Pure zero-knowledge

Built so we can't read your brain.

Hippo handles your most intimate work data — your projects, your clients, your voice, your decisions. So we designed it so the secrets never reach us in the first place. Your keys and plaintext stay on your Mac — there's no readable copy of your brain anywhere else.

The foundation

Your brain never touches a server.

No copy of your memories, keys, or index ever leaves your Mac. The only thing our backend ever knows is who’s paying — never what you know. There’s nothing of your brain to breach, leak, or subpoena, because it was never on our side.

01

Keys & plaintext stay on your Mac

Encryption keys live in the Secure Enclave. Your vault and the searchable index that powers it stay on your Mac and never leave the device — there's no cloud copy of your brain to read.

02

Every fact has a receipt

Every memory is inspectable, editable, and deletable in each project's Brain view. Every line in a packet drills back to its source. Nothing is hidden from you — and nothing is shown to us.

03

Honest revocation

Revoke any agent's future access in one click. We cut it off and log it. We never pretend a model “forgets” what it already saw — revocation is a future-access cutoff, and it's recorded.

04

Fiduciary by design

No ads. No data resale. No selling your brain to anyone, ever. Hippo's only business is the subscription — your incentives and ours point the same way.

What “zero-knowledge” means here

The secrets never reach us.

Most apps promise to protect your data. Hippo's promise is stronger and simpler: we never get readable access to it at all. The compute that builds your brain runs where the data already is.

Reasoning — the actual writing — runs on the AI you already pay for. Retrieval — assembling a Context Packet — runs locally. Learning — organizing memory — runs on a small model right on your Mac. Nothing about your projects leaves the device for us to read.

That's not only a privacy stance — it's the architecture. Because we can't see your data, there's nothing on our side to breach, leak, or subpoena. You can't leak what you never had.

The short version: Hippo is a safe in your house — not a vault in our bank.

Where the work happens
ReasoningYour ChatGPT / Claudeyour acct
RetrievalBuild the packeton-device
LearningOrganize memoryon-device
StorageYour vault & indexon-device
Hippo can readYour plaintextnever
Per-project walls

One project's AI never sees another's data.

A project is an isolated, sealed brain — a company, a client, a personal project, or your own work brain. Projects never share data with each other. When you brief an AI for one project, the packet is scoped to that project alone; every other project is walled off. For consultants and fractional execs juggling several clients at once, that per-project confidentiality wall is the whole point: one client's AI can't touch another client's data, and the ledger proves it.

The Consent Ledger

Proof of what each agent saw.

Every read, every approved write, every revocation — logged like a bank statement. Aligned, timestamped, scoped to a project. You can always answer the question: who saw what, when, and with whose permission?

Consent Ledger · today
09:14Claude · read · Acme only
09:31ChatGPT · read · Acme only
11:02Accountant bot · read · finance project
13:48Claude · read · Beta only
14:20Grok · revoked · future access
14:21Write · "launch is Q3" · approved by you
  • Every read, logged. When an agent pulls a packet, the entry records the agent, the scope, and the project. Cross-project reads simply can't happen.
  • Guarded writes. An agent that wants to write a new fact back into your brain has to be approved by you — and the approval is on the record.
  • Revocation is honest. The ledger shows the cutoff, not a fantasy. Future access ends; we don't claim the model unlearns the past.
  • Audit-ready. The ledger is built to be shared and audited — the answer to “prove the wall held” is one export away.
What we will and won't claim

Precise about privacy.

Trust is built on honest claims. Here's exactly where the lines are.

What we promise

  • Your keys and plaintext never leave your Mac in readable form.
  • You can inspect, edit, pin, or delete any memory at any time.
  • Revoking an agent ends its future access and logs the cutoff.
  • Projects stay walled off from each other — provably.

What we won't pretend

  • We won't claim a model “forgets” something it already saw. Revocation is forward-looking.
  • We won't claim to control what a third-party AI does with text once you've sent it.
  • We won't over-capture to look smart — Hippo is conservative on purpose.
Your brain is yours

Calm, fast, and a little stubborn about your privacy.

Start free on one Mac. Zero-knowledge on every plan, including Free.

60 seconds · no account · no API keys

Runs on Apple Silicon Macs with Apple Intelligence (macOS 26+) · free to start · no account