No alwyse employee or cloud admin can read your content
- Self-host Not applicable
- Cloud Not offered
- Cloud Confidential Not offered
On self-host, this question doesn't arise. There is no alwyse operator to be blind: the
person who installs it is both the operator and the user, and that is you. The sentence is
trivially true, which is exactly why we won't sell it to you as something we provide. The
moment an operator does enter the path on self-host — when you reach your box from
your phone, over our relay — it becomes a real question, and it has its own row below.
On Cloud it is not true, and we won't pretend otherwise. Cloud uses standard isolation, the
same kind most software you already rely on uses. That's a reasonable protection, but a
determined administrator with infrastructure access could reach your data. This is not a gap
we are racing to close on that tier: standard isolation is the tier, by design. What
we built instead is the next claim, and it is a real one.
Cloud Confidential is the tier that would close it without asking you to run anything, by
sealing your content inside confidential-computing hardware. It does not exist. The approach
is designed, no build is scheduled, and so we make no present-tense claim about it anywhere.
Your device can cryptographically verify that blindness
- Self-host Not applicable
- Cloud Not offered
- Cloud Confidential Not offered
A promise you can't check is just a promise. Attestation is the proof: your device asks the
hardware to show it's running the exact sealed software we published, before it trusts
anything to it. On self-host there is nothing to attest, since you already hold the keys and
run the code. On Cloud there is nothing to attest either, because Cloud is not operator-blind
to begin with, and it never will be. Attestation is the defining feature of Cloud
Confidential, and it arrives when that tier does. No build is scheduled, so until then we
don't claim it.
Running the service never requires reading your content
- Self-host Not applicable
- Cloud Shipped
- Cloud Confidential Not offered
"We don't offer operator-blindness" is a non-answer for the tier nearly everyone is actually
on. So here is what Cloud does promise, and it is built, not planned. Your cognition lives in
a cell of its own: its own instance, its own database, not a row in a shared table. The
control plane that handles your account, your payment, and finding your cell holds only
account records, content-free meters, and key fingerprints. It never receives your content.
When alwyse thinks, your cell calls the selected model provider directly; that traffic never
passes through our control plane. A destination may use a key you bring or an Alwyse-funded
provider account. For the funded option, we can see the provider-side usage metadata named
in the handling facts you accept, but never the model content through the control plane.
Your export is served by your cell, never by our control plane. Each cell holds only its own
keys, so a compromise of one is an event confined to one.
And our logs cannot contain your content, because the content is never captured to begin
with. Where a log could be read by an operator, alwyse doesn't build the payload rather than
building it and filtering it. A filter is a leak waiting to be misconfigured. What the
model-crossing record names is the destination authority, never the path, the query, or a
word of what was in it.
Here is the limit, stated in the same breath. We operate that cell. An administrator with
access to the underlying infrastructure could reach the data at rest inside it. That is
precisely why this is not operator-blindness and why we never call it that. This claim says
running the service does not require reading you, and that we built it so it doesn't.
It does not say we cannot.
You can run alwyse entirely inside the boundary
- Self-host Shipped
- Cloud Building
- Cloud Confidential Not offered
AI needs a model to run, and where that model runs decides who sees your content. A model
inside your boundary sees it and tells no one. A model outside it is a vendor, under their
terms. On self-host you can run entirely on local models, and then nothing crosses at all:
there isn't even a crossing to record.
On Cloud today, background cognition uses a named Alwyse-operated inference destination
outside the cell boundary. You may separately choose an external provider for interactive
thinking. The trust sentence names both legs rather than collapsing them into one route. A
shared model host inside the boundary, so a Cloud instance can think without model content
leaving, lands before broad launch.
A sealed enclave does not by itself stop your content reaching a model vendor. Those are
separate questions, and conflating them is how a privacy claim quietly becomes false. What
would keep content inside Cloud Confidential is that its models run inside the seal too, and
that arrives with the tier. Even then, you may still choose to reach out to a frontier model
from inside it. That choice stays yours.
Recorded model crossings, and the levers over them
- Self-host Building
- Cloud Building
- Cloud Confidential Not offered
The model path is real. Settings presents only destinations granted for interactive and
background thinking. Selecting either leg advances its destination generation and presents
the exact current handling facts. No owner content is sent until you separately accept them.
Every model crossing is then destination-guarded and recorded content-free, and the trust
sentence names both selected legs.
The broader levers do not exist. There is no general consent dial, no compartment-aware
routing, and no unified egress gate. You can choose and sever sources, and you can choose
model destinations, but alwyse cannot enforce a standing subject rule over everything it may
reach. We name the model guarantee precisely rather than letting it stand in for every kind
of crossing.
You can reach your own instance remotely without alwyse seeing your traffic
- Self-host Building
- Cloud Not applicable
- Cloud Confidential Not offered
Self-host is the one place where alwyse has no operator in your path, and the relay is the
one thing that would put us there. Reaching the box in your home from a phone on a train
means passing through something of ours. The backend relay substrate now exists, and native
clients can pair, pin the instance identity, and switch between direct and relay paths.
The public claim still waits. The production sidecar must be isolated so it has no route to
direct ingress, and the real path must pass live cross-client verification. Until both are
true, public reach remains LAN and local discovery only. Remote reach and blind transport
ship together or the copy waits.
You can take everything out
- Self-host Shipped
- Cloud Shipped
- Cloud Confidential Not offered
Ownership means you can leave with everything you said and everything alwyse concluded.
Full export ships today. It withholds only the recall search index, which a rebuilt instance
recomputes from that cognition. The export is served directly by your own instance and never
passes through our control plane, so it is content-blind on both offered tiers. On self-host
and on Cloud you can do this now. On Cloud Confidential it arrives with the tier.
You can delete anything
- Self-host Building
- Cloud Building
- Cloud Confidential Not offered
Ownership also means you can erase, and most of this is real today. In every alwyse app — on
the web, on iOS, on macOS, and on Android — you can delete a single entry, or everything
derived from a connected source, from your settings. It is gone from every live read
immediately, cascading through whatever alwyse inferred from it, and any copy sitting in a
backup expires within thirty days.
This is the standard we hold ourselves to, in the words alwyse uses with you:
Deleted means gone — removed from everything I show you right away, and then erased
for real. Not hidden.
The live removal, physical compaction, service-readable backup expiry within thirty days,
and the first owner-sealed quarantine-restore path ship. The row remains building because a
total-loss recovery still needs continuous signing authority, an independently durable
latest head, and control-plane journaling that prevents an old backup from silently
resurrecting deleted content. Automated content-blind retention custody also remains.
None of this is in tension with alwyse keeping a faithful record of your life. Append-only
is a promise about integrity, not a refusal to forget: it means your history is never quietly
rewritten, and that corrections supersede rather than falsify. You decide what alwyse holds;
alwyse decides only that it won't rewrite the past behind your back.
Boundaries you set over sources
- Self-host Building
- Cloud Building
- Cloud Confidential Not offered
The source boundary ships on both offered tiers. You choose which accounts and sources feed
alwyse, every connection can be severed, and a severed source stops supplying new material.
That is the boundary this site means when it says you choose what feeds alwyse.
A subject boundary does not exist. You cannot mark a domain such as medical conversations
off-limits, split work from personal cognition, or set a rule that routing, retrieval, and
egress then enforce. The consent dial, compartment-aware routing, and unified egress gate are
not built or scheduled. We do not describe source choice as enforcement over subjects.
Understanding you can see and correct
- Self-host Building
- Cloud Building
- Cloud Confidential Not offered
The “You” surface ships on web, iOS, macOS, and Android. It shows standing profile facts,
says whether you stated or alwyse inferred them, and puts controls over learned adaptation
and standing instructions beside that view.
Correction is conversational or confirmation-mediated: tell alwyse it got something wrong,
or reject a grouped confirmation, and the correction supersedes what came before. There is
no per-fact edit or remove control. The true promise is that the understanding is visible and
corrections reshape the model, not that every item is editable.