Memory is useful precisely because it is personal. That is also why treating it as an API payload is a bad habit.
A useful private agent needs durable context, but sending an entire personal model to a backend defeats the premise. The problem is selective recall: enough relevant memory to help, no ambient plaintext collection, and an honest erase path.
Giving a model every fact you have is a lazy version of retrieval. It makes the answer harder to inspect, the privacy boundary larger, and the failure mode more expensive.
A current question might need one preference, one recent decision, or one source note. The system should prove that it can choose that small card before it reaches for anything bigger.
An encrypted record is only part of the story. The key’s lifecycle matters: who holds it, when it disappears, and whether another signed-in account can ever see the first person’s context.
Prototype a local relevance gate with a fixed context budget, then measure answer quality, leakage surface, and failure behavior against a deliberately over-broad baseline.
Read the source-backed research note before treating this essay as a product promise.
🤫 One is made by Hushh Technologies Corporation, an independent company. We name the hardware and clouds One runs on to say where it runs. None of them endorse us, and we call a company a partner only once the agreement is signed.