private memory · one owner · many invited minds

Give your intelligence somewhere to return to.

Hearth is one private, governed memory for the models and coding agents you choose. Change the intelligence whenever you want. Keep the continuity that is yours.

Step inside

local-first on macOS · sources stay whole · models cannot approve their own memory

00 / a hearth

01 / the source vault

It keeps what actually happened.

Hearth preserves every approved source byte-for-byte. Search, summaries, and memories can be rebuilt; the original cannot be silently rewritten.

source verified local only
conversation / 17 july
“Keep the decisions, but never lose the exact words that made them.”
source bytes04,812
line range118—121
sha-2569d8a…7c21
provenanceexact
01 / preserve

02 / living memory

It remembers that you change.

Yesterday’s truth stays part of the record without pretending to be today’s truth. Hearth keeps belief, correction, and current reality in the right order.

12 maysuperseded

“The release should be cloud-first.”

02 junequalified

“Cloud can come later, after the local trust boundary is proven.”

nowcurrent

“The first release is local-only.”

02 / time

03 / context compiler

It brings back what matters now.

A model does not need your whole life pasted into one prompt. Hearth assembles a bounded package: identity, immediate work, exact evidence, and the corrections that could change the answer.

01 / core Owner-approved identity pinned
02 / now Immediate continuity recent
03 / proof Verbatim evidence cited
04 / check Corrections & counterevidence reserved
03 / context

04 / authority

Nothing stays without you.

Models may notice something worth remembering. They may gather evidence and propose it. Only the owner can let high-impact memory become active.

memory proposal #0047
proposed by / coding agentawaiting owner
“Prefer the smallest verified change before expanding scope.”

Supported by 3 exact passages across 2 project sessions. No contradiction found.

Awaiting your decision — this is a local interface demo.
04 / govern

05 / model independence

Change the mind. Keep the memory.

Invite the local model or coding agent that fits today’s work. Hearth stays behind a stable boundary, carrying forward only the context that tool is authorized to receive.

a hearth / connected toolauthorized
H
Local model private runtime · active now
verified sourcesunchanged
owner decisionsunchanged
accessbounded
05 / continuity

06 / signed installation

Verify the package. Trust the exact bytes.

Start with an up-to-date Apple-silicon Mac, FileVault, and Docker Desktop. Before opening anything, verify the exact package, its Developer ID signature, and Gatekeeper assessment.

before opening anythingterminal · recommended
macOS 14+Apple siliconFileVault onDocker running
package verification
PKG="$HOME/Downloads/A-Hearth-0.1.65-arm64.pkg"
EXPECTED_SHA256="bd685919f0dac1c71a230c7b5893dfd6c50faf86a6a3b6ff202cdc3a6625dbc8"
printf "%s  %s\n" "$EXPECTED_SHA256" "$PKG" | shasum -a 256 -c -
pkgutil --check-signature "$PKG"
spctl --assess --type install --verbose=4 "$PKG"
package bytesmatch release
signerDeveloper ID · 5CAH2XK44B
Gatekeeperaccepted
06 / install

07 / macOS installer

Install it normally. Open it signed.

Open the verified package in Finder or Terminal, complete the standard macOS Installer flow, and keep A Hearth in its fixed signed location. Do not remove quarantine metadata or bypass Gatekeeper.

install and openfinder or terminal
01
verified package

Open macOS Installer

normal flow
02
fixed signed location

/Applications/A Hearth.app

do not move
03
first launch

Open A Hearth

signature intact
open installer and application
open "$HOME/Downloads/A-Hearth-0.1.65-arm64.pkg"
# Complete macOS Installer, then:
open -a "A Hearth"
Keep the trust chain: never use a quarantine-bypass command to force the app open.
07 / open

08 / first launch

Create the room. Draw the authority line.

Choose “Create new Hearth.” The app prepares owner-only local state, Keychain secrets, the private database, migrations, service, backup, and an isolated restore check before anything is invited in.

owner setupthree ceremonies
01
first launch

Create new Hearth

local state ready
02
trusted core

Activate the owner constitution

owner only
03
operations

Save the recovery kit separately

backup verified
04
diagnostics

Verify this Mac

FileVault on
08 / ownership

09 / deliberate access

Connect one model. Approve one source.

Verify a local runtime with a content-free challenge, then authorize the first source directory yourself. Connections can use bounded context; they cannot grant themselves access or approve what becomes memory.

M
models → add connection

Verify and activate

Ollama · LM Studio · compatible local server
S
sources → authorize path

Begin ingestion

original bytes preserved · exact provenance retained
Owner boundary: a model, agent, or downloaded file can never approve a source path for you.
09 / connections

10 / connected tools

Invite your tools. Make the first Ask.

Connect the coding client you already use through local stdio MCP, keep its own tool approvals enabled, then confirm readiness in Diagnostics. Search one known source, inspect the citation, and ask for the same fact.

a hearth / local AI connectionsno network port
Add Hearth to Codex CLI
codex mcp add hearth -- '/Applications/A Hearth.app/Contents/MacOS/A Hearth' --mode mcp
Claude Desktop: import A-Hearth-Claude-Desktop-0.1.65.mcpb from the signed release.
diagnosticsinstallation · database · backup · retrieval · connection
ready
10 / first ask

the first hearths

Somewhere private to come home to.

A Hearth is approaching its first personal macOS release: one owner, one private installation, and the models and agents they choose.

11 / return
private release / a hearth

one person · one hearth

Join the founding release.

Planned founding pricing offers monthly, annual, or permanent access when invitations open. Joining is free; no payment is taken today.

Monthly

$39 per month

Annual

$399 per year

Founding Owner includes 12 months of updates and asynchronous support. Final commercial terms will be shared before purchase.