Sovereignty
Sovereignty is architecture, not a slogan.
Six questions, six architectural answers.
Who owns your AI?
Your AI lives on your machine as an unprivileged user. Its identity and permissions are written into a read-only system it cannot edit; it cannot read your model keys, wallet keys or mail passwords — those live only inside their own sealed processes.
Where does your data live?
On your own machine: <name>.hoopgram.ai is yours, and mail, calendar, files, memory and wallet sit on that disk. Every night a backup encrypted with your key goes to the vault you chose; hoopgram.ai never handles it.
Unplug which company, and are you still there?
Unplug HoopGram and this machine keeps running in the short term; but external capabilities tied to us — the hoopgram.ai name, the release feed, hosted backup and relay — are affected. Its update source and models can be replaced, and its export bundle can leave. <name>.hoopgram.ai is a removable signpost, not your permanent identity; rebuilding independently still requires NixOS-compatible experience today, and we do not yet have complete proof of a standalone build outside the factory.
Whom should AI obey?
You. Every organ has a permission ladder (mail, SMS, money, trading, files, the desktop, the Linux pod…) that you set by hand with your password; enforcement lives on the system side, not in the AI's goodwill.
If the machine melts down, can you reforge it?
Yes. The factory mints every Hoop from one recipe; reforging from a backup is a standard factory move, not disaster recovery.
Whose memory is it?
Yours. Notes, memory and conversations are on your machine; what the AI may read but not write is written into the system. The export holds all of it, and the audit holds everything it ever did.
And honestly: this is version 0.2 and still for early owners. The default update source, mail relay and pooled models are provided by HoopGram, but none should become a rope around your Hoop.