On your own machine, your memory never leaves it. In the cloud, it is encrypted under a passphrase only you hold — locked, it is unreadable to everyone, us included. The processing runs in a secure compute instance in Zurich, Switzerland, and keeps nothing. And it is already there: rules arrive with almost every message, the records that bear on a prompt arrive with it, a brief opens every session — and when that is not enough, everything ever said can be searched.
Free tier · no credit card · recall is never metered or capped
🇨🇭 Zurich secure compute Passphrase-locked memory 🛡️ Zero data retention thinking Local container edition
There's a reason most "memory" tools end up unused. They're a drawer: you have to remember to open them. You have to recall that the drawer exists, and that the thing you need is in it, and then you have to make the model's next step be "go look in the drawer." That only works when you're diligent enough to ask — which is exactly the moment you won't. Brethof-brain is not a drawer. Four things, and as far as we know no one else offers them together.
On your own machine, the memory never leaves it — we could not read it if we wanted to. In the cloud, the memory is encrypted under a key only you hold; locked, it is unreadable to everyone, us included.
Every conversation passes through our hub — that is how memory gets made — but the hub only processes: each exchange stays only long enough to be understood, and the hub keeps none of it. It holds your standing rules and each project's one-line purpose, nothing else. It runs in a Tier III+ datacenter.
The model provider is bound by contract not to log, retain or train on what passes through. We state that as their commitment.
Rules arrive with almost every message. The records that bear on a prompt arrive with it. A brief opens every session. And when that is not enough, everything ever said can be searched.
At the start of every session the agent is handed the standing rules, what each project is, where the last sessions left off, and an index of what is known. On every prompt, the records that bear on it are added before the agent answers. Everything is organised by project, each with its own memory, its own knowledge and its own focus, set by a one-line purpose.
The current truth of each project, handed to your agent with every message they bear on. The memory curates itself: it reads what was said and keeps what a future session would need, reconciling new facts against old ones.
Standing instructions, loaded with most messages. Every agent on every project works the same way.
Every session kept in full and searchable. It is protected: it cannot be deleted piecemeal.
The connections and the history. Backtrack what happened, and when.
Your agent's own handover, written by it, loaded at the start of the next session.
A procedure written once and run by any agent on any project. A project's atlas — the map of the whole system — lives here.
Catches, in the background, the things that were said and meant. You check it later.
Export the whole history, delete a project, delete an exact phrase, or delete the account — from the panel, behind your own identity. If the network or our side is unavailable, the memory on your machine keeps recording and recalling; nothing is lost.
One choice at signup: memory lives local, on your own machine, or hosted, in our cloud, encrypted, in Germany. Both editions run the same memory and connect to the same hub. Plans and packs can change any time; only this choice is made once.
The memory — the records, the archive, the graph, the search — lives on your machine and never leaves it. We could not read it if we wanted to. Needs Docker or Podman, about 3 GB of disk including the memory model, a passphrase and a key from the panel; no elevated privileges. Storage is your own disk, unlimited by us.
The whole memory is encrypted under a key derived from a passphrase only you set and hold. It unlocks when you start a session and locks itself after an idle period you choose. While locked it is ciphertext to everyone, including us. If the passphrase is forgotten, no one can open it — and deleting the account still works without it.
Brethof AI is a company in Poland, in the EU. The processing runs in a secure compute instance in Zurich, Switzerland. Each exchange passes through it only long enough to be understood; the hub keeps none of it. The only things it holds are your standing rules and the one-line purpose of each project — the instructions, never the conversations or the memory itself.
The thinking uses a model provider bound by contract not to log, retain or train on what passes through. We state that as their commitment. On the hosted edition, memory is stored and searched in Germany; the processing pass runs on our secure compute in Switzerland; a single model pass goes to that zero-retention provider, transiently. Backups are the encrypted memory itself, in Germany, on a short cycle, deleted when the account is.
Records, the archive, the graph and the search live on your box — or, hosted, in a memory locked under your passphrase.
It passes through the secure compute instance in Zurich — a Tier III+ datacenter — only long enough to be understood. The hub keeps nothing.
A model under a zero-data-retention contract reads the exchange and answers. Nothing is logged, kept or trained on.
What was worth remembering comes back to your memory. The exchange is gone from everywhere else.
The archive is protected for you: individual messages cannot be quietly deleted; an exact phrase can be redacted; recent history is protected; a whole project or the account can be removed. Full legal detail is on the privacy, terms and security pages.
Most memory systems work by extraction rules and filters — a model is told what to keep, what to drop, how to file. That's caging it.
This memory is run by a model taught the way you'd teach a new hire: this is what's true, this is what changed, this is what we decided. It grows into the shape of your work instead of being fitted with a shape you have to maintain.
Don’t gate models. Teach them.
How we build everything at Brethof AI.
Summaries are what you have when you can't afford to keep the original. The summary is good until the detail you didn't think to keep is the detail you needed. This memory doesn't summarize. Every session is archived and can be searched later. The curated memory is the current truth — dense and up to date. The archive is the complete raw recording. Notes are fast but lossy; the recording is the insurance.
Curated records, rules, the full chat history, the graph, notes, playbooks and the Ledger — and how they arrive on their own.
Read more →Each project has its own memory, its own knowledge and its own focus, set by a one-line purpose. Rules are standing instructions loaded with most messages.
Read more →Install the client the harness's own way — a plugin or a native adapter. It talks only to your own memory. Proven on Claude Code (Linux and Windows), dsh, Codex, Qwen Code, Cline, OpenCode, Kilo, OpenClaw and Hermes Agent.
Read more →The unit is the message — one exchange, a prompt and its reply. No token counts. Everything the memory does under a message is inside its price. Reaching the allowance stops the learning, never recall. Same price everywhere on Earth, on both editions.
See plans →The free plan needs no credit card. These are launch prices, available for a limited time — anyone who subscribes keeps their price for as long as they stay subscribed. Get started free
Local speech-to-text that learns your voice. Perpetual licence. Our flagship.
PAID · flagship
Long-term memory for your AI agents — full-text + vector + graph. Briefed at session start, recalled on every prompt, archived automatically.
PAID · free tier
Print-ready digital models. GLB and OBJ included. Lifetime access.
PAID · digital catalog
Five printers and real capacity. No self-serve shop yet — tell us what you need and we quote it by email.
BY ARRANGEMENT · email us
Our YouTube channel. A cyber-tiger host walks through local AI tools and what they actually do.
CHANNEL · live
Curated GitHub lists for AI coding agents, MCP servers, local AI and Linux for AI. Every entry carries a source link.
FREE · curated
Long-form how-tos for local AI on Linux, Windows and macOS, with the configuration files included.
FREE · live
Negative-curation: practices and tools that waste your time, ranked. Receipts required.
FREE · live
Who we are, why we build privacy-first AI, and what we won't do.