AI knows everything.
Helix knows you.
A portable memory vault for your AI life. Fill it once, grant scoped access — and every AI you approve knows who you are: Claude, ChatGPT, Cursor, Gemini, and anything else that speaks MCP. Nothing gets remembered — or generated — without your approval.
The problem · two layers
Every AI now has memory. None of it is yours.
In six months, every major AI shipped a memory feature. Each one lives on their servers, serves their product, and stops at their wall. Use two assistants and you maintain two strangers. Switch, and you start from zero.
And the deeper problem is worse:you don't control what they remember about you.
Lock-in by memory.
Your context is the switching cost. The better an assistant knows you, the more expensive it becomes to ever leave — which is exactly why platforms build it this way.
Ungoverned memory.
Platform memory is silent capture: things you said in passing become permanent facts about you. You can't read it on one page, can't veto an entry, and can't see who read what.
The control test
“Wait — when did it learn that about me?”
That moment — an AI surfacing something you never agreed to have remembered — is the tell. The memory was accurate. The consent was missing.
Helix inverts the model. Apps propose memories; you approve or reject each one. Every read lands in an audit log. And your entire vault fits on one page you can actually read — a biography you wrote, not a file they keep.
The missing layer
One memory. Every AI. Owned by you.
Helix is a vault that speaks MCP — the open standard every major AI client already supports. Connect an app once, grant it exactly the categories you choose, revoke it anytime.
Fill your vault once.
Plain-language facts about who you are — your work, your projects, your people, how you like to communicate. One page. You wrote it. You can edit every line.
Connect any AI.
Claude, ChatGPT, Cursor — each gets a consent screen with per-category checkboxes. Like OAuth, but for who you are. Work app reads work; nobody reads what you didn't grant.
Approve every memory.
Apps propose learnings; nothing is saved without your sign-off. An audit log shows who read what, when. Revoking an app kills its access instantly.
Stop re-introducing yourself to every AI.
One vault, one source of truth — every assistant you approve reads the same you.
- Fill it once, edit it anytime. It's a page, not a profile buried in settings.
- Approve or reject every new memory before it exists.
- See exactly who read what — and revoke in one click.
Your users bring their own context.
Skip building memory infrastructure. Ask the user directly — through a protocol they control.
- Two doors, one consent model: MCP for assistants, REST for apps.
- Consent, scopes, and audit built into the protocol.
- Personalization from the first message. No cold start.
- Your users' faces are a liability sitting in your S3 bucket.With Helix they never touch your servers — photos stay in the user's vault, your app receives finished images. No biometric database, no breach headline, no face-data laws on your back.
A working protocol for user-owned memory across every AI client.
Not a whitepaper — a running server. Remote MCP with self-issued OAuth 2.1, per-category scopes, a human review queue, an audit log, and instant revocation — now with a likeness layer serving real photo apps. Verified across Claude, ChatGPT, Cursor, Gemini, and a shipping iOS app: one vault, five competing surfaces, one consent page owned by the user.
Portable
MCP-native. Any client that speaks the open standard can connect — today, not someday.
Scoped
Per-category grants — work, projects, relationships. Apps see only what you check.
Governed
Every proposed memory waits in your review queue. Approve it, or it never existed.
Auditable
Who read what, when — a plain log on one page, for every connected app.
Revocable
One click cuts an app off and kills its tokens immediately. Verified, not promised.
Likeness (live)
Photo apps see names and thumbnails — never your photos. Images are generated vault-side and delivered as one-hour links. Voice is next: same door, stricter rules.
Act 2 · Likeness — live
Never upload your face again.
A dog was added to a vault from inside a photobooth app — photos traveling straight from the phone to the vault — and minutes later two competing AI assistants generated postcards of him on request. Neither app ever saw a photo. They received names, thumbnails, and finished artwork; the audit log recorded every step.
That's the likeness layer: your pets' photos held as a scoped vault category with the same consent screen, audit log, and one-click revocation as your memories. Apps request likeness like any other scope — and generation happens on the vault's side of the door, so the app holds a link, not your face-data.
We started with pets on purpose — the friendly wedge for a consent model that matters much more later. Your own face, and your family's, come next: same door, higher stakes, stricter rules.
Act 3 · Voice — live
Your voice, on your terms.
A cloned voice is the most dangerous likeness there is — which is exactly why it belongs in a vault, not scattered across every app that asks for a sample. Voice shipped with the strict tier from day one: verified as yours before it can be vaulted, owner-only — nobody vaults a voice on someone else's behalf — and held behind its own consent scope, never bundled silently with photos.
Apps never receive voice samples. They send text; your vault synthesizes speech through a declared provider and returns finished audio on an expiring link — every request audited, every grant revocable. The modality changes; the rules never do.
Proven yours, first.
A spoken-script check proves the voice you're vaulting is your own — the ceremony that earns the right to hold it.
Text in, audio out.
Apps request speech; the vault generates it. Samples never leave, output expires, and the audit log names every request.
“Your memory shouldn't be a retention feature. It should be portable, legible, and yours.”
— The Helix thesis
The part nobody puts on a homepage
Built so you can leave.
A vault you can't walk out of is just someone else's database with better manners. So the exits came before the growth features, and they're not on a roadmap — they shipped.
One click downloads your whole vault as a single file: facts, subjects, photos, voice takes, labels, audit log. One upload loads it into any other Helix — including one you run yourself, on your own domain, for nothing. The format and the protocol are published, so somebody else can build a vault that reads your file without asking us.
The server itself is open source under AGPL-3.0. If we ever became the wrong custodian, you would not need our permission, our cooperation, or our continued existence.
Everything, in one file.
No support ticket, no waiting period, no “contact us to request your data.” A link, and it's on your machine.
Load it anywhere.
Into a vault you host yourself, or a compatible one someone else builds. Merges rather than overwrites, and importing twice changes nothing.
Check our work.
Your audit log is hash-chained — each entry carries the fingerprint of the one before it, so tampering shows. Read what that does and doesn't prove.
Get your vault.
Free, and yours in about a minute. Connect Claude, ChatGPT or anything else that speaks MCP, and decide what each one gets to see. Helix is in beta: it works, it's open source, and you can export or delete everything yourself at any time.
Building something?
The MCP server, the REST app door and the likeness layer are documented at helix.ai/docs, with a worked integrationfrom a shipping iOS app. Access to the app door is still by conversation. Tell us what you're making.