Hosted chat
Useful from anywhere, but the request and response travel through the chat provider. Pasiero keeps file excerpts out of the conversation unless you deliberately share them.
convenient · provider-visible
pasiero / privacy
A personal file assistant touches three sensitive things: the files themselves, the channel where you talk, and the context that makes the assistant feel familiar. Pasiero treats them as separate boundaries so each can be understood and controlled.
Three different kinds of trust
| What it includes | What can reveal it | Pasiero's rule | |
|---|---|---|---|
| File access | documents, photos, names, dates | the folders you connect | chosen scope stays visible |
| Conversation | requests, answers, previews | the communication channel | show the channel's boundary |
| Personal context | preferences, people, routines | saved assistant memory | inspectable and forgettable |
| File contents | the bytes inside personal files | remote AI processing | keep them local |
The content rule
Pasiero may use remote intelligence for general language help, but the contents of your documents, photos, notes, and other personal files should not be sent to a remote AI service. Work that requires reading content happens locally or does not happen.
A filename such as
2026-08-25_oncology-follow-up.pdf can reveal
plenty without opening the file. Pasiero should distinguish
names and metadata from harmless technical details.
If local understanding is unavailable, Pasiero should explain the limitation rather than quietly send a file elsewhere to finish the request.
The history can say that a warranty was moved without storing the warranty's text, a photo's pixels, or the full prompt used to understand it.
You should be able to remove a remembered person, preference, project, or conversation without rebuilding the whole assistant.
Every channel has a boundary
A message sent through a communication service passes through that service. A desktop or terminal interaction may remain on the device. Pasiero should make that difference visible without pretending every channel has the same privacy properties.
Useful from anywhere, but the request and response travel through the chat provider. Pasiero keeps file excerpts out of the conversation unless you deliberately share them.
convenient · provider-visible
Better for private review, large plans, and content-aware work that should remain on the device holding the files.
local · detailed · close to files
Helpful for capture and reminders, but each connected service adds another boundary. Pasiero should name it before using it.
optional · explicit · removable
Changing channels should never silently change what Pasiero can read, remember, or send elsewhere.