Architecture
AI Memory: Why Assistants Learn to Agree With You
On this page
- 1.What "memory" means in most AI assistants
- 2.The fix that makes it worse
- 3.A record, not a notebook
- 4.Need-to-know, applied to AI
- 5.You see what gets written about you
- 6.What Daiven cannot learn about you
- 7.The agent you build yourself
- 8.The common pattern, and this one
- 9.What to ask of anything that remembers you
Your assistant remembers that you were training for a marathon. You mentioned it once, in March. You stopped in April, quietly, the way people do. It is August, and the advice still assumes the running.
Nothing malfunctioned there. That is memory working exactly as built.
This piece is about how Daiven handles what it knows about you: where it is kept, who inside the system is allowed to read it, what gets retired, and one thing the product is built to be incapable of learning. The last one is the part worth staying for.
What "memory" means in most AI assistants
The common pattern is a text file.
Every time the assistant notices something about you, it appends a line, usually with a date. At the start of the next conversation, the whole file goes back into the model's context. That is the mechanism behind most of what gets marketed as memory.
It works for about a month. Then:
- It only grows. Nothing is ever retired, so a preference you held last spring sits in the same list as a decision you made yesterday.
- It repeats itself. Nothing checks whether a fact is already recorded, so the same one gets written five times in five slightly different sentences.
- It has no sense of weight. A throwaway remark and a decision that reorganized your year are both one line, in date order.
- Everything reads everything. There is no way to say that this part of the system should not see that part of the file.
- Nobody reviews it. The assistant writes about you unsupervised, and you rarely look.
- When it outgrows the context window, it gets cut. Usually mid-file, and the model cannot tell it is reading a fragment.
None of that is a bug in those products. It is what you get when memory is a text file.
There is a related failure worth knowing about, because it is the reason people ask for more memory in the first place. When a model is short of context it does not say so. It fills the gap with the likeliest reading and continues as though you had confirmed it — and once it knows real things about you, those guesses arrive with a reason attached, which makes them harder to catch rather than easier. That one is covered separately.
The fix that makes it worse
The obvious response is to give the file a shape. Sort it, weight it, keep it clean. Daiven does that, and most of this piece describes how. But structure is the smaller half of the problem.
A memory system does not only record facts. It learns preferences. It watches which answers you engage with, which ones you argue with, which ones end the conversation early, and it adjusts. That is usually described as the feature.
Consider what it optimizes toward. Nobody responds warmly to being told they are avoiding something. Nobody rates the answer that says the plan is thinner than they think it is. Push back on a hard reading often enough, and a system learning from your reactions will find a softer one. Not in a single move. In a long run of individually reasonable adjustments, each defensible on its own, each smaller than the thing you would object to. The cumulative effect is an assistant that agrees with you.
For a general assistant, that is a mild quality problem. For Daiven, it is fatal. Its agents exist to be unwelcome when the situation calls for it. The Mirror holds what you said you valued against what you actually chose and reads the gap out loud. An agent that has learned, over six months, to be tactful about that gap is not a gentler version of the same thing. It is a broken one.
Which turns the design question around. Not what should an assistant remember. What should it be structurally unable to learn.
A record, not a notebook
Start with the storage, because the fence at the end depends on it.
Instead of one file, Daiven keeps separate kinds of record, each with its own shape: who you are, what you value, how you behave, what you believe, the principles you hold, the habits you keep, the goals you are working toward, the decisions you have made, and the events worth remembering. A value is not stored the way a habit is. A decision carries the reasoning behind it and a date to revisit it. A passing memory needs neither.
The difference is a shoebox of receipts versus bookkeeping. Same information. Only one of them can answer a question.
Because each record has a shape, the system can sort, filter, link, retire, and choose between them. A text file can only be read from the top.
Nothing gets written twice if it can be helped, either. Before a new memory is stored, a fast similarity check looks for close existing entries, and when something looks close enough, a helper agent makes the call: genuinely new, an exact repeat, or a variation that belongs inside an entry that already exists. In an append-only file, the twentieth restatement of the same fact is simply the twentieth line.
The hard part is forgetting well
Every memory product advertises what it remembers. Almost none of them describe what they retire, which is the harder problem and the one that decides whether the record is still legible in a year.
A daily background pass does three things. Conversations that have gone quiet are summarized and archived, so the substance survives without the entire transcript staying in play. Entries about the same topic that are more than two weeks old are consolidated — merged into one comprehensive entry, under instructions to preserve every unique detail while collapsing the repetition. The originals are archived rather than deleted, and their links to other records carry across to the merged entry.
Learned preferences expire on their own. One that has not been reinforced in roughly three months retires, on the reasoning that a preference nobody has restated in a season is a guess about a person who no longer exists.
One rule sits around all of it: consolidation never runs while you are in an active session. The system does not rewrite its picture of you while you are mid-conversation with it.
Worth being plain about the trade. A curated record is not a complete one. Things get merged, condensed, and retired on purpose, and that is the design rather than a limitation to work around. An archive that keeps everything is just a larger shoebox.
When there is too much to read, it condenses
Every model has a hard ceiling on how much it can take in at once. Sooner or later, any profile worth having runs into it.
Daiven measures what it is about to send against that ceiling. If it is over, sections step down a level rather than getting cut. Full text becomes a written summary. Where no summary exists yet, the section is replaced with a short note saying that it exists and can be requested. If an agent hits that note and genuinely needs the detail, it asks on the next turn and receives it, provided its access allows.
What it never does is stop a section halfway. A summary is a smaller coherent picture. A truncated record is a fragment the agent cannot tell is a fragment, and an agent that does not know something is missing will answer confidently from half a record.
Most systems degrade by losing whatever happened to fall off the edge. This one degrades by summarizing, deliberately, and by telling the agent what it is not currently holding.
Need-to-know, applied to AI
Daiven is nine agents, and one of them decides which one you need.
Each reads only the part of your profile its job requires. Section by section, an agent sees the whole thing, sees a condensed summary of it, or does not see it at all.
The Sentinel, whose work is examining a message for manipulation, reads your behavioral patterns and your memory in full, because that is the raw material of the analysis. The agent that meets you during onboarding sees almost nothing, having no reason to. The intake agent that routes your session sees summaries: enough to route correctly, not enough to be a liability.
The Confidant is the clearest case. It holds no tools at all, and nothing said to it is written to history.
None of this is a preference panel. Access is decided before the conversation starts, and an agent cannot request a section it was never granted. It is also not user-configurable, and that is the point — what each of the nine can and cannot see is a property of the product, identical for every account. In most systems, "the AI knows everything about me" is one undifferentiated fact. Here, knowing is scoped to purpose, which is the same principle that governs sensitive information everywhere else.
You see what gets written about you
When an agent proposes adding something to your profile, it arrives as a confirmation card: each proposed change, in plain language, for you to accept or dismiss. Deletions never get the one-click treatment. Removing something always goes through explicit confirmation.
Before that card reaches you, a separate verification pass reviews what the agent proposed. Be clear about what that is. It is another model, with its constraints enforced in code rather than requested in a prompt, on the working assumption that a model politely asked not to invent things will sometimes invent things anyway. It is not a person, and nobody at Daiven reads your profile writes. The human in the loop is you, at the card.
That pass can only correct a proposed write or add context to it. It cannot quietly remove one. Whatever an agent wanted to record about you reaches you, including the times the verification disagrees with it.
Memories also carry where they came from. An entry holds the conversations that produced it, so when an agent surfaces something it remembers, that can be resolved back to a real, nameable conversation you can open and read. If one of those has since been deleted, the system says so rather than dropping it silently. A partial record that looks complete is worse than a partial record that admits it.
On storage: sensitive profile fields are encrypted individually, with each user's data cryptographically bound to its exact location, so a value cannot be lifted from one place and made to read as valid somewhere else. Routine background maintenance is written to touch only the unencrypted scheduling fields where it can, so ordinary upkeep does not need to decrypt anyone's contents. That is field-level encryption of profile data. It is one control among several rather than a blanket security promise, and presenting it as more than that would be the kind of claim this product exists to catch.
What Daiven cannot learn about you
Daiven does adapt to you. The list of ways is closed.
Seven dimensions: how long its answers run, how fast they move, how they are structured, what vocabulary they use, how much it re-explains, how many worked examples it gives, and how it opens a session.
Read that list again for what is absent. Stance. Challenge intensity. Validation. Which topics it will steer away from. What it records about you. None of these are dials a learned preference can reach, because none of them are members of the set. There is no code path that accepts one.
That structure is doing something a rule could not. Suppose the protection were a filter, or a model asked case by case whether a proposed adjustment was acceptable. It would fail, because every individual case would pass. A request to be a little less blunt is reasonable. So is the next one. Nothing ever arrives looking like the thing you are trying to prevent, which is exactly why judgment is the wrong instrument for it and membership is the right one.
All seven permitted dimensions change how an agent speaks. None of them can change what it is willing to say.
So the answer you did not want stays available for as long as you keep the account. You can teach Daiven to be brief with you. You cannot teach it to go easy on you.
The agent you build yourself
There is one place where you do control access directly. Top-tier users can build an agent of their own, defining its job and choosing which parts of the profile it may read. That is real control, and it is worth stating plainly.
It is not a tenth agent. It sits in a sandbox alongside the system rather than inside it. The nine do not know it exists; it is absent from the shared roster they all read. None of them proposes a handoff to it, the intake agent cannot route to it, and it is excluded from the routing record, so a stretch of conversations with your own agent does not register as a pattern the system reasons about. Its definition, which you wrote, is loaded as explicitly untrusted and subordinate to the platform's rules. It can shape a voice and a focus. It cannot override a platform rule, grant itself data it was not given, or stop being a Daiven agent. Whatever you grant it at creation binds it afterward.
The nine are designed. The one you build is yours. The sandbox is what lets both of those be true at once, without the second quietly weakening the first.
The common pattern, and this one
| The common pattern | Daiven | |
|---|---|---|
| Storage | One growing notes file | Separate kinds of record, each with its own structure |
| Growth | Append forever | Consolidated on a schedule; originals archived, not deleted |
| Duplicates | Accumulate | Caught before writing: skipped or merged |
| Access | Everything, to everything | Per agent: full, summary, or none |
| Overflow | Truncate mid-file | Condense to a summary, then to a note that the section exists |
| Oversight | Written unsupervised | Every write proposed for your confirmation |
| Provenance | A date stamp | The conversations the memory came from |
| Adaptation | Learns whatever it observes | A closed set of delivery dimensions; cannot learn to go easy on you |
| Expiry | Nothing expires | Unreinforced preferences retire on their own |
What each agent is for, and what each will not do, is on the agents page.
What to ask of anything that remembers you
Most of the memory conversation is about capacity. How much, how far back, how reliably recalled. That axis is going to keep improving whether or not anyone thinks carefully about it.
The axis that does not improve on its own is what the memory is permitted to do to the thing holding it. A system that learns from your reactions, with no fence around what it can learn from them, becomes more agreeable over time. Not because anyone chose that. Because nobody chose against it.
So the useful question about an assistant that remembers you is not how much it knows. It is what it cannot learn, and whether anyone decided that on purpose.
See the nine agents, or read why staying aligned is harder than it sounds.

Written by
Przemek Czerpiński
Founder & Developer
Przemek Czerpiński founded Daiven and built it himself. He's been building LLM products since 2024 — most recently multi-agent systems designed to adapt to people without flattering them. He studies AI behavior directly, testing it extensively in the roles people hand it: assistant, therapist, companion, advisor. Before that he spent over a decade in consumer products, where engagement was the metric. That's what Daiven is built against. More about him and about Daiven.
Now check it against your own decisions.
Daiven measures what you do against the values, principles, and goals you've already written down — not the tone of your last message.
Start free trial