A personal AI should not treat every useful fact as permanent memory. Stable, low-risk preferences may be remembered; consequential instructions should be reconfirmed; temporary context should expire; credentials and unapproved sensitive data should not be stored as ordinary memory at all.
That is the difference between a personal assistant that becomes more useful and one that quietly accumulates risk. The question is not whether memory is convenient. It is whether each piece of context has a purpose, an owner, an expiry rule and a visible way to remove it.
The remember, confirm, expire or never-store matrix
| Control | Appropriate examples | Required behaviour | Why it matters |
|---|---|---|---|
| Remember | Preferred language, accessibility choice, usual cabin class, approved briefing format | Show the saved item, its source and a delete control | Repeated low-risk preferences improve continuity |
| Confirm each time | Recipient, payment, booking change, document release, enterprise action | Restate the action, target and material consequence before execution | Yesterday's instruction may be unsafe in today's context |
| Expire | Temporary itinerary, event location, short project state, one-trip dietary constraint | Apply a date or purpose-based expiry and notify the user before extension | Temporary context should not become an indefinite profile |
| Never store by default | Passwords, passcodes, recovery codes, raw identity documents, private third-party data without permission | Refuse ordinary memory storage or route to an approved protected system | Convenience does not justify creating a new secret store |
The categories are policy decisions, not labels an AI should infer silently. A user needs to be able to move an item between them and understand the effect.
Why an expiry date changes the privacy model
Traditional contact books are intentionally persistent. Conversational AI is different: a user can disclose a medical appointment, a negotiation position or a client's travel plan in the same natural tone used to state a coffee preference. If all of those facts enter one undifferentiated memory layer, sensitivity and purpose disappear.
An expiry rule restores context. “Remember that I prefer aisle seats” can reasonably be durable. “Remember that I am staying at this hotel until Thursday” has a natural end. “Send the revised contract to this recipient” is an instruction that should be confirmed at the point of action, not turned into a standing permission.
The UK Information Commissioner's Office stresses purpose limitation, data minimisation, accuracy and storage limitation in its guidance on AI and data protection. A useful personal-memory design translates those principles into controls the owner can see: why the item exists, how long it will be used and how to revoke it.
Deleting a conversation is not always deleting memory
Users often assume that removing a chat removes everything learned from it. That is not a safe assumption across AI services. OpenAI's current Memory FAQ distinguishes saved memories from chat history and tells users that fully removing a remembered fact may require deleting both the saved memory and the original chat.
That is useful industry evidence, not a claim that every product works identically. The operating lesson is broader: a private-phone assistant should show separate controls for conversation history, extracted memory, connected-app permissions and active sessions. “Delete” must identify which layer it affects.
A good memory screen answers six questions without requiring a support ticket:
What exactly is remembered?
Which conversation, app or person supplied it?
When was it last used?
Which actions may rely on it?
When will it expire?
How can the user delete it and verify deletion?
Four memory scopes for a private phone
Personal preferences
Preferences are the strongest candidate for durable memory when they are stable and low risk. Language, display accessibility and a preferred summary format can save time without authorising a transaction. Even here, the user should be able to review and correct them. A stale preference can be inconvenient; a wrongly inferred identity or health attribute can be harmful.
Task context
Task context should normally expire. A meeting brief may be relevant until the follow-up is complete. A packing list may last for one journey. A research project may need a named retention period. The assistant should offer a clear end point instead of asking the user to remember to clean up months later.
Action authority
Memory must not become invisible permission. Remembering a frequent-flyer number does not authorise a booking. Remembering a colleague does not authorise sending them a confidential file. High-impact actions need confirmation of the object, recipient, cost or consequence at execution time.
The distinction also supports a strong AI-agent and human-concierge travel matrix: software can organise context and options, while a person confirms judgement-heavy exceptions and accountable hand-offs.
Connected services
An AI connected to email, calendar, documents or enterprise tools gains capabilities beyond conversation. Access should be scoped to the minimum required resource and task. The user needs a single place to see active connections, last use, granted scope and a revoke control.
Before connecting work documents, use the ChatGPT work-file permissions checklist as a practical model: classify the material, check organisational policy, minimise access and avoid uploading secrets simply because a tool can process them.
The private-phone control panel
A credible control panel should separate five functions.
View and correct
List memories in plain language, not only in a technical export. Show whether each item was stated by the user, imported from an approved service or inferred. Inferred items deserve particular scrutiny because confidence can be mistaken for fact.
Set scope and duration
Offer “this session”, “until date”, “until task completes” and “remember until I delete it”. Default short-lived operational context to expiry. Persistent memory should be an affirmative choice for sensitive categories.
Confirm consequential action
Before a payment, booking modification, message send, permission grant or document release, display the intended action and material details. A remembered preference can prepare the draft; it should not eliminate confirmation.
Revoke and end sessions
Memory deletion and access revocation solve different problems. Removing a preference does not necessarily disconnect an app; disconnecting an app does not necessarily remove previously retained context. Give the user both controls and an active-session list.
Use a temporary session
Temporary conversations should not create durable memory. They are appropriate for one-off sensitive questions, shared devices and tasks whose context has no future value. The interface should state what is still logged for safety or legal purposes instead of suggesting that “temporary” means invisible.
How this applies to VERTU's Hermes Agent
The current VERTU product knowledge base describes Hermes Agent as a personal AI agent designed to work across selected devices and services with user-controlled memory, permission and session management. Capability and availability depend on the product, software version, account configuration and connected service.
The right standard is not “the agent remembers everything”. It is that useful context is curated and revocable. A user should be able to approve what Hermes may remember, review permissions, revoke sessions and remove memories. Where an external app is involved, that app's own retention and access rules also apply.
On products such as VERTU Agent Q and the VERTU Agent Q collection, privacy claims should remain configuration-specific. Hardware isolation, permission controls and human concierge workflows can reduce particular risks, but no handset can make an unsafe recipient, exposed recovery account or over-broad connected service harmless.
Availability, interface wording and supported integrations can change. Check the live product page and device settings before relying on a particular control for a sensitive workflow.
A seven-minute memory audit
Open the assistant's memory or personalisation settings.
Remove anything inaccurate, obsolete or unexpectedly inferred.
Identify temporary context and give it an expiry date where the product permits.
Check whether deleting a chat also deletes extracted memory.
Review connected apps and revoke those no longer needed.
End sessions on devices you do not recognise or control.
Test a temporary session before using it for a sensitive one-off task.
Confirm that payments, messages, bookings and file releases still require explicit approval.
Never paste passwords, recovery codes or private keys into ordinary memory.
Record enterprise retention requirements outside the assistant so that personal settings do not override policy.
If the service cannot show what it remembers, assume that the user has less control than the interface suggests. Avoid adding sensitive context until the retention model is clear.
A product standard worth demanding
Personal AI becomes more valuable when it can preserve continuity. But continuity should be selective. The best memory system is not the one with the largest profile; it is the one that preserves the right context, asks again when consequences change, forgets temporary information on schedule and declines to become a casual vault for secrets.
For a private phone, that standard can be expressed in four verbs: remember, confirm, expire and refuse. If each memory has one of those states—and the owner can see and change it—the assistant's convenience is much less likely to become uncontrolled accumulation.




