My AIfa
All of this is personally yours
The cabinet is not a pricing display. It is a workplace with eight sections, and nearly every one of them shows something that belongs to you alone: chats that saved themselves without a single click, a passport you can write into Arweave forever, a level grown out of your own conversations, and a referral grid that names the exact amount your tier cost you. One login covers every site in the ecosystem.
Memory, keys, export and deletion
The longest part of the cabinet, and the only one where a mistake is expensive.
The cabinet reads your memory for you
Decryption used to require an act of will: type the password your memory was encrypted with, or sign a message with your wallet, and only then would the files become readable. The scheme was honest and inconvenient at exactly the wrong moment — when you are on a borrowed laptop with no wallet extension in sight.
Now it is simpler. You sign in, and the Memory section is already showing your dialogues. No encryption password, no browser extension, no file shuffling. Older archives encrypted with a wallet key are detected automatically, with a one-time migration button; after that they read without a wallet too.
Dialogues are separated by source — Terminal, Oracle, main chat — and grouped by date inside each. The newest session is expanded, previous ones are folded. That is not decoration: a year of conversation becomes an unnavigable wall of text unless it folds.
Three layers, not one folder
In the PADAM architecture memory is split across three layers, because their jobs and their lifespans are opposites. The operational layer (Redis or Vercel KV) holds the context of the current conversation and lives exactly as long as the conversation does. The semantic layer (pgvector on Neon) stores compressed meaning rather than verbatim lines, so similar situations can be found later. The eternal layer (Arweave plus a Solana cNFT) is an immutable backup that depends on no single company.
In the cabinet you see the second and third layers. The Memory section is what is remembered and used. The Eternal archives block is what has already been written to the chain and will outlive the server, the company, and — with luck — all of us.
The split explains why memory never becomes an infinite feed. What grows is not the volume of text but the density of understanding. A year-old transcript is dead weight; the conclusion folded out of it is useful the next time the same fork appears.
Eternal archives: what a stranger sees
Each entry in the Eternal archives block is its own Arweave transaction with a date and a size. Two buttons sit next to it, and they do fundamentally different things. The ARWEAVE link opens the file the way any person on the internet sees it: a run of bytes with not one readable word. That is not a bug and not a placeholder — that is the protection, demonstrated live.
The Read button decrypts the very same file with your key and unfolds the conversation inside the cabinet, turn by turn, timestamped, with you and AIfa visually separated. One address, two outcomes: that gap is the whole difference between data being stored and data being yours.
The copy travels to the chain on its own: once an hour, or immediately the moment a dialogue file crosses 90 KB. There is deliberately no Save button. Memory that depends on your discipline is not memory but a habit, and the first hard week breaks it.
Export: taking your own away
This is the question people ask first, so here is the blunt answer: there is no single Download everything as one archive button in the cabinet today. There are two working paths instead. The first is to open a record with Read and copy the unfolded text — it is rendered in full, as plain text, with nothing blocking selection.
The second is to take the file itself through the ARWEAVE link. That is your ciphertext sitting in a public network: download it, put it on your own drive, copy it to a stick, keep it anywhere you like. It decrypts with your key, so holding a copy gives a stranger nothing — and gives you everything.
We will not promise one-click export before it exists in the interface. Promises in the privacy section cost more than anywhere else on a site, because these are the ones people check.
A PIN, and deletion on a 72-hour delay
At the very bottom of the Memory section sits a block called Protection and deletion, framed in red because the button inside it is irreversible. First you can set a PIN of four to eight digits. It does not replace your password; it has a different job — keeping a passer-by away from the delete button on your unlocked laptop.
That button removes both memory and account, but not instantly. The request is queued for 72 hours and a cancellation email goes out immediately. The delay exists against exactly one scenario: a decision made at three in the morning that will be regretted by breakfast.
If a PIN is set, the cabinet asks for it before queuing anything. If it is not, you get a confirmation that states in plain words what will happen and how long you have to change your mind. No fine print: deletion deserves the same clarity as saving.
Data is yours not when a policy says so, but when you can open it yourself and watch a stranger fail to.
— From the cabinet design principles
The referral grid and the tier-matching rule
The section support hears about most. Taken apart piece by piece.
What the Ambassadors section shows
Two numbers at the top: how many people came through your link and how many dollars sit on your balance. Below them, three cards for the three grid levels — 15 % on level one, 7 % on level two, 3 % on level three. Each card carries a head count and an amount, so you can see which level is alive and which one stalled.
Then the link itself. It is assembled from the address of whichever site you are on: one cabinet serves several domains, and an invitation should land your friend where the two of you were actually talking. One click copies it.
Below that comes the downline: each person's email, their level in the grid, their tier. The list is paginated, because for an active ambassador it stops fitting on one screen very quickly.
The tier-matching rule
Referral income is calculated from your tier, not from your invitee's. If you are on Spark at $15 a month and the person who used your link bought Family Archive at $100 a month, you are credited fifteen percent of $15, not of $100. The difference does not vanish quietly — it is shown on its own line.
The rule looks strict until you consider the alternative. Without it the winning move would be to buy the cheapest plan and harvest percentages from other people's expensive purchases while putting nothing into the ecosystem. Tier matching inverts that: you earn the full rate exactly in the zone you occupy yourself.
It cuts both ways. From an invitee on a lower tier than yours you take the full percentage of their purchase — the ceiling only appears where the invitee climbed above you.
Lost opportunity is a counter, not a penalty
When invitees buy tiers above yours, a warning appears with the exact figure: this many dollars went past you. Nothing was deducted, nothing is owed. It is an answer to the question support would otherwise receive: how much am I actually losing?
The number is built from real purchases in your grid, not from a forecast. That is why for one person it stays at zero for years while for another it clears the cost of an upgrade within a month. Numbers lie less often than persuasion does, and we would rather have the upgrade conversation in numbers.
Moving up unlocks the full rate on subsequent payments from your grid. Nothing is recalculated retroactively — what was lost stays lost, and we do not pretend otherwise.
Payouts: USDT on TRC20
Withdrawal is requested inside the cabinet. You paste a USDT address on the TRC20 network and the field validates the format on the spot — the address starts with T and has a fixed length. A typo in a crypto address is the most expensive mistake on this page, so the check happens before sending rather than after.
The request is then processed by hand. We say so openly instead of burying it in a footnote: a person looks at the payout before it goes out. Slower than an automated pipe, and steadier.
Payouts go to active participants: your tier must be at least the tier of the purchase the percentage comes from. Same matching rule, seen from the other side.
Where the percentages come from
On-chain memory transactions are divided by a fixed split: 5 % to the Founder's Fund, 5 % burned, 15 % to referral level one, 7 % to level two, 3 % to level three, and 65 % to the treasury, which buys AR to pay for permanent Arweave storage.
If a level has no referral on it, that share is not kept and not pushed upward — it goes to the burn. $GALATIN is issued on Solana with a hard cap of 10,000,000,000, so every empty level makes the remaining supply a little scarcer.
Partner companies in the Ambassador Team program get more on top: a fiat channel paying 7 / 3 / 1 % across the three levels, and a $GALATIN buy-back channel paying 8 / 4 / 2 %. In the second case the platform buys the token on the open market for the amount of the reward.
A button you cannot press by accident and a button you never regret are two different buttons. The second one waits three days.
— On the deletion delay