We can't train on you — and here's why we built it that way
Anyone can promise not to train on your data. We wanted something stronger than a promise: architecture that removes our ability to, evidence you can check, and incentives that are structurally opposed to it.
If your InfiniMe becomes your most valuable asset — a durable record of your judgment, your relationships, your accumulated skill — then the obvious fear is the important one: what stops the platform from using it to train your replacement?
“We promise not to” is the weakest possible answer. Privacy policies are revisable. Promises are cheap. We wanted a hierarchy of assurances, strongest first.
Tier 1 — “We can’t”
The strongest guarantee is architectural incapacity. The memory core is designed to be self-hostable open source; the exit-to-your-own-infrastructure path exists even if most people never take it, and its mere existence disciplines us. Bring-your-own inference lets you route agents through your own provider keys or local models, removing our aggregation point entirely. Tenant-held encryption keys protect memory at rest — with the honest caveat that agents need plaintext at inference time, which is why confidential-compute inference is on our roadmap and described as exactly that.
Tier 2 — “Check us”
Where we can’t make it impossible, we make it verifiable. An owner-visible access ledger means you can always see who read what, and why — there is no black-box access class. An annually renewed, published third-party attestation speaks specifically to the claim that no training pipeline consumes tenant memory. And deletion certificates plus open-format export mean leaving is real, not theater.
Tier 3 — “We don’t need to”
The deepest assurance is incentive alignment. Our revenue is subscriptions and marketplace fees — you are the customer, not the corpus. The no-training covenant lives in the contract, with liquidated damages, not merely in a policy. And the thesis itself is structurally opposed to the fear: training on users’ InfiniMes would manufacture their replacements and vaporize the asset they pay us to protect.
What we won’t overclaim
Determined distillation — draining knowledge by bulk-querying an identity — can’t be fully prevented by technology alone, and we don’t pretend otherwise. It’s priced and detected: query budgets, anomaly detection, immutable audit, and enforceable damages. Monitored and legally armed. Never “unbreachable.” The honesty is part of the product.