Research · Personal assistant context

Knowledge in personal assistant context

The hard part at human scale: a personal assistant that knows your emails, calendar, messages, and habits raises privacy, control, and legal questions under regimes such as the DPDP Act in India and the GDPR in Europe. Memory is useful. Memory without control is a liability.

Back to home · Research · Standards · Adoption

Direct answer

What is the personal-knowledge problem?

A personal assistant is only useful if it knows you — your emails, your calendar, your messages, your habits, your preferences, your history. The moment it does, the questions become: who else can see that knowledge, who controls it, how long it lasts, and what legal regime it falls under. Memory across short, medium, and long term is useful. Memory without control and compliance is a liability.

The personal shift

The shift from enterprise knowledge to personal knowledge is not a change of scale. It is a change of stakes. Enterprise knowledge is about assembly and governance — the knowledge is in the building and the problem is to assemble and govern it. Personal knowledge is about control and trust — the knowledge is about one person, and the problem is to make the assistant useful without making it a liability.

The personal assistant is the most intimate knowledge layer an agent can hold. It is also the one where the cost of wrong knowledge is most personal — not operational, not financial in the company sense, but private, embarrassing, and sometimes legal. A personal assistant that acts on the wrong knowledge is not just wrong; it is wrong about you, in a way that touches the things you did not want it to touch.

This is why the personal-knowledge problem is its own thing, and not just the enterprise problem with fewer people.

What personal assistants know

What a personal assistant knows — and what it means for the knowledge layer
Thing What it is What it means for the knowledge layer
Emails The messages you send and receive — the commitments, the plans, the personal things, the things you would rather not have summarized in a sentence someone else can read. The assistant must know enough to be useful — the current commitment, the next step, the thing that needs a reply — without becoming a system that re-surfaces the private things at the wrong moment. The boundary between "the assistant can see it" and "the assistant can act on it" is the boundary that matters most here.
Calendar The meetings, the appointments, the gaps, the things you have committed to and the things you have not. The structure of your time. The assistant must know what is current — which meeting is still on, which one was moved, which one was cancelled — and must know what it is allowed to do with that knowledge. A calendar is useful; a calendar that the assistant acts on without knowing whether the meeting is still on is a source of embarrassment and wasted time.
Messages The chats, the DMs, the things said in private channels. The knowledge that is the most useful and the most sensitive — the thing you would tell a friend and would not want the assistant to repeat. The assistant must be able to use the useful part of the message — the plan, the date, the commitment — without becoming a system that can repeat the private part at the wrong moment. This is the hardest boundary to get right, because the useful part and the private part are often in the same message.
Habits The patterns — when you work, when you rest, what you prefer, the things you do without thinking about them. The knowledge that makes the assistant feel like it knows you. Habits are the knowledge that makes the assistant useful over time. They are also the knowledge that makes it feel intrusive if it acts on them in the wrong way, at the wrong moment, or in front of the wrong person. The knowledge must be there, and it must be under your control.
History The long memory — what happened last month, last year, the thing you did and the thing you decided and the thing you changed your mind about. The knowledge that makes the assistant more useful the longer you use it. Long memory is the most valuable knowledge and the hardest to govern. It is the knowledge that accumulates trust over time — and the knowledge that accumulates risk over time, if it is not controlled, if it is not possible to forget, if it is not possible to say "this no longer applies."

The three memory levels

A useful personal assistant has memory at three levels, and each level has its own knowledge question.

Short term

What is happening now

The current turn, the current message, the current meeting, the thing the assistant is acting on right now. Short-term memory is the easiest to get right and the easiest to get wrong — because if the assistant does not remember what it just saw, it is not a useful assistant, and if it remembers the wrong thing, it is an embarrassing one.

Medium term

What has happened recently

The last few days, the last few weeks, the thread of what is going on. Medium-term memory is the knowledge that makes the assistant feel like it is keeping up — the thing you mentioned last week is still in mind this week. The knowledge question here is currentness: which of these is still true, which has changed, which has ended.

Long term

What you are like

The habits, the preferences, the history, the things that do not change often and that make the assistant more useful the longer you use it. Long-term memory is the most valuable knowledge and the hardest to govern — because it is the knowledge that accumulates over time, and the knowledge that is hardest to forget, to correct, to say "this no longer applies."

Privacy, control, and compliance

The personal-knowledge problem is not only a technical problem. It is also a legal and ethical one, and the legal regime depends on where the person is and where the knowledge goes.

  • DPDP Act, India. The Digital Personal Data Protection Act governs personal data in India. A personal assistant that knows your emails, calendar, messages, and habits is handling personal data — and the questions of consent, purpose, storage, and deletion are real ones, not abstractions.
  • GDPR, Europe. The General Data Protection Regulation governs personal data in the EU. The same questions — consent, purpose, storage, deletion, the right to be forgotten — are real ones, and the threshold is higher.
  • The rest. Other regimes apply in other places. The point is not the list. The point is that a personal assistant that knows you is handling personal data, and the legal questions are real ones, not things to solve after the assistant is built.

The technical side and the legal side are not separate. They are the same problem, seen from two angles: how do you make the assistant useful without making it a liability. The answer is the same in both: control. The knowledge must be under the person's control — what it knows, how long it keeps it, who else can see it, when it forgets, and how the person can tell it to forget.

Control

Control is the discipline that makes personal knowledge useful. Without control, the knowledge is a liability, and the assistant is a risk, not a help. With control, the knowledge is a help, and the assistant is a sidekick — something that knows you and works for you, not something that knows you and works for someone else.

The controls that matter are the ordinary ones, done well:

  • What it knows. The person must be able to tell what the assistant knows about them — not in a forensic dump, but in a form they can understand and act on.
  • How long it keeps it. The person must be able to tell how long the assistant keeps each thing — the short-term thing, the medium-term thing, the long-term thing — and must be able to shorten that time.
  • Who else can see it. The person must be able to tell who else can see the knowledge — which is the most important control and the one that is most often missing.
  • When it forgets. The person must be able to tell the assistant to forget — a thing, a period, a subject — and the assistant must actually forget, not just bury it.
  • How to correct it. The person must be able to correct the knowledge — this is not my habit, this meeting is still on, this is not what I said — and the correction must stick, not be worn down by the next re-read.

These are not exotic controls. They are the ordinary controls, done well, in a system that is designed for them from the start, not bolted on when the person asks.

Where to start

If you are building a personal assistant and you are wondering how to handle the knowledge layer, the usual sequence is:

  • Pick one thing the assistant will know — one email stream, one calendar, one message thread — and design the knowledge layer for that thing before you add the next.
  • Put control on that knowledge from the start — what it knows, how long it keeps it, who else can see it, when it forgets, how to correct it. Not as a feature to add later. As a property of the knowledge, from the start.
  • Make the boundary between "can see" and "can act on" explicit for that knowledge. The assistant can see the message to extract the plan; it cannot act on the private part at the wrong moment.
  • Make the basis retrievable for the actions the assistant takes — what it used, whether it was current, whether it was permitted. Grounding is the same discipline here as anywhere else, and the stakes are more personal.

The goal is not a perfect memory. The goal is a useful one — one that knows you, works for you, and is under your control, in a way that survives the person who built it.

FAQ

It is both. The product decision is what the assistant does. The knowledge decision is what it knows, how long it keeps it, who else can see it, and how it forgets. The two are not separable, because the product cannot deliver on its promise without the knowledge, and the knowledge cannot be useful without the control. The knowledge layer is where the product promise meets the privacy risk.

On-device and local models change the control picture — less data leaves the device, more control stays with the person. That is a real improvement, and it is not the whole story. The assistant still needs to know the right thing, in the right shape, at the right moment, with the right controls. On-device is one way to improve the control side; it does not replace the knowledge discipline.

The enterprise page is about assembly and governance — the knowledge is in the building, and the problem is to assemble and govern it. The personal page is about control and trust — the knowledge is about one person, and the problem is to make the assistant useful without making it a liability. The disciplines overlap — currentness, ownership, deprecation, grounding — but the stakes and the legal regime are different, and the controls that matter are different.

About the author

Knowledge Sidekick is written by Janardan Revuru. Background relevant to this topic: M.Tech in Data Science (BITS Pilani, 2024); PhD in progress on multi-agent communication (expected around 2028); three patents; an AI Centre of Excellence built and scaled from zero to roughly 50 engineers and 15 models; and organizer of the Bengaluru JavaScript Meetup.

Full engineering portfolio: janalogy.com · Email: janardan.revuru@gmail.com · LinkedIn