pasiero

pasiero / privacy

Your files, conversations, and context.

A personal file assistant touches three sensitive things: the files themselves, the channel where you talk, and the context that makes the assistant feel familiar. Pasiero treats them as separate boundaries so each can be understood and controlled.

05 · what stays where

Three different kinds of trust

"Private" is not one switch.

What it includes What can reveal it Pasiero's rule
File access documents, photos, names, dates the folders you connect chosen scope stays visible
Conversation requests, answers, previews the communication channel show the channel's boundary
Personal context preferences, people, routines saved assistant memory inspectable and forgettable
File contents the bytes inside personal files remote AI processing keep them local

The content rule

Personal files stay on your side.

Pasiero may use remote intelligence for general language help, but the contents of your documents, photos, notes, and other personal files should not be sent to a remote AI service. Work that requires reading content happens locally or does not happen.

  1. 01

    Names are sensitive too

    A filename such as 2026-08-25_oncology-follow-up.pdf can reveal plenty without opening the file. Pasiero should distinguish names and metadata from harmless technical details.

  2. 02

    No invisible privacy downgrade

    If local understanding is unavailable, Pasiero should explain the limitation rather than quietly send a file elsewhere to finish the request.

  3. 03

    Activity history avoids content

    The history can say that a warranty was moved without storing the warranty's text, a photo's pixels, or the full prompt used to understand it.

  4. 04

    Personal context can be forgotten

    You should be able to remove a remembered person, preference, project, or conversation without rebuilding the whole assistant.

Every channel has a boundary

Convenience should come with an honest label.

A message sent through a communication service passes through that service. A desktop or terminal interaction may remain on the device. Pasiero should make that difference visible without pretending every channel has the same privacy properties.

Hosted chat

Useful from anywhere, but the request and response travel through the chat provider. Pasiero keeps file excerpts out of the conversation unless you deliberately share them.

convenient · provider-visible

Desktop or terminal

Better for private review, large plans, and content-aware work that should remain on the device holding the files.

local · detailed · close to files

Voice and integrations

Helpful for capture and reminders, but each connected service adds another boundary. Pasiero should name it before using it.

optional · explicit · removable

Changing channels should never silently change what Pasiero can read, remember, or send elsewhere.