Personal releases runs on your own machine Personal: Apache 2.0

An assistant that actually knows you.

Soulacy learns how your days work, what you have promised, and who is waiting on you — by asking, not by watching. It handles what it can and asks before the rest. Run Soulacy Personal on infrastructure you control. Everything it learns about you stays there. The installation and footprint details here describe Personal.

Honest about setup: Soulacy runs on your own machine or a small VPS. Expect a terminal and about ten minutes. There is no hosted version to sign up for, which is the same reason nobody else holds your data.

$ curl -fsSL https://soulacy.io/install.sh | bash
Binary Size Build-dependent 44.2 MB measured example
Idle RAM Depends on setup Local model memory is extra
Start Time Readiness-checked Hardware and services matter
Dependencies Core: no Node/Python Tools and providers may need more

Personal's prebuilt gateway includes the web UI; platform libraries, TLS trust, model access, and optional tool runtimes still apply. Size excludes the CLI, container image, and model downloads. Measurement details and requirements →

Interactive Prompt Injection Sandbox

Probe the deterministic pattern scanner & intent gate rules in real-time.

Input Payload (e.g. tool output, untrusted web page, or user chat): <external_content>
Activity — Security Doctor · Interactive Sandbox
Scanner rules matches: 0 Max Finding: none
what it does for you

Most assistants answer questions. This one keeps track.

Ask a chatbot the same thing twice and it has forgotten you in between. Soulacy keeps a structured picture of how your days actually go, and every agent you run reads the same one.

it learns you, by asking

Not a chat history. Your routine, the people who matter, what you owe and when, how you want to be helped. It asks a few questions on your first day and records your answers in your words. This is a conversation in your browser; no phone, no sensors, nothing switched on.

it can also notice — optional

Add the iPhone app and allow a sense, and it keeps up on its own: a deadline moving, a Focus turning on, today not looking like a normal Tuesday. Skip it and Soulacy still works; it just knows only what you told it.

it stays quiet

“Nothing needs you today” is a real answer, and the system prefers it. An assistant that finds something urgent every morning is one you stop reading.

it stays yours

Every line says where it came from, and you can correct or delete any of it. Nothing is watched until you switch it on, and switching it off erases what it worked out. See the model →

Everything past the first card is opt-in, one sense at a time, and the phone app is optional throughout. “Private” is a claim anyone can make. Soulacy runs on your own machine, which is why ours is checkable.

why soulacy

Why not a chatbot, or one of the many frameworks?

A chatbot forgets you between questions and cannot act. A framework hands you the parts and leaves the assistant for you to build. With every other option, what an agent may do is something you trust; with Soulacy it is something you can check.

what an agent may do

Others: whatever the code, the canvas, or the hosted service was set up to allow. You audit it or trust it.

Soulacy: nothing risky happens unless you approved it, or you can point to the line that allowed it. Enforced by the runtime. Check it yourself →

what you have to build or rent

Others: frameworks like LangGraph or CrewAI leave you to build hosting, sign-in, a UI, channels, and scheduling. Visual platforms and hosted services rent you theirs.

Soulacy: one binary on your own hardware with all of it inside, including a native iPhone companion.

how an agent is written

Others: a program in Python or JavaScript, or boxes on a canvas that export poorly and diff worse.

Soulacy: one YAML file anyone can read, review in a pull request, and roll back. Studio writes it from plain English.

What that looks like in practice

Three things people run today. Each links to a walkthrough with sample input, a checkable result, and the failure cases.

every morning · 7:00

A briefing on your iPhone before you get up

Point an agent at the notes and sources you choose, set a schedule in its file, pair your phone once. Each morning it writes the briefing and pushes it to you. No app to build, no cloud account, and it runs on a laptop or a $5 server you own.

Why it is different: scheduling and native iPhone delivery are built into the runtime, not something you assemble.

See the walkthrough →
on demand · with sources

Answers from your own documents, with the passage they came from

Load a handbook, a policy set, or your project notes. Ask a question from Slack, Telegram, or the web UI and get an answer that cites the exact passage. The documents never leave your machine, and the run record shows what the agent read.

Why it is different: evidence you can inspect, on private data, instead of an answer you have to trust.

See the walkthrough →
writes to real systems · reversible

Update a customer record, see the change first, undo it later

Ask an agent to reassign an account. Before it writes, it shows exactly which fields will change and waits for your approval. It writes only those fields, and Safe Undo can reverse the change without losing notes added afterwards.

Why it is different: approval and undo are enforced by the runtime, not left to whoever wrote the agent.

See the walkthrough →

More worked examples: meeting notes to an action plan, teach an agent your report format, and release an agent only after it passes checks.

Not for you if you are embedding agents inside a product you are building, or you want a drag-and-drop canvas for business workflows. A code framework or a visual platform fits those better, and the comparison says so plainly.

recent platform work

It learns you now, and it knows when to stay quiet.

The latest work is the part that makes Soulacy an assistant rather than a set of tools: a structured picture of the person that every agent reads, an agent that fills it in by asking, one that decides what is worth your attention today, and triggers that fire because something changed rather than because a clock struck.

👤

A picture of you every agent reads

Six parts: who you are, your usual day, how you are right now, the people who matter, open commitments, preferences. Every agent reads the same one instead of working out your context from scratch. What you say outranks what any agent infers or any sensor notices, permanently. How it works →

💬

An agent that asks, and quotes you

Getting to Know You is installed on a new gateway from the first boot. It asks about the gaps, stops after six questions, and records each answer in your own words. An agent can only mark something certain if it quotes what you actually said; invent a quote and the write is refused.

🧭

The Steward

Reads that picture, works out what is different about today, and proposes at most three things with the reason for each. A commitment counts only if it is overdue, due today, or due tomorrow. "Nothing needs you today" is a complete answer and it prefers one. Read the walkthrough →

Triggers, not timers

An agent can run because a deadline moved, a Focus turned on, or today stopped looking like a normal Tuesday. Three guards stop it firing constantly: it compares before and after rather than reacting to writes, a condition already true stays quiet, and a cooldown absorbs the burst a phone delivers after being offline. The conditions →

🎚️

Senses, off until you allow them

Small digesters turn phone signals into the picture: how you are now, the usual shape of each weekday, what you are on the hook for. Each is a switch with its purpose written next to it, off by default. Switching one off deletes what it worked out and the raw signals behind it.

🔍

Every line says where it came from

About You, on the web and on the phone, shows the whole picture labelled: what you told us, with your words underneath; what an agent guessed; what a sense noticed. Low-confidence lines are marked as guesses. Correct any line, delete any line, or forget everything, which drops the raw signals too.

Apple Watch

A complication with the approvals waiting on you and how long the oldest has left, a dictated question read back aloud, and an approvals list. The watch pairs through the phone and then holds a credential of its own, so revoking it signs out the watch alone.

📎

Photograph a receipt, ask about it

Attach a photo or file from anywhere in the iPhone app, including the quick-question sheet. Photos are read on the phone before upload, so a receipt reaches the agent as text rather than an opaque image, and the recognition never leaves the device.

🧠

Adaptive memory, still underneath

Facts distilled from conversations, superseded when they stop being true, with a per-fact history and a 50-token prompt budget. Separate from the person model: memory remembers sentences, the model holds the shape every agent agrees on. Swap in Mem0 with one setting. How it works →

native iPhone companion

Optional, and the difference between knowing you and keeping up with you.

Soulacy works without a phone: it asks, you answer, agents read what you said. Add the iPhone and it can keep up on its own — where you are, what is on your calendar, how you slept, whether a Focus is on — and it becomes where an agent asks for a decision when you are not at a desk. Every phone capability an agent can touch is a line in its file and a switch on the phone, off until you turn it on.

🔒

Approve on the lock screen

A run that needs your yes appears as a Live Activity with Approve and Deny. High-risk tools ask for Face ID. The approval is a durable record on your own gateway, so you can always answer who approved what. Only here: cloud assistants have no approval object to show you.

📍

Phone sensors as declared tools

Location, calendar, reminders, contacts, motion, Health totals and Focus state are available only to an agent whose SOUL.yaml lists them, and only after you enable the matching toggle on the phone. Two gates, both readable. Only here: user-authored agents with a permission line you can review and roll back.

🏠

Signals that stay on your network

Sleep, steps, location and Focus feed your agents and adaptive memory on a box you own, with a local model if you choose. Only here: Apple keeps Health on-device but will not run your agents; every cloud assistant needs the data uploaded.

🌙

Attended and unattended are different

A privileged step in a scheduled 3 a.m. run is refused unless the agent file says unattended: true. An attended run pages your phone and waits. The rule is in the runtime; the phone is the proof a human is reachable.

🗺️

Arrive, and an agent runs

An agent with trigger: location runs when you reach or leave a place it declared. It inherits the same permissions and records as any other run.

🚗

Siri, Shortcuts and CarPlay

“Talk to Planner in Soulacy” works on the phone, on AirPods and in the car, with replies read back. Run an agent, remember a fact or approve a pending action from a Shortcut. Approvals always wait for the phone.

📤

Share sheet in, durable inbox out

File a document, photo, link or text from any app into a knowledge base or an agent; photos are read on the phone first. Scheduled results land in an inbox on the gateway, so a missing push never loses a result.

🧾

The same safety, in your pocket

Safe Undo previews and receipts, the Learning Notebook, release gates and published-file previews all work from the phone. Offline actions queue in an outbox; sensitive writes stay online.

👪

One gateway, a household of phones

Pair a phone for someone else with their own identity, inbox and memory, as Can run agents or View only. Unpair revokes the phone and keeps their memory on the gateway.

👤

About You, in your pocket

The whole picture Soulacy holds of you, on the phone, with where every line came from. Something you said shows your own words underneath. Guesses are marked as guesses. Swipe to delete, add a line by hand, or forget everything. The sense switches live on the same screen.

🙋

Asked during setup, not after

Pairing ends with "What may Soulacy notice?", before the finish screen rather than buried in settings afterwards. Everything is off when it opens and "Not now" is a first-class answer. Consent asked after the fact is not consent.

And on your wrist

A complication showing approvals waiting and how long the oldest has left, a question you dictate and hear answered, and an approvals list. It pairs through the phone once and then talks to your gateway with a credential of its own.

Device capabilities start off and are foreground-bound. Pairing is not consent to monitoring. The iOS app and gateway are versioned independently.

Why we exist

A shipped defense-in-depth security stack.

Self-hosting does not make agent actions safe by itself. Soulacy treats untrusted content, capability scope, confirmation, filesystem access, outbound networking, identity, audit, and spend admission as first-class runtime boundaries—not optional plugins.

1. INGEST Untrusted Data Web/MCP/Channel 2. ENVELOPE (S1) <external_content> Isolate instructions 3. SCANNER (S2) 14 Regex patterns Fires severity logs 4. INTENT GATE (S3) Tool vs Goal check Intermediary audit ALLOW & RUN DENY / BLOCK
S1 · trust envelope

Untrusted-content envelope

Every external tool result is wrapped in an <external_content trust="untrusted" source="…"> block. Every agent's system prompt teaches the model to treat wrapped content as data, not instructions.

S2 · injection scanner

14 patterns · 8 attack families

Deterministic scanner runs on every wrapped body. Covers prompt_override, role_swap, secret_exfiltration, tool_incitement, hidden_text, obfuscation, data_exfiltration, channel_abuse.

S3 · intent gate

Refuses adversary-steered actions

High-risk tool calls (shell_exec, write_file, http_request, MCP write verbs) that the operator's goal didn't request AND that land on untrusted evidence with a High-severity finding are DENIED at dispatch. Before policy, guardrail, and confirm layers run.

S4 · production readiness

Blocks unsafe launch state

The production deployment profile BLOCKS launch when any privileged agent is exposed on a shared channel (Telegram, Slack, etc.) without explicit accept_privileged_exposure:true.

S5 · red-team regression pack

7 fixtures. Every push.

Web-page injection, uploaded-document exfil, channel-message injection, KB retrieval role-swap, MCP result injection, malicious tool descriptions, obfuscated base64. Full CI pack on every PR.

S6 · Studio preflight

Can't save an unsafe agent

Save is blocked when a workflow uses a system-requiring tool without capabilities:[system]. Warnings surface privileged-channel exposure and ingest+privileged coexistence. Recommendations name scoped alternatives.

S7 · Security Doctor

Per-agent report + dry-run simulator

Full risk report per agent — tier, tools, channels, policy, findings. Dry-run simulator lets you probe adversarial content against the S1+S2+S3 pipeline without executing anything.

bridge

Workspace-scoped intent-gate default

Set security.intent_gate: deny once at the workspace; it flows through runtime, Studio review, and Doctor. Per-agent SOUL.yaml still wins when needed.

honest positioning

How Soulacy compares.

Different products solve different layers. This research-backed snapshot compares operating models, not logos or feature counts.

Primary-source review · updated September 10, 2026

the one hard reason

Nothing risky happens unless you approved it, or you can point to the line that allowed it.

Every other option makes what an agent may do a matter of trust: code someone wrote, a canvas someone configured, or a service in someone else's cloud. In Soulacy it is a property of the runtime. Agents fail closed by default, and every exception is a line in a YAML file you can read. So for any action an agent ever takes, you can answer one of two questions: who approved it, or which line permitted it.

Do not take our word for it. Check it in five minutes on your own machine.

  1. 1Ask for something risky. Write a small agent and ask it to delete a file. It cannot: system tools are not even offered until runtime.allow_system_tools: true is in your config and the agent declares them.
  2. 2Turn them on and ask again. Now the agent stops and waits for your approval before the privileged step runs.
  3. 3Schedule it for 3 a.m. The same step is refused because nobody is there to approve it, until the agent's file says unattended: true.
  4. 4Read the diff. Every change that made the agent more capable is a line you wrote in a file you can read, review, and roll back. Safe Undo covers the changes it makes.

The simple version

Soulacy is a private system that runs your AI agents. You describe an agent in one file. It runs on a computer you control. You reach it from your phone or your chat apps. It cannot do anything risky without your say-so.

where it runs

Yours, on your hardware

Code frameworks leave you to build and host the application. Visual builders need a server stack. Hosted agent services keep your agents in their cloud. Soulacy is one binary that runs on a laptop, a $5 VPS, or a Raspberry Pi, with the web UI, login, channels, and schedules already inside it.

how you describe an agent

One readable file

Not a program you write, not a canvas you drag boxes around. A Soulacy agent is a single YAML file anyone can read, review in a pull request, and roll back. Studio can write it from plain English and repair it when it breaks.

what keeps it safe

Safety you cannot forget to add

Elsewhere, approvals and guardrails are something you wire in per project. Soulacy's runtime enforces them for every agent: confirmations for risky tools, the intent gate against injected instructions, a sandbox for tool code, and Safe Undo for reversible changes.

Building agents into a product of your own? A code framework or vendor SDK fits better. Want a drag-and-drop canvas for business workflows? A visual platform fits better. Soulacy is for people who want their own agents running privately, reachable from their phone, without building or renting the system around them. The full comparison below covers each product and the operating details.

Soulacy LangGraph CrewAI Agent SDKs Visual platforms OpenClaw
Product shape Private agent runtime + control plane Low-level orchestration runtime Multi-agent framework + AMP Code libraries and managed services Visual app/workflow platforms Personal-assistant gateway
Authoring Versionable YAML + Studio Python / JavaScript graphs Python Crews and Flows; Studio in AMP Code or versioned service config Canvas, nodes, and plugins CLI, config, skills, and plugins
Deployment Self-hosted binary or container Your app; LangSmith managed/hybrid/self-hosted Your Python app or CrewAI AMP Your app or vendor-managed workers Cloud or self-hosted server stacks Self-hosted Node.js gateway/daemon
Operations Runs, schedules, logs, diagnostics, delivery Persistence in runtime; LangSmith for tracing/ops Framework events; AMP for deployment/monitoring Tracing/sessions; app owns surrounding ops Execution history, logs, and platform UI Gateway state, sessions, Control UI, doctor
Human oversight Approvals + capability, intent, and readiness gates Durable interrupts; approve/edit/reject policies Guardrails and human-feedback patterns Guardrails or permission policies; app supplies UX Human-input and approval features vary by product Exec approvals, allowlists, tool policy, sandbox
Mobile + channels Native iPhone + web/chat channels Application-defined clients Application-defined integrations and clients Application-defined clients Published web apps, APIs, and integrations Broad chat catalog + iOS/Android companions
Best fit Private multi-agent operations with versionable config Custom stateful agent applications Code-first multi-agent applications Agents embedded in custom products Canvas-centric automation and LLM apps Personal assistant across devices and chat networks

Read the methodology, product-by-product analysis, and primary sources. OpenClaw is included as the closest personal-assistant gateway comparison.

self-hosted Personal

Run Personal on your infrastructure.

A gateway with an embedded web UI and a locally-issued API key. Configure your model provider and verify readiness before using it.

AWS · EC2

Deploy to AWS

guided setup

Creates an isolated network, encrypted Ubuntu VM, generated login secret, Postgres, Qdrant, automatic recovery, and an HTTPS endpoint. No inbound SSH.

Deploy to AWS Typically 8–12 minutes

After creation, use the direct Secrets Manager link in CloudFormation Outputs. Reveal api_key, sign in, then pair your iPhone from Mobile.

Microsoft Azure · VM

Deploy to Azure

guided setup

Creates a private virtual network, encrypted Ubuntu VM, static address, Postgres, Qdrant, and an Azure-hosted HTTPS endpoint. No inbound SSH.

Deploy to Azure Typically 8–15 minutes

Azure asks you to choose a 24+ character Soulacy login key. Save it, open the deployment URL, then pair your iPhone from Mobile.

Railway · Docker

Deploy to Railway

guided setup

Deploys the complete Personal gateway with HTTPS, persistent storage, health monitoring, and unique generated login and signing secrets. No configuration fields are required.

When it is online, open Railway Variables, reveal SOULACY_SERVER_API_KEY, and use it once to sign in. Then pair the iOS app from Soulacy’s Mobile screen.

One secure mobile handoff · every cloud

Sign in once. Pair your iPhone without copying the permanent key.

AWS generates the key in Secrets Manager, Azure asks you to choose it, and Railway generates it in Variables. After signing in to your new Soulacy URL, choose Mobile → Pair a device. The QR code expires in two minutes, works once, and gives the iOS app a scoped credential stored in Keychain.

Permanent key stays private
Never placed in a QR code, URL, or notification.
Render · Blueprint

Deploy to Render

one click

Creates a Docker web service with a persistent disk, production security profile, health monitoring, and generated login and session secrets.

Render generates the Soulacy login key; save it from the service environment after provisioning.

Coolify · Your VPS

Deploy with Coolify

self-hosted

Runs the published Personal image on infrastructure you control, with durable workspace storage and explicit login and JWT secrets.

The repository includes a ready-to-import Compose file; Coolify provides the domain and TLS proxy.

or install on your own machine
macOS · Linux

One-line install

$ curl -fsSL https://soulacy.io/install.sh | bash

Installs soulacy + sy into ~/.local/bin. Boots with a printed API key.

Docker · production

Full stack

$ docker compose up

Postgres + Qdrant + gateway. Security posture defaults ON (intent-gate=deny, sandbox=on, profile=production).

Docker · lite

SQLite-only

$ docker compose -f docker-compose.lite.yml up

Embedded storage in one container, without a separate database service. Model access and optional tools still have requirements.

what's in the box

Everything you need. Nothing you don't.

🧭

Studio

Intent-first agent authoring with authoritative trigger, destination, provider, and model controls. Auto is the default; fixed-graph Workflow stays explicit and experimental. Debug repairs remain diff-previewed and reviewable.

📡

10 channels shipped

HTTP, Telegram, Slack, Discord, WhatsApp, Email/SMTP, Teams, Google Chat, Webhook. Each with a delivery doctor that categorizes failures into 15 stable categories.

Schedule + hung-run detection

Cron and one-shot triggers with startup catch-up. Session Activity tracker exposes hung runs with per-last-event-type reasons.

🧠

Learning loop

Successful runs become sanitized structural patterns; accepted repairs become semantic lessons; repeated edits become user-scoped preferences; thumbs feedback adjusts evidence without auto-editing the agent.

🔌

MCP client + server

Connect to any MCP server (stdio or HTTP). Expose Soulacy itself as an MCP server via sy mcp serve.

📊

Cost governance

Prompt-free estimates, atomic reservations, hard or soft budgets, chargeback dimensions, pricing coverage, provider reconciliation, and readiness alerts across every inference path.

learn by doing

A useful result. A clear way to check it.

Six step-by-step guides with sample input, expected results, failure tests, and recovery instructions. Start read-only, then add access deliberately.

Guides follow current source. Your deployed gateway or iOS build may need an update. Connect your iPhone · Find the failing step

positioning honesty

Stay in control. Know the boundaries.

Operate your own gateway, choose your model, and understand what each safety control can and cannot do.

Self-hosted, on your terms.

Soulacy Personal is open-source and self-hosted. Run the gateway locally or in your own cloud account, with control over configuration, updates, and provider access. Understand the setup →

Not automatic correctness.

Explicit checks make results inspectable. You still choose meaningful acceptance criteria and verify high-impact outcomes independently.

Not an always-listening phone agent.

The native iPhone companion connects to your gateway. Device capabilities are opt-in and foreground-bound; pairing does not grant continuous monitoring or unrestricted phone access.

Not vendor-locked.

Not tied to Anthropic, OpenAI, Google, or any provider. Provider-agnostic via config.

Not a low-code node editor.

Studio helps, but the audience is developers/ops who prefer YAML and Python tools. If you want drag-and-drop nodes, use n8n or Flowise.

Not "just another agent framework."

The 7-story security stack is real, shipped code with a red-team pack on CI. Fork the repo and grep internal/injection/.

Put agents in production.
Not on a whiteboard.

Self-hosted agents. Reviewed learning. Governed inference. Evidence you can inspect.