The boundary that makes everything else safe to share. Raw personal life lives in a vault Claude is denied, and only a scrubbed, human-reviewed summary ever crosses into Brain.
Nothing personal reaches the cloud unreviewed. The path is always the same.
Finances and Relationships never cross. Ever. Health stays raw in the Journal; only a thin overview reaches Brain. What DID change: the walled side now has its own local analysts — see below.
A separate vault, outside Brain, that Claude cannot read and that is never git-tracked or graphed. (These pages don't read it either; this is the documented structure.)
The day-to-day journal, including a privacy-walled mood capture from the Command Center. Claude denied.
Raw Apple Watch / HealthKit export, synced via iCloud. Apple-only transport. Claude denied.
Goals, Health, Finances, Relationships. The real personal source docs. Claude denied.
Finances and Relationships get no cloud derivative, by rule. Full stop. No derivative.
Personal-data synthesis runs on a local LLM. Claude builds the scaffolding but is denied the data path, so the denied-zone steps are run by hand.
Local Ollama produces high-level Goals and a thin Health derivative, staged as a draft I review and accept before it ever reaches Brain/Context.
A weekly local-only review reads the Journal + Calendar + Reminders through Ollama and writes back into the Journal. No claude -p, no API key, no cloud.
Pulls the Watch export from iCloud into ~/Journal/Health daily. Never writes Brain, never commits.
It makes Brain shareable by default: because the raw data is structurally walled off, the vault can be pushed to GitHub and graphed without risk.
The newer half of the story: the private side grew its own working ecosystem. Local models supply the intelligence, so nothing has to cross to be useful. Cloud AI built all of it without ever reading any of it — every pipeline was developed against synthetic fixtures.
A nightly pipeline syncs the journal into a local-model advisor that works as a grounded sounding board — friend-level pushback, one question at a time, and “your journal doesn't say” is a correct answer. It writes weekly and monthly theme rollups back into the Journal, and advisor conversations are distilled into journal entries overnight: talking is journaling.
The daily Watch rollup grounds two local advisors. The guardrail is calibration, not topic bans: interpreting labs and naming possibilities are in scope, but every claim is source-marked (my data / general knowledge / unsure) and inventing a number is never allowed.
No Mint, no Plaid — no transaction ever leaves the machine. A deterministic pipeline owns the numbers (categories, recurring vs. habit spend, installment plans); a local advisor only reasons over the rollup, and rates, fees and terms may never be generated — they're hand-entered or asked for. Proven on real statement data.
The private side has its own dashboard, separate from the Command Center: personal tasks with recurrence, health at a glance, advisor hand-off. Its founding rule is what makes it safe: no cloud model, ever — which is exactly why it's allowed to read the Journal freely. It never logs content, only counts.