What we can and cannot see, and why the architecture, not our word, is the answer.

Before you hand over twenty years of email, the reasonable question is what Mandaire can actually do with it. The honest answer is less than you might assume.

What is true today. What is being built.

Your data lives on a dedicated server, isolated to your account and not shared with any other user. It is never used to train any model. Two things are true about it right now: only you can access it through Mandaire, and no one on the Mandaire team can read it through any normal operational channel (no admin panel, no support tool, no bulk access path).

We are building toward a stronger guarantee: zero-knowledge cryptographic primitives that will make it architecturally impossible for anyone, including us, to read your data even under legal compulsion. The goal is the same guarantee Signal has for your messages: a government request or hosting breach produces encrypted data the requester cannot read, because we do not hold the key. That architecture is under active development and not yet complete. We will update this page when it ships and what ships.

The LLM that reasons over your context is the one you bring: Claude Max, ChatGPT Plus, Gemini. Mandaire holds the context; the inference runs on your existing subscription. Neither sees more than the specific context needed for the specific question. No bulk archive is sent to any provider.

If Mandaire shuts down, you get your data back. Full export in portable formats. Mandaire is built on widely-audited open-source components and the architecture is fully documented. No lock-in is an architectural commitment, not a preference.

The honest list of what works today, what is next, and what requires your reach.

A page that publishes a failure admission referencing "Signal is not yet a connected source" should also name the full connected-source list so you can decide whether your stack is supported before you onboard. As of this writing:

Source Status Notes
Gmail / Google WorkspaceLIVE20-year backfill supported; live sync via API
iCloud MailLIVEIMAP; live sync
Google Calendar / iCloud CalendarLIVECalDAV; live sync
iMessageLIVERequires a Mac mini on your network (or ours); messages stay local
WhatsAppLIVEVia Matrix bridge; phone QR-scan to connect
iCloud PhotosLIVEFace / GPS / scene indexed; binary content not stored remotely
Contacts (Google + iCloud)LIVECardDAV / People API
ChatGPT / Claude / Gemini conversation historyLIVEDrop the export ZIP; backfill in minutes. Live ChatGPT capture via Chrome extension
TripItLIVEEmail-forwarding ingest + Chrome-extension scrape for past trips
Notes (Apple / Google Keep)LIVERead-only
LinkedIn (people-graph, connections, posts you authored)LIVEVia Chrome extension; rate-limited to respect LinkedIn TOS
SignalNEXTQ3 2026; meanwhile decay flags carry a "Signal-blind" caveat for relationships you message there
Telegram / DiscordNEXTQ3 2026 via Matrix bridges (same pattern as WhatsApp)
Microsoft 365 (Outlook / Teams)NEXTQ4 2026; gated on multi-tenant work-account isolation review
Slack (workspaces you own)NEXTQ4 2026
Notion / Obsidian / JoplinBACKLOGFrequently asked; not yet scheduled. Workaround: export to markdown and drop into the chat-history uploader
Facebook / Instagram messagesBACKLOGVia Matrix bridge (mautrix-meta); waiting for Meta connector maturity

If your stack is mostly LIVE, you can onboard meaningfully in the first week. If your most-load-bearing channel is in NEXT or BACKLOG, tell us when you request access and we will be honest about whether the value lands for you in this beta window or whether you should wait for the relevant connector.

If your stack is supported, the next step is one email.