Why an AI that reads your life has to run on hardware you own, and why an answer you cannot check is not an answer.
Thirty years of records, scattered everywhere. Email across three services and two that no longer exist. Text messages on a phone, and on the phone before that. Contracts, leases, amendments, the signed version and the nine drafts that came before it. Tax returns, K-1s, statements. Photographs by the tens of thousands. Voice notes to myself. Calendars going back further than I can remember caring about.
Somewhere in all of it was the answer to almost any question I had about my own life. And there was no way to ask.
The tools that could actually answer wanted the same thing first: upload it. All of it. Hand over three decades of your life to a company’s servers, and in return you get a search box that works.
I am an operator and an investor, not a programmer, and I have spent a long career reading agreements carefully. That one is not a good deal. Not because anyone is necessarily acting in bad faith — but because once the copy exists, it exists. Policies change. Companies are acquired. Terms are updated. The only version of that arrangement I would sign is the one where the copy never gets made.
Useful and private were being sold as a choice. I did not accept that they were.
So I built the thing I wanted. It reads everything on my own hardware. It answers in plain English. And it shows me the actual emails and documents behind every answer, so I never have to take its word for anything. Nothing leaves the building.
While I was building it for myself, something larger was happening. AI stopped being a thing you consulted and became the thing quietly doing the work. It drafts the emails. It summarizes the meeting you missed. It recommends the action, writes the code, and increasingly decides — on your behalf, at speed, and without being asked twice.
Everyone talks about the leverage this creates. Very few people are talking about what it costs, which is visibility. The person accountable for a decision is steadily further away from the reasoning that produced it.
I do not think the hard problem of the next decade is building smarter AI. Plenty of very capable people are on that. I think the hard problem is far less glamorous: letting the people who are responsible for a decision see what their AI actually did, and why.
This is the part I feel most strongly about, and it is the same principle whether the question is about my roof or about a company’s margin.
Every significant decision should be explainable. Every important answer should be supported by evidence. Every recommendation should trace back to the thing that produced it — the email, the contract, the meeting, the financial record, the photograph with a date on it.
That layer mostly does not exist. What exists instead is a generation of tools that are extraordinarily good at sounding right. They answer in confident, well-formed prose whether or not the underlying claim survives contact with the documents. And they sound exactly as confident when they are wrong.
Convincing and trustworthy are not the same word. The next generation of this software will not compete on which one produces the most convincing answers. It will compete on which one produces answers you can check.
Trust comes from evidence. Evidence creates confidence. Confidence is what actually improves a decision. Everything else is a well-written guess.
It means an assistant that finishes a task is not what I am after. I want something that investigates the question — that goes and looks across everything, finds the evidence for each claim, weighs explanations that compete with each other, and says out loud what it cannot see yet.
That last one matters more than it sounds. A system willing to tell you “the March figures have not posted, so this number may move” is worth ten that answer smoothly and leave you to discover the hole yourself.
And it means never a silent merge. If two companies have similar names, they stay two companies until I say otherwise. A guess never overwrites something I have stated as fact. The system asks; it does not decide on my behalf and tell me afterwards.
What I built for my own archive is what we are finishing first, and it is what the rest of this site is about. It runs on your hardware, it answers in your own words, and it hands you the documents.
There is a second thing, and I will be plain that it does not exist yet: the same idea pointed at a company rather than a life. An organization’s memory — its mail, its contracts, its ledgers, its meetings — investigated the same way, with the same rule that every conclusion arrives with its evidence attached. I have written about that on its own page, marked clearly as what it is: in development.
In the long run I think those are one system, because a leader’s own context and their company’s memory turn out to be the same question asked from two directions. But I would rather tell you where we are than where I hope to be.
No advertising. Nothing here is funded by showing you anything. No selling or licensing your information, and none of it used to train anybody’s model. No analytics script sitting inside the product watching what you ask.
And no cloud copy of your archive — not a backup, not a cache, not a copy retained for support purposes. That is not a policy we could quietly revise in a future version of the terms. It is a consequence of where the data sits, which is the only kind of promise I would ask anyone to rely on. The security page spells out exactly what that means, in language you could hand to your accountant.
Privy started as one man’s archive. It is becoming available to yours.
Lowell Sharron
Founder, BePrivy.ai
The internal draft this letter grew out of, reproduced unedited. It is written for an investor audience and in the present tense about things still being built — read it as a statement of intent rather than a description of a shipping product.
Nothing leaves the building.
Privy is in development. If you would like to hear when it is ready, write to us.
Request early access