Trust
Phronesis keeps your workspace in readable files on your own computer. Here is where the work lives, what can reach a model, and what stays with you if you leave.
Your local folder is the source of truth.
Your installation is a directory of Markdown files on your machine: your domain workspaces and your shared codex. No database, no proprietary block format, no upload step. The folder is the source of truth.
The current product has no hosted workspace, hosted index, or Phronesis cloud sync. Use the CLI with your chosen assistant, or open the workspace in the macOS app. The same local folder holds the work.
No telemetry in V1.
Phronesis ships no product telemetry in V1: no analytics, no usage pings, no opt-in metrics. The event log that records what happened inside your workspace is not emitted as analytics or usage telemetry. Importing material saves it locally. Using that material with an assistant can send it to your selected model provider, as described below.
If you place the workspace in a folder synced by another service, that service handles the files under its own settings and terms.
The model is your choice.
When you use Claude Code or Codex, that assistant processes the material you give it through your existing model access. In the macOS app, assistant work requires an Anthropic, OpenAI, or OpenRouter connection. Browsing saved records and reviewing changes does not require a model connection.
Content sent to a remote provider is subject to that provider’s terms and your account settings. Phronesis does not provide a bundled model subscription.
Ownership you can check.
Three ownership commitments guide the product and its release checks.
Export: the command that packages your installation must produce a folder that opens cleanly in Obsidian and VS Code with zero Phronesis dependencies present, and keeps working with the vendor gone.
Model swap: your saved work remains readable when you change providers or assistants. Each assistant still needs its own supported setup and access.
Skill portability: skill instructions are readable Markdown. You can inspect them and carry them into another assistant; particular workflows may still need the CLI commands or tools they describe.
The goal is practical: you can keep using the files even when you stop using Phronesis.
Employer content stays behind the gates.
If you are a PM, the content you most want Phronesis to hold is often your employer's: meeting transcripts, stakeholder threads, calls made in rooms you were in. Here is the honest picture.
Everything not authored by you is treated as untrusted, including meetings you attended. Your presence in the room does not sanitize what other people said in it. Untrusted content lands in your workspace's raw folder and never becomes canonical state on its own. Compiling untrusted material produces a proposal for your approval before it becomes accepted context. This review governs the saved record; it does not replace the model-provider boundary described above.
What Phronesis cannot do is know your employer's policy on where that content is allowed to live. Because your workspace is a local folder and your model provider is your own choice, you keep the controls that answer that question. Check your own agreements before you point a connector at work content. Use only material you are allowed to store and process with the tools you choose.
The short version: the disk is yours, the model is your choice, and the ownership is tested, not asserted.