Trust & evidence
Marketing says trust us. This page says check. Every claim we make in public, and how you can verify it — today, and as the client opens up.
How to read this page. Where the proof is public today, it links to our covenant — which is version-controlled, so its history is auditable.
Where the proof is in the code, it isn't fully public yet: the client is on a path to open source (our stated commitment, not something we've shipped), and we mark those rows forthcoming rather than pretend otherwise. We'd rather you catch us being honest about a gap than sell you a claim you can't check.
“Encrypted on your device.”
The claimWhat Prumo learns is stored encrypted on your phone — not on our servers, not for sale, never used to train a model.
How it worksYour context lives in a SQLCipher-encrypted store on the device. Values, reflections, and transcripts are never written in plaintext — that's a hard rule we enforce in review, not a preference.
The honest boundaryBlocks Prumo holds on your calendar are the one deliberate exception: they live in your calendar service, on Prumo's own calendar, carrying the name and the hours, nothing else — and the app tells you this before the first write. Delete that calendar and they're gone.
How to checkRead covenant principle 2 (public, version-controlled). When the client opens source, the encryption and key-handling become directly inspectable.
Live: covenant · Forthcoming: open client
“Only the minimum ever leaves your device.”
The claimWhen Prumo needs the cloud to think, a membrane goes first: known people and patterns become tokens, and only the minimum needed to answer ever crosses.
How it worksBefore any request leaves, the membrane pseudonymizes and minimizes it. It replaces the people and patterns it recognises with tokens and strips the rest to what the question needs.
The honest boundaryThis covers the identifiers the resolver knows and the patterns we seed — not yet every arbitrary name. So we say “known people and patterns become tokens,” never “all personal information.” And we never say “zero-knowledge”: no practical AI can reason over data it can't momentarily read, so instead of pretending otherwise we prove no-retention, no-training, and no-access.
How to checkRead covenant principle 3. The mechanism is described there in the same words we use here.
Live: covenant · Forthcoming: open client
“Your most sensitive context never crosses without your say-so.”
The claimYour most sensitive context stays on the device unless you grant a live, revocable exception — and every crossing is logged.
How it worksThe most sensitive tier is fail-closed: it never crosses the membrane on its own. It crosses only under a grant you make in the moment, that you can withdraw, and every crossing is recorded so you can always ask what left and why.
Live: covenant · Forthcoming: open client
“We can't monetize what we can't read.”
The claimSubscription only. No ads, no data sale, no engagement games. Success is measured in your absence, not your attention.
How it worksThe only way we make money is a subscription you pay. There is no advertising business and no data business to trade your attention or your context into — the architecture above means we couldn't read your data to sell it even if we wanted to.
Live: covenant
“Built in the open.”
The claimWe show our work — the founder posts what shipped every week, and the client is on a path to open source.
How to checkRead the build log — the unmediated copy of the weekly evidence stream.
The honest boundaryThe open-source client is a commitment we've stated, not something we've shipped. Until it lands, the code-level claims above rest on the covenant and the build log, not on a public repo. We'd rather say that plainly than imply a repo you can't open.
Live: build log · Forthcoming: open client
What we don't claim yet
The fastest way to lose you is to claim something that isn't real. So, plainly, here's what Prumo does not do today:
Guardian — active protection that holds the noise until you're ready — is in build, not shipped. When it lands, it'll be here with its own evidence.
Reading your email and messages isn't connected yet. It's the keystone, and precisely because it's the most sensitive, it waits for the confidential-compute path that keeps it private. We ship the trust before we ask for the data.
Confidential compute (attested hardware, client-held keys) is the architecture that makes the above safe. It's research in progress — we name it as the plan, not as a thing you can use today.
Found a claim on this site that this page doesn't back up? That's a bug, and we want it. Tell us:
hello@prumo.life.