Your data belongs to you
Last updated July 26, 2026
Lethe minimizes what leaves your device, and remembers you through a structured understanding of what you've said rather than a transcript of how you said it. This page walks through exactly what happens to your data at each step, what Lethe permanently remembers, what you can export or delete, and where things stand on privacy protections we haven't finished building yet.
Your data's journey
Raw data → Understanding → Memory → Features. Every step below is what actually happens today, not what's planned.
1. Raw data
What you type in chat, documents you upload, and conversation exports you import. This is the only stage where your original wording exists.
2. Understanding
Lethe reads raw data once to extract structured understanding — goals, decisions, relationships, and preferences you've actually stated — each piece paired with a short verbatim quote as evidence for why Lethe believes it. That extraction step runs on a backend model Lethe chooses for you, regardless of which model is generating your chat replies.
Separately, to generate each chat reply: the AI model you choose (or Lethe Auto, which picks one for you) processes your message text as you wrote it. Different models may have different privacy characteristics — Lethe always aims to minimize what's sent according to the capabilities available today, whichever one is handling a given request. No redaction or anonymization happens before your message leaves your device yet (see "Planned" below).
3. Memory
What persists: the structured understanding from step 2, documents you write and save yourself, and anything you put in your private Vault — because you explicitly asked Lethe to remember those as-is.
What doesn't: raw chat messages and imported conversation exports. They're processed in memory to extract the understanding above, then discarded — nothing about your account depends on keeping the original wording around once that's done.
One deliberate exception: when you open a project workspace and chat inside it, that project conversation is kept as the project's running log — including in the cloud, so it’s there when you sign in on another device. It’s the one place a raw transcript is stored rather than discarded, because a project’s own thread is part of the project. Ordinary chat outside a project is not kept.
Life preferences
As you talk, Lethe also notes durable everyday preferences — the food you like, how you dress, how you like your space, how you prefer to work — the same way it notes anything else: as a structured fact with the quote behind it, not a transcript. This is what lets it stop asking you the same things.
Health and money are deliberately excluded — Lethe does not record preferences about your medical situation or your finances at all. And anything it infers, you can correct; a correction always outranks a guess.
Connecting Lethe to other AIs
You can connect Lethe to Claude, Cursor, or any MCP client. They receive only your derived understanding — never your raw conversations, and never your Vault — along with how confident Lethe is in each item, so a guess is passed on as a guess. You choose which categories each connection can read, every read is written to an access log you can see, and you can revoke any connection instantly.
4. Features
Animus, and everything else Lethe shows you, reads only from the memory graph built in step 3 — never from your raw conversation history. That's true whether it's answering a question, building your workspace, or generating a report.
Your Vault is fully on-device
Vault chat never reaches a cloud AI provider — it runs entirely on your device through a local model, and if that local model isn't running, Vault simply tells you rather than quietly falling back to the cloud. Everything you store in Vault is encrypted before it's saved, using a key derived from a passphrase only you hold — we cannot read your Vault contents, and losing the passphrase means losing that data permanently, by design.
Two more Vault protections run automatically: Scanner flags things like API keys or ID numbers before you save a document, and offers to move them to Vault instead — it never acts on its own or shows us the matched value. Boundaries asks before connecting a normal chat to something in your Vault (once, always, or never) — it never happens silently.
| Standard | Vault | |
|---|---|---|
| Chat | Cloud AI (your chosen model) | Local model on your device — never the cloud |
| Documents | Processed by a cloud model to build understanding | Stays local if saved into Vault instead |
| Memory | Stored as a derived graph (see steps 2–3 above) | Stored encrypted, separately, key held only by you |
| Export / delete | Export or delete everything from Settings | Delete conversations one at a time, inside Vault — not covered by Settings' export/delete |
Export, back up, or delete your data
From Settings you can export your entire derived memory as a portable file anytime, or download it one area of life at a time. You can also make an encrypted backup — a complete copy locked with a passphrase only you hold, which you save wherever you like. We never receive that backup and cannot open it; lose the passphrase and it can’t be recovered, by design.
Delete everything does two things: your raw project conversations are deleted from the cloud and this device for good, and your derived understanding is deactivated — it disappears from your workspace, search, chat, and any connected AI, but stays exportable so you can still retrieve it. Vault is separate: delete a Vault conversation from inside Vault itself (see the table above).
What's shipped vs. what's next
Today
✓ Structured memory instead of storing raw chat history
✓ Vault — runs on a model on your own device, encrypted at rest (AES-GCM); only your passphrase can unlock it, and we never store it
✓ Privacy modes — choose how much is minimized before a request leaves your device
✓ Names replaced with pseudonyms before anything is stored
✓ Connected AIs get your understanding with its confidence — never raw chat, never Vault — and every read is logged
✓ Export your memory, or an encrypted backup only your passphrase opens
✓ Delete: raw conversations erased, derived memory deactivated but still exportable
Planned
Encrypting the derived memory layer at rest — today it's protected by account-level access controls, not encryption; only you can reach it through your signed-in account, but it isn't yet encrypted in our database. We're deliberately building this after the data model has stabilized from real use, rather than encrypting a shape we may still need to redesign.
Local extraction and entity resolution, so building your memory graph doesn't require a cloud call either.
Lethe is an early, evolving product, and this page will change as the product does — we'll keep it accurate rather than aspirational. Questions? Reach out any time.