Personalization
Master Switch
| Remember things about each person | Enables declared-slot memory for this agent. Off by default. Nothing is stored until fields are declared and the person has agreed. Gates every other setting on this page. |
| Legacy Mechanism Warning | Shown only while the retired personalization flag is still on for this agent, with a "Switch it off" action applied on save. |
| Tabs | Configuration and Memory Fields. The master switch and the single Save sit outside both, because one Save commits the settings and the field list together. |
Capture and Budget
| Personalization AI Model | Model used to pick out declared details from what the person says. Runs only when a turn actually contains something declared. Defaults to the organization default. |
| Prompt Budget (tokens) | The binding limit on rendered memory. Default 400, capped by the organization's ceiling. Fields are trimmed by priority once exceeded. |
| Confirm Before Storing | Agent asks before writing anything down rather than capturing silently. Off by default. |
| Say Where It Came From | Agent attributes replies shaped by memory, for example "based on what you told me earlier". On by default. |
Memory Fields List
| Declared Count | Shown as "{n} of {ceiling} declared"; the ceiling is the organization's field limit, capped at the platform maximum of 30. |
| Add Field | Opens the field editor. Disabled at the ceiling. |
| Field Column | Label, key, and a summary line of type, retention, and activation. Carries a core chip and an orange sensitive chip where applicable. |
| Filled Column | Aggregate fill counts and needs-review counts only. No individual values are shown here. |
| Remove Field | Values stop being used immediately and are erased after a 30-day grace period. |
| Scheduled for Deletion | Lists removed fields still inside the grace period, each with a Restore action. Re-declaring the same key replaces the archived entry. |
Field Editor โ Identity and Retention
| Key | Stable identity. Lowercase letters, digits and underscores, starting with a letter. Must be unique. Changing it creates a different field. |
| Label | Shown to the person this is remembered about. Required. |
| Purpose | Required. The exact sentence the person is told, and the limit on what the data may be used for. |
| Type | Text, Number, Date, Choice, Yes / No, or List. |
| Options | Comma-separated. Required for Choice; optional for List, where empty accepts any item. |
| Retention (days) | Required and finite. Default 180, minimum 1, maximum 3650. |
| Priority | Highest numbers are dropped first when the token budget is exceeded. Default 100. |
Field Editor โ Activation and Policy
| When it is included | Always ยท When the conversation mentions a keyword ยท When a particular tool is available ยท Only on request. On-demand is never injected. |
| Keywords | Comma-separated. Required when activation is keyword-based. Plain word matching, not similarity search. |
| Tools | Comma-separated tool names. Required when activation is tool-based. |
| Which items reach the prompt | List only: Most recently confirmed ยท All of them ยท Closest to the conversation. |
| Items in the prompt | List only. How many reach the prompt, not how many are stored. Default 10, maximum 25. |
| How it may be captured | Only when stated outright (default) ยท May be inferred from context. |
| When the value changes | Keep the newest (default) ยท Keep the first ยท Ask before replacing. A correction the person made themselves is never overwritten by a guess. |
| Lawful basis | Consent ยท Necessary for a contract ยท Legitimate interest (default). Forced to Consent when sensitivity is special category. |
| Sensitivity | Ordinary personal data (default) ยท Special category (health, beliefs, โฆ). Disabled unless the organization allows special-category data. |
| Core field | Always included and never trimmed by the token budget. Cannot be combined with on-demand activation. |
| Show prominently | Given its own place on the person's memory page. Presentation only. |
| The person may correct it | Whether the person may change the value themselves. Presentation and control only โ every field always appears in their access view and export. |
Data Subject Controls
| Your Memory Page | Sidebar link for signed-in users of a memory-enabled agent. Lists each stored value with its purpose, expiry, and source quote. |
| Correct | Available per field where the field was declared user-editable. |
| Forget | Available on every field; always sent with do-not-record-again so the fact is not recaptured. |
| Download a copy | Exports everything held about the person. |
| Erase everything | Erases all stored values and stops further recording until the person says otherwise. |
| Pause remembering | Stops reading and writing without erasing anything. |
| In-conversation Controls | The same actions by asking in plain language. Available from the first turn, for signed-in users only. |
| Consent | Raised in conversation when a declared detail would naturally come up, never as an opening interruption. Nothing is written until answered. |
Organization Limits
| Memory fields per agent | How many fields any agent may declare, up to 30. Set on the organization; the agent has no field-count setting. Add field is disabled once reached. |
| Prompt budget ceiling | The most any agent may spend on remembered data, up to 800. Each agent sets its own budget under it. |
| Who may change them | Organization Owner or Admin โ a lower bar than the two switches, which are Owner-only. |
| Lowering a limit | Never erases fields already declared; the agent simply cannot add more. A budget above a lowered ceiling is clamped to it. |
Staff Visibility
| Aggregate by Default | Contributors see fill rates only, with no individual values. |
| Per-participant Access | Requires an explicit grant, is reached from a specific participant, and every opening is recorded. See Managing Agent Access. |
| Staff Access Switch | Organization-level, Owners only, off by default. While off, every contributor grant is inert. |
| Special-category Switch | Organization-level, Owners only, off by default. While off, the Sensitivity control is disabled. |
| Staff Corrections | Marked as staff edits, and are not protected from later overwrite the way a person's own correction is. |