Privacy Policy
Short version: everything PriorStates makes is local-first. Your memory, your documents, your apps and what you shape run on your own device or your own computer, with the AI you already have there. Nothing is sent to us unless you choose a hosted feature, and then only what that feature needs. No telemetry, no analytics, no accounts except the optional Memory server.
Last updated: 27 September 2026 · one policy for every PriorStates product; Palmtop's phone app also has its own, store-facing policy.
PriorStates Memory (open source)
Memory runs entirely on your device. Your memory, journal and project
data are stored locally (under ~/.priorstates and your per-project
.priorstates/) and never sent to us. The software contains no telemetry, no
analytics and no usage tracking, and needs no account or API key.
The only outbound requests it makes are the ones you ask for:
- installing the package from PyPI or GitHub;
- a one-time download of the local embedding model from Hugging Face (skippable with
--lite); - connecting to an AI agent on your own machine over the Model Context Protocol (MCP).
If you point Memory at a third-party model or service yourself, that provider's own privacy terms apply to those requests.
The Memory server (optional, hosted)
Memory is open core. If you choose to create a free account on the Memory server at priorstates.com/w to share packs, keep them across devices or join a group, we store the minimum needed: your account email, a hashed password, and the packs you explicitly publish. That data is used only to provide the features you opted into, is never sold, and is deleted on request. Nothing reaches the server unless you send it.
PriorStates Hub (on your computer)
The hub is a free program you run on your own computer. It keeps its
settings, its pairing identity and your apps there (~/.config/palmtop and
~/.local/share/palmtop). Builds and answers come from the coding agent you
already have on that computer — Claude Code, Codex, the Gemini CLI or Antigravity — under
that provider's terms and your own subscription; the hub adds no model of its own and
never sees your login. It keeps a local log of what it did, on that computer only.
When a phone or a browser reaches the hub away from home it goes through our relay at priorstates.com/relay. Everything that passes through is encrypted end to end on your devices: the relay sees that a hub with a random id is online and moves sealed messages it cannot read. It keeps no content. Pairing links carry the key; they are yours to share or not.
The hub reports nothing to us. There is no telemetry and no account.
Desk and its apps
Desk in the browser (priorstates.com/desk) keeps the styles you shape, with their history, in your browser's own storage, and nothing on our server. Its assistant runs where you set it up: on your paired computer through the hub, or with a Google AI Studio key you paste, which stays in your browser and is used only to call Google — under Google's terms. Desk logs, in your browser, the requests an app could not express, so the app's publisher can learn what to add; that log leaves your browser only if you export it.
Desk on your computer (served by the hub, only to the browser on that machine) runs the apps that need your folders, your Python and your coding agent. Each app keeps its data on that computer, in its own folder. What the apps reach:
- Resume Writer keeps your documents in your browser on its own origin (resume.priorstates.com); AI review runs through your hub or your Google key. No account.
- Reader reads the folders you add — on that computer, or on another one of yours over ssh with your own keys. Nothing is copied anywhere.
- Page reads the web page in front of you only when you ask (see the extension below) and hands it to your coding agent on the same computer. On Gmail that can include the open conversation, so a reply can be drafted; "Put reply in page" types the draft and never sends it.
- Docs talks to Google Docs with an OAuth client you create in your own Google account; the tokens are stored on your computer, in the app's folder, and Google's terms apply to that access.
- Workspaces run your coding agent in folders you list in the hub's settings, on that computer or on another one of yours over ssh. Each run's transcript and files stay on that computer; nothing about them reaches us.
Desk's assistant only ever sees an app's declared style settings, the current style and your request — never an app's code and never your documents.
The Desk browser extension
Desk for Chrome is a side panel for PriorStates Hub. The extension has no server of its own and sends nothing to us: no telemetry, no analytics, no account. When you ask it to, it reads the page in the tab in front of you (its text, headings, links and selection, or what you last copied, for editors such as Google Docs that expose no selection) and the tab's address and title, and passes them only to the hub on the same computer, at 127.0.0.1. The extension stores one setting in Chrome, the port the hub listens on. Reading pages on every site is off until you turn it on, and you can turn it off again on the extension's options page. What the hub does with a page follows the sections above: it stays on your machine unless you point the hub at a third-party service yourself.
Palmtop and PriorStates Link
Palmtop, the phone app, keeps your mini-apps and their data on the phone; sharing, circles and replies travel through the relay sealed end to end; it sends at most one anonymous usage count per day, which you can turn off. Its full policy, written for the app stores, is at priorstates.com/palmtop/legal/privacy.html.
PriorStates Link is a program you put on a server to send alerts to your own devices. Each alert is sealed on that machine to your devices' keys; the relay stores what it cannot read, for a limited time, and a machine can be revoked from the phone. The credential it keeps is its own, on that server.
This website
priorstates.com is a static site. We do not set tracking cookies or run third-party advertising or analytics. Our web server keeps standard access logs (IP address, timestamp, requested URL) for a short period to operate the site and protect it from abuse. Some installers are served from GitHub Releases and the app stores, which have their own policies.
Your choices & contact
Because the software is local, you are in control: you can inspect, export or delete your data on your own device at any time — Memory's files, the hub's folders, Desk's export, Palmtop's backup. For anything about the Memory server, the relay or this policy, write to service@priorstates.com.
We may update this policy as the products evolve; material changes will be reflected here with a new "last updated" date.