Skip to main content
Glama
jmfraga
by jmfraga

LM-Pocket — Longitudinal Memory Pocket

tests

Your AI memory, physically yours.

Español

Your model can change. Your history doesn't have to.

LM-Pocket is a personal, portable, local-first, model-agnostic memory layer that you own. It lives in a folder — on a USB stick, an external SSD, or your laptop — and keeps your context, preferences, decisions and learnings across time, regardless of which LLM, app, company or device you use.

It is not an assistant and not a model. It is a continuity layer: storage, provenance, governance and access control for your long-term memory, exposed to any LLM through MCP or through copy/paste prompt bridges.

Status: v0.1 prototype. The first demo works end to end on a real USB-style volume: encrypted pocket, passphrase unlock, MCP reads limited by profile, proposals approved in a localhost UI, prompt-bridge import/export, and MCP access cut off when the pocket is locked or unplugged. Not audited, not for real secrets yet. Spec frozen at tag spec-v0.2-frozen.

Quick start

Needs uv. Offline machines: see docs/offline.md.

git clone https://github.com/jmfraga/lm-pocket && cd lm-pocket
uv sync
uv run lm-pocket init /Volumes/MyUSB/LM-Pocket --sample   # prints your recovery key once
uv run lm-pocket open /Volumes/MyUSB/LM-Pocket            # opens the localhost UI; unlock there

The home page shows the exact MCP config for each permission profile. For Claude Code:

claude mcp add pocket-work -- "$(uv run which python)" -m lm_pocket mcp --profile work

Then ask Claude something that depends on your memory. Lock the pocket (or unplug the USB) and ask again.

See the first demo — including a real Claude session — or run it yourself on macOS with a throwaway exFAT disk image:

uv run python scripts/demo_usb_macos.py

Related MCP server: Citadel

Why

Every AI provider is building memory, and every one of them keeps it on their servers, in their format, under their rules. Switch providers and you start from zero. Lose your account and your history goes with it.

LM-Pocket bets on the opposite: the canonical copy of your memory belongs to you, in an open format, and the model is a replaceable processor that reads only what you allow.

What makes it different

Pieces of this exist elsewhere (memory engines, MCP memory servers, portable agent memory formats). What LM-Pocket combines:

  • Physically yours — the canonical copy is a folder you can unplug.

  • Spaces — personal, portable_professional, work:<id>… isolated by default. Your employer's LLM never sees your personal life or your previous employer's secrets.

  • Proposal → review → durable — no LLM ever writes directly to your canonical memory.

  • Provenance on everything — every memory answers "where did this come from?" and inferences are distinguished from facts you stated.

  • Portable experience — keep the lesson ("validate small hypotheses before scaling") without carrying the proprietary data it came from.

  • Open export format — nothing should stop another program from reading your memory.

How models connect

Client

Path

Notes

Claude Desktop / Claude Code / Cursor

Local MCP (stdio)

Native, nothing leaves your machine except what the model reads.

Gemini CLI

Local MCP (stdio)

Native MCP support.

Local models (LM Studio, Open WebUI, Ollama-based clients)

Local MCP (stdio or HTTP)

Fully offline end to end.

ChatGPT

Remote MCP bridge (Cloudflare Tunnel or similar) or prompt bridge

ChatGPT only accepts remote HTTPS MCP. Optional, off by default. See docs/bridge.md.

Gemini app and other closed chats

Prompt bridge

Copy a context package in; paste the model's memory export back.

Client support changes fast — see docs/mcp.md for details and please send corrections.

Documents

Spanish versions live in docs/es/.

Principles that must not break

  1. The memory belongs to the user.

  2. The system works offline.

  3. An LLM never writes directly to canonical memory.

  4. Spaces are isolated by default.

  5. Every memory has provenance.

  6. The format is exportable.

  7. MCP is an interface, not the memory.

  8. The model is replaceable.

  9. The user can physically disconnect their memory.

  10. The developer disappearing must not destroy the user's history.

License

The business, if there ever is one, can live in hardware, UX, support, enterprise administration, optional sync or managed services. Never in charging rent to access your own memory.

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    A
    maintenance
    Local-first, file-based memory layer for AI agents — one shared Markdown vault across Claude, Codex, Gemini, Cursor and any MCP client. Provides read/write memory tools with an audit trail, per-agent trust levels, and Git sync; no cloud and no lock-in.
    2
    MIT
  • A
    license
    A
    quality
    A
    maintenance
    Local-first memory engine for AI-agent teams: private/team/project ACL, associative recall, and federated sync across nodes. One SQLite file, no LLM required.
    12
    6
    Apache 2.0
  • A
    license
    A
    quality
    C
    maintenance
    User-owned portable memory vault as an MCP server: agents can fetch context, search entries, and propose new memories, while humans curate the vault via a web app.
    3
    MIT