Your data belongs to you
Last updated July 18, 2026
Lethe minimizes what leaves your device, and remembers you through a structured understanding of what you've said rather than a transcript of how you said it. This page walks through exactly what happens to your data at each step, what Lethe permanently remembers, what you can export or delete, and where things stand on privacy protections we haven't finished building yet.
Your data's journey
Raw data → Understanding → Memory → Features. Every step below is what actually happens today, not what's planned.
1. Raw data
What you type in chat, documents you upload, and conversation exports you import. This is the only stage where your original wording exists.
2. Understanding
Lethe reads raw data once to extract structured understanding — goals, decisions, relationships, and preferences you've actually stated — each piece paired with a short verbatim quote as evidence for why Lethe believes it. That extraction step runs on a backend model Lethe chooses for you, regardless of which model is generating your chat replies.
Separately, to generate each chat reply: the AI model you choose (or Lethe Auto, which picks one for you) processes your message text as you wrote it. Different models may have different privacy characteristics — Lethe always aims to minimize what's sent according to the capabilities available today, whichever one is handling a given request. No redaction or anonymization happens before your message leaves your device yet (see "Planned" below).
3. Memory
What persists: the structured understanding from step 2, documents you write and save yourself, and anything you put in your private Vault — because you explicitly asked Lethe to remember those as-is.
What doesn't: raw chat messages and imported conversation exports. They're processed in memory to extract the understanding above, then discarded — nothing about your account depends on keeping the original wording around once that's done.
4. Features
Animus, and everything else Lethe shows you, reads only from the memory graph built in step 3 — never from your raw conversation history. That's true whether it's answering a question, building your workspace, or generating a report.
Your Vault is fully on-device
Vault chat never reaches a cloud AI provider — it runs entirely on your device through a local model, and if that local model isn't running, Vault simply tells you rather than quietly falling back to the cloud. Everything you store in Vault is encrypted before it's saved, using a key derived from a passphrase only you hold — we cannot read your Vault contents, and losing the passphrase means losing that data permanently, by design.
Two more Vault protections run automatically: Scanner flags things like API keys or ID numbers before you save a document, and offers to move them to Vault instead — it never acts on its own or shows us the matched value. Boundaries asks before connecting a normal chat to something in your Vault (once, always, or never) — it never happens silently.
| Standard | Vault | |
|---|---|---|
| Chat | Cloud AI (your chosen model) | Local model on your device — never the cloud |
| Documents | Processed by a cloud model to build understanding | Stays local if saved into Vault instead |
| Memory | Stored as a derived graph (see steps 2–3 above) | Stored encrypted, separately, key held only by you |
| Export / delete | Export or delete everything from Settings | Delete conversations one at a time, inside Vault — not covered by Settings' export/delete |
How you can export or delete your data
From Settings, you can export your entire derived memory as a portable file at any time, or delete everything — locally and in the cloud — permanently and immediately. Nothing about your account requires keeping data you've asked us to remove. Vault is separate: delete a Vault conversation from inside Vault itself (see the table above) — Settings' export and delete don't reach it.
What's shipped vs. what's next
Today
✓ Structured memory instead of storing raw chat history
✓ Vault — fully on-device chat, encrypted at rest, only you hold the key
✓ Export your entire derived memory, anytime
✓ Delete everything, locally and in the cloud, immediately
Planned
Encrypting the derived memory layer at rest — today it's protected by account-level access controls, not encryption; only you can reach it through your signed-in account, but it isn't yet encrypted in our database. We're deliberately building this after the data model has stabilized from real use, rather than encrypting a shape we may still need to redesign.
A user-facing privacy mode, so you can choose how much gets minimized before a request leaves your device. The anonymization pipeline itself is already built and tested — it just isn't switched on for anyone yet.
Local extraction and entity resolution, so building your memory graph doesn't require a cloud call either.
Lethe is an early, evolving product, and this page will change as the product does — we'll keep it accurate rather than aspirational. Questions? Reach out any time.