Then the people you choose can get an answer out of it without going through you.

What does it do for me this week. Not someday?

Walk into every meeting already knowing the whole history. Not the last email. The relationship: every thread, what they’ve promised you, what you’ve promised them, what was left hanging, what’s changed since you last spoke. The brief is ready before the meeting is.

Know who to call, and why, before you’re told. Who’s going quiet that shouldn’t be. Who just changed companies, which is the best reason to reach out anyone ever gets, and the one everybody misses. Who’s been waiting three weeks on your answer, and who’s had yours for three weeks.

Get the answer in one line, with the receipt. Your deductible, the contractor’s quote, the terms you agreed to in 2019, instead of twenty minutes of digging.

And yes, it catches the leaks: the receipt that stopped because a card lapsed, the renewal about to bite, the subscription paying for nothing. That’s the floor, not the product.

I know a lot of people. What does this do with that?

A network is only worth what you can remember at the right moment, and nobody can. The record holds every relationship whole: the full history, the open promises in both directions, the rhythm of contact, and who you actually invest in versus who you think you do. It notices when someone in your world moves, and hands you the reason to reconnect while it’s warm. People who know a thousand people don’t lose deals for lack of contacts. They lose them for lack of recall. This is the recall.

Who is it for?

Everyone is a single point of failure for what they know. We’re for the people where that costs something.

You use it first: the fee you couldn’t name, the terms you agreed to in 2019, the answer that took twenty minutes to dig for. Then the people you choose use it too. Your wife shouldn’t have to ask you, she should be able to ask it, and neither should your accountant or whoever needs an answer on a day you can’t give one.

Why does this exist?

The old fix was sitting down for months and telling someone, which just creates a second point of failure. Brief your spouse, train a successor, write the memo, hire the family office: every version of that answer moves the dependency instead of removing it. We remove it.

And you can take the whole thing and leave. Exported free, in plain files, whenever you say.

What makes it different?
  • It builds from what you’ve already written down.Not from forms you’ll never finish.
  • It asks you for the part you never wrote down.Why you left that carrier, who to call, what you’d never do again. Forty questions, not four thousand, because it already read the forty thousand documents. Building: today it asks about documents, not judgment.
  • It hands over any piece of it, to anyone, on your terms.A seat scoped to exactly the parts you choose, closed whenever you say, with a ledger showing who read what and when.
  • Everything has a receipt.The message, document, or word of yours each fact came from.
  • Silence gets named.The statement that quit arriving, the policy that went quiet. The things absence hides.
  • Your data never moves in with an AI company.Search and storage run on our own engine, in our own walls. A model sees a few sentences of context per answer, never your archive, and with your own keys, not even through our account.
  • It leaves whole, whenever you say.Exported free, in plain files. Deletion destroys the key that unlocks your documents.
What's a seat?

A key you hand someone. Your wife, your brother, an agent you trust. What they can see through it is your call, seat by seat, and you can close any seat at any time. Every seat leaves a trail: you see who opened what, and when. Sharing without receipts on the readers is just leaking slowly.

What does it cost?

One price, everything in it, $999 a year: the full twenty-year read, new information as it arrives, the watch for what stopped, seats for your family, export any time. Non-payment never deletes a record. Details

Part two, How it works

Where does your record come from?

Every door you open. Connect an account, email and calendar today, more connections on the way, and your record reads what’s already there. Put a document in, and it’s read and filed with the facts it proves. Tell it something in your own words, and your word goes on your record with your name as the receipt. Add a person, a picture, an account. Mail is a starting point, because it happens to hold years of your life nobody ever organized. It is not the product. Your record is everything you know, from wherever it lives.

How does it know things I never told it?

Because you already wrote them down, to your lawyer, your insurer, your bank, your family. One message and one document at a time, over years. The record reads what you connect, keeps the facts, and files the source each one came from as its receipt. You never told it who your attorney is. What you already had did.

What does “it names what stopped” mean?

Most of what matters in a life arrives on a rhythm: the statement every month, the premium every year, the license renewal. When something with a rhythm goes quiet, nothing tells you. There is nothing to see. Your record learns each rhythm from years of arrivals and says, plainly: this used to come, and it stopped in April. A receipt that stops arriving is how you find out about the card still billing, the policy that lapsed, the subscription you forgot.

Why should I trust the answers?

Receipts. Every claim cites the actual source it came from, and anything that can’t be proven is said plainly, not guessed at.

Do facts just sit there forever?

No, facts age, and your record says so. A deductible learned two years ago and never confirmed since reads “unconfirmed since March 2026”, not as flat truth. Confirming takes one sentence from you; fresh evidence resets the clock on its own.

Will anything ever act as me?

Not without your word. Today, your record reads and answers. It never sends, signs, or speaks for you on its own, and a wrong fact is wrong somewhere only you can see. If it ever acts on your behalf, it will be because you chose it, scoped it, and can read the receipt afterward. Your say-so is the switch, and it ships off.

Part three, Security and control

Where does my data actually live?

In our own walls, end to end. Everything you connect or add is indexed by our own search engine and stored encrypted. The vault holds ciphertext only. It is not handed to a third-party search or embedding service to be indexed. Each item is encrypted before it is stored; per-account keys are live for new material and rolling out to the rest.

Who else touches it?

One egress, and we name it, and it carries context, not your data. Because search runs on our own engine, inside our walls, the AI model never holds your archive: when a question needs answering or a document needs reading, only the few passages relevant to that one moment are sent to the model, today Anthropic, through our account, under an agreement that forbids training on them. The archive stays home. Nobody trains on it. Not us, not them.

If you’d rather even that context never touch our account, you can connect your own model credentials, then every call for your data runs inside your agreement, not ours. If your credentials stop working, your copy stops working; it never quietly falls back to ours. Building: the setup screen, today we’ll wire it up for you.

What about account numbers and SSNs?

They never enter the searchable record. Before any extracted text is stored, government identifiers, account and routing numbers, IBANs and card numbers are masked to their last four digits, in code, on the way in. The record keeps the map (you bank at PNC; this account pays the mortgage) and destroys the key (the number that opens it). We did it this way because we caught the alternative failing: a model that had been told never to extract a full account number wrote one anyway. An instruction is not a boundary. Code is.

Can I see every touch of my data?

Every touch is recorded. What was read, when, and each time your context went to a model. And the ledger points both ways: for every seat you grant, you see who opened what, and when. The readers get receipts too. Building: the full touch-by-touch screen; the ledger itself is being kept now, and the who-looked view is live.

What are sealed items?

Some things belong in your record but not on any screen. A letter for your children, an instruction for after. A sealed item shows its name and nothing else, to everyone, everywhere: screens, answers, even the readable export. The contents never leave custody.

How do I get my data out?

Two doors, both free, both always. Download everything. The complete record as one machine-readable file, sealed items included, because an exit that holds anything back is a hostage situation. A readable copy, plain markdown files, one per part of your life, receipts included, that open anywhere, forever, with no product in the way; sealed items ride by name only, because a friendly zip is exactly the file that gets forwarded.

What does deletion actually delete?

Something stronger than a promise to press delete. Your stored data is encrypted under a key that exists only for your account. When you delete, we destroy that key, so everything encrypted under it, including any copy in a backup, becomes permanently unreadable, then delete the files, then every derived record within 30 days. You get a written record of the moment the key died.

What if I stop paying?

Your record freezes; it is never deleted for non-payment, and export stays free while it’s frozen. Leaving is always possible with your data in hand. That’s the deal, and it doesn’t expire when your card does.

Part four, Can I build this myself?

Honestly, can I?

Yes. Garry Tan did. G-Brain. His personal knowledge system, on the order of 146,000 plain-markdown pages, open-sourced in 2026, is proof that a determined person can build a second brain that actually works. We’d rather tell you that than hope you never find out. If you have the time and the discipline, his write-up is a better starting point than most products.

Then what am I paying you for?

The librarian. Read Garry’s own account and one thing stands out: the system works because he staffs it. He files, he enforces the schema, he catches the errors. His rule, in his words: schema discipline required, no automatic structure synthesis. That job doesn’t go away when you self-host it; it just becomes yours, every day, forever. Our whole product is replacing that librarian with code: your record builds itself, checks itself, ages its own facts, and names what stopped, while you do nothing.

What did it take you to build?

More than we expected, and we expected a lot.

  • Search we could own. We run our own engine inside our walls, so your archive is never handed to a third-party index or embedding service, and the model only ever sees context, never the corpus. If you build your own, that decision is yours on day one. Every convenient shortcut ships your data to someone.
  • Security as code, not policy. Per-account encryption with key-destruction deletion; identifiers masked to last-four before anything is stored; a rule we learned the hard way. An instruction to a model is not a boundary, only code on its output is.
  • The noise everyone deletes. Absence detection needs exactly the receipts, statements, and renewal notices every sane pipeline filters out. We had to keep a pulse of them, metadata only, going back years, to learn the rhythms worth watching.
What surprised you?

The measurements that killed our first architecture. We assumed semantic search would find what was worth reading, so we tested it against the items that had actually produced facts, and it found under one in ten. A cheap reader that misses 90% of your life is not cheap; it’s broken. So this product reads everything once, instead of guessing what matters, which forced serious cost engineering to make a full read of a very large archive affordable. If you build your own: measure retrieval against ground truth before you trust it, because it will demo beautifully and quietly miss almost everything.

If I build my own anyway, what should I get right?
  • Decide where the bytes live before anything else. Every default sends them somewhere.
  • Keep receipts from day one; a fact without its source is a rumor you wrote to yourself.
  • Mask identifiers in code, on the way in, never trust the model’s promise not to extract them.
  • Plan for facts aging. A record that can’t say “unconfirmed since” slowly becomes fiction.
  • Make the system audit itself. Every failure we’ve had was silent; the errors that announce themselves are the easy ones.
  • Budget for the librarian. The daily filing and correcting. That’s the real cost, and it’s paid in your evenings.

Part five, The competition

How is this different from estate organizers?

They’re blank forms. You only get out what you type in, and almost nobody finishes typing a life into a form, which is why those products are graveyards of half-filled profiles. Your record starts from the other end: it reads what already exists and holds what you never told it. The first week, it knows things. That’s the difference a family actually feels.

Everyone is building agents and second brains. Why yours?

We don’t know which agent wins. Neither do you, and that’s the point. Agents will come and go for years; what every one of them will need is the thing none of them can make: an accurate, receipted, current record of your life. That’s the durable layer, and it’s the layer we build. Yours is portable on purpose, plain-file and machine-readable exports, and seats you can grant to any agent you choose, scoped to exactly what you allow, with a ledger of what it read. You’re not betting on us winning the agent war. You’re making sure whoever wins has something true to read, and permission slips you control.

How is this different from building my own G-Brain?

There are two ways to end up with a record of what you know. Build one and staff it yourself, Garry Tan proved it works, at the cost of being his own librarian for years. Or let one build itself from what you already have. Same destination; the difference is whose evenings pay for it. We also do two things a hand-built brain doesn’t: name what stopped (a librarian files what arrives; nobody files silence), and keep receipts on the readers when you share it.

Why not just point an AI assistant at my accounts?

Try it, honestly, and watch what it can’t do. An assistant answers the questions you already know to ask; it will never walk up to you with “your umbrella policy stopped billing in April” because you didn’t ask, and it wasn’t looking. It searches at question-time, and we’ve measured that kind of search against ground truth: it finds under one in ten of the items that matter. It holds no standing facts, so the same question gets a different answer on Tuesday than it got on Sunday, and neither one ages or says “unconfirmed since.” It has no receipts a family can walk without you, no seats, no ledger of who read what, and when your login dies, it knows nothing and owes nobody. An answer is not an estate. An assistant is a mouth; a record is a memory. You can put any mouth you like in front of ours.

Isn't my password manager enough?

A password manager holds keys. It cannot tell your wife which accounts exist, which policy lapsed in April, who the attorney is, or what you promised your brother in 2019. Keep the password manager. It holds the keys; your record holds the map. A family needs both, and the map is the half nobody has.

Still asking? The precise versions live on the trust page.