Memory is useful precisely because it is personal. That is also why treating it as an API payload is a bad habit.
A useful private agent needs durable context, but sending an entire personal model to a backend defeats the premise. The problem is selective recall: enough relevant memory to help, no ambient plaintext collection, and an honest erase path.
Giving a model every fact you have is a lazy version of retrieval. It makes the answer harder to inspect, the privacy boundary larger, and the failure mode more expensive.
A current question might need one preference, one recent decision, or one source note. The system should prove that it can choose that small card before it reaches for anything bigger.
An encrypted record is only part of the story. The key’s lifecycle matters: who holds it, when it disappears, and whether another signed-in account can ever see the first person’s context.
Prototype a local relevance gate with a fixed context budget, then measure answer quality, leakage surface, and failure behavior against a deliberately over-broad baseline.
Read the source-backed research note before treating this essay as a product promise.
One is a product of Hushh Technologies Corporation (brand: 🤫 “hussh”), an independent company. One runs on third-party silicon, systems, and cloud; platform names are used solely to describe where One software runs and imply no affiliation, endorsement, or sponsorship by those platforms. Our own go-to-market and bill-of-materials partner programs are real and actively in pursuit; we name a partner only once an agreement is executed.