Most AI tools ask you to make a quiet trade. You get something useful, and in exchange your data takes a trip to someone else’s computer — to be processed, logged, and, depending on the fine print, retained or reused. For a lot of everyday software that bargain is tolerable. In a consulting room, with a patient in front of you and a medical history on the screen, it is not.

We think there is a better default for the tools clinicians and the public reach for first: useful, free, and completely local. Two of our tools are built exactly this way — MedPodGP for general-practice documentation, and Emu for general- purpose, multi-modal AI. Neither sends your work anywhere. There is no cloud account to create, nothing watching in the background, and no copy of your data sitting on a server you do not control. The tool runs on your machine, and your work stays on your machine.

MedPodGP: documentation that never leaves the room

General practice runs on conversations, and those conversations have to be turned into notes. That second job — the documentation — is where a great deal of a GP’s day quietly disappears. MedPodGP is built to give that time back without asking the consultation to leave the room.

MedPodGP is completely-local ambient-voice GP documentation. It listens to the consultation as it happens and helps the clinician produce the written record, using ambient voice AI to do the listening and the drafting. The defining fact about it is simple and absolute: nothing leaves the computer. The audio is not streamed to a remote service, the transcript is not uploaded for processing, and the draft note is not assembled somewhere out of sight. Everything happens on the device in front of the clinician.

That is not a minor implementation detail; it changes what the tool is allowed to be. An ambient documentation tool that sends audio of a medical consultation to a remote server is handling some of the most sensitive material there is, and every clinician using it has to reason about where that audio goes and who can reach it. A tool that keeps the audio on the local machine removes the question entirely. There is no remote recording to secure because there is no remote recording. The clinician remains the author of the note — drafting and review stay in human hands — and the patient’s voice never travels further than the room they are sitting in.

For a GP, that combination is the point. The documentation gets easier, and the duty of confidentiality that sits at the centre of the relationship is not quietly outsourced to make it so.

Emu: a capable local assistant for everyone

Not everything is a clinical task, and not everyone reaching for an AI tool is a clinician. Emu is our general-purpose assistant, and it follows the same principle: it runs entirely on your own computer.

Emu is cross-platform and multi-modal. It runs on Windows and Linux today, with macOS planned, and it works on the hardware people already have — CPU or GPU, whichever the machine offers. “Multi-modal” is not a buzzword here; it describes the range of things Emu can actually do on-device: generative AI for drafting and summarising, a multi-modal large language model for working across text and other inputs together, voice AI for speech, and computer vision for images. It is meant to be the kind of broad, everyday assistant most people now expect — except that it does its work where you are rather than somewhere you cannot see.

Because Emu is local, it is useful in places a cloud tool struggles to reach. It works without a reliable connection. It does not depend on a remote service staying online, or on that service’s terms staying the same. And whatever you do with it — the documents you draft, the images you look at, the questions you ask — stays on your machine. For members of the public who are understandably wary of where their words and pictures end up, and for clinicians who want a general tool that respects the same boundaries their clinical software does, that local-by- default posture is the whole appeal.

Why “free” and “local” belong together

It is worth being clear about why these tools are free, because “free” software usually has a catch, and the catch is usually the data. The familiar model is to give the tool away and recover the value by collecting what flows through it. These tools are built to make that impossible. With no telemetry and no cloud account, there is nothing to collect; the data never reaches us to begin with.

So the reason we can offer them freely is the same reason they are trustworthy: they do not run on a stream of your information. The cost of running the tool falls where the tool runs — on the device — rather than on a service that has to be paid for by watching you. Free and local-first are not two separate generosities here. They are the same decision, seen from two sides.

This matters beyond any single clinician. Good clinical tools should be accessible, and accessibility should not require surrendering privacy as the entry fee. A junior doctor, a rural GP, a curious member of the public — none of them should have to choose between a capable tool and keeping their information to themselves. Making the genuinely useful version free, and making it local, is how we try to close that gap.

What “private by design” actually means

“Private by design” gets said a lot, so it is worth saying precisely what it means for these tools. It does not mean we have a strong privacy policy, careful access controls, and good intentions about the data we hold. It means we do not hold the data at all.

There is no account quietly linking your activity to your name. There is no telemetry measuring what you do so it can be analysed later. There is no copy of your consultation, your documents, or your questions sitting on a server waiting to be protected — and a copy that does not exist cannot be leaked, sold, or demanded. Privacy stops being a promise you are asked to trust and becomes a property of where the software runs. You can verify it by the simple fact that nothing left.

Try them, and keep your data

MedPodGP and Emu are our way of showing what we think good tools should look like: genuinely helpful, free to use, and built so that your work stays yours. The clinician keeps authorship and judgement; the public keeps its privacy; and in both cases the data never has to leave the device to make the tool worthwhile.

If you want to see what local-first AI feels like in practice — for documenting a consultation, or just for the everyday work an assistant can take off your plate — these are a good place to start. They are useful on their own terms, and they ask nothing of you in return except that you let them run where you already are.