Legible AI memory

Recall: a memory manager for what an assistant knows about you

Attribute every fact. Scope it to a context. Revoke it on your terms.

Personalization is supposed to help, but it accumulates in the dark. The assistant builds a picture of you from things you said once and things it inferred, and you never see the picture. You can't tell what it knows, where a belief came from, which project it's bleeding into, or how to take it back. Recall makes that memory legible. Every remembered fact is a card you can read, attributed to its source, scoped to where it applies, edited when it's wrong, and forgotten, precisely, when you want it gone.

Live app: Recall, the assistant memory manager.

The problem: personalization that accumulates out of sight

Personalization is invisible by default. You can't manage what you can't see, and right now there's nothing to see.

A helpful assistant remembers. But memory without a surface becomes a quiet dossier: facts you stated, guesses it made, preferences from one project leaking into another, all piling up with no way to inspect or correct them. The fix isn't to remember less. It's to make memory legible. Four capabilities turn an invisible store into something you control.

In use
Scoped to a project
Withheld
Forgotten

Drag the handle. The opaque store is on the left, the same memory rendered legible on the right. State colors follow the memory palette: indigo in use, slate scoped, coral withheld, rose forgotten.

01
See it

Every remembered fact is a card you can read. No hidden dossier, no guessing what it knows.

02
Attribute it

Each fact shows its source: “you told me directly” or “inferred from 3 chats,” with a confidence read.

03
Scope it

Decide where a memory applies: this project, everywhere, or off. One context never bleeds into another.

04
Revoke it

Forget a fact precisely, from one project or from everywhere. Named explicitly, never a vague wipe.

The thesis: every remembered fact is an object you can inspect

If the assistant remembers something about you, that something should be a thing you can point at, with a source, a scope, and an off switch.

Recall treats each remembered fact as a first-class object: the claim, where it came from, how confident the inference was, and exactly where it's allowed to apply. Rendered that way, memory stops being a vague sense that the assistant “kind of knows you” and becomes a list of discrete cards, each one editable, scopable, and revocable on its own. Legibility is the precondition for control.

A single memory card, rendered live in the Minia design system, the same theme as the app above.

Scope: where a memory is allowed to apply

The question isn't only what the assistant remembers. It's where that memory is allowed to act. Context is the dial.

A fact that helps in your work project can be irrelevant or unwelcome in a personal chat. Recall makes scope explicit: a memory can apply everywhere, stay pinned to one project, or be switched off. As you move between contexts, a live panel shows what's in use right now and what's being held back, so personalization never follows you somewhere it doesn't belong.

What's used versus withheld, by context, rendered live in the Minia design system, the same theme as the app above.

Forgetting one fact without wiping everything

“Clear all memory” is a blunt instrument. Forgetting should name exactly what's leaving and from where, so you can remove one thing without wiping everything.

The right to be forgotten only means something if it's specific. Recall's forget flow states the exact fact in plain language and offers a real choice: remove it from this project, or forget it everywhere. No silent deletion, no all-or-nothing wipe, no ambiguity about what the assistant will carry forward. Revocation is a deliberate, legible act, which is the natural endpoint of memory you can see.

Forgetting, named and scoped, rendered live in the Minia design system, the same theme as the app above.

What legible memory changes for the person

When memory is legible, personalization becomes a negotiation instead of a surveillance byproduct. You keep what helps, scope what's situational, and drop what you never wanted kept.

Try it in the app above. Keep or discard the four notes the afternoon produced, then switch from the Strategy desk to the Job search workspace and watch which memories drop out of what the assistant will draw on. Scope one fact to a single workspace, bring a fact home from another, and forget the noisy inference for good. The memory log records every change, so what the assistant knows is a ledger you can read, not a box you have to trust.

How the design changed from v1 to v6

Legible memory didn't start as a manager. Each version exposed one more layer, from an opaque on/off switch to provenance, scope, and precise revocation.

It began as one toggle that hid everything behind it and ended as a surface you can read and steer. Each step closed a gap between what the assistant remembered and what you could see and decide, until memory was attributable, scopable, and revocable, fact by fact.

  • 1

    A single “memory: on/off” switch

    All or nothing. You could switch memory off, but never see or touch a single thing it held.

  • 2

    + A readable list of memories

    Surfaced the facts as text. Visible at last, but flat, with no sense of where any of it came from.

  • 3

    + Provenance & confidence

    Tagged each fact “you told me” or “inferred,” with a confidence hint, so a guess no longer looked like a quote.

  • 4

    + Edit in place

    Made memories correctable. A wrong inference became a quick fix instead of something you had to wipe and re-teach.

  • 5

    + Scope by context

    Added this project, everywhere, or off, with a live read of what's used where, so contexts stopped bleeding together.

  • 6

    + Precise revocation · current

    Forgetting that names exactly what leaves and from where: one project or everywhere, on purpose.

Explore more in the AI Product Design Lab

Steer settles the brief before the model writes, Ground traces every claim back to what supports it, and Oversee gates what an agent may do on its own.

Steer, settling the brief before the model writes
A loose request lets the model quietly decide audience, goal and tone for you. Steer turns it into a visible brief, every inferred assumption an editable chip, and flags the forks it should not resolve alone.
Ground, seeing what a claim rests on
A fluent paragraph reads as one confident thing, but some of it is well sourced, some rests on a single stale page, and some is invented. Ground attaches sources, confidence and freshness to every claim, flags what nothing backs up, and sets conflicting sources side by side rather than averaging them. Moment two of four.
Oversee, autonomy you can supervise
Chatbots talk; agents send the money and change the records, and an are you sure prompt does not scale to work running for minutes across dozens of steps. Oversee makes autonomy a setting, previews effects in a dry run, treats interruption as a first class action, and keeps everything reversible. Moment three of four.