LM-Pocket
Enables Ollama-based local model clients to access the user's memory through local MCP, fully offline end to end.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@LM-Pocketwhat do you remember about my Q3 planning decisions?"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
LM-Pocket — Longitudinal Memory Pocket
Your AI memory, physically yours.
Your model can change. Your history doesn't have to.
LM-Pocket is a personal, portable, local-first, model-agnostic memory layer that you own. It lives in a folder — on a USB stick, an external SSD, or your laptop — and keeps your context, preferences, decisions and learnings across time, regardless of which LLM, app, company or device you use.
It is not an assistant and not a model. It is a continuity layer: storage, provenance, governance and access control for your long-term memory, exposed to any LLM through MCP or through copy/paste prompt bridges.
Status: v0.1 prototype. The first demo works end to end on a real USB-style volume: encrypted pocket, passphrase unlock, MCP reads limited by profile, proposals approved in a localhost UI, prompt-bridge import/export, and MCP access cut off when the pocket is locked or unplugged. Not audited, not for real secrets yet. Spec frozen at tag
spec-v0.2-frozen.
Quick start
Needs uv. Offline machines: see docs/offline.md.
git clone https://github.com/jmfraga/lm-pocket && cd lm-pocket
uv sync
uv run lm-pocket init /Volumes/MyUSB/LM-Pocket --sample # prints your recovery key once
uv run lm-pocket open /Volumes/MyUSB/LM-Pocket # opens the localhost UI; unlock thereThe home page shows the exact MCP config for each permission profile. For Claude Code:
claude mcp add pocket-work -- "$(uv run which python)" -m lm_pocket mcp --profile workThen ask Claude something that depends on your memory. Lock the pocket (or unplug the USB) and ask again.
See the first demo — including a real Claude session — or run it yourself on macOS with a throwaway exFAT disk image:
uv run python scripts/demo_usb_macos.pyRelated MCP server: Citadel
Why
Every AI provider is building memory, and every one of them keeps it on their servers, in their format, under their rules. Switch providers and you start from zero. Lose your account and your history goes with it.
LM-Pocket bets on the opposite: the canonical copy of your memory belongs to you, in an open format, and the model is a replaceable processor that reads only what you allow.
What makes it different
Pieces of this exist elsewhere (memory engines, MCP memory servers, portable agent memory formats). What LM-Pocket combines:
Physically yours — the canonical copy is a folder you can unplug.
Spaces —
personal,portable_professional,work:<id>… isolated by default. Your employer's LLM never sees your personal life or your previous employer's secrets.Proposal → review → durable — no LLM ever writes directly to your canonical memory.
Provenance on everything — every memory answers "where did this come from?" and inferences are distinguished from facts you stated.
Portable experience — keep the lesson ("validate small hypotheses before scaling") without carrying the proprietary data it came from.
Open export format — nothing should stop another program from reading your memory.
How models connect
Client | Path | Notes |
Claude Desktop / Claude Code / Cursor | Local MCP (stdio) | Native, nothing leaves your machine except what the model reads. |
Gemini CLI | Local MCP (stdio) | Native MCP support. |
Local models (LM Studio, Open WebUI, Ollama-based clients) | Local MCP (stdio or HTTP) | Fully offline end to end. |
ChatGPT | Remote MCP bridge (Cloudflare Tunnel or similar) or prompt bridge | ChatGPT only accepts remote HTTPS MCP. Optional, off by default. See docs/bridge.md. |
Gemini app and other closed chats | Prompt bridge | Copy a context package in; paste the model's memory export back. |
Client support changes fast — see docs/mcp.md for details and please send corrections.
Documents
SPEC.md — the MVP specification (v0.2, frozen for v0.1)
docs/demo.md — the first demo, step by step, with real output
docs/spec-conflicts.md — what implementation found that the spec must decide
docs/threat-model.md — what LM-Pocket protects against, and what it cannot
docs/mcp.md — MCP tools, permission profiles, client setup
docs/bridge.md — exposing a read-only bridge for ChatGPT and other remote clients
docs/memory-format.md — the open export format
schemas/ — JSON Schemas for the format
examples/ — a fictional sample memory export
ROADMAP.md — what gets built, in what order
CONTRIBUTING.md — how to join
Spanish versions live in docs/es/.
Principles that must not break
The memory belongs to the user.
The system works offline.
An LLM never writes directly to canonical memory.
Spaces are isolated by default.
Every memory has provenance.
The format is exportable.
MCP is an interface, not the memory.
The model is replaceable.
The user can physically disconnect their memory.
The developer disappearing must not destroy the user's history.
License
Code: Apache-2.0
Specification, documentation and schemas: CC-BY-4.0
The business, if there ever is one, can live in hardware, UX, support, enterprise administration, optional sync or managed services. Never in charging rent to access your own memory.
This server cannot be deployed
Maintenance
Related MCP Connectors
Person-owned AI memory that learns, not just stores — portable context for any MCP client.
Governed personal world model and memory for your AI agent. Pair once, connect over MCP.
Private, portable memory and reusable skills for AI agents.
Governed local-first memory and continuity for AI agents — signed receipts, optional hosted lane.
Related MCP Servers
- AlicenseNot gradedqualityAmaintenanceLocal-first, file-based memory layer for AI agents — one shared Markdown vault across Claude, Codex, Gemini, Cursor and any MCP client. Provides read/write memory tools with an audit trail, per-agent trust levels, and Git sync; no cloud and no lock-in.2MIT
- AlicenseNot gradedqualityAmaintenanceLocal-first, encrypted memory for AI agents, with cryptographic forgetting.1,301 PyPI3Apache 2.0
- AlicenseAqualityAmaintenanceLocal-first memory engine for AI-agent teams: private/team/project ACL, associative recall, and federated sync across nodes. One SQLite file, no LLM required.126Apache 2.0
- AlicenseAqualityCmaintenanceUser-owned portable memory vault as an MCP server: agents can fetch context, search entries, and propose new memories, while humans curate the vault via a web app.3MIT