Smart AI, Zero Surveillance

Sathi uses AI to understand you — but your data never leaves your phone unless absolutely necessary. Conversations stay encrypted on-device. The AI proxy stores nothing. Token budgets cap what the AI sees. No analytics, no ads, no tracking. And you can delete everything with one tap.

How Data Flows — And Doesn't

How Sathi Uses AI — And Protects Your PrivacyYour PhoneEncrypted Realm DBAll data stored here64-byte encryption key🔒Prompt BuilderCompresses contextEnforces token budgetsStrips personal data📦Stateless ProxyNo data storedRate limiting onlyForwards → LLM🔄LLMGenerates responseNo history retainedStateless inferenceToken Budget — Max 3000 Tokens Per Request400500400400500450System Prompt (400 tokens)Long-term Memory (500 tokens)Short-term Memory (400 tokens)Feature Context (400 tokens)Current Message (500 tokens)Reserve / Overhead (450 tokens)Hybrid Intent Parser — 20+ Intent TypesLocal Regex (Fast Path)Pattern matching on-deviceNo network call needed✓ Clear intents → instant routing?LLM Parser (Ambiguous)Only for uncertain inputsStructured JSON extraction✓ Complex/mixed-language → precise parsingPrivacy by Design🔒Encrypted Realm64-byte key, AES-256📵No AnalyticsZero tracking SDKs🗑️Delete AnytimeOne-tap data wipe📦Minimal ContextOnly summaries sent🔇No Raw AudioOnly embeddings kept

What We Promise

Encrypted On-Device Database

All your data — conversations, tasks, expenses, memories — lives in an encrypted Realm database on your phone. A 64-byte encryption key protects it. Even with physical device access, the data is unreadable without the key.

Stateless AI Proxy

The server that talks to the LLM stores nothing. No conversation history, no user profiles, no files. It takes your request, forwards it to the AI, returns the response, and forgets everything. Rate limiting is the only state it holds.

Token Budget Enforcement

Every AI request is capped at 3,000 tokens. Your current message gets 500. Short-term memory gets 400. Long-term memory gets 500. Feature context gets 400. This means the AI sees the minimum needed to help you — not your entire life story.

Hybrid Intent Parser

Clear commands ("add task", "₹200 grocery") are parsed entirely on-device using regex — no network call. Only ambiguous or mixed-language inputs reach the LLM. Most interactions never leave your phone.

Zero Analytics & Tracking

No Google Analytics. No Firebase Analytics. No Mixpanel. No ad SDKs. No tracking pixels. Your usage patterns are computed locally by the behavior learning engine and never transmitted anywhere.

Delete Everything, Instantly

One tap in Settings wipes all data — conversations, tasks, voice profile, memories, everything. No confirmation emails, no 30-day retention, no hidden backups. When you delete, it's gone.

What the AI Actually Sees

Every request to the AI is capped at 3,000 tokens. Here is how that budget is divided:

400

System Prompt

Persona instructions injected by the proxy — tells the AI how to behave.

500

Long-term Memory

Compressed summary of your profile and preferences. Not raw conversations.

400

Short-term Memory

Recent session context — what you talked about in the last few exchanges.

400

Feature Context

Today's tasks, expenses, wellness — hydrated from your local database.

500

Current Message

Your actual message, plus a response style instruction.

~450

Reserve

JSON overhead, margin for mixed-language text expansion.

Privacy Isn't a Feature. It's the Foundation.

Download VivaLyn Sathi and experience AI that respects your data.