Product
No Record is a private online AI workspace at app.norecord.app. It combines current Cloudflare Workers AI routes with browser-custodied history, client-side pattern minimization, content-free usage metering, adaptive Loom orchestration, independent Council answers, local media galleries, local JavaScript execution, MCP, API keys, and optional encrypted sync.
Custody model
- Displayed conversations, galleries, code source/queues/assets, favorites, and settings stay in browser IndexedDB.
- Requests transmit selected context to the Worker and selected model route.
- No Record application storage does not receive plaintext prompts, outputs, generated bytes, or code source.
- Usage rows contain daily aggregate totals; active-seat analytics use distinct rotating-HMAC actor buckets for the current hour.
- Privacy audit rows contain policy/route metadata and rotating commitments, never prompt or output content.
- Encrypted sync stores AES-256-GCM ciphertext, digest, vault metadata, and version; the key remains in the recovery code held by the browser/user.
Live capabilities
Chat with in-page generation continuity, health-aware Auto routing, Council, Loom, images, browser-local motion video, local JavaScript execution, two-way code candidate queues, code image assets/artifacts/repair, MCP App chat/image UI, inbound/outbound MCP, route safety shutdown, visible cooldowns, scoped API keys, usage, encrypted sync, and local wipe are live.
Preview and blocked states
- Online credits: preview; new vaults start at zero balance. Desktop private credits are source-live.
- Online payments: unconfigured. Desktop-local Solana, Stripe, and x402 contracts are source-live but fail closed until configured.
- Browser Run: implementation deployed, acquisition capacity unavailable.
- Cloud code containers: blocked pending Cloudflare account authorization.
- Provider-generated video/audio are not exposed.
- Native iOS and desktop source are live; App Store and signed-installer releases are not claimed.
Verification boundary
The source contract, tests, and live behavior can verify No Record-side persistence rules and capability states. They do not prove provider deletion, model forgetting, anonymity, absence of network metadata, or unavailable infrastructure.