Trust

An AI this close to your life is only worth having if the terms are yours. Here they are, in plain facts.

Where Sathi lives

Today Sathi runs as a private deployment we operate. The same architecture is being shaped so execution can move closer to you without creating a second Sathi — or moving its understanding merely because a stronger model is consulted.

Sathi can live with us, live with you, or belong entirely to you.*

Sathi Systems operates your private deployment. Your archive is not stored by the model provider.

Models may change. Your archive and understanding stay with your Sathi.*

What leaves, and to whom

Sathi keeps your archive on its operated node. To help with a task, relevant messages, document or image content, audio and reply text may reach configured model and speech providers. Storage custody is different from processing. The provider entry below describes this boundary; self-hosting suitable models remains a direction.*

It is yours to take

Export your supported records and files as a sealed, signed archive. Deletion removes live records and their derived understanding; encrypted backups expire separately, and recipients or external processors may retain copies. Leaving issues a signed receipt of the operation, not proof every copy is gone; erasing the account removes more and issues no receipt. You can bring an archive back to a fresh Sathi.*

What we will not do

No advertising. No engagement optimization. Sathi never sells your personal data or pools it with anyone else’s to train anything; what a provider may do with a request it serves follows that provider’s terms, described below. Guests are never remembered; guest conversations are kept for testing and feedback for as long as an operator setting allows (30 days by default).

The honest limits

Sathi is in beta. The operator still runs the database, and during the beta operator support access is on by default — shown in your account, one tap to switch off — so problems can be found and fixed; it becomes opt-in once Sathi runs reliably without us looking. Every admin request lands in a tamper-evident audit log, but that is application-level enforcement, not yet cryptographic. Nightly backups are encrypted and kept off-site in Google Drive; a full restore was verified on 2 September 2026. There is no third-party security audit yet. When any of this changes, this page changes.

About the asterisk

Our product pages describe the experience we are building toward. An asterisk marks something still being implemented, planned, or awaiting verification. During beta, some functions use external providers. We intend to self-host suitable open models as scale makes that practical. The entries below describe today’s behavior and remaining limitations. Implementation status and independent review are separate questions.

A day at home

Intended experience
One Sathi helps each person in a household in their own way: a parent's school mail and calendar, a child's questions, the family's shared list, a grandparent's reminders.
Current behavior
The homepage shows a fictional household, drawn in code. Each moment uses something that works today: reading connected mail, offering a calendar event that you confirm before it is added, answering questions by voice or in writing, adding to a list shared with your family circle, and setting a reminder, or changing one when asked; reminders arrive as notifications. The home speaker is a prototype in a team pilot.
Remaining work / limits
On the speaker, only alarms and timers are spoken aloud; other reminders arrive as notifications. Mail and calendar need a connected account. Anything Sathi reads or changes stays within the permissions each person gave.

Source review: 20 September 2026. Availability and provider routing depend on live configuration and account permissions.

Read the detailed privacy account and provider terms →

Transcribe and external processing

Intended experience
Natural mixed-language transcription, with suitable open models self-hosted as scale makes that practical.
Current behavior
The current beta account names Google Gemini for transcription. Audio is sent to Google for processing; Sathi-owned weights are not serving this demo. The request is handled by Sathi’s API.
Remaining work / limits
The transcription backend is configurable. Self-hosted models must pass licensing and quality checks. Do not upload sensitive audio on an assumption of zero provider retention: downstream handling follows the applicable provider terms.

Source review: 20 September 2026. Availability and provider routing depend on live configuration and account permissions.

Read the detailed privacy account and provider terms →

Storage, models and serving providers

Intended experience
Your archive and understanding stay with your Sathi; external capabilities receive the context they need.
Current behavior
Sathi stores the archive on its operated node. Reasoning, image and speech routes are configurable and may use direct provider APIs or OpenRouter. Relevant context can reach the serving provider; a model’s developer, an intermediary and the actual host are different roles. Google processing and Resend account mail are supported. This source review does not certify each live route.
Remaining work / limits
This is not a promise that no data leaves Sathi or that all connectors will become self-hosted. Provider routing and retention must be read with the processing terms; no independent audit is claimed.

Source review: 20 September 2026. Availability and provider routing depend on live configuration and account permissions.

Read the detailed privacy account and provider terms →

Deletion and receipts

Intended experience
Delete from your Sathi and carry a clear record of what was removed.
Current behavior
Live deletion removes the affected records and derived understanding. Encrypted restic backups are kept separately in Google Drive and Oracle storage, with 14 daily, 8 weekly and 12 monthly snapshots. These counts do not guarantee deletion within 12 months: gaps in backups or failed cleanup can leave older copies.
Remaining work / limits
Only leaving issues a signed receipt today; erasing does not. A receipt authenticates the recorded operation; it does not prove every backup or downstream copy is gone. Backup expiration is separate from live deletion. External processors have their own retention obligations.

Source review: 20 September 2026. Availability and provider routing depend on live configuration and account permissions.

Read the detailed privacy account and provider terms →

Independent composition

Intended experience
Different personal and community systems cooperate recursively while retaining their capabilities, identity and legitimate control.
Current behavior
Sathi is the current implementation testbed; an independently reusable generalized framework has not been released.
Remaining work / limits
Preserved capabilities and lower reconfiguration costs are hypotheses to test. Organs may keep their own databases, models and runtimes. Replication should enable an independent cooperating participant, without requiring our brand or control.

Source review: 20 September 2026. Availability and provider routing depend on live configuration and account permissions.

Read the detailed privacy account and provider terms →

Every privacy question, answered →

The security posture, with its limits →

Company background and disclosed security partnership →