Privacy & safety
Approved architecture intent β not a legal compliance claim. No COPPA, biometric, or trademark clearance is asserted as complete.
theBRAIN is designed so your intelligence stays close to you: on-device by default, with a visible listening state, and with cloud help only when you choose it.

What stays local
- Local GGUF inference is the default path for answers and assistance.
- Camera and face matching default off; enrollment is explicit; embeddings stay on-device.
- Raw audio is intended for short processing windows β not silent always-on capture.
- Shell LEDs show listening and assist state so the room can see what the unit is doing.
Technical details β on-device posture
- Models and working memory stay on the Pi unless you opt into frontier assist.
- No provider API keys are stored in shell firmware, adapters, or provenance logs.
- Unauthorized runtime effects for gated features remain hard-coded false until enabled.
Data flow

- Frontier assistance is opt-in, routed through Scooling, with a distinct LED state.
- Provider API keys never live on the Pi.
- Scooling owns identity, pairing, parental gates, signed work packets, and revocation.
- Knowtation owns canonical knowledge and write-back.
- MuseHub owns artifact provenance.
- Hybrid mode sends scoped retrieval context β not the full vault.
- Review-before-write; outbound-only edge connections; signed, expiring, revocable packets.
Technical details β Scooling
- Identity, pairing, parental gates, and work-packet dispatch live in Scooling.
- Frontier calls are brokered there; the device never holds cloud provider secrets.
- Packets are signed, time-bounded, and revocable from the control plane.
Technical details β Knowtation
- Canonical notes and write-back belong to Knowtation β not the shell.
- Retrieval is scoped; hybrid assist sends context slices, never the full vault by default.
- Review-before-write keeps humans in the loop before knowledge is committed.
Technical details β MuseHub
- Artifact provenance and creative power-ups surface through MuseHub.
- Provenance records must not include secrets, credentials, or raw key material.
- theBRAIN consumes MuseHub capabilities via adapters β not direct vault ownership.
Child posture
- Push-to-talk by default for child profiles
- Camera parent-enabled and default off
- Parent/teacher-scoped context
- Raw audio deleted after transcription (intent)
Technical details β child profiles
- Parental gates and scoped knowledge are enforced through Scooling account posture.
- Child sessions inherit push-to-talk and camera-off defaults until a parent changes them.
- Write-back into a childβs scoped vault still requires review paths where configured.

Team posture
- Explicit, discoverable recording consent
- Visible listening state via LEDs
- Neutral shared-device framing β a mentor in the room, not a hidden recorder
Technical details β shared rooms
- Shared units keep a visible listening state while active in a room.
- Personal brains remain private; joining a room brain is an explicit choice.
- Consent and revocation for group capture follow the same signed-packet model.
FAQ Β· How it works
