Skip to content
Docs menu

Concepts

Privacy & local-first

Where your memory lives, what (if anything) leaves your machine, and how to keep secrets out.

Where data lives

  • A local install stores everything in ~/.tam/ (older installs: ~/.claude-memory/, moved automatically on first run). The main file is ~/.tam/memory.db, a SQLite database.
  • Embedding models are downloaded once and run locally (FastEmbed, ONNX).
  • The dashboard binds to 127.0.0.1 only.
  • There is no account, no telemetry and no analytics.

What can leave your machine

In the default fast mode, saving and searching make no network calls. Network traffic happens only for things you turn on:

FeatureSendsTurn off with
A cloud LLM provider (OpenAI, Anthropic, OpenAI-compatible)The text used in that task: records being enriched, questions and retrieved context for memory_answerMEMORY_LLM_ENABLED=false, or use a local Ollama
A cloud embedding provider (OpenAI, Cohere)Record and query text to compute vectorsKeep MEMORY_EMBED_PROVIDER=fastembed (default)
The Jev contradiction scorerPairs of statements to TypeSafe’s APIKeep MEMORY_CONTRADICTION_SCORER=llm (default)
First-run model downloadNothing about you; downloads model filesPre-cache models (FASTEMBED_CACHE_PATH)
The weekly update check (a background service installed by install.sh)A request for the latest release to the GitHub APIRemove that service

A local Ollama keeps LLM features on your machine.

Keeping secrets out

Since 14.6.0, TAM redacts on every write path, before anything reaches disk: the arguments of every tool call, the raw call log, prompts captured by the UserPromptSubmit hook, tool output queued by the PostToolUse hook, and transcript extraction. It removes:

  • anything between <private> and </private> (nested and unclosed sections too);
  • PEM private keys and passwords in URLs (postgres://user:pass@host);
  • Anthropic, OpenAI, Stripe, GitHub, GitLab, Slack, Google, Hugging Face, npm, Telegram and AWS keys, JWTs and Bearer … headers;
  • password=, *_secret:, token= and api_key= assignments, email addresses and card-like numbers.

Redacted parts become [REDACTED]. This is a safety net, not a guarantee: patterns cannot catch every secret. Do not ask the agent to remember credentials.

Earlier versions redacted only memory_save and missed several key formats. To clean a store saved before 14.6.0:

tam redact-existing            # report only
tam redact-existing --apply    # back up to backups/pre-redact-<time>*.db, then redact

The dashboard’s Settings → Stored credentials does the same. The backup keeps the old values; delete it once you have checked the store.

API keys for the LLM and embedding providers are stored encrypted; see Settings page. On Linux and macOS the memory directory is made owner-only (0700, database files 0600).

Deploy uses the ops account <private>password: hunter2</private> on bastion-2.
→ stored as: Deploy uses the ops account [REDACTED] on bastion-2.

Deleting

  • memory_delete soft-deletes one record: it disappears from search but stays in the database.

  • memory_delete(id, hard=true) erases it for good, together with:

    • its earlier versions and vectors;
    • its full-text, graph, evidence and queue rows;
    • its copies in Chroma and in the raw call logs;
    • quotes of it in later versions.

    Freed database pages are zeroed. Search queries that mention it are not rewritten; set a raw-log retention period on the Settings page to limit how long those are kept.

  • memory_forget applies the retention policy (archives stale, never-recalled records and purges very old archived ones). Run it with dry_run=true first.

  • To remove everything, uninstall and delete ~/.tam/. Back it up first if you might want it back; see Upgrade & backup.

On a team server

On a team server your personal memory is a separate database only your tokens can reach; team and shared memory are visible to their members. The server’s LLM settings apply to everyone’s content, so check them with your administrator.

Found a mistake? Open an issue on GitHub.

Search