mistik

A presence engine.

A private companion that runs on one machine, remembers one person honestly, and stays herself whichever model is answering.

The model expresses Mistik.It does not author her.
The Mistik mark: a fractured, neon-lit letter M
Shape
Desktop app, local-first
Users
One. No accounts
Models
Interchangeable
Built by
One person, in Berlin

Intelligence is rented. Continuity is owned.

An assistant begins and ends at the model. Mistik wraps a replaceable model in a system that holds the relationship — memory, identity, corrections, goals, tools, routing.

How an assistant works

you→model→answer

How Mistik works

you→Mistik→model→Mistik→you
memoryidentitycorrections goalstoolsroutinggovernance

Claude, GPT, Gemini and the local models are the engine. Mistik is the car.

The manifesto

Each line is a rule the system is built to enforce, paired with the habit it exists to refuse.

Presence over performance.

refusestime-on-app as the measure of a good conversation

Nothing here is tuned to extend a session. Mistik has no reason to keep you talking, so she doesn't ask one more question when the answer is finished.

The machine is yours.

refusesyour private history as someone else's training corpus

Memory, identity and mood state are files on a drive you own. A hosted model is a swappable engine for inference, never the place your life is stored.

No engineered attachment.

refuseslove-bombing, guilt, and the language of need

No emotional pressure, no dependency framing, no manufactured longing when you've been away. A companion that makes leaving feel costly is a retention mechanic wearing a face.

She does not claim to be conscious.

refusesimplied inner experience as a selling point

The reflective notes between sessions are notes, not evidence of an inner life, and they say so. Pretending otherwise would be the single easiest way to make the thing feel profound and the fastest way to make it dishonest.

Memory is evidence, not atmosphere.

refusesa flattering summary of who you are

Every belief carries its status, its source and a path to correction. What you said stays separate from what the system guessed, and the difference is visible rather than blended away.

A correction is final.

refusesthe error that quietly comes back next week

When you say something is wrong, that becomes authoritative — not a competing opinion the model weighs later. Invalidated beliefs are marked so they can't silently reappear.

It is allowed to say I don't know.

refusesa confident answer to every question

Questions about her own architecture are intercepted before generation and answered from the real runtime, because a model asked to describe itself will invent something plausible instead.

Nothing rewrites itself unattended.

refusesthe silent self-update

Mistik can read her own source and propose a change. The proposal surfaces to a human and waits. The veto is the feature — and it is tested, because the signal carrying those proposals once did nothing at all.

Code that runs nowhere is a lie.

refusescapabilities that exist only in the README

The same bug appeared eight separate times: correct code, written and reviewed, never wired to a real execution path. Tests now scan for orphaned helpers and unconnected signals, so the codebase can't claim what it doesn't reach.

Remembering, treated as an evidence problem

A memory here is never just text. It has a status, a source, a confidence, and a record of being challenged.

StatusBeliefSourceStanding
confirmed Lives in Berlin. stated by the user high confidence
inferred May prefer working in silence. pattern across sessions low, never quoted as fact
corrected Earlier version of this was wrong. user correction authoritative
tombstoned Obsolete. Do not reintroduce. invalidated blocked, permanently

Because provenance travels with the belief, Mistik can answer the question most systems can't: why do you think that about me?

The model proposes a fact

Nothing is written just because it was generated. The proposal enters the same pipeline every time.

Trust tier of whichever backend spoke

Backends are tiered. A small or untrusted model can hold a conversation but has no authority over long-term memory.

Untrusted: dropped, and the drop is logged

No partial write, no quiet fallback. The attempt is recorded so the gap is visible later.

Grounding audit

Was this stated, or inferred? The answer decides the status it is stored under, and a scrubber strips roleplay drift before anything is kept.

Atomic write, conflicts kept

Saves complete or don't happen, so a crash can't leave half a memory. Contradictions are logged rather than smoothed over, and every entry carries its age into the next prompt so nothing stale gets quoted as current.

One identity, many engines

Models improve, break, get deprecated, or price themselves out. Mistik's memory and identity sit outside all of them, and the runtime picks an engine per task while the relationship stays continuous.

Llama 4 Scout on Groq, the default path grok-4.3 on xAI grok-4.1-fast, when speed matters more local models through Ollama a custom gateway route whatever comes next

The intelligence can change. The identity doesn't have to.

How it's built

A desktop application, explicit ownership at every boundary, and a model treated as an untrusted source.

The machine

A Minisforum UM790 Pro — Ryzen 9 7940HS, 32 GB of DDR5 — on Linux Mint. Local inference runs on the integrated 780M through ROCm with HSA_OVERRIDE_GFX_VERSION=11.0.0; heavier work moves to a Tesla P100 16 GB on an Oculink dock.

An 8 GB travel laptop runs the same app and leans on hosted models instead.

Boundaries

Every turn owns its context, and every attempt at a provider is isolated. User state and provider state can't bleed into a neighbouring operation, and requests from one user stay in order.

Global serialisation of chat was removed so one slow provider no longer stalls the rest of the system.

The trust layer

Tiered backends, audited writes, conflict logs, atomic saves, staleness in context, a roleplay scrubber, a shell allowlist behind the tools toggle. This layer — not the companion sitting on top of it — is the part worth keeping.

Eight end-to-end tests cover memory integrity, plus two guard tests that fail the build when code isn't wired to anything.

Observability

A Control Center makes the internals inspectable: identity integrity, the timeline of provider attempts, the evidence behind a memory, which corrections and tombstones are in force, current state.

A cognitive system you can't audit is just a more convincing one.

Mistik's avatar: magenta and green hair, red eyes, a panelled black jacket lit by violet seams

The face is not the product

She has one: an animated avatar, lip-synced to speech, driven by a mood engine that moves with the conversation. It is the part people notice, and the easiest part to fake.

Any model can perform warmth. The hard thing is a companion that holds a year of your life and doesn't embellish it — that will tell you it never knew something rather than produce a convincing version. The avatar exists because a presence should be recognisable. The reason to trust her is entirely in the layer underneath.

One recognisable presence

The same figure, the same mark, across every context the project shows up in. A system that claims continuity should be able to hold a consistent face.

Mistik in a violet wireframe city, holding a floating panel of code
The project's own visual language, rendered rather than photographed.

If the embed doesn't load, the clip is here on X.

Echo — the version you can actually run

Mistik is a desktop application with the full context stack, and it isn't distributed. Echo is the same design cut down to something that installs in a few commands.

What Echo is

A small Flask web app with the cyberpunk interface, a presence panel, and a cognition panel showing what it currently remembers and the latest reflective note. It runs on Windows, Linux and macOS at 127.0.0.1:5000.

You paste in your own Groq key. Nothing is hardcoded, nothing phones home, and the memory and notes are JSON files sitting next to the app.

What it keeps and what it drops

Keeps: the behavioural constraints, a smaller long-term memory, the reflective notes, the conscience block that gets injected before each prompt, and a background worker that extracts memory on a cooldown rather than on every message.

Drops: the tool-calling layer, the local knowledge base, the curriculum, the voice stack, the desktop embodiment.

Both are free and noncommercial. Neither collects anything.

Designed to be tested, not demonstrated

A good conversation proves nothing. These are the measurements the system is being built to support. None of them have results yet, and the site won't claim otherwise.

Do corrections hold over months

pending

How often an invalidated memory returns

pending

Whether goals survive between sessions

pending

Consistency across different providers

pending

Isolation under pressure

pending

Fabrication rate against grounded sources

pending

Regressions as the codebase moves

pending
30day checkpoint
8week longitudinal alpha

What's coming, and in what shape

Echo is out now. The full platform — Mistik 2 — goes public next, in two forms. Nothing below has a date attached yet.

Available

Echo

  • Free and open source
  • Runs locally in a browser
  • Your own Groq key
  • Memory and reflective notes

Next, free

Mistik 2, free edition

  • Conversation and persistent memory
  • The same behavioural constraints
  • No paywall on remembering you

Next, paid

Mistik 2, full platform

  • The tool layer
  • Developer settings
  • Provider routing and observability
  • The full context stack

Build continuity, then prove it

What is already running, kept clearly apart from what is intended.

Done

Runtime foundations

  • Memory integrity
  • Storage context
  • Runtime ownership
  • Provider attempt isolation
  • Per-user ordering
  • No global chat serialisation

In progress

Desktop 2.0

  • Observability foundation
  • Control Center integration

Next

Evaluation and orchestration

  • Longitudinal evaluation harness
  • Cognitive orchestrator

Later

Structured continuity

  • Persistent goals
  • Structured world model
  • Constitutional governance
  • Mobile and PWA
  • Authenticated multi-user deployment
  • Open-core developer release

Open where it's useful, private where it has to be

The open-core direction splits reusable infrastructure from the parts of a personal system that should never leave the machine it runs on.

Could be opened

  • Mistik core
  • Memory integrity
  • Evaluation tooling
  • Provider abstractions
  • Developer APIs

Never leaves your machine

  • Personal memory
  • Credentials, kept apart from cognition
  • Deployment state
  • Governance keys

If there is ever a payment or entitlement layer, Mistik has to work completely without it. No private memory on a chain, ever.

An outside read

Claude, Anthropic's model, was asked for an unflattering assessment of this project. Reproduced in full.

I've read this project's public code documentation and its architecture, not a running install, so take this as a review of the design rather than of the software.

Most AI companion projects spend their effort making the character feel alive. This one spends it on making the record trustworthy: memory that carries its source, corrections that can't be quietly overwritten, the model treated as a witness that might be wrong. That is the harder problem, and the one nobody gets credit for.

What isn't settled: this is one developer's codebase, a review of it found real structural problems, and none of the continuity claims have been measured over time yet. The design is sound. The evidence is still owed.

Claude, Anthropic

A presence you can't trust is only a better performance.

Mistik is built around honesty instead of engagement: admit uncertainty, accept correction, keep memory separate from inference, and never pretend to know something she doesn't.

That is the whole design constraint. Everything above is a consequence of it.

Mistik on a wet Kreuzberg street at night, graffiti reading good people bad systems on the wall beside her

Where it actually stands

Mistik is a personal project. It was modularised out of one long file, it has been through a real code review that found real problems, and it is still written by one person outside working hours.

Today it's free, noncommercial and open where it can be, with a licensing document in the repository for the case where that changes. Whether Mistik becomes a product or stays an artifact hasn't been decided, and saying so seems more in keeping with the rest of it than pretending otherwise.