Skip to main content
Every capture you make lands in your personal core, and your core is visible to exactly one person. Not your team. Not your company’s admin. Not us, browsing. You — until the moment you deliberately share something, and even then, only what you chose. That’s the whole model. Here’s what it means in practice.

Default: nobody

A capture in your Home is yours alone. It isn’t discoverable, isn’t searchable by anyone else, and doesn’t appear anywhere until you act. There is no setting that makes your core visible to someone else, no admin view of it, and no “org-wide sharing” switch waiting to be flipped. Privacy isn’t a mode you enable — it’s the state everything starts in.

Sharing is a verb

Nothing leaves your core passively. Sharing is something you do: you pick the capture, pick the Space and channel, and send it — deliberately, one decision at a time. What you share is what arrives; everything else stays home. And joining a Space changes nothing about your core — membership gives your team what you share, never a window into what you don’t.

Your agents follow the same rule

Your personal agent answers from your core because it’s yours. A space agent knows only what’s been shared into its space. An agent you connect through Gobi CLI reads your core with your token, and the pipe flows one way — out to your agent, never from it into anyone else’s view. The lines are drawn precisely, and they’re all in one table.

And the data itself

Two more promises complete the picture, each with its own page: nothing trains on your data unless you switch it on — the switch ships off — and your data leaves when you do: export everything or delete everything, any time, no questions.
The short version, if someone across the table asks: it’s private until I share it, only what I share arrives, and nothing trains on it. That’s not a settings page. That’s the architecture.