Kioku is a cloud product. Here is exactly what that means.

A recorder you switch on should tell you where your day goes and who can touch it. This page is that, in plain language — including the parts that aren’t flattering.

The short version

  • Queryable memories and account state live in private, encrypted Cloud SQL PostgreSQL.
  • Cloud SQL and authorized Kioku/Google Cloud administration are inside the structured-data plaintext trust boundary.
  • Large raw audio and screenshots are separately encrypted per user before GCS storage.
  • Raw audio and screenshots are scheduled for deletion after 30 days.
  • Your assistant gets read-only access, behind a safety boundary that refuses sensitive-category searches.
  • The enclave application that terminates public TLS and processes requests is open source. You can read it.

What leaves your Mac

While capture is running, the Mac app uploads bounded microphone and system-audio snippets, screenshots, application and window titles, browser URLs and tab observations, timestamps, and device and stream metadata. It captures only while you have capture on: you start and stop it from the menu bar, and macOS shows its own recording indicator whenever a microphone is live.

The Mac adds screenshots and available browser context; the iPhone records microphone audio only.

What each app captures
Kioku for MacKioku for iPhone
Bounded microphone and system-audio snippetsBounded microphone audio
Screenshots, application and window titlesNo screenshot or photo acquisition path, and no Photos access requested
Browser URLs and tab observations
Timestamps, device and stream metadataTimestamps, device and stream metadata

Neither app transcribes, runs OCR, or identifies speakers on your machine. They capture, timestamp, encrypt, and upload. Kioku for iPhone is in limited private testing and is not on the App Store.

Where it is processed, and by whom

The open-source Kioku service runs in a Google Cloud Confidential Space enclave with AMD SEV memory encryption. Bounded raw audio and screenshot pixels are sent from that enclave to Google Vertex Gemini for timestamped transcription, diarization, OCR, and screenshot understanding. Settled-episode transcripts, OCR text, application and window provenance, URLs, browser-tab metadata and derived textual context may also be sent for summaries and recall features. Google processes this material under its applicable enterprise data terms.

Queryable account, transcript, OCR, browser, memory, people/voice, search, job, and delivery state lives in private regional Cloud SQL PostgreSQL. Connections and storage are encrypted, access is role-limited and audited, and the database is not public. This is conventional managed-cloud trust, not end-to-end encryption: the database engine and authorized Google Cloud/Kioku administrators can process structured plaintext, including retained backup copies.

That processing happens outside the hardware-attested enclave. On iPhone, recording and media upload remain blocked until the signed-in user explicitly allows Google AI processing, and withdrawing that permission stops new capture and future uploads. The Mac cloud-capture pipeline continues to use this processing as the step that turns capture into memory.

One thing is not delegated: voice embeddings and persistent cross-meeting identity matching are computed by Kioku inside the enclave, not by Gemini.

The enclave

Pure Swift capture clients

Apple-native clients capture, encode, timestamp, spool, and upload. Transcription, OCR, diarization, identity learning, and indexing run in the cloud, with no Python, model, or local server in the Mac app.

Hardware-attested application runtime

Public TLS termination, authorization, media decryption, voice inference, and provider orchestration run in a GCP Confidential Space fleet with AMD SEV memory encryption. Structured storage is the separate Cloud SQL boundary above.

GCP Confidential Space · AMD SEV

Per-user encrypted large media

Raw audio and screenshots in GCS are encrypted with per-user AES-256-GCM keys released to the exact attested application image. PostgreSQL isolation instead uses account-qualified schema, authorization, and database roles.

Open source — verify it yourself

The enclave image is open source. You can inspect exactly what code runs in the trusted environment and confirm that the attestation matches the published source.

What your assistant can and cannot do

Connecting Kioku to ChatGPT or another supported assistant uses OAuth authorization, and the grant is read-only. Your assistant can search and read your own archive. It cannot start or stop capture, edit your archive, delete anything, or send email.

Six tools are exposed: search_transcripts, search_screenshots, list_episodes, get_context, summarize_time_range, get_capture_status.

An MCP-only safety boundary refuses searches aimed at payment-card data, health information, government identifiers, passwords, API keys, tokens, or authentication codes. Those requests are refused before archive retrieval. Incidental matches are redacted before anything leaves, and URL query strings and fragments are removed. Kioku does not persist the text of MCP search queries.

Kioku access tokens expire after approximately 15 minutes. The web dashboard stores one rotating Kioku refresh credential in that browser profile for up to 90 days so reloads stay signed in; provider tokens and memory content are not stored there, and explicit sign-out removes it. Same-origin script, extensions, and device access remain browser-endpoint risks. Assistant refresh authorization separately expires after 90 days, or earlier if you disconnect or delete the account. You can disconnect Kioku from the assistant’s own connection settings, and deleting your Kioku cloud account invalidates its authorization.

One honest caveat: content already returned to an assistant may remain in that provider’s chat history, and Kioku cannot retract it.

What ages out, and what stays

Encrypted raw audio and screenshot objects are scheduled for application deletion after 30 days. The dedicated current-media bucket adds a 35-day orphan lifecycle failsafe.

The derived archive — transcripts, OCR text, metadata, summaries, learned people, voice profiles, facts, and source evidence — stays until you delete your cloud account. Kioku does not use inactivity alone to silently delete your archive.

Your controls

Recording is never silent or always-on: you start and stop it yourself from the Kioku icon in your Mac menu bar, and the menu shows whether capture is running. From the dashboard at kiokuu.com/app you can choose whether Kioku emails you when a memory is ready and whether that email carries content; add, pause or delete webhook destinations (content-free finalized-episode notifications are the default); and under Settings → Data & Privacy export supported account data or permanently purge your cloud account. An assistant connection is revoked from that assistant’s own connection settings, and deleting your Kioku cloud account invalidates its authorization.

Purging removes capture metadata, raw-media objects, transcripts, OCR text, episode summaries, learned people, facts, identity evidence, voice profiles and samples, account preferences, stored OAuth grants, push installations and delivery handoffs, webhook endpoints, and webhook signing secrets from Kioku’s serving systems. It cannot retract content already transferred to ChatGPT, Apple, a webhook destination, or another provider.

One thing to be straight about: Mac audio/screenshots and automatic voice/person learning are part of the normal Mac cloud-capture pipeline rather than separate opt-in features. The iPhone app is voice-only and asks for explicit permission before sending microphone recordings, transcripts, or voice characteristics to Google Vertex AI/Gemini; declining blocks recording and upload, and withdrawing permission stops future capture and processing.

What Kioku does not do

Kioku does not sell your personal information, use your private archive for advertising, or train a Kioku model on your archive.

Kioku does not receive complete payment-card details. Apple processes App Store in-app purchases under Apple’s terms. Paddle is the merchant of record for web purchases and handles their checkout, payment methods, billing addresses, tax, invoices, refunds, and disputes under Paddle’s terms.

Kioku never links two accounts by matching email addresses. Sign-in providers are linked only by an explicit, authenticated action.

What Kioku is not

Kioku does not process your media on your Mac. Cloud synchronization and understanding need an internet connection, although bounded capture may wait in an encrypted, backup-excluded local retry queue during an ordinary outage after account authority has already been established. Your media is encrypted in transit and at rest, decrypted for processing inside an attested enclave, and bounded media is sent from that enclave to Vertex Gemini for understanding — so it is not end-to-end encrypted from your machine to us.

Several products in this space are vague about exactly this. We would rather you decide with the real architecture in front of you.

Reporting a problem

Found a security or privacy issue? Email security@kiokuu.com. Product questions go to support@kiokuu.com or the support page.

Now the boring part is over.

If none of the above was disqualifying, the free plan needs no card and takes about two minutes to set up.

Download free for Mac

macOS 14 or later · Signed and notarized by Apple · Free plan, no card required