Client-owned vaults for memories, private files, and credentials. Start on your device; connect other devices and AI tools when you choose.由你持有的保险库,保存记忆、私人文件和凭据。从本机开始,再按需连接其他设备与 AI 工具。
A conceptual view of a vault, not an app screenshot.保险库概念示意,非应用截图。
01 /Keep data on your device数据保存在自己的设备上
02 /Choose what to connect按需选择连接方式
03 /Grant access explicitly明确授权后再访问
A useful, private foundation实用的私人数据基础
One vault system. More ways to use it.一套保险库, 多种使用方式。
Shared Rust foundations across the command line and mobile clients. Optional services extend how you connect, not who owns your data.命令行与移动客户端共用 Rust 核心。可选服务拓展连接方式,数据仍由你持有。
01
Local vaults & encryption本机保险库与加密
Store memories, knowledge cards, private files, and credentials with local encryption. Read, search, and follow revision history; explicitly private content stays out of ordinary search.记忆、知识卡片、私人文件与凭据在本机加密保存。支持读取、搜索和版本历史;显式标记为私有的内容不进入普通搜索。
Your data, your device自己的数据,自己的设备02
CLI & local daemon命令行与本机守护进程
Use the memories Rust CLI through a local daemon: a Windows named pipe or a Linux/macOS Unix socket, restricted to the current OS user.Rust 命令行 memories 通过本机守护进程工作:Windows 使用命名管道,Linux/macOS 使用 Unix socket,仅限当前操作系统用户。
Local IPC本机进程间通信03
Optional remote daemon可选远程守护进程
Connect through token-authenticated HTTP/WebSocket or relay RPC when needed. Remote access uses the service protocol and remains subject to unlock and elevation checks.按需通过令牌认证的 HTTP/WebSocket 或中继 RPC 连接。远程访问使用相同的服务协议,仍需经过解锁与提权检查。
Centers issue device enrollment and scoped MCP grant tickets. They can disable local self-bootstrap; they provide authorization policy, not vault key escrow.授权中心签发设备注册票据和限定范围的 MCP 授权票据,也可禁止本机自行初始化。它负责授权策略,而不是托管保险库密钥。
Android/iOS clients call the shared Rust service through memories_ffi. A local MCP server and AI skill injection bring authorized ordinary memories and cards into your AI workflow, without returning stored credential values.Android/iOS 客户端通过 memories_ffi 调用共用的 Rust 服务。本机 MCP 服务与 AI skill 注入,让 AI 工作流访问获授权的普通记忆和卡片,不返回已保存的凭据值。
Android / iOS / MCP06
Device pairing & transfer设备配对与保险库传输
Pair devices with invitations, fingerprint checks, and approval. Transfer encrypted vaults by file or a WebSocket relay. Online transfer is explicit and whole-vault, not automatic incremental sync.通过邀请、指纹核对与批准完成设备配对。加密保险库可经文件或 WebSocket 中继传输;在线传输需明确发起,采用整库传输,并非自动增量同步。
Explicit connections明确建立连接
How it fits together各部分如何协作
Local at the core. Connected by choice.以本机为核心, 按需连接。
Start with a local vault. Add a relay, remote endpoint, or authorization Center only if your workflow calls for it.从本机保险库开始。只有在工作流需要时,才添加中继、远程端点或授权中心。
01 / Your tools01 / 你的工具
CLI, mobile, AI命令行、手机、AI
Desktop CLI and MCP use the local daemon. Mobile uses the shared Rust core through FFI.桌面 CLI 与 MCP 使用本机守护进程;移动端通过 FFI 使用共用的 Rust 核心。
memories · memories_ffi→02 / On your device02 / 在你的设备上
Encrypted vaults加密保险库
Local storage, keys, and authorization checks. The local daemon serves the current OS user.本机存储、密钥与授权检查。本机守护进程仅服务当前操作系统用户。
Local is the starting point从本机开始⇢03 / Optional connections03 / 可选连接
These are separate optional services, not a required chain. The stateless memories-relay does not store assets or queue transfers for offline devices.这些是独立的可选服务,不是必须依次经过的链路。无状态的 memories-relay 不存储资产,也不为离线设备排队传输。
A small beginning从简单的一步开始
Your first local vault.创建第一个本机保险库。
You’ll need Rust 1.88+ and a platform C toolchain for bundled SQLite. These examples follow the repository README.需要 Rust 1.88+ 和平台 C 工具链,用于编译随附的 SQLite。以下示例来自仓库 README。
01
Install from source从源码安装
Clone the repository and install the Rust CLI from its root directory.克隆仓库,在仓库根目录安装 Rust 命令行程序。
Terminal终端01
git clone https://github.com/mbcc2006/memories.git
cd memories
cargo install --path crates/cli --locked
02
Start the local daemon启动本机守护进程
Keep this running in a separate terminal. Use a new, dedicated data directory: --home restricts its permissions. Never use an existing general-purpose folder.在单独的终端中保持运行。使用新的专用数据目录:--home 会限制目录权限,切勿指向已有的通用文件夹。
Terminal A · keep running终端 A · 保持运行02
memories --home ./memories-demo daemon
03
Create, write, search创建、写入、搜索
Open another terminal in the same directory. Replace VAULT_ID with the ID returned by vault creation, and create a notes.md file before importing it.在相同目录打开另一个终端。将 VAULT_ID 替换为创建保险库时返回的 ID,并在导入前准备好 notes.md 文件。
Packages are served from r2.ivjn.us. Verify the SHA-256 checksum before you run anything. macOS builds are Apple silicon (arm64) only for now.包托管在 r2.ivjn.us。运行前请先核对 SHA-256。macOS 目前仅提供 Apple 芯片(arm64)版本。
Memories, private files, credentials, and private key material are encrypted in the local store. Keys stay on user devices. Public device keys and fingerprints are intentionally visible. Once unlocked, authorized clients can access permitted content; local encryption is not protection against a compromised endpoint.记忆、私人文件、凭据与私钥材料在本机存储中加密,密钥留在用户设备上。设备公钥与安全指纹有意保持可见。解锁后,获授权的客户端可以访问权限范围内的内容;本机加密不保护已被攻陷的设备。
What can the relay see?中继能看到什么?+
The relay forwards encrypted traffic, not asset plaintext. It can observe traffic metadata. The shipped relay stores no assets and does not queue for offline devices, but a relay operator could record ciphertext or block connections. Device fingerprint verification remains important.中继转发加密流量,而非资产明文,但能观察流量元数据。随附的中继不存储资产,也不为离线设备排队;不过,中继运营者仍可能记录密文或阻断连接。设备指纹核对仍然重要。
Do I need a relay or a Center?必须使用中继或授权中心吗?+
No. A local vault and daemon are enough to begin. A relay supports online encrypted device transfer, a remote daemon offers token-authenticated access, and a Center issues enrollment and MCP grant tickets. Each is optional and serves a different purpose.不需要。本机保险库与守护进程即可开始使用。中继用于设备间在线加密传输,远程守护进程提供令牌认证访问,授权中心签发设备注册与 MCP 授权票据。它们各有用途,均为可选。
Can AI tools read my credentials?AI 工具能读取我的凭据吗?+
MCP access is limited by explicit vault grants. It can work with authorized ordinary memories and cards, but does not return stored credential values or explicitly private content, and cannot inherit terminal elevation. Skill injection helps supported AI clients use these tools; it does not remove their access boundaries.MCP 访问受明确的保险库授权限制,可处理获授权的普通记忆和卡片,但不返回已保存的凭据值或显式标记为私有的内容,也不继承终端提权。Skill 注入帮助受支持的 AI 客户端使用这些工具,不会取消访问边界。
What is the project’s development status?项目目前处于什么阶段?+
This is a development release using storage format v1, with executable code and security regression tests. It has not undergone an independent cryptographic or application security review. See the security notes for its guarantees and current limits.这是使用 v1 存储格式的开发版,包含可执行代码与安全回归测试,尚未经过独立的密码学审查或应用安全审计。具体保证与当前限制请参阅安全说明。
Begin with what’s yours从自己的数据开始
Make room for your memories.给自己的记忆留个位置。
Explore the code, read the guides, and try a local vault.了解源码,阅读指南,试用本机保险库。