Why
Every generation before ours left boxes. Ours is leaving invoices.
What historians, families and courts have always read is the residue people left behind: letters, photographs, ledgers. None of it was preserved on purpose. It survived because it was physical and nobody bothered to throw it away.
Yours is rented, format-locked, and quietly inaccessible the moment an account lapses. Your life is stored on services that will not outlive you — and the parts of it that other people need, the professionals you pay to specify your care, are the parts you can least easily produce on demand.
A life is not a folder. It is a set of things that keep touching each other: the photograph, the appointment, the message and the walk all belong to one afternoon. Human Memory reassembles those afternoons on your phone, out of evidence you already own, and never sends the result anywhere.
This is a small tool with a large argument behind it.
- Build
- 40On TestFlight. No App Store listing yet, and nothing in it is for sale.
- Atoms
- 67,995Photographs, messages, appointments, workouts and visits in the library it is built and tested against.
- Events
- 6,413Occasions assembled from those atoms, each one a day the record can actually place.
- Servers holding it
- 0No account, no login, no sync. The vault is a file inside the app on your phone.
How
Two hows, one library.
The phone is where a life is captured. The machine is where it is kept. They are the same argument at two scales, and only one of them exists today — so the page says which.
On your phone · available now, in testing
Human Memory for iPhone
Your photographs already know roughly where you were and when. The app turns twenty-odd years of them into a map you can walk and a timeline you can scroll, and reads your contacts, calendar and workouts to give the days real names instead of dates. It runs on the phone.
TestFlight, build 40. There is no public invitation link yet — ask for one below.
On your machine · in development
The desktop archive
The full archive: your folders, an extracted Takeout, exported chats, a bank's OFX file. Originals sealed and never altered, every move written down before it happens, and the whole library described in plain markdown, so a person with nothing but a text editor can still find their way through it.
In development, not released. The waitlist below is for this one.
What the phone actually does with a photograph
It reads what is already attached to it — the date, the coordinate, the faces you have confirmed — and files it as one atom among many. Atoms that belong to the same stretch of time and place become an event. Events become a day with a name, a map pin and a list of who was there. Nothing about the original file changes: the app never modifies a photograph, a contact or a calendar entry, and deleting a blurry frame does not erase the fact that you were at the beach.
The five tabs, and what each is for
- Atlas A map whose spine is your journey. Nodes sized by how long you stayed; the opacity of a line is how confident the app is that you were on it.
- Timeline Places per month rather than photo count, with season washes, day bands and person ribbons. Pinch to zoom a decade down to a week.
- Reflect A session that describes the shape of what it found and asks you yes-or-no questions about it. It contains no model and makes no network call at all: it reads your vault and writes your corrections back.
- Vault The ledger. Every source, what it brought, background work, the export, the calendar publish, and Erase Everything with a receipt telling you how much went.
- People Who appears in your events, ranked by how often. Merge duplicates, mark one as yourself, hide anyone, and confirm photo collections person by person.
Not every photograph is evidence that you were there
A screenshot places you nowhere. Neither does a picture somebody sent you. The app ranks its evidence before it will put a pin on a map, and it says which rank it used, because a record that cannot tell you why it believes something is a record you cannot check.
| Rank | What placed the day | Trusted to place you |
|---|---|---|
| 1 | A correction you made yourself | |
| 2 | A visit your phone recorded | |
| 3 | A photograph from your own camera | |
| 4 | A screenshot, a scan, or something you were sent | never |
What
A record that still reads in a hundred years.
Not an app you have to keep. Not a subscription that has to keep being paid. A library, on media you control, in formats a stranger could open — arranged so that the photographs, the messages and the paperwork agree with each other, and show you where they don't.
Vault → Export → Export My Vault writes the whole thing as Markdown and JSON: your journal, every correction and merge you made, your people, events, places and history, plus every table in the database whether the exporter understands it or not. Then a share sheet appears and you put it where you like.
Two things about that archive, said here rather than left for you to discover. Your photographs and videos are referenced, not copied — each is pointed at by its Photos identifier, so deleting it from Photos still loses the photo. And the archive is plain, unencrypted files: wherever you put it is exactly as private as that place is, and the app can no longer protect it. That is the point of an export, and it is the one operation where the responsibility moves to you.
And the part you hand to somebody else
A whole archive is the wrong thing to give a doctor taking a history or a lawyer reconstructing a year. They need the shape of it: where you were, when, and who was there.
Vault → Your life in places builds that document out of records the vault already holds — the years it covers, the places and the months you were in them, how many of your own photographs stand behind each one, and the display names your address book already had for the people who were there. Then it hands you a PDF through the ordinary share sheet.
No model writes any of it. There is no generator in it: every sentence is assembled on the device from a place name, a month, an integer or a name your vault already holds, which is why building it sends nothing anywhere and costs nothing. It carries no coordinates at any depth, and it leaves out anyone you have hidden, marked "don't feature", or marked as yourself. Sharing it is the moment it stops being private — for you and for the people it names, who were not asked.
The software is how this gets made. The record is what you are left holding.
What leaves
We don't mine your data.
No analytics. No telemetry. No account. Nothing about your life is stored on our servers, sold, shared, or used to train a model — there is no "our servers" for it to be stored on.
What does leave your phone, in full:
- Rounded coordinates, to Apple, to name a place. A photograph's location is rounded to about 110 metres before it is sent — a grid cell rather than your position — once per cell, and the answer is cached. Your exact fix never goes. Recorded visits are never geocoded at all.
- The part of the map you are looking at, to Apple, to draw it. Atlas is a real Apple map, so panning it fetches that area, the same as every map on your phone. Nothing of yours travels with it.
- Your answers, to Anthropic, while an interview you started is open. The interview asks you questions and sends your answers, its questions, and a summary of the shape of your life — months only, no exact dates, no coordinates, no internal identifiers. Never in the background. Those results can carry other people's names from archives you have imported, and you are told that before the first message. This build sells nothing: there is no subscription and no in-app purchase, so the interview runs only if you have stored your own Anthropic API key under Vault → Use your own API key, billed to you by Anthropic. Clearing the key turns it off.
- A request for one of your own photos, to Apple, when you tap Download. Items that live only in iCloud show as a small preview with a Download button. Tapping it fetches that one item from your own iCloud Photos account, over Apple's infrastructure. Only when you tap, one at a time, cancellable — and off Wi-Fi it uses cellular data.
- A calendar you publish, to wherever you publish it. Vault → Review & Publish to Calendar writes a copy of your memories into a calendar the app makes. If you put it in an account that syncs — iCloud, Exchange, work — it syncs, and its events reach every device signed in to that account. The app works out which before you tap, names the account, and makes you acknowledge it.
- Your vault, to your own iCloud backup, if you turn it on. Vault → iCloud Backup is off by default. Turned on, your whole vault rides inside the backup Apple already takes of your phone, under your own Apple ID. None of it comes to us.
- A question to Apple's purchase system, at launch. The app asks StoreKit whether a purchase from an earlier version was left unfinished, and settles it if one was. It carries nothing of your library, and it is here because this list says it is complete.
That is the list. It is longer than a tagline and shorter than a policy, and it is checkable: every line of it is in the privacy policy, next to the file in the source that makes it true.
Two of those are Apple drawing a map and naming a place, and carry nothing of your library; neither does the question to Apple's purchase system. The other four happen because you did something in the app — asked, tapped, published, or turned a backup on.
Health data has a page of its own, because Washington's My Health My Data Act asks for a separate one rather than a section: Consumer Health Data Privacy Policy.
Get it
Two things you can do now.
The iPhone app exists and is in testing. The desktop archive does not exist yet. One form covers both — say which you want.
A TestFlight invitation goes out by email, because there is no public link yet. Your address is stored so we can send you one and tell you when the desktop archive is real. It is not used for anything else, and there is nothing else it could be used for — see the privacy policy.