The core idea. live
No server of mine, anywhere.
Most apps keep your data on a company's servers. Arkhelion keeps it on your own Mac and puts your Mac in charge. An engine on your own Mac holds your keys and does the work; the screen just shows you the results. When you ask a cloud AI a question, the request goes straight from your Mac to that AI company, under your own key, never through anything of mine, because I don't run a thing in the middle. That's why Arkhelion never sees or sells your data and you hold the keys: there is nowhere in the middle for me to sit. Everything below is a consequence of this one choice.
Your data, your keys. live
One locked file. Your key.
Everything Arkhelion knows about you is a single scrambled file on your Mac. No cloud database, no account, no sync. It's locked with a key that only you hold, and even the tools built into your own Mac can't open it, which is the plainest proof the lock is real and not just promised. Nothing about you is tracked or sold: no analytics, no usage tracking, no ad networks. The app you'd download never reports what you did, when you opened it, or that you exist.
- The key Made on your Mac the first time you run the app, from the system's own randomness. It's never sent anywhere, and I have no copy and no way to make one.
- On paper You see the key once, at setup, to write down. Lose that paper and the file is gone for good, even to me. That isn't a flaw. It's the honest cost of the promise.
- Backups The same locked file, copied to a spot you pick, scrambled before it ever leaves. A rolling thirty days are kept.
- Deleting it Delete the file and its backups and Arkhelion's memory of you is gone. Nothing is kept anywhere else.
- The crash log A crash reporter is built into the app, and it's switched off: it can only send anything if it's handed an address at launch, and the app you'd download carries none. I use it on my own test builds only. If that ever changes, it'll be opt-in and said here first.
Fingerprint unlock. coming soon
Built. Just not switched on.
The fingerprint unlock (Touch ID) is written and it works. It's simply not turned on yet, and I'd rather say so here than let you assume otherwise. The reason is boring: macOS only lets an app use the fingerprint reader if the app is signed with a paid Apple certificate, and I'm buying that certificate last, right before real strangers use this. Until then it can't switch on, so it isn't part of what protects you today. What protects your file today is the lock and key above. When the certificate lands, this turns on and this page changes to say "live".
The AI. live
Your account. Your key.
Arkhelion doesn't sell you AI. You bring your own account and paste your key once at setup; after that the screen never sees it again. The key is attached to each request down in the engine, and the request goes straight from your Mac to the AI company. Nothing of mine sits in between. You bring the account and the key, which means the company on the other end is one you signed up with yourself: it's on your own bill, in your own dashboard, not hidden behind a logo on this page.
The honest part, said plainly: when you ask a cloud AI a question, that company receives what you asked and the slice of your record the engine pulled to answer it, up to twenty items and fifty recent messages. For a health question, that's your health context. Not your whole file, but not nothing. That is simply what a cloud AI is. What Arkhelion controls is that it's your account, your key, and that your whole file is never handed over. What no one can do is make a company un-see a question you chose to send it. Anyone who tells you otherwise is selling something. The on-device AI further down is the real fix, and it isn't finished.
- Hard questions Some questions deserve more than the first answer that comes back. For those, Arkhelion takes the slow path: it works the question harder and argues with its own answer before it shows you anything. It takes longer and it costs more, which is exactly why it's saved for questions that earn it.
- Everyday questions Ordinary questions get a quick answer instead. Not everything is a board meeting.
- The optional second key Setup offers you a second AI account to connect. It's optional and Arkhelion works without it. If you do connect it, that's a second company seeing the questions that reach it, on your account, the same deal as the first. Leave it out and there's one company in the picture instead of two.
What's inside. live
One core, a few rooms.
Arkhelion is one engine with separate rooms built on top of it. Health and your calendar read the same engine and the same file, which is what lets it read your recovery against your week. That join is the whole point, and it's the thing a second, separate app can never do.
- Health Your body and your week, read together. Connect an Oura ring to fill it. This is the wedge, and the most finished part.
- Hard questions A room for the ones worth the slow path, described above.
- Home base The screen that knows your day.
- Type anywhere Start typing to jump to any room or run any command. Its quick-answer box uses the optional second key; jumping and commands don't.
Those four are live today. A calendar room is wired up and reachable, waiting for you to connect a calendar. Three more (money, school, and faith) have code written but are switched off for this version, so they aren't in the app you'd open. I'd rather list them here as "not yet" than let a screenshot argue with this page.
What it looks like.
Ask in plain words.
First read · Keyless · Local
Your recovery, read against your week. When the two move together, you see it in plain language: a correlation in your own record, never a diagnosis. When a stretch looks worth a closer look, it says so, with a question you could bring to your doctor.
What it protects, and what it can't. live
Both halves, said honestly.
A security promise is only worth what it admits it can't do. So here is both halves, in plain terms.
What it holds up against
A lost or stolen Mac: the file is locked and the key lives in your Mac's keychain. A break-in on my end: there's no server of mine holding your record, so there's nothing to steal. A court order served on me: I can't hand over what I never had. Me changing my mind, or getting bought: the architecture stops it, not my good intentions.
What it can't protect against
Your own Mac, broken into while you're logged in: at that point the attacker is you, and no app on your machine survives that. Losing your key with no paper backup: the file is unrecoverable, on purpose. The AI company you chose: it sees the questions you send it, and the slice of your record sent along. Someone with your Mac, your password, and enough time.
The one server I run
A waitlist, which is probably how you got here. It holds your email, and if you chose to say, how you heard. Like any sign-up form, it also keeps a little anti-spam metadata: a shortened version of your IP address, a scrambled fingerprint of your browser, and your country. The app never talks to it. No part of the product calls home to me. I'd rather name it than let you find it.
Not true yet
Fingerprint unlock is off, for the certificate reason above. The promise that the key never touches your disk is best-effort, for the same reason. Nothing here has been through an outside security audit. It's built by one person, and one person is a real limit on how sure you can be, whatever the design says.
AI that never leaves home. future
The goal: nothing leaves.
The end of this whole argument is an AI that runs on your Mac itself, so no question ever leaves and you'd need no outside key to use it. Here is exactly how far off that is, because it's the easiest thing to fudge. The on-device piece that exists today does one narrow job: it reads your own text to pull structure out of it. What is not written is the part that would send your questions to it instead of to a cloud company. Every answer today still goes to a cloud AI through your key. The model itself doesn't ship, the local path is off unless you turn it on, and it wants more memory than my own machine has. So: real code, not a shipped feature, and not yet the thing that keeps your questions home. I won't call it live because a file exists. When it answers an ordinary question on an ordinary Mac, it moves up this page.
Where it's going. future
It proposes. You approve.
None of this ships yet. No code for it exists. It's the direction, and it's why the parts above are built the hard way.
Propose, then approve
The long-term shape is an AI that does real work: drafts the message, books the trip, preps the appointment. The line that never moves is who says yes. No autopilot, no "it learned your habits, so it went ahead." You approve each action, and that has to hold precisely when approving is inconvenient, or it isn't a promise.
A record you can prove
Every approval would be written down on your device: what was proposed, what you said yes to, when, and what was then done. Local, yours, and checkable. You could prove what you agreed to, and prove what you didn't. New rules for AI are all headed for one question: can you show the person said yes? This would answer it by design, because the yes is per-action, provable, and held by you.
It already knows you
Every assistant today starts each task as a stranger, asking your dates, your budget, your size. Arkhelion would already hold that, so the task would start knowing you. That value stays in your file, under your key, and leaves with you if you go. No one can offer the same thing without the same architecture. It isn't that you're stuck.
Who's building it.
One person. In the open.
Solo and bootstrapped, on a Mac, in public. The Mac app is what runs today, and it's my own daily command center, so the product's first demanding user is me. The real product is the phone, because health lives on your phone, and it doesn't exist yet. It will share this same engine and this same locked file, not a second codebase with a second set of promises. The order is on purpose: win the hard cases first, people whose health is complex and unresolved, then widen. If this page reads as underclaiming, that's the intent. I'd rather you find it modest and be surprised later than find it slick and be let down.
If you want to check the work.
This is the plain version. There is a longer one.
The technical dossier describes the same system for someone who wants to verify it rather than be reassured by it: the exact encryption and where the key lives, the data model, the dependency and licence list, how a question escalates through the models, what the test suite actually asserts, and the same honest list of what isn't true yet. Every claim in it is written against the source code. It is long on purpose. If you're an engineer, or you're deciding whether to trust this with a health record, read that one instead of this one.
Runs on macOS today. iPhone is next.