An encrypted memory vault that lives on your Mac. Your memories, your projects, and your working state follow you across the AI apps you use. Start a piece of work in Claude, pick it up in Codex or Cursor, and the second agent can pick up where the first one stopped.
Free and open source · Apple Silicon · signed & notarized · private by default, nothing leaves your machine unencrypted unless you share it (a new project an app you connected creates is shared automatically, and so are your later edits to it), message a cloud model you picked or run a memory review on one (masked first, either way), or approve a tool call
Both start from the same encrypted vault on your machine. You decide what each app may read, and NorthKeep is honest about what reaches the cloud.
One click wires NorthKeep into Claude Desktop, Claude Code, or Cursor on this Mac. For the cloud apps you use elsewhere (ChatGPT, Claude on your phone), an optional connector lets the scopes you choose reach them. Either way you decide, per app and per scope, exactly what it may read.
Review what they save. The Review page finds duplicates and has a model suggest fixes for near-duplicates, showing the memories behind each one. Nothing changes until you approve it, and each change is recorded and can be restored. Review needs Ollama on this Mac; a cloud model is optional, confirmed each run, and memories are masked before they are sent.
Honest boundary: Connect gives you ownership and portability, not a firewall, and it can't redact what you type into someone else's app. The cloud connector is opt-in per scope, with one exception: a new project that an app you connected creates arrives already shared, so that app can keep it updated. Shared memories are encrypted at rest there: the connector database holds no key that can read them, and the key is rebuilt each request from your app's own credential plus a secret on our server, which briefly decrypts them so the apps you connect can read the result in full. Scope names, counts, and timestamps stay visible to the server. Private scopes never leave your machine.
Each project keeps its status, next actions, decisions and log in your vault. Claude Code, Codex and Cursor (per project) resume it when a session starts, checkpoint along the way, and wrap it when the work is done, so the next app starts from the latest save instead of from scratch.
Honest boundary: a short standing instruction asks each app to resume and save. It is advisory, so a session that ends abruptly keeps only what it saved with a checkpoint.
Start a project in Claude Code, pick it up in Codex or Cursor. Its status, next actions, decisions and log live in your vault, and the next app can resume where the last session stopped.
project_resumeWhen a session starts, the app reads the live project and picks up where the last session stopped. It also lists up to three other sessions on this Mac, from the last 30 days, that read the project and did not save back.
project_checkpointPart of the way through, the app saves progress. On this Mac, each save names the version it read, and a save made from an outdated copy is refused.
project_wrapWhen the work is done, the app saves once more and ends the session. On any save, older Log entries move into archive memories, so the live document stays small for the next app.
Honest boundary: the session contract, a short standing instruction, asks the app to take these steps. It installs only into Claude Code, Codex, and Cursor (per project). Claude Desktop plain chat and ChatGPT have no instruction file, and apps reaching NorthKeep only through Cloud Connect cannot follow the three local tools. It is advisory: a session that ends abruptly keeps only what it saved with a checkpoint.
The app name on a save is the one the app reported. NorthKeep records it and does not verify it.
northkeep projects board
Each project shows its current status, next actions and decisions, the app name reported with the last save, and whether it is still a draft. You can rename a project, edit its summary, or delete it after a confirmation that names it.
An AI app using the hosted connector, for example Claude.ai, can create a project. When you sync, the new project arrives marked Shared, and later edits to it are pushed. Anything an app writes into a project you have not shared is held until you share it.
northkeep projects export writes your projects as readable files into a git folder you set up and commits them. It never pushes or fetches, and --schedule runs it hourly or daily. The files are plaintext in the folder you chose.
northkeep projects board lists stale projects, dated items, open sessions, drafts and projects that need repair, with no model and no network. Connected apps on this Mac can read it with project_board.
One encrypted file you can copy, back up, and move. Your memory lives in none of the AI apps, so switching costs nothing.
Keys with a known issuer prefix, card numbers, SSNs, emails, phone numbers and similar identifiers are always masked before a cloud memory review leaves your machine, and names too at Tier 2 and up. A key with no recognizable prefix or a password is not caught.
Grant one app your work memory only, another nothing sensitive. Enforced at the vault, not on trust.
Import your ChatGPT or Claude export. Extraction runs entirely on your machine, and you review every memory before it's kept.
Run memory review on a local model via Ollama, or on Anthropic or an OpenAI-compatible endpoint with your own key. Near-duplicate checks still need Ollama with nomic-embed-text on this Mac. You pay the provider directly.
Move your vault between machines. The server only ever holds ciphertext it cannot decrypt, never a key, never plaintext. We could not read it if we wanted to.
Share the scopes you choose to the AI apps you already use, so Claude and ChatGPT remember you on your phone too. Stored encrypted at rest with no key kept in that database; decrypted only for the moment it takes to answer your app. Opt-in per scope (a new project an app you connected creates arrives shared), reversible.
Everything that runs on your machine is free. You only pay for the one thing that runs on ours.
Then that session's work is not in the project. The session contract asks each app to checkpoint and wrap, but it is advisory, and a session that ends abruptly keeps only what it saved with a checkpoint. If the session read the project through NorthKeep's local server on this Mac, the next resume lists it as an open session, so you can see that it happened.
No, with one exception you turn on yourself. Your vault is encrypted on your device, and we never receive your key. If you use hosted sync, our server stores only ciphertext it cannot decrypt plus a version number. The exception is a scope you deliberately share with the connector (see Connect above): it is stored encrypted at rest, the connector database holds no key that can read it, and the server briefly rebuilds the key per request (from your app's credential plus a server-side secret) to decrypt it so your AI apps can read it. There's no telemetry and no analytics in the app.
Their memory lives on their servers and stays in their app. NorthKeep's memory lives on your machine and plugs into whichever apps you use, so it's portable, owned by you, and you set what each app can read.
No, and we won't pretend it does. When you type into another company's app, that company sees what you type. Connect gives you portable, owned memory with per-app scopes.
Converse, NorthKeep's own chat that masks your message before it leaves and restores the details in the reply, is now a legacy feature. Honestly, it wasn't getting much use: people would rather keep working in the AI apps they already pay for, and NorthKeep does more good making those apps remember you and pick up your projects. NorthKeep has no telemetry, so that is our read, not a usage count. Converse still runs where it runs today, in the iPhone app (beta) and from a source install, but we are not adding to it, and it will be retired over time. Memories it saved from the terminal stay in your vault like any others.
The vault is unrecoverable. There's no back door, which is exactly why no one else can get in either. Back up your device.secret file and keep your passphrase safe.
Yes, AGPL-3.0. You can read the code, run it, and self-host the sync server for free. A commercial license is available for businesses that don't want the AGPL's obligations.
Occasional notes when something ships. Leave an address if you want them.