Privacy & safety

Approved architecture intent β€” not a legal compliance claim. No COPPA, biometric, or trademark clearance is asserted as complete.

theBRAIN is designed so your intelligence stays close to you: on-device by default, with a visible listening state, and with cloud help only when you choose it.

theBRAIN on a private desk β€” local by default

What stays local

  • Local GGUF inference is the default path for answers and assistance.
  • Camera and face matching default off; enrollment is explicit; embeddings stay on-device.
  • Raw audio is intended for short processing windows β€” not silent always-on capture.
  • Shell LEDs show listening and assist state so the room can see what the unit is doing.
Technical details β€” on-device posture
  • Models and working memory stay on the Pi unless you opt into frontier assist.
  • No provider API keys are stored in shell firmware, adapters, or provenance logs.
  • Unauthorized runtime effects for gated features remain hard-coded false until enabled.

Data flow

Shared room with visible listening state
  • Frontier assistance is opt-in, routed through Scooling, with a distinct LED state.
  • Provider API keys never live on the Pi.
  • Scooling owns identity, pairing, parental gates, signed work packets, and revocation.
  • Knowtation owns canonical knowledge and write-back.
  • MuseHub owns artifact provenance.
  • Hybrid mode sends scoped retrieval context β€” not the full vault.
  • Review-before-write; outbound-only edge connections; signed, expiring, revocable packets.
Technical details β€” Scooling
  • Identity, pairing, parental gates, and work-packet dispatch live in Scooling.
  • Frontier calls are brokered there; the device never holds cloud provider secrets.
  • Packets are signed, time-bounded, and revocable from the control plane.
Technical details β€” Knowtation
  • Canonical notes and write-back belong to Knowtation β€” not the shell.
  • Retrieval is scoped; hybrid assist sends context slices, never the full vault by default.
  • Review-before-write keeps humans in the loop before knowledge is committed.
Technical details β€” MuseHub
  • Artifact provenance and creative power-ups surface through MuseHub.
  • Provenance records must not include secrets, credentials, or raw key material.
  • theBRAIN consumes MuseHub capabilities via adapters β€” not direct vault ownership.

Child posture

  • Push-to-talk by default for child profiles
  • Camera parent-enabled and default off
  • Parent/teacher-scoped context
  • Raw audio deleted after transcription (intent)
Technical details β€” child profiles
  • Parental gates and scoped knowledge are enforced through Scooling account posture.
  • Child sessions inherit push-to-talk and camera-off defaults until a parent changes them.
  • Write-back into a child’s scoped vault still requires review paths where configured.
Parent and child with a desk theBRAIN β€” supervised, calm home scene

Team posture

  • Explicit, discoverable recording consent
  • Visible listening state via LEDs
  • Neutral shared-device framing β€” a mentor in the room, not a hidden recorder
Technical details β€” shared rooms
  • Shared units keep a visible listening state while active in a room.
  • Personal brains remain private; joining a room brain is an explicit choice.
  • Consent and revocation for group capture follow the same signed-packet model.

FAQ Β· How it works

Team in a shared studio with a visible-listening theBRAIN on the table