Skip to content

What reMaestro keeps

reMaestro runs on hardware you own, so most questions about what is stored have an answer of the form “on your box, until you delete it”. That is true and it is not sufficient. Which box, for how long, who in the house can read it, and what leaves — those are the questions this section answers, in detail, per setting.

There are two pages, because there are two places bytes can land:

  • What the hub keeps — the box under your television. This is where anything resembling a conversation lives, and it is the page to read if you are deciding whether to switch conversation logging on.
  • What reMaestro Cloud keeps — the optional paid service. Only relevant if you use it, and it never sees a word of what anybody said.

There is a third, shorter telling of the same facts on the marketing site — what happens to your data — written for somebody deciding whether to install this at all, and carrying the one thing these two pages do not: a single table naming every outside company anything is ever sent to. If it and these pages ever disagree, these are the longer answer and the source is the actual one.


WhatWhereOn by default?How long
A conversation in progressHub, in memoryYes5 minutes idle for voice, 2 hours for the console assistant
The live event and command feedHub, in memoryYesThe last 400 events and 500 commands, lost on restart
Counts, costs and timings of AI callsHub, on diskYes2 years
What was actually saidHub, on diskNo90 days by default, adjustable, or forever
Counts, costs and timings of gateway callsreMaestro CloudOnly if you use the gateway30 days per call, 2 years as hourly totals
Your backupsreMaestro CloudOnly if you switch it onUntil you delete them — encrypted, unless you opted out

The row most people do not expect is the third one. A hub keeps a two-year record of how much AI it used and who asked for it, out of the box, whether or not you ever touch reMaestro Cloud. It contains no words — that is enforced, not promised — but it is a record of activity per person and it is on by default. It has its own section.


Some of what follows is enforced by a test that fails the build. Some of it is a default nobody has changed. Some of it is nothing at all. Those are three different kinds of statement and running them together is how a document like this becomes reassurance rather than information, so they are marked apart throughout:

  • Guaranteed — enforced in code, with a test, and a change would fail the build. Not “we intend to”: the code that would break the promise does not compile, or the test that catches it is named on the page.
  • Merely likely — true today, and true because of a default nobody has changed or a judgement somebody makes. Nothing stops it changing, and nothing would notice if it did.
  • Unguarded — nothing in the product addresses this. Named anyway, because the alternative is that you find out.

This is the same three-way split the internal audit in docs/ai-safety.md uses, deliberately, so the two documents cannot drift into two vocabularies for one distinction.


This is not a privacy policy. It is a description of a system: what the software writes down, where, and for how long. A privacy policy is a statement of commitments to you as a customer — who the data controller is, on what legal basis anything is processed, who it is shared with, and what you can compel us to do about it. Those are legal claims, they are not answerable by reading source code, and writing them in a documentation page would be inventing them.

The distinction matters in practice, and not only formally: for a self-hosted hub, most of what a privacy policy would cover is not ours to describe. The hub is your machine. We are not processing anything on it, we cannot see it, and there is no relationship in which we could make you a promise about it. What we can tell you is what the software does, which is what this is.

The part that genuinely is a service — reMaestro Cloud — is the part where a privacy policy would say something. If you need one for that, ask, rather than reading a commitment into the cloud page.


Deliberately, at the point where you make the choice rather than only from a footer:

  • Settings → AI → Keeping what was said, on the hub, next to the switch that turns conversation logging on.
  • The hub’s setup page, under the form that creates the first account — the one record that is on by default is described there, because first run is where somebody decides whether to trust the box and a default nobody is told about is not one they weighed.
  • Your account, on the cloud console, next to what the service holds about you.

If you got here from one of those, the page you want is probably the one that sent you.