One remote connector. Everything an OpenClaw-style agent needs to be yours, minus the parts that made people nervous.
A memory that never forgets
A knowledge graph of people, projects, orgs and topics. Hot inside your AI app, cold in a ledger that keeps every detail. Every claim cites the event it came from.
A persona that travels
Same Cornelius, same manners, same knowledge of you on every platform you connect.
Skills it already knows
Meeting prep, inbox triage, follow-up tracking, weekly review. And one prompt grows it into your job search, pipeline or research.
A morning that runs itself
In its first session it sets up its own daily brief and weekly review. Then it wakes before you, reads your day and writes the brief.
The OpenClaw idea, without the OpenClaw risk
Hundreds of thousands of people wanted an agent with a name, a memory and a morning routine. Then the exposure reports came out. Cornelius keeps the first half.
Kept
A Markdown memory graph you can read, over a ledger that never forgets
A named persona with its own personality file
SKILL.md skills, agentskills-compatible
Heartbeat-style proactivity, every morning
Removed
A local gateway listening on 0.0.0.0
Provider API keys sitting in a plaintext .env
Unsandboxed shell and browser execution
A skills marketplace that can leak credentials
Honest note: OpenClaw is more capable than Cornelius will ever be. It runs shell commands and drives a browser. If you can secure a server, run it. If you would rather not, this is for you.
It wakes up before you do
Every morning, on a schedule it set up itself, Cornelius reads your inbox and calendar through your own connectors and writes the brief before you sit down.
Meeting briefs for today's calls, with what you promised last time
Draft replies waiting in your own Gmail drafts, never sent for you
Routines it sets up with you: a daily brief and a weekly review to start, more as it evolves
CorneliusMorning brief, Tuesday 07:00
Good morning, Maya. Three things matter today:
The Danone workshop moved to Thursday 14:00. I updated the project note and your prep list.
Teva still has not answered the proposal after 9 days. A short nudge is in your Gmail drafts.
11:30 with Noa Feldman. Last time you promised her the pricing sheet; it is linked from the calendar event.
Nothing else in the inbox needs you before noon.
Skipped topic-monitor: no sources connected yet.
Was this brief useful? YesNot really
A knowledge graph that never forgets a detail
Everything your agent learns becomes part of a graph: people, projects, organizations and topics, linked to each other and to the moment they were learned. The part you need today stays hot inside Claude or ChatGPT. The rest rests cold on the Cornelius MCP, one question away and never erased.
Hot is the active corner of the graph, already in your AI app, so answers arrive with context instead of a search.
Cold is an append-only ledger under the graph. Every fact points back to the event it came from.
When a fact changes, the old one is superseded, not erased. You can always see what it believed, and why it changed.
Hot · in Claude or ChatGPTCold · on the Cornelius MCP
Cold ledger · 145 earlier entries, all kept
e:146 Yael's budget note
e:147 Start moved to Q4
e:148 Open: who signs?
e:151 Sunday call booked
e:152 Task: cut-down option
Pick a node to see what Cornelius knows about it. Pick a cold one and it is recalled into hot memory. The nodes can be dragged, too.
Secure by construction, not by promise
The parts of OpenClaw that leaked were removed by design, not patched. Four things Cornelius structurally cannot do.
No inference on our side
We store and serve text. All interpretation happens on your platform. There is no model of ours to poison and no prompt of yours that we run.
No API keys, no credentials
Gmail and Calendar run through your platform's own connectors. We never hold a token, so there is nothing on our side to leak.
The agent cannot delete
Seven tools: six read, one write, zero delete. Every write is versioned and reversible. Only you delete, from the dashboard, with email confirmation.
Every write is auditable
Provenance and trust tags on every event, an injection-pattern scan on every commit. Suspicious spans are flagged, never silently absorbed.
Memory poisoning is reduced, not eliminated. We would rather say so than overclaim.
Three steps, a few minutes
Nothing to install, nothing to host, no API keys. Log in at cornelius.bot and the setup page walks you through it.
Add the connector. One click on Add Cornelius to Claude, then confirm in Claude.
Create its project. A new Claude Project, with one line pasted into its instructions.
Set the house rules. One more paste into Claude's settings, so Cornelius listens everywhere but speaks only in its project.
Then open the project in Cowork and say hi. In its first session Cornelius reads your last 30 days, asks you about 30 questions, and sets up its own daily brief and weekly review.
Everyone is building a personal agent. Only one does not send you a bill. Six agents, five simple questions.
Question
Corneliuspersonal agent
DotsOpenAI
OpenClawself-hosted
Hermesself-hosted
MuseMeta
Instinctinvite only
What does it cost?
Free. It runs inside the AI you already pay for
$100 a month, on the Pro plan
Every token, billed to you
Every token, billed to you
You pay with your privacy
You pay with your privacy
Who sees your data?
Only you. An encrypted MCP server, and the access stays with you
Only you, until you tap “Share with OpenAI”
Only you
Only you
Meta. What could go wrong?
Instinct, under a perpetual, irrevocable license
Is it secure?
It sits inside Claude or ChatGPT, with all their guardrails
Fairly. OpenAI's cloud, and approval for sensitive actions
Thousands of exposed servers, and leaked API keys
Your server, your keys, your problem
Meta has a history. Not the good kind
Unknown. They are in no hurry to say
Hard to install?
One connector, two instructions, and you are off
No. It is already in ChatGPT
Easy. Securing it is the hard part
Hard. A server, API keys and an evening in the terminal
Easy. Get the app and go
Easy, if you get an invite
Works where you already work?
Lives inside the Claude or ChatGPT you already work in
Yes, inside ChatGPT
Yes, after a pile of plugins and add-ons
Yes, after a pile of plugins and add-ons
Yes, but it is less suited to work
Reads your email, but lives only in WhatsApp
Elephants remember everything. Cornelius remembers for you, not for someone else. Accurate as of October 2026.
Questions people ask
Is it really free?
The private beta is free and there is no billing anywhere in the product. Our running cost is close to storage, because we never pay for inference. When we do price it, we will price it like a consumer product, not like infrastructure, and beta users will hear first.
Do you read my email?
No. Gmail and Calendar are connected to your platform, not to us. Cornelius only receives the summaries your agent decides to write into memory, tagged with their source and trust level. Full message bodies and attachments are never stored.
What happens if I switch from Claude to ChatGPT or Codex?
Nothing is lost. Connect the same account on the other app and your agent shows up with the same name, the same memory and the same routines.
ChatGPT support is read-first today: the morning brief always works, and writes may ask you for a one-tap confirmation.
Can the agent delete or rewrite my memory?
It cannot delete anything; there is no delete tool. It can update its interpretation files, but every version is kept and every fact cites the event behind it. Only you can delete, from the dashboard.
What about prompt injection?
External content can still reach your memory through your platform's summaries. We reduce the risk rather than pretend it is gone: trust tags on every event, an injection-pattern scan on every write, flagged spans rendered as flagged, and an immutable raw layer so you can always see what actually happened.
Which apps does it work with?
Cornelius works in Claude Cowork, in the desktop app and on the web, and in ChatGPT Desktop and Codex, added as a custom connector. Ordinary Claude chat outside Cowork is not supported, and neither are the mobile apps or Gemini yet. Your memory is the same everywhere, so you can use more than one.
My company uses Claude Team or Enterprise. How do I get access?
On those plans only an Owner can add a custom connector, so your admin adds Cornelius once for the whole organization. It takes about two minutes and needs no API key or client secret. Then you connect with your own Cornelius account, and nobody else in the organization can see your memory.
The admin kit has a ready message to send them, the exact settings, and the security answers IT will ask for.
Cornelius already works for me. How do I make it do more?
Evolve it. Cornelius starts as a morning brief and a memory, and one setup prompt grows it into the tool your work needs: a job search, a deal pipeline, project management, research and more. Paste the prompt into a chat with your agent. It reads what it already knows about you, asks up to 7 questions, then adds the connectors, the things to track and the routines that job needs, and keeps them from then on.
See the 8 evolutions and copy the setup prompt that fits. You can also ask for a mix.
Do I need to run anything?
No server, no Docker, no API key. Log in at cornelius.bot, add one connector, paste two instructions, and say hi in Cowork. Cornelius sets up its own daily brief and weekly review from there.
Say good morning to your agent
Private beta. Works inside Claude Cowork, ChatGPT Desktop and Codex. Free, on the subscription you already pay for.