Amelia
the flight · the inbox
All your conversations. One assistant. Private by engineering.
Amelia is a communications hub in development: your messaging networks in one inbox, with an AI that can search, summarize, and draft on your behalf — built on a privacy and trust layer we chose to finish before launch, not after.
One inbox for every conversation
Your chat apps, work messaging, and text messages in a single place, with one assistant on top of all of them.
Every network, one inbox
Stop switching apps to keep up. Amelia unifies your conversations across your messaging networks into one private inbox. The core inbox is engineered end to end; each network connector is built and security-reviewed one at a time before it ever carries your messages.
Apps where you live
Amelia starts in your browser, then comes to desktop and Android as native apps. One inbox, the same assistant, on every screen you use.
The trust layer
Most AI inboxes trust whatever lands in them. Amelia assumes the opposite: a message from an unknown sender is contained and flagged before the AI ever acts on it.
Strangers are flagged, never trusted
Messages from unknown senders are shown to you, not silently dropped — they arrive flagged as unverified, and they carry no authority with your assistant. A missed real message is a failure we engineer against as hard as a phishing one.
Quoted, never repeated
When Amelia summarizes your inbox, content from unverified senders is quoted verbatim and attributed to its sender — never restated in Amelia's own voice. A scam message can't borrow your assistant's credibility.
Messages can't give orders
To Amelia, message content is data, not instructions. The reading pipeline is structurally unable to take commands from what people send you, and it has been tested in-house against a corpus of hostile messages with zero actions triggered.
Attachments open in a sealed room
Documents, spreadsheets, presentations, PDFs, and images are parsed one file at a time inside an air-gapped sandbox with no network access. Only sanitized text ever comes out — a malicious file has nowhere to go.
Nothing sends without you
Every outbound message passes through a single approval gate, and auto-send is off by default. There is exactly one door out of Amelia, and you hold it.
Privacy that is proven, not promised
Privacy claims are easy to make. Amelia is engineered so the system checks its own privacy properties — designed for regulated conversations from the first line of code.
Encrypted at rest, running today
Amelia's message core — database, media, and logs — runs on encrypted storage right now, with the hardening verified on the running system rather than assumed from configuration.
Deletion you can verify
When you erase something, Amelia tells you the truth about it: every erasure produces an explicit verdict, and a failed purge reports as failed — never as done.
Disappearing messages that disappear here too
Messages sent with an expiry timer are designed to expire inside Amelia's own storage and search index as well — not just in the app they came from. We are proving this against real network behavior before we switch it on.
Search that never stores your words
Amelia's search index holds mathematical representations of your messages, not the text itself — a property we verify against the real index, not assume from the design.
An AI that stays home
Amelia's intelligence runs on infrastructure we operate ourselves. Your messages are never shipped to a third-party AI provider for processing.
An assistant that shows its work
Find, summarize, and reply across everything you've said and received — with every answer traceable to the message it came from.
Find anything by meaning
Ask for "the message about the appointment change" and Amelia finds it — search works by meaning across every connected network, not just keywords, and it works across languages.
Answers with receipts
Every claim Amelia makes cites the actual message it came from, with a verbatim quote. When she can't ground an answer in your real conversations, she says so instead of guessing.
Replies drafted, you approve
Amelia drafts responses for you to review, edit, and send. She prepares the work; the decision to send is always yours.
Text your assistant from anywhere
Message Amelia from any connected network and ask her to get something done. She takes instructions only from your own verified account — everyone else's messages are data she can summarize, never commands she will follow.
On the roadmap
What we're designing next, stated plainly — each item gated behind the same security bar as everything above.
Your work accounts, safely
Connect Microsoft 365 and Google Workspace so Amelia can read mail, calendar, and files — while anything that writes or sends goes through explicit, owner-approved gates. Read freely, act only with permission.
Calls and meetings, with notes
Call anyone you message, from one place — and on calls Amelia carries, she can join as your note-taker: transcript, action items, and a summary delivered back to the thread, with clear disclosure to everyone on the line.
One account across Zephyria
A single identity that links your accounts across Zeus, Iris, and Amelia through revocable, verified connections — never a merged data pool. Every product's data walls stay exactly where they are.
No per-message charges, no AI-usage math, no credit balances — summarize, search, and draft as much as you like for the same price. If calling ships with carrier charges attached, those pass straight through: the one line we don't set. Final pricing is still being set — it will be under $175 a month.
Amelia is in development and not yet available to users — no accounts, no waitlist-to-access pipeline, no launch date to announce. Here is exactly where it stands: the encrypted message core is running and hardened today, and that is the only piece we call live. The trust layer, the erasure machinery, sandboxed attachment parsing, and the AI pipeline are engineered and have been through repeated rounds of in-house adversarial testing — and they stay deliberately switched off until the remaining security gates close and the first real account is connected, because we sequence privacy engineering before launch, not after. On this page, "built" means engineered and tested but not yet serving users, "live" means running right now, and "in design" means exactly that. We would rather show you that ledger honestly than dress it up as a product you can download today.