आपके नोट्स और कोड · भरोसेमंद AI
Altretta

AI जवाब जिन पर आप सच में भरोसा कर सकें.

Altretta आपका निजी दूसरा दिमाग है: आपके नोट्स और आपका कोड एक ही हस्ताक्षरित ग्राफ़ में। कुछ भी पूछें और हर जवाब उसी सटीक स्रोत का हवाला देता है जहाँ से वह आया — निर्णय, नोट या फ़ंक्शन — और कुछ भी आपके कंप्यूटर से बाहर नहीं जाता।

शुरू करने के लिए मुफ्त·macOS · Windows · Linux·प्लान से शुरू €4.99
sthanantaran-yojana.md

माइग्रेशन कब अनुमोदित हुई?

माइग्रेशन को मंजूरी मिली 12 मार्च, बजट के साथ €48.000.

baithak-vivaran-2026-03-12.mdbajat-q1.md
सत्यापितहस्ताक्षर 8f3a…c1

हर जवाब, अपने प्रमाण के साथ

संक्षेप में

Altretta एक निजी, local-first नोट्स ऐप है: आपके नोट्स और आपका कोड आपकी अपनी Markdown फ़ाइलें हैं, और AI का हर जवाब उसी सटीक स्रोत का हवाला देता है जहाँ से वह आया, हस्ताक्षरित इतिहास के साथ।

आपकी फ़ाइलें
आपके डिवाइस पर Markdown, कोई साइलो नहीं
आपकी अपनी AI
अपना मॉडल MCP से जोड़ें
हर चीज़ प्रमाण छोड़ती है
हस्ताक्षरित, प्रतिवर्ती इतिहास
उपलब्ध
macOS · Windows · Linux · मुफ़्त
समस्या

ज्ञान बेहतर का हकदार है।

आपके नोट्स दूसरी ऐप्स में बंद हैं

स्वामित्व डेटाबेस, बंद फॉर्मेट और सिंक्रोनाइज़ेशन जो एक दिन गायब हो जाती है। आपका ज्ञान हमेशा के लिए आपका होना चाहिए।

AI बिना प्रमाण के जवाब देती है

असिस्टेंट बनाते हैं, स्रोत मिलाते हैं और आप सत्यापित नहीं कर सकते कि हर दावा कहाँ से आया। बिना सबूत, कोई भरोसा नहीं।

टीम का ज्ञान अलग-थलग रहता है

खंडित Wikis, वापस लेने में असंभव अनुमतियाँ और तीसरे पक्ष को उजागर संवेदनशील डेटा। साझा करने का मतलब नियंत्रण खोना नहीं होना चाहिए।

सत्यापन

भरोसा मत कीजिए। जाँचिए।

भरोसा आप देते हैं; जाँच आप करते हैं। Altretta इस तरह बना है कि किसी भी ज़रूरी बात के लिए आपको न उसकी बात माननी पड़े, न अपने AI की।

वह टिक जिसे कमाना पड़ता है

बैज तभी दिखता है जब दो बातें एक साथ सही हों: सिग्नेचर सचमुच सही निकले, और नोट अब भी उसी से मेल खाता हो जिसे वह सिग्नेचर कवर करता है। दोनों में से एक भी जाँच चूकी तो बैज नहीं — गड़बड़ी में यह मना करने की तरफ़ झुकता है, ख़ुद को संदेह का लाभ नहीं देता।

कुछ बदला हो, तो यह बता देता है

अगर कोई नोट साइन होने के बाद एडिट हुआ है, तो आपको ठीक यही बताया जाता है — चुपचाप उसे “बिना सिग्नेचर” नहीं कर दिया जाता। जो सिग्नेचर अब उस चीज़ को कवर नहीं करता जो आप पढ़ रहे हैं, उसे खुलकर कहना बनता है।

ऐसा असिस्टेंट जो कह देता है कि उसे नहीं पता

ऐसा कुछ पूछिए जो आपके नोट्स में नहीं है, और वह आपको बता देगा — जवाब बनता ही नहीं। फिर भी जवाब चाहिए, तो वह अलग विकल्प है जो आपको जान-बूझकर चुनना पड़ता है।

जवाब फ़ाइल नहीं, पन्ने की ओर इशारा करते हैं

PDF, Word फ़ाइलें, प्रेज़ेंटेशन और स्प्रेडशीट अपनी संरचना के साथ पढ़ी जाती हैं — पेज नंबर, स्लाइड नंबर, यहाँ तक कि किसी विनियमन के अनुच्छेद नंबर भी — इसलिए आधारित उत्तर सिर्फ़ फ़ाइल का नाम नहीं, बल्कि ठीक वही जगह उद्धृत करता है जहाँ से वह आया है।

आपको क्या मिलता है

आपके नोट्स आपके रहते हैं

हर नोट आपके कंप्यूटर पर एक सामान्य फाइल है। कोई lock-in नहीं, कोई ऐसा फॉर्मेट नहीं जो खुल न सके। इसे move करें, backup लें, या जब चाहें Altretta छोड़ें — आपका ज्ञान आपके साथ आता है।

altretta — notesq3-planningbudget-q3team-notesroadmapq3-planning.md€48,000Yours · Markdown · Verified

वो connections ढूंढता है जो आप चूक जाते

Altretta संबंधित नोट्स को अपने आप जोड़ता है, महीनों पहले लिखा वो विचार सामने ला देता है जो आप भूल गए थे — सब आपकी मशीन पर, कुछ upload नहीं होता।

altretta — graphAnaQ3€48kq3-planning.mdbudget-q3.mdteam-notes.mdq3-planning.mdLinkedAnaQ3€48,000証 Verified
नया · Estratos 3D

जो कुछ आप जानते हैं उसका आकार देखें

एक क्लिक आपकी नोट्स को एक ऐसी दुनिया में बदल देता है जिसमें आप टहल सकें। फ़ोल्डर मंज़िलें बन जाते हैं, छिपे कनेक्शन सतह पर उभर आते हैं, और आपकी सोच की आकृति आख़िरकार सामने आ जाती है।

एक क्लिक में 3Dफ़ोल्डर बनें मंज़िलेंछिपे कनेक्शन सामने
altretta — 3D graph/ projects/ notes/ people2D ↔ 3D · floors by folder
ज्ञान और कोड

अपने पूरे प्रोजेक्ट को समझें — जो आप लिखते हैं और जो आप कोड करते हैं।

Altretta आपकी रिपॉज़िटरी पढ़ता है और उसे एक हस्ताक्षरित मानचित्र के रूप में बनाता है: हर सिंबल, वे एक-दूसरे को कैसे कॉल करते हैं और वह निर्णय जो हर एक को नियंत्रित करता है। इसलिए आपका AI सिर्फ़ आपके नोट्स नहीं जानता — वह आपका कोड और उसे बिना कुछ तोड़े बदलने का तरीका समझता है।

आपके कोड का मानचित्र बनाता हैकुछ बदलने पर क्या टूटेगाजब डॉक पीछे रह जाए तो बताता हैअपने प्रोजेक्ट से पूछें
altretta — codeHeader.tsxapi.tsPage.tsxfnrender{ … }governed byadr-render.mdsymbol · callers · decision
अपना AI लाएं

अपना AI जोड़ें। अपनी शर्तों पर।

वो AI लाएं जो आप पहले से use करते हैं — ChatGPT, Claude, Cursor — अपने नोट्स में अपनी subscription के साथ। आप तय करते हैं कि वो क्या देखे, और जो कुछ भी करे वो sign किया और undo किया जा सकता है।

एक क्लिक में सेटअपआप तय करें कि वो क्या देखेहस्ताक्षरित और पूर्ववत करने योग्यसाक्ष्य पर आधारित, अनुमान नहींउस AI के साथ काम करता है जो आप पहले से pay करते हैं
altretta — askQWhat was the Q3 budget?AThe Q3 budget was€48,000.q3-planning.md · line 12Grounded in your notes — no guessing.
विभेदक

एन्क्रिप्टेड, सत्यापन योग्य और revocable टीम ब्रेन।

नियंत्रण छोड़े बिना ज्ञान साझा करें। End-to-end एन्क्रिप्शन, तुरंत वापस लिया जाने वाला पहुँच और एक सिद्ध करने योग्य इतिहास।

End-to-end एन्क्रिप्शनकिसी को हटाएं, access तुरंत खत्महमेशा जानें किसने क्या बदलाएक undo जिस पर भरोसा करें
altretta — team brain証 e2eANJDRVrevokedEnd-to-end encrypted · revocable

कम टोकन, डिज़ाइन से ही

Altretta, MCP के ज़रिए आपके AI से जुड़ता है और AIngle (इसका सिमैंटिक इंजन) की बदौलत मॉडल को सिर्फ़ ज़रूरी नोट्स देता है, स्रोत और उद्धरण के साथ। आपका AI पूरे वॉल्ट के बजाय प्रासंगिक संदर्भ पर काम करता है, इसलिए कम टोकन लगते हैं और आपको सब कुछ दोबारा पेस्ट नहीं करना पड़ता।

-94%वादा नहीं, मापा हुआ
क्वेरीAltretta के बिनाAltretta के साथबचत
प्रति क्वेरी औसत23,0201,36394.1%
8 क्वेरी की बातचीत184,60946,70974.7%

Studio Ghibli के मानक डेमो वॉल्ट (43 नोट्स) पर मापा गया: पूरा वॉल्ट संदर्भ के रूप में vs Altretta द्वारा MCP से असली इंजन के साथ दिए गए उद्धृत अंश। इनपुट टोकन; अनुपात टोकनाइज़र के बीच स्थिर है। प्रकाशित प्रोटोकॉल से पुनरुत्पादन संभव।

बचत आपकी AI को MCP से Altretta की skill से जोड़ने से आती है: उसे सिर्फ़ ज़रूरी उद्धृत अंश मिलते हैं, आपका पूरा वॉल्ट नहीं। इसे आप ख़ुद Studio Ghibli के डेमो वॉल्ट के साथ दोहरा सकते हैं।

Altretta की skill पाएँ

इसे Apilium Hub के स्किल्स और प्लगइन्स से बढ़ाएँ।

hub.apilium.com

Hub पर जाएँ
कैसे काम करता है

नोट से सत्यापन योग्य ज्ञान तक।

01

Markdown में लिखें

हमेशा की तरह नोट्स लें। हर विचार एक फाइल के रूप में सेव होता है जो आपकी डिस्क पर आपकी है।

02

Altretta सब कुछ जोड़ता है

यह संबंधित नोट्स को connect करता है और हर बदलाव का एक signed history रखता है — सब आपके कंप्यूटर पर।

03

एक क्लिक में AI connect करें

अपनी subscription का AI plug करें। यह आपके नोट्स पढ़ता है; आप तय करते हैं कि वो क्या देख सकता है।

04

पूछें और सत्यापित करें

ऐसे जवाब पाएं जो आपके नोट्स को quote करें, एक confidence score के साथ जो आप खुद जांच सकें।

पहले दस मिनट

खोलने पर असल में होता क्या है।

कोई अकाउंट नहीं, कोई सेटअप विज़ार्ड नहीं, कुछ अपलोड नहीं। आप एक फ़ोल्डर दिखाते हैं और यह काम शुरू कर देता है।

  1. 01

    बस एक फ़ोल्डर दिखाइए

    आपका मौजूदा नोट्स फ़ोल्डर जैसा है वैसे ही चलता है। कुछ भी इम्पोर्ट, कन्वर्ट या मूव नहीं होता — Altretta आपकी डिस्क पर पहले से पड़ी Markdown फ़ाइलें ही पढ़ता है।

  2. 02

    जिस AI का पैसा आप पहले से दे रहे हैं, उसे जोड़िए

    यह आपके कंप्यूटर पर पहले से इंस्टॉल Claude, Cursor, VS Code, Windsurf, Zed और दूसरों को ढूँढ़कर ख़ुद सेट कर देता है। न कोई की पेस्ट करनी है, न कोई कॉन्फ़िग फ़ाइल एडिट करनी है।

  3. 03

    कुछ ऐसा पूछिए जो सिर्फ़ आपके नोट्स जानते हैं

    पहला स्रोत-आधारित जवाब ही वह पल है जब बात समझ आ जाती है: जवाब उसी नोट को उद्धृत करता है जहाँ से वह आया, और आप वह नोट खोलकर ख़ुद देख सकते हैं।

  4. 04

    फिर इसे पकड़ने की कोशिश कीजिए

    ऐसा कुछ पूछिए जो आपने कभी लिखा ही नहीं। यह कह देगा कि उसके पास कोई आधार नहीं है — और किसी भी जवाब से ज़्यादा, यही वजह है इसे रखने की।

खोने को कुछ नहीं

जानने में आपका कुछ नहीं जाता।

ऐप मुफ़्त है, आपके कंप्यूटर पर चलता है, और आपकी फ़ाइलें ठीक वहीं रहती हैं जहाँ हैं। न कोई ट्रायल की घड़ी, न कुछ कैंसिल करने को।

अकाउंट की ज़रूरत नहीं

डाउनलोड कीजिए, खोलिए, काम कीजिए। साइन-इन सिर्फ़ पेड फ़ीचर्स के लिए है — साइन-आउट रहते हुए भी लोकल सब कुछ चलता रहता है।

नेटवर्क बंद हो तो भी चलता है

आपके नोट्स आपकी डिस्क पर हैं, और ऐप भी। फ़्लाइट हो, कनेक्शन ठप हो, या कंपनी ग़ायब हो जाए — इनमें से कुछ भी आपको पढ़ने या लिखने से नहीं रोकता।

ऐसे फ़ॉर्मैट में फ़ाइलें जो हमसे ज़्यादा जिएँ

एक आम फ़ोल्डर में सादा Markdown। न कोई डेटाबेस, न कोई कंटेनर। किसी भी एडिटर में खोलिए — आज, या दस साल बाद, हमारे साथ या हमारे बिना।

आपके बारे में कुछ नहीं मापा जाता

न एनालिटिक्स, न उपयोग की रिपोर्टिंग, न क्रैश टेलीमेट्री। नया इंस्टॉल तो यह भी पता नहीं लगाता कि वह किस मशीन पर चल रहा है।

मूल्य निर्धारण

मुफ्त शुरू करें। भुगतान तभी करें जब आप बढ़ें.

आपके कंप्यूटर पर ऐप हमेशा के लिए मुफ्त है, और एक synced folder भी। Paid plans में unlimited synced folders, verifiable pages publish करना, और एन्क्रिप्टेड team brain जुड़ता है।

लोग अपग्रेड क्यों करते हैं

पैसे देने पर क्या बदलता है।

एक व्यक्ति, एक मशीन के लिए मुफ़्त ऐप सचमुच पूरा प्रोडक्ट है। पैसे देना पहुँच के बारे में है — ज़्यादा डिवाइस, ज़्यादा इतिहास, दूसरे लोग।

हर मशीन पर वही वॉल्ट

लैपटॉप पर लिखिए, डेस्कटॉप पर वहीं से उठाइए — उसी स्टोरेज के ज़रिए जो पहले से आपका है और आपने ख़ुद चुना है: आपका Dropbox, आपका OneDrive, कोई नेटवर्क शेयर, एक USB स्टिक। वहाँ जो पहुँचता है वह एन्क्रिप्टेड होता है, फ़ाइलों के नाम बदले हुए और फ़ोल्डर की कोई संरचना नहीं, और हमारे सर्वर पर कोई कॉपी नहीं होती — क्योंकि हमारे सर्वर इस रास्ते में हैं ही नहीं।

चुने हुए नोट्स को ऐसा पन्ना बनाइए जिसे दूसरे खोल सकें

अपने वॉल्ट का चुना हुआ हिस्सा एक साइट के रूप में प्रकाशित कीजिए, हर पन्ने के साथ उसका स्रोत जुड़ा हुआ।

और पीछे तक पहुँचिए

मुफ़्त में पिछला हफ़्ता आसानी से हाथ में रहता है। पैसे देने पर पुराने वर्ज़न खुल जाते हैं, ताकि आप वहाँ लौट सकें कि राय बदलने से पहले कोई चीज़ कैसी लिखी थी।

साझा दिमाग़, फिर भी आपका अपना

अपनी टीम के साथ एन्क्रिप्टेड वॉल्ट साझा कीजिए, एक-एक व्यक्ति को एक्सेस दीजिए और वापस लीजिए, और हमेशा जानिए कि किसने क्या बदला।

Local
Free
€0हमेशा के लिए
सभी के लिए
  • पूरी desktop app
  • नोट्स, graph, Bases & Canvas
  • वो AI use करें जो आप पहले से pay करते हैं
  • आपके नोट्स पर आधारित जवाब
  • अपने cloud से एक folder sync करें
डाउनलोड करें
लोकप्रिय
Individual
Pro
€4.08/माह€4.99
वार्षिक बिलिंग · €49/वर्ष
जितने चाहें उतने folders sync करें
  • Unlimited synced folders
  • ऐसे pages publish करें जिन्हें दूसरे verify कर सकें
  • लंबा version history
  • Notion और Confluence से import
  • Priority support
Pro खरीदें
टीम 2–50
Team
€6.58/सीट/माह€7.99
वार्षिक बिलिंग · €79/सीट/वर्ष
न्यूनतम 2 सीटें
  • Shared encrypted team vault
  • एक क्लिक में लोगों को जोड़ें या हटाएं
  • टीम में encrypted sync
  • Roles और team dashboard
  • देखें किसने क्या लिखा
टीम के साथ शुरू करें
विनियमित / >50
Enterprise
कस्टम
बड़े संगठनों के लिए

हर संगठन अपनी सुरक्षा समीक्षा, खरीद प्रक्रिया और अनुपालन आवश्यकताओं के साथ आता है। अपनी आवश्यकताएँ हमें बताइए, हम उन पर आपके साथ काम करेंगे।

बिक्री से बात करें
  • हमेशा के लिए मुफ्त
    लोकल ऐप और आपके नोट्स ऑफलाइन भी आपके हैं, भले ही आप भुगतान न करें।
  • कोई lock-in नहीं
    सब कुछ मानक Markdown फाइलें हैं। जब चाहें जाएं, अपने ज्ञान के साथ।
  • जब चाहें रद्द करें
    Individual plans month-to-month हैं; team plans सालाना renew होते हैं। आपके portal से manage होते हैं।

मूल्य EUR में · VAT शामिल · सब्सक्रिप्शन प्रबंधन my.apilium.com

यदि वैध कर संख्या के कारण कोई कर देय नहीं है, तो कर-पूर्व राशि ली जाती है।

मापा गया: कुछ नहीं

हमें पता ही नहीं कि आप इसे इस्तेमाल कर रहे हैं।

यह कोई पॉलिसी नहीं जिसे हम बदल सकें, यह ऐप की बनावट है। इसके भीतर कोई एनालिटिक्स लाइब्रेरी नहीं है, कोई क्रैश रिपोर्टर नहीं, इंटरफ़ेस बनाने के लिए सर्वर से कुछ नहीं मँगाया जाता, और नया इंस्टॉल कभी पता नहीं लगाता कि वह किस मशीन पर है।

किसी भी तरह की एनालिटिक्स नहीं

ऐप में कोई एनालिटिक्स या प्रोडक्ट-यूसेज लाइब्रेरी बंडल नहीं है। डिफ़ॉल्ट रूप से बंद नहीं — है ही नहीं।

न क्रैश रिपोर्टिंग, न एरर रिपोर्टिंग

जब कुछ ग़लत होता है, वह आपकी मशीन पर होता है, और आपकी मशीन पर ही रहता है।

कहीं और से कुछ लोड नहीं होता

फ़ॉन्ट और एसेट ऐप के भीतर ही आते हैं। इंटरफ़ेस ख़ुद को बनाने के लिए कभी किसी सर्वर को नहीं पुकारता।

नया इंस्टॉल गुमनाम ही रहता है

जब तक आप ट्रायल शुरू न करें या लाइसेंस एक्टिवेट न करें, कुछ भी आपके डिवाइस का ब्योरा नहीं देता — और वही एकमात्र पल है जब आपकी मशीन की पहचान होती है।

हमारी बात पर मत जाइए

ऐप नेटवर्क से गिनी-चुनी, बेहद मामूली जगहों पर ही जुड़ता है, और आप हर एक को देख सकते हैं: एक स्टैटिक फ़ाइल से अपडेट की जाँच, और — तभी जब आप उन्हें सचमुच इस्तेमाल करें — आपका अपना AI प्रोवाइडर, आपका Notion या Confluence अकाउंट, और हमारा लाइसेंस सर्वर। कोई नेटवर्क मॉनिटर लगाइए और ख़ुद देख लीजिए।

Under the hood

For the reader who does not believe marketing copy.

Everything above, restated as mechanism — names, curves, sizes, thresholds, and the places where a limit exists, including the ones that are not flattering. If you find something here the code does not do, we would rather hear about it than not.

The signed history

Every change is an action in a directed acyclic graph. An action carries its parent hashes, the author node, a per-author sequence number, a UTC timestamp and the payload. Its identity is BLAKE3-256 over those fields concatenated in a fixed order — parents, author, sequence, timestamp, payload — with the signature deliberately excluded, so signing never changes the hash. The signature is Ed25519 over the 32 raw digest bytes, not over the preimage and not over its hex rendering. The byte layout is published as a spec, aingle-dag-action-v1, so you can rebuild the preimage yourself; a test pins the published spec against the code that actually hashes, so the two cannot drift apart in silence.

Removal is a retraction, not a delete

Deleting a note does not erase anything. It appends a signed deletion action naming what it retracts, so the earlier state stays reachable and provable and time-travel survives. One exception, stated because you would find it: a prune operation does physically remove old actions under an explicit retention policy. It never prunes the tips, and it writes a checkpoint recording what it removed — but it is a real delete, and where it is exposed to AI tooling it is marked destructive rather than hidden among the read-only calls.

What the lock proves — and what it does not

A verified lock means two things at once: the Ed25519 signature on the anchoring action verified, and the note on disk still hashes to exactly what that signature attests. Either one failing yields no lock, and every error path fails closed — no key, no graph, a malformed hash or a missing action all produce "unverified" rather than the benefit of the doubt. "Signed, then edited" is reported as its own state instead of collapsing to unsigned. What it does not prove: the key is your vault's own, generated locally, so this is a self-attestation, not an identity — there is no certificate authority and no binding to a person. The timestamp is your machine's clock, sealed inside the signed bytes; there is no timestamping authority, so anyone holding the seed could back-date. And the signing seed is stored unencrypted next to the database. It proves these bytes were ingested and signed here and have not changed since. That is a smaller claim than "authentic", and it is the one we make.

Encryption at the sync target

One random 32-byte master key per target, generated on the device. Three subkeys derived from it with BLAKE3 derive_key under distinct context strings: one for content, one for blob names, one for a public target id. Content is XChaCha20-Poly1305 with a fresh random 24-byte nonce per write and a 16-byte tag. The master key is reachable two ways, both held only by you: a passphrase wrapped with Argon2id — the argon2 crate defaults, 19 MiB, 2 iterations, 1 lane, with a 16-byte random per-target salt — stored in a keybox on the target itself so any machine that can see the folder can unlock it; or a one-time recovery key, which is the master key rendered as 56 Crockford base32 characters with a checksum. Nothing is escrowed. We hold no copy and there is no reset, which is the same thing as saying we could not read your files even if we wanted to.

What actually lands in the folder

A blob's name is a keyed BLAKE3 hash of its vault path, Crockford base32 encoded — always 52 characters, so the length of a path leaks nothing either. The real path travels inside the sealed payload, so decrypting one blob is enough to place it: there is no manifest and no name table that could be lost or corrupted. The authentication tag covers the path, so a blob renamed or moved by anything other than the app is detected rather than silently accepted. Padding is applied to the plaintext before sealing: the padded length is the next multiple of 4 KiB up to 64 KiB, and the next multiple of 64 KiB above that. On disk a blob is that padded length plus exactly 40 bytes — a 24-byte nonce and a 16-byte authentication tag.

What an observer of that folder can still see

Stated here because you would find it anyway, and because a limitation you discover for yourself is worth far more doubt than one we hand you. Someone who can read the synced folder learns: that it is an Altretta target, because the header file is plaintext on purpose so a second machine can find the salt; the number of notes, since there is one blob each; and each file's size to within its padding bucket. Because a blob's name is a deterministic function of its path, every note keeps the same name for its whole life — a stable pseudonym. That determinism is what lets two machines agree where a note lives without a shared index, and it is also what lets an observer watch how often you edit any single note, note by note, from timestamps alone — without ever learning which note it is. Deletions are the sharpest of these, and they are exact rather than approximate: a removed blob is moved into a trash directory rather than unlinked, keeping its name and gaining the millisecond it was removed. So the precise number of notes you have deleted, the exact moment of each deletion, and which pseudonym each deleted note had while it existed are all plainly readable. The public target id is a stable fingerprint linking two folders to the same key. None of it discloses a title, a path, or a word of content.

What makes the assistant refuse

Retrieval embeds your question, over-fetches from the memory index, keeps only chunk entries and re-ranks them by pure cosine similarity — deliberately discarding the composite recency-and-importance score the memory layer would otherwise apply, because relevance to the question is the only thing that should decide a citation. A verdict of "grounded" requires the best match to clear the high threshold and at least 2 chunks to clear it: corroboration, not one lucky passage. With the neural embedder the product ships, those thresholds are 0.80 and 0.77, calibrated against a measurement that unrelated pairs top out near 0.76. Between the two is "weak"; below both is "ungrounded". The answerability gate is then: at least one visible source after your folder exclusions have been applied, and — if you asked for grounded answers only — a verdict of exactly "grounded". When that gate fails, no model call is made at all. Answering anyway is a separate flag that is never inferred on your behalf, and when you set it the weak passages are withheld from the model so it cannot cite what did not qualify.

The symbol graph

Twenty languages have symbol extractors, each a tree-sitter parse plus a query: Rust, TypeScript, JavaScript, Python, Go, Swift, Java, C, C++, C#, Kotlin, PHP, Ruby, Dart, Scala, Objective-C, Bash, Lua, R and SQL. Symbols get canonical identifiers and are emitted as signed triples through the same path as everything else in the graph. Edges are typed — defines, imports, references, calls — and carry a confidence tier: a call resolving to exactly one candidate is high confidence, while a call with homonyms and every bare reference are marked uncertain rather than asserted as fact. Files over 2 MiB are recorded as skipped rather than quietly ignored, and a project is budgeted at 750,000 symbols. Drift compares a note's last-written time against the newest signed change to the symbol it documents. The limitation, which the source states plainly: that time is the filesystem mtime, so a checkout, a restore or an rsync that rewrites mtimes will change the verdict.

Reading documents, and what gets dropped

Word, PowerPoint and their OpenDocument equivalents are parsed in pure Rust — no rasterising, no OCR, no native dependency. Spreadsheets go through calamine. PDFs use the pdf.js text layer; rasterising with OCR is a separate, opt-in tier that runs only on pages with no usable text, and pages left unread are recorded as debt rather than silently dropped. Extraction emits citation anchors — a page marker per PDF page, a heading per slide, a sheet-and-row anchor per spreadsheet block, and a section anchor for numbered sections in a regulation, keeping the numeral in the heading because it is the only stable name that section has. Slides are ordered numerically, so slide 10 follows slide 9 rather than slide 1. Caps are enforced by bounded reads instead of trusting a declared size: 32 MiB per XML part, 128 MiB per archive, 16 MiB of emitted text, 5,000 slides, 50,000 rows. A gap worth naming: spreadsheets report truncation as a warning and the other converters do not, so a very large document can be trimmed quietly. The extracted text is written as an ordinary companion Markdown file beside the source, so the normal ingest signs it like any other note — there is no extraction database, the companion file's recorded source hash is the idempotency record.

Where everything lives on disk

Your notes are Markdown files in your folder. The only thing the app adds inside it is a hidden control directory holding the vault format stamp and, for a team vault, the keyring. Everything derived — the graph database, the search index, the snapshot store, the signing seed — lives outside the vault in application data, and the app refuses to start if you point the database inside the vault, because its own writes would trigger a re-ingest loop. That separation is why removing the app leaves your folder untouched, and why the derived index is always safe to delete and rebuild. It is also, honestly, why version history does not travel with a synced folder today. Licence checks are offline: a signed token verified against a key compiled into the app, with no server call. If we disappeared tomorrow, the app keeps opening, reading, writing, searching and answering.

How to check all of this yourself

The engine is open source. github.com/ApiliumCode/aingle holds the signing, hashing, graph and grounded-retrieval implementation, under Apache-2.0 for individuals, academia and organisations under $1M revenue, with a commercial licence above that. The application itself is not open source, and we would rather tell you that than imply otherwise.

  • Reproduce a content hash: run any BLAKE3 tool over a note and compare it with the hash the app shows you. There is a pinned test vector in the public source to check your tooling against first.
  • Rebuild an action hash and verify its signature independently: the byte layout is published as a spec, and the public test suite exercises tamper-rejection and the fact that signing does not change the hash.
  • Confirm there is no telemetry: grep the source for the usual analytics and crash-reporting names, then list every URL literal in the Rust. What comes back is your own AI provider, your own connectors, and our licence and publishing endpoints — nothing else.
  • Watch the network: open a vault with a monitor running. Nothing should be contacted until you configure a model or deliberately click an account action.
  • Prove the deletion leak to yourself: turn on encryption for a scratch folder, add five notes, delete two, then list the target's trash directory. Two timestamped files. That is the leak, reproduced in a minute.
  • Confirm no reset exists: forget the passphrase and lose the recovery key on a scratch target. Nothing in the app, and nothing we hold, can open it again.
github.com/ApiliumCode/aingle
डाउनलोड

आज आपके प्लेटफॉर्म के लिए उपलब्ध।

macOSApple Silicon (M1–M4)macOSIntel (x86_64)Windows10 / 11 · x64LinuxAppImage · deb

macOS universal (Intel + Apple Silicon) · Windows x64 · Linux AppImage/deb

अक्सर पूछे जाने वाले सवाल

जो आप शायद पूछना चाहते हैं।

क्या मैं सच में अपने नोट्स का मालिक हूँ?

हाँ। हर नोट आपकी डिस्क पर एक मानक Markdown फाइल है। इसे किसी भी editor से खोलें, बैकअप करें या जब चाहें Altretta छोड़ें: आपका ज्ञान आपके साथ रहता है।

अगर app मुफ्त है तो pay क्यों करूं?

Desktop app, आपके नोट्स पर आधारित जवाब, और एक synced folder हमेशा के लिए मुफ्त हैं। Paid plans में unlimited synced folders, ऐसे pages publish जिन्हें दूसरे verify कर सकें, और encrypted team brain जुड़ता है। अगर एक synced folder से आपका काम चल जाता है, तो Free plan सच में आपके लिए काफी है।

मैं AI के जवाबों पर भरोसा कैसे करूं?

हर जवाब ठीक उन नोट्स को quote करता है जिनसे वो आया, citations और एक confidence score के साथ। अगर कोई दावा आपके नोट्स से support नहीं होता, तो Altretta कुछ बनाने की बजाय आपको बता देता है।

क्या AI connect करने के लिए technical होना जरूरी है?

नहीं। Altretta उन AI apps को खुद detect करता है जो आपके पास पहले से हैं — जैसे Claude, Cursor या VS Code — और उन्हें एक क्लिक में connect करता है। कोई config file नहीं, कोई key paste नहीं, और आप चुनते हैं कि AI कौन से folders देख सकता है।

क्या मुझे AI के लिए अलग से भुगतान करना होगा?

Altretta एक शुद्ध मेमोरी layer है: इसमें अपना LLM शामिल नहीं है। आप अपनी सब्सक्रिप्शन के साथ MCP के माध्यम से अपना पसंदीदा मॉडल जोड़ते हैं, इसलिए जो AI आप पहले से भुगतान करते हैं उसे उपयोग करें और अपनी keys का नियंत्रण बनाए रखें।

क्या मैं अपने मौजूदा नोट्स ला सकता हूं?

हाँ। Altretta सामान्य Markdown पढ़ता है, इसलिए आपका मौजूदा नोट्स folder जैसा है वैसे काम करता है। Pro में Notion और Confluence से one-click import मिलता है।

एन्क्रिप्टेड टीम ब्रेन कैसे काम करता है?

आप एक ऐसा वॉल्ट साझा करते हैं जिसकी नोट सामग्री आपके डिवाइस पर एन्क्रिप्ट होती है, इसलिए टीम के बाहर कोई यह नहीं पढ़ सकता कि नोट में क्या लिखा है — न हम, न फ़ोल्डर होस्ट करने वाला। पहुँच हर व्यक्ति के लिए अलग है और वापस ली जा सकती है: किसी को हटाइए और कुंजी बदल जाती है, वह फिर कुछ नहीं पढ़ सकता। एक सीमा जो हम आपके खोजने से पहले बता देना चाहते हैं: फ़ाइल नाम और फ़ोल्डर संरचना एन्क्रिप्ट नहीं होते, इसलिए होस्ट को वॉल्ट का ढाँचा और हर नोट का नाम दिखता रहता है।

किन प्लेटफॉर्म पर काम करता है?

Altretta आज macOS (Apple Silicon और Intel), Windows और Linux के लिए उपलब्ध है। डाउनलोड हमेशा नवीनतम प्रकाशित संस्करण की ओर इशारा करते हैं।

अपने ज्ञान का नियंत्रण लें।

Private, offline, और verifiable। आपके नोट्स, आपका AI, आपके नियम।