Fetchi, in detail.

What it does, where it stops to ask, and what it does not do yet. Back to the homepage.

What it does

Four requests, step by step.

What you say, what Fetchi does next, and where it stops to ask you.

01 · Gmail, connected

Reply to Dana’s email and say Thursday at 3 works.

  1. Finds Dana’s latest thread in your Gmail.
  2. Writes the reply.
  3. Shows a card with who it goes to and the exact words.
  4. You say yes. It sends, and the result goes in the record of what ran.

Card: a send through a connected account like Gmail shows one.

Send this reply to Dana?

ToDanaSubjectRe: ThursdaySaysThursday at 3 works for me.
Yes, send itNo

Drawn in HTML · what the card holds

02 · Calendar

Add lunch with Sam Friday at 1pm.

  1. Puts the event on your Mac’s own calendar.
  2. Reads it back from Calendar to check it is there.
  3. Tells you it was added, and that nobody was invited.

No card: your words set the time. If Fetchi would be picking the time, or took it from an email, a card asks first.

Added to your calendar — “Lunch with Sam”

WhenFriday, 1:00 pmInvitedNobody

Drawn in HTML

03 · Files

Organize my Downloads.

  1. Looks at the loose files in Downloads.
  2. Sorts them into folders by kind or by month.
  3. Shows one card that names every file it will move.
  4. You say yes. It moves them. It never renames or deletes a file.

Undo: say “undo that” and every file goes back where it was.

Move these files in Downloads into folders?

PDFslease.pdf, tax-2025.pdfImagesIMG_2041.jpg, receipt.pngDeletesNothing
Yes, move themNo

Drawn in HTML · what the card holds

04 · Chrome or Safari

Go to apple.com and open the MacBook Air page.

  1. Brings up the browser on your screen and takes the mouse and keyboard.
  2. Loads the page and clicks through to MacBook Air.
  3. Looks at the screen afterwards to check it got there. If it didn’t, it says so.

No card: reading, browsing and opening apps never ask. A checkout or payment page counts as spending, and that asks.

On apple.com — MacBook Air

CheckedThe page on screen matches what you asked for

Drawn in HTML

Also: Notes, Reminders, Apple Mail, Music, opening any app, finding a file with Spotlight, and your iPhone as a remote.

Fetchi, Instinct, Muse

Fetchi, Instinct and Muse, side by side.

Fetchi compared with Instinct and Muse on five questions
QuestionFetchiInstinctMuse
Where your memory lives On your Mac, as Markdown pages you can open, edit and delete. Their cloud desktop. Meta’s servers, as files you can edit.
What it can touch Your own Mac and its apps, your browser, and your phone as a remote. A computer in their cloud, with your saved passwords. Files, Mail, Messages, Calendar and Notes on your Mac, and a browser on a cloud computer.
What it costs them to serve you Tokens. The work runs on your Mac. A cloud computer for every user, plus the model. A cloud computer for every user, plus the model.
What the terms say Nothing money-shaped or destructive, and no send to someone it chose, happens without a card you saw. It asks. Its terms appoint it as your agent, authorised to enter binding transactions. Meta’s terms. An approval card before it acts.
How you get in Invite-only for now. Join the waitlist. An invite-only beta, with a waitlist. A Mac app, Meta’s other apps and WhatsApp. US only, 18 and over.

From public descriptions of Instinct as of 15–16 September 2026, and of Muse as of 24–25 September 2026.

Try it here

Pick an app. Watch one request run.

A simulation drawn in HTML. Each one shows the sentence, the card if there is one, and the result.

Choose an app. Watch the notch, the action and the result.

Clear the clutter. Keep control.

Fetchi finds the old screenshots, asks before deleting, then records the result. Deleting data always needs your yes.

240 screenshots deleted · 1.8 GB freed · VERIFIED

Product simulation · no real actions
Also works with Notes, Reminders, Apple Mail and Music.Memory you can open and edit ↗

Not built: restaurant bookings and purchases. In the app but not ready to be promised: phone calls, and texts and iMessages handed to the Messages app. The questions below say what each one needs.

How it works

The card, then the record.

01Stay in control

Some actions need your yes.

For this deletion, a card shows exactly what will go and how much space it frees. Choose how independently Fetchi works; the safeguards below apply at every setting.

Standard, the default: sends and replies on its own when you give the exact address or point it at the thread, and stops before a whole group, a public post or comment — and before money. A send through a connected account like Gmail still shows you a card, and at every setting it checks with you when it picked who a message goes to — unless you turn on Act without asking in Settings, which lets the kinds you pick, like email, go without a card after a 5-second Undo.

6always askSpending money, passwords, deleting data, posting or commenting in public, changing a security setting and destructive system changes always wait for your explicit yes — at every setting, including Autonomous. Reading, browsing and opening apps never ask at any setting, except opening a checkout or payment page, which counts as spending.

Waiting on you11:05

Delete 240 old screenshots?

Where~/Desktop, older than 90 days Frees1.8 GB Why it asksDeletion always does Asked at11:05 · queued in the ledger until you answer At AutonomousStill asks
Yes, delete themNo

Nothing moves until you answer.

Drawn in HTML · what the card holds · the app draws it in its own chrome

02Check the result

Every action writes a row
you can read later.

Every action writes a row: which tool, what it was handed, what came back, word for word, with secrets redacted and long fields cut short. No model narrates it.

Today's ledgerthis job's rows in white

09:12Opened the Q3 deckRAN

09:40Summary slide draftedVERIFIED

11:05Delete 240 old screenshots? — the card, waiting on your yesQUEUED

11:06240 screenshots deleted from ~/Desktop — 1.8 GB freedVERIFIED

14:20Thursday's 3pm moved to 4:30 — invite updatedVERIFIED

16:31Check-in sent — the Q3 deck is still openDELIVERED

Invented rows0

3 verified

Memory

Its memory is
a folder you own.

People, projects, preferences: Fetchi keeps the useful details in ~/Fetchi Brain. Open the folder in Finder. Read a fact, edit it, or delete it. Each fact links back to when it was learned.

The folder stays on your Mac. A short digest of what it knows accompanies requests to the answering model. See what leaves your Mac ↗

The technical details

Everything Fetchi works out about you is written to plain markdown at ~/Fetchi Brain — one page per person, project, place, preference and routine, one bullet per fact, each citing the day it was learned. It syncs to no account and there is no copy of it on our server. The code that writes it imports no network client at all, and the app grants no browser an origin, so no web page can reach it either — a test in this repo sweeps the source to keep it that way.

~/Fetchi Brainpeople/dana.md

people/

dana.md

mum.md

projects/

q3-deck.md

places/

the-office.md

preferences/

writing.md

routines/

mornings.md

BRAIN.md

log.md

# Dana

- Dana doesn't take meetings on Fridays _(source: [[sessions/2026-08-15]])_

- Dana's team ships on the 1st _(source: [[sessions/2026-08-22]])_

- Prefers a time proposed, not a "when suits?" _(source: [[sessions/2026-08-22]])_

## Previously

- Dana doesn't take meetings on Mondays _(source: [[sessions/2026-06-02]])_

Plain text on your disk · a fact with no source is refused

Questions

Is Fetchi always listening?

Honestly: the microphone is open. With the wake word on, which is the default, every frame of audio is checked against your Fetchi's name — on your Mac, by two modules that import no network client of any kind, so none of that audio is uploaded. No audio leaves the machine until you start a turn: say the name, hold the talk key, or press Talk or its shortcut. When it can leave, named here rather than buried: on a Mac that can't recognise speech by itself, Apple's speech servers hear any turn you speak rather than type. (Until 0.2.5, build 107, the paid plans also had a realtime voice lane that streamed live audio to OpenAI; it is switched off now.) If you'd rather Fetchi not listen at all, switch the wake word off and hold ctrl+option to talk instead; then it hears nothing until you press the key.

What does it remember about me, and where does that live?

In a folder on your Mac called Fetchi Brain. Plain markdown: one page per person, project, place, preference and routine, one bullet per fact, each fact citing the day it was learned. That folder is not uploaded anywhere. The code that writes it imports no network client, and the app hands no website a way in. Open it in Finder, read it in any text editor, put it under git, delete a page you'd rather it didn't have — Fetchi re-reads the folder and never restores what you removed, and it asks before forgetting anything itself. It is not on your Desktop on purpose: the Desktop syncs to iCloud on a lot of Macs, and that would upload the whole thing. It sits in your home folder instead (Finder → Go → Home). What does travel is the working set — to answer a turn, a short digest of what it already knows about you rides along with your words, the same trip they make. Our server doesn't keep it; what Anthropic or OpenAI keep is set by their API terms, which the privacy policy names.

What can it actually do today?

It works your Mac: it reads the screen, takes the mouse, clicks and types. It drives a browser, writes a Gmail into an open compose window, reads Apple Mail, makes Notes and Reminders, controls Music, opens any app, finds a file by asking Spotlight and opens the one you meant, picks a command you name from an open app's menus, pulls a YouTube video's transcript, searches the web, and checks in on you unprompted. It reads your calendar — the one you actually look at: every account in Calendar.app, iCloud included, plus Google Calendar through a connected account. Gmail links up the same way. Quick questions — the time somewhere else, a unit conversion, days until a date, the weather, what’s on your calendar, a fact you told it — are answered on your Mac in about a second. It can also place phone calls from your own number and send an iMessage or text once you approve the exact words, but those are not ready to be promised yet. What it does not do yet: book restaurants or buy anything.

Can I choose what it may do in each app?

In Fetchi 0.2.4 and later. The installer's file name carries its version, and the bottom of Settings names the one you have. Settings → Connections → What Fetchi may do in each app lists Mail, Messages, Calendar, Notes, Reminders, Files and every app you connected, each set to Off, Read only or Read and act. Read only: Fetchi can read the app but won't send, change or delete anything in it, and if you ask it to, it tells you which switch to change. Off: it won't read the app or act in it, its background checks leave it alone, and it won't look at your screen while that app is in front. The switch is enforced by Fetchi's own code, not by asking the model: where every tool is used, before it takes over the screen, at every click and keystroke, and again when you approve a card. Every app starts at Read and act, which is what Fetchi did before these switches existed, so nothing changes until you choose. Reading your Messages stays off until you turn it on. The Terminal and code tools have switches of their own and aren't covered by these.

Can I see what left my Mac?

In Fetchi 0.2.4 and later, too. Settings → Privacy & control → What left this Mac lists every server Fetchi sent something to, today or over the last 7 days, grouped by what it was for: your requests to the AI model, your mail server, the weather, and so on. Each line is the server's name, how many requests, how many bytes went out, and whether something you asked for caused it. Never the words, addresses or pages themselves. The list stays on your Mac for 8 days, is never sent anywhere, and has a button that clears it. It counts what Fetchi itself sends. When Fetchi hands something to another program, like your browser opening a link or a Terminal command you approved, that program's own traffic isn't on the list. Anything inside Fetchi that no part of it has named yet is still listed, as “Not labelled yet”. On a Mac that can't turn speech into text by itself, what you say in any turn you speak rather than type also goes to Apple's speech recognition servers; macOS makes that request, not Fetchi, so it isn't on the list. And Fetchi does not read your notifications: nothing in it opens macOS's notification database or reads Notification Center. A screenshot is a picture of the whole display, so a banner that is on screen at that moment is in it. In 0.2.5 and later the same card can hold things back: each purpose can be set to Allow (the default, and what Fetchi has always done), Ask or Block. Block: the request is never sent. Ask: a server that purpose hasn't been allowed to reach puts a card on your screen, and until you say yes, nothing is sent and the request fails, saying so. “Ask before anything new leaves” is off unless you turn it on. Your requests to the AI model can't be blocked, because Fetchi can't work without them, and the card says so next to that row.

What else is in 0.2.4?

In Fetchi 0.2.4 and later. “What happened today?” builds an end-of-day digest on your Mac: who emailed you and the subject line (never the message), today's and tomorrow's calendar, the titles of notes you changed today, reminders done or overdue, and, only if you turned on Read my Messages, who texted you and how many times. One short request to the model gets just those lines, and the digest ends by naming which sources it read and which it couldn't. A daily digest at a time you pick is off until you pick one. “Organize my Downloads” sorts the loose files into folders by kind or by month, on one card that names every file it will move. Nothing moves until you say yes, it never renames or deletes a file, and “undo that” puts every file back where it was. “Draft a reply to Sam in Messages” puts the text in Messages' box without sending it, and “draft an email to the landlord” saves it to your mailbox's Drafts folder when your mailbox is set up in Settings. Fetchi says “It's in the draft — nothing was sent” only after reading the draft back. Sending it is a separate request; saying yes to a draft never presses Send. And when Fetchi holds a plan for your yes, the card that asks shows its steps, numbered, and What I did in Settings lists every step with how it ended.

What's new in 0.2.5?

In Fetchi 0.2.5 and later. “Add lunch with Sam Friday at 1pm” puts the event on your Mac's own calendar, and Fetchi says it was added only after reading it back from Calendar. At the default setting, when your words gave the time, it adds it without a card; when Fetchi would be picking the time, or is working from something it read, like an email, a card asks first. It never sends an invitation, and its reply says that nobody was invited. “What did I write in my note about the lease?” searches Apple Notes and reads the note to you; it has no way to change a note. A “done” has to match what ran. If Fetchi only drafted an email, a written reply that says it was sent is rewritten to say what actually ran; on voice, the correction is spoken straight after. And Settings → Privacy & control → Guardrails is Standard, the default, or Strict. Strict asks the way Safe does, whatever your trust level: before anything Fetchi sends, posts, replies or submits, even to an address you gave it, and before it changes Do Not Disturb, Focus, notifications, dark mode or Night Shift, or adds anything to a cart. It never asks less than Standard.

How can I check any of this myself?

How to check Fetchi takes five promises and gives each one a check you can do on your own Mac in about a minute: what left it, a card that moves nothing until you say yes, the memory folder, a switch set to Read only, and the record of what ran. The checks need Fetchi 0.2.4 or later. From 0.2.5 the same list is in the app, under Settings → Privacy & control. The page also says what you can't check from your Mac: what our server logs and what the model providers keep.

It checks in

Tell it what you're trying to get done today. It holds on to those, and comes back on its own with one small next step — no prompt from you. Then it goes quiet: a clock decides when it may speak again, not the model.

What if it gets something wrong?

Three safeguards, and they work differently. When your own words name a checkable result — "go to apple.com", "open Calculator" — Fetchi goes and looks at the screen afterwards, and that answer beats every other signal in both directions: if the page isn't there it says so, however many clicks landed. On a multi-step job with no such goal, each step is checked against something observable before it's allowed to count as verified — a step that merely ran says "ran", not "done", and a closing sentence claiming the job is finished is rewritten to say what is in doubt. And on any single action, a written claim that Fetchi did something is blocked unless a receipt proves the tool actually ran; on voice, a spoken claim it can't back is corrected out loud straight after. That rule exists because earlier versions did tell people work was finished when it wasn't; catching it in the logs afterwards wasn't good enough. Typing has its own stop: if the cursor is sitting in a document you never mentioned, Fetchi asks before it types a character — your own draft is not somewhere it gets to write by accident. You also choose how much rope it gets: Safe, Standard or Autonomous — and the things that always ask still ask at all three.

Where does what I say actually go?

Your wake word and speech-to-text run on your Mac; on a Mac that can't recognise speech by itself, Apple's speech servers also hear any turn you speak rather than type, outside a live voice session. To answer you, the text of what you said goes to our server, which passes it to Anthropic's Claude and passes the answer back — and when the question is about what's on your screen, the screenshot goes with it. That server's database has no column a prompt, a transcript or a screenshot could go into: its tables hold your account, metering, sign-in, billing and pairing bookkeeping, and the privacy policy lists every one. It counts usage so that you don't need your own API key. We also don't log request bodies — but that half is a policy rather than a schema, and it is worth knowing which of the two you are relying on. Fetchi's own voice, the default on an account, sends the sentence Fetchi is about to say through that server to a text-to-speech provider — calendar answers included; choose the Mac's built-in voice in Settings and it is synthesised on the Mac itself. Indexing never sends brain text out: that upload was removed from the app on 8 September 2026 and our server's route for it is closed. The turns that act on your Mac or the web, and the ones that read what's on your screen, go with their screenshots through that same server to OpenAI's GPT-6 Astra by default, and to Claude only when that setting is off or the model is unavailable. It's all written out plainly, including the awkward parts, in the privacy policy.

Does the model see my screen?

When the answer is in the pixels, yes. Fetchi captures your screen and sends it along with your words to the model that answers, and we are not going to dress that up. Asking what is on your screen is one picture and one look — it does not take the mouse, and Fetchi's own window is cut out of the picture so it can't read its last reply back to you as though it were your screen. What we can tell you is that Fetchi does not keep it. On your Mac the capture is deleted in the same function that made it. On our server there is no column an image could go into. What the model's provider keeps is up to the provider, and one case needs saying out loud. When Fetchi is driving your Mac through OpenAI's model, test builds of 0.2.2 before build 89 sent each step in a way that had OpenAI store it, picture included, for 30 days by default; none of them was ever public. Every public build that has this lane, from 0.2.2 (build 89) on, tells OpenAI not to store any of them. Until 18 September 2026 this answer said "it is not kept" with no exception, and that was wrong. Fetchi also declines to capture at all when a password manager, a banking page or a sign-in screen is what's in front of it. On a turn with nothing visual about it no capture is taken in the first place — what goes is your words, the recent conversation and a capped digest of what Fetchi knows about you — a few kilobytes. The window at the top of this page is drawn in HTML from the shipped window, in grey.

Who it is for

Lawyers, doctors, accountants — anyone holding a file they are not allowed to paste into a chat window. What Fetchi learns about the matter is markdown in your folder, not a memory in an account somewhere else. Read the list of everything that does leave your Mac before you decide it clears your bar.

How much does it cost?

Fetchi is invite-only for now. Join the waitlist for access. The paid plans are Pro, $20 a month, with 150 agent tasks, Max, $100 a month, with 1,000 agent tasks, and Ultra, $200 a month, with 2,000 — Max doubled, and no feature Max does not already have. An agent task is a job where Fetchi picks up a tool or takes the mouse — asking it something, or just talking to it, is not one. On every paid plan, conversation carries on after the agent tasks are gone: talk runs to its own, further ceiling, so what stops is the hands, not the voice. Teams is that same Pro plan bought by the seat — $20 per seat, per month, on one bill, every seat a full Pro account metered against the person using it rather than drawn from a pool, and the owner sees each person's spend in dollars but never what they asked Fetchi (how a team works, including what it does not have yet). The pricing page has the whole of it, and cancelling is one button inside the app that opens Stripe's own billing page — here's exactly where it is.

Can I change how it talks to me?

You can shape how it speaks, and it learns how you like things done — that is what the folder is for. It answers to "Fetchi" for now; choosing your own name for it is coming, not shipped.

Invite-only · macOS 14+ · Apple Silicon

Get on the list.

Fetchi is invite-only for now. Join the waitlist and we’ll email you when there’s a spot. What first launch asks for is listed here, before you install.

Before you install

The machine

macOS 14 or later on Apple Silicon (M1 and up). It will not run on an Intel Mac — the app and the Python inside it are built for arm64 only, so on an Intel machine the download simply won't launch. Notarized by Apple.

An account

One email address, no password — it mints the key every hosted answer is made with, and Fetchi cannot answer you without it.

Three permissions

Microphone, Screen Recording and Accessibility — which are what hearing you, seeing your screen and moving your mouse are made of; refuse one and that part stops working. Location is a fourth, and it is optional: macOS asks only the first time you ask something that needs it, like the weather with no city named, and refusing just means telling Fetchi your city instead.

Setup

About twenty screens, including reading a short passage aloud so it learns your voice.