docs: disclose current self-hosted security and telemetry behavior (#1711)

This commit is contained in:
Dhravya Shah 2026-10-03 21:10:09 -07:00 • committed by GitHub
parent 62cc57eda6
commit 7cc19fa346
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
4 changed files with 9 additions and 10 deletions

View file

@ -336,7 +336,7 @@ const client = new Supermemory({
- **Bring any model** — OpenAI, Anthropic, Gemini, Groq, or any OpenAI-compatible endpoint. An interactive wizard walks you through it on first boot.
- **Embeddings** — local `Xenova/bge-base-en-v1.5` by default (no API key); optionally OpenAI, Gemini, or Ollama. Same provider stack as cloud.
- **Fully offline if you want** — point it at Ollama (`gpt-oss:20b` works great) and nothing leaves your machine.
- **Offline text memories if you want** — point it at Ollama (`gpt-oss:20b` works great), disable telemetry with `SUPERMEMORY_DISABLE_TELEMETRY=1`, and use local text or file inputs after the first embedding-model download. URL ingestion uses a hosted reader service.
- **Your data, one directory** — everything lives in `./.supermemory`, easy to back up or move.
- **Same API as the platform** — prototype locally, ship on the hosted platform by changing `baseURL`.

View file

@ -14,8 +14,11 @@ The installer writes API keys to `~/.supermemory/env`, which is loaded on every
| Variable | Purpose | Default |
|---|---|---|
| `PORT` (or `SUPERMEMORY_PORT`) | HTTP listen port | `6767` |
| `SUPERMEMORY_HOST` | In the next release, controls the listen address; not supported by v0.0.8 | `127.0.0.1` in the next release |
| `SUPERMEMORY_DATA_DIR` | Where the graph engine's data, auth secret, and model cache live | `./.supermemory` |
**The currently published v0.0.8 binds all interfaces and its implicit local authentication is unsafe when exposed to untrusted networks. Do not expose it; restrict access with a firewall or run it on an isolated machine.** The next release will bind loopback and require the generated key for every API request, including requests from localhost. Its browser welcome page will no longer reveal the key; enter the key printed at first boot in the Memory tab. If you later expose that release through a reverse proxy, protect the endpoint with TLS and access controls.
## LLM providers
In production, Supermemory uses its own proprietary models tuned for long-horizon data understanding. Self-hosted, you bring your own LLM for the intelligent steps — summaries, contextual chunking, and memory extraction. Embeddings default to a local model (no API key) and can optionally use OpenAI, Gemini, or Ollama — see [Embeddings](/self-hosting/embeddings). Configure **at least one** LLM provider:
@ -118,11 +121,7 @@ Raise the limit and concurrency on machines with spare RAM for faster bulk impor
## Telemetry
The self-hosted binary sends no analytics — there is nothing to opt out of. The only related switch:
| Variable | Purpose | Default |
|---|---|---|
| `SUPERMEMORY_DISABLE_TELEMETRY` | Set to `1` to also disable internal AI SDK telemetry instrumentation | unset |
Supermemory collects telemetry. You can disable it with `SUPERMEMORY_DISABLE_TELEMETRY=1`.
## Platform-only features

View file

@ -5,7 +5,7 @@ description: "Supermemory local is for builders. Supermemory Enterprise is for o
icon: "/icons/hugeicons/building-03.svg"
---
Supermemory local — the self-hosted binary — is free, open source, and built for individual developers: local-first workflows, prototyping, air-gapped experiments, privacy-sensitive side projects.
Supermemory local — the self-hosted binary — is free within its lite license limit and built for individual developers: local-first workflows, prototyping, and privacy-sensitive side projects. Its server source is not in the public repository. Text-memory processing can run offline after the first embedding-model download; URL ingestion uses a hosted reader service.
**Supermemory Enterprise** is the full platform, run for your organization: the same memory engine with proprietary models, organizational controls, and infrastructure that scales with you — without you operating any of it.

View file

@ -17,7 +17,7 @@ npx supermemory local
```
</CodeGroup>
No Docker. No database to provision. No config files. It boots in seconds with everything built in, and it's [open source](https://git.new/memory).
No Docker. No database to provision. No config files. It boots in seconds with everything built in. The SDKs and other components in the [public repository](https://git.new/memory) are open source; the downloadable self-hosted server binary is built from a separate, non-public codebase.
## Zero config, actually
@ -41,7 +41,7 @@ OPENAI_MODEL=gpt-oss:20b \
supermemory-server
```
Local graph engine, local embeddings, local LLM. Your data never leaves the building.
Local graph engine, local embeddings, local LLM. Text-memory processing can stay on your machine after the embedding model's first download. Supermemory collects telemetry; you can disable it with `SUPERMEMORY_DISABLE_TELEMETRY=1`. URL ingestion uses a hosted reader service; use local text or file inputs for offline operation.
## Drop-in with your existing code
@ -58,7 +58,7 @@ Everything in the [Memory API docs](/quickstart) works the same way. The coding
## Self-hosted vs. the platform
Self-hosted is free, open source, and great for local development, air-gapped environments, and privacy-sensitive workloads. The hosted platform is where the full product lives:
Self-hosted is free within its lite license limit and useful for local development and privacy-sensitive workloads. The server binary is not open source; the hosted platform is where the full product lives:
| | Self-hosted | Platform |
|---|---|---|