Sept 22, 2026
One question does not open every door in Yu
Task-relevant context, visible use, and the privacy architecture we are committed to.
Some of what’s described here is still in development. Follow our progress in Build in Public.
A Yu can eventually contain a lot, which is why having access to it does not mean having access to all of it at once. Your assistant takes the context that belongs to the task in front of it. A project question does not need every memory you have ever saved. Connecting a workspace does not open every file inside it. One question does not open every door in Yu. When your assistant uses your context, Geode Labs shows you what it used.
When your assistant needs an outside model, we do not hand that provider a permanent Geode identity and let it quietly assemble its own version of you. Requests are separated from your stable Geode account through randomized identifiers, and only the context needed for that request goes with them. The model gets what it needs to do the job. It does not get your whole Yu.
The same principle applies when what people contribute can help Geode Labs improve the wider system. Useful pieces can teach us something without becoming somebody’s dossier. Contributions used beyond an individual Yu are anonymized and randomized so they cannot simply be stitched back together into a coherent profile of the person they came from.
We never sell or monetize your personal data. Context Coins are not payment for disclosure, and your private life is not inventory. Your Yu belongs to you. You decide what enters it, what remains, what changes, what disappears, what your assistant can use and what is allowed to leave.