Your personal agent.
Inside your Claude. Claude, ChatGPT or Codex.

Proactive like OpenClaw. Free, secure, and running on the subscription you already pay for. No server, no API key.

Cornelius, a bone-white vinyl elephant figurine with cobalt ears and a gold bell, waving like a lucky cat in front of its box
Runs inside Claude Desktop ChatGPT Desktop Codex

Meet Cornelius, in two minutes

An autonomous agent like OpenClaw, but 100% free, secure, and living inside the Claude or ChatGPT you already pay for. One short film.

The Cornelius packaging box: bone white with a cobalt line drawing of the elephant and a cobalt band

What's in the box

One remote connector. Everything an OpenClaw-style agent needs to be yours, minus the parts that made people nervous.

  • A memory you can read

    A graph of Markdown files: people, projects, orgs, topics. Every claim cites the event it came from.

  • A persona that travels

    You name it once. Same name, same manners, same knowledge of you on every platform you connect.

  • Skills it already knows

    A small curated library: meeting prep, inbox triage, follow-up tracking, weekly review. Read-only, no marketplace.

  • A morning that runs itself

    Your platform's scheduler wakes it before you. It reads your day and writes the brief.

The OpenClaw idea, without the OpenClaw risk

Hundreds of thousands of people wanted an agent with a name, a memory and a morning routine. Then the exposure reports came out. Cornelius keeps the first half.

Kept

  • Markdown memory files you can open in any editor
  • A named persona with its own personality file
  • SKILL.md skills, agentskills-compatible
  • Heartbeat-style proactivity, every morning

Removed

  • A local gateway listening on 0.0.0.0
  • Provider API keys sitting in a plaintext .env
  • Unsandboxed shell and browser execution
  • A skills marketplace that can leak credentials

Honest note: OpenClaw is more capable than Cornelius will ever be. It runs shell commands and drives a browser. If you can secure a server, run it. If you would rather not, this is for you.

It wakes up before you do

Every morning your platform's scheduler runs the cycle. Cornelius reads your inbox and calendar through your own connectors and writes the brief before you sit down.

  • Meeting briefs for today's calls, with what you promised last time
  • Draft replies waiting in your own Gmail drafts, never sent for you
  • Routines composed by you: standups, dossiers, topic monitors, weekly review
CorneliusMorning brief, Tuesday 07:00

Good morning, Maya. Three things matter today:

  1. The Danone workshop moved to Thursday 14:00. I updated the project note and your prep list.
  2. Teva still has not answered the proposal after 9 days. A short nudge is in your Gmail drafts.
  3. 11:30 with Noa Feldman. Last time you promised her the pricing sheet; it is linked from the calendar event.

Nothing else in the inbox needs you before noon.

Skipped topic-monitor: no sources connected yet.
Was this brief useful? Yes Not really

A memory you can open in a text editor

Two layers. An immutable log of what actually happened, and a Markdown overlay of what the agent currently thinks. Every version kept, every claim traceable, the whole thing exportable as a zip.

  • Wiki-links between people, projects, orgs and topics; the server derives the graph.
  • Superseded facts stay visible, struck through, with the event that replaced them.
  • Export everything from the dashboard. Only you can delete, and the agent has no tool for it.

Secure by construction, not by promise

The parts of OpenClaw that leaked were removed by design, not patched. Four things Cornelius structurally cannot do.

Close-up of the Cornelius figurine's cobalt collar and gold bell

No inference on our side

We store and serve text. All interpretation happens on your platform. There is no model of ours to poison and no prompt of yours that we run.

No API keys, no credentials

Gmail and Calendar run through your platform's own connectors. We never hold a token, so there is nothing on our side to leak.

The agent cannot delete

Seven tools: six read, one write, zero delete. Every write is versioned and reversible. Only you delete, from the dashboard, with email confirmation.

Every write is auditable

Provenance and trust tags on every event, an injection-pattern scan on every commit. Suspicious spans are flagged, never silently absorbed.

Memory poisoning is reduced, not eliminated. We would rather say so than overclaim.

Set up in four steps, under ten minutes

Nothing to install, nothing to host. The web wizard holds your hand through each step and shows you when the connection is live.

  1. Sign up

    Get your connector URL and your one-line bootstrap instruction.

  2. Connect

    Add Cornelius as a custom connector on your platform and authorize with OAuth.

  3. Paste one line

    Into your project instructions: a Claude Project, a ChatGPT Project, or Codex's AGENTS.md. That is the whole install; the line is below.

  4. Schedule

    Create the daily task in your platform's scheduler. Cornelius writes the exact prompt for you at the end of setup.

The one line you paste

You are my personal agent, and this project is my Cornelius Project: the place where I talk to you. At the start of every conversation here, call bootstrap() on Cornelius with source: "project" and follow AGENT.md.

Then say hello. Your agent introduces itself, you give it a name, and it asks how you actually work: what a good week looks like, which two to four jobs would change it, when your day starts. From that it plans your connectors and your routines.

How it compares

Four honest alternatives. Each is good at what it does. Cornelius sits in the one slot none of them occupy.

Criterion Cornelius Claude or ChatGPT memory OpenClaw Mem0, Zep and other memory infra
Where it runs Inside Claude Desktop, ChatGPT Desktop or Codex Inside one vendor's product A server or Mac mini you run Your own app's backend
Who pays for inference Nobody extra. You already do. The vendor You, per API token You, per API token
Memory you can read and export Markdown files plus the raw event log No, and quiet rewrites are hard to audit Markdown files Opaque rows, or a paid graph tier
Persona plus a daily routine Named agent, ROUTINES.md No SOUL.md, heartbeat Facts only
Follows you across platforms Same agent on Claude, ChatGPT and Codex Siloed to one vendor Any model, via your API keys Wherever you wire it
Runs shell commands and a browser No, on purpose No Yes, unsandboxed Not applicable

Basic Memory is the closest comparable substrate and its Markdown conventions are excellent; it is a knowledge base, not an agent.

Questions people ask

Is it really free?

The private beta is free and there is no billing anywhere in the product. Our running cost is close to storage, because we never pay for inference. When we do price it, we will price it like a consumer product, not like infrastructure, and beta users will hear first.

Do you read my email?

No. Gmail and Calendar are connected to your platform, not to us. Cornelius only receives the summaries your agent decides to write into memory, tagged with their source and trust level. Full message bodies and attachments are never stored.

What happens if I switch from Claude to ChatGPT or Codex?

Nothing is lost. Connect the same account on the other app and your agent shows up with the same name, the same memory and the same routines.

ChatGPT support is read-first today: the morning brief always works, and writes may ask you for a one-tap confirmation.

Can the agent delete or rewrite my memory?

It cannot delete anything; there is no delete tool. It can update its interpretation files, but every version is kept and every fact cites the event behind it. Only you can delete, from the dashboard.

What about prompt injection?

External content can still reach your memory through your platform's summaries. We reduce the risk rather than pretend it is gone: trust tags on every event, an injection-pattern scan on every write, flagged spans rendered as flagged, and an immutable raw layer so you can always see what actually happened.

Which apps does it work with?

Cornelius works in Claude Cowork, in the desktop app and on the web, and in ChatGPT Desktop and Codex, added as a custom connector. Ordinary Claude chat outside Cowork is not supported, and neither are the mobile apps or Gemini yet. Your memory is the same everywhere, so you can use more than one.

Do I need to run anything?

No server, no Docker, no API key. Sign up, add one connector, paste one line, schedule one task. That is the entire footprint on your side.

Say good morning to your agent

Private beta. Works inside Claude Desktop, ChatGPT Desktop and Codex. Free. Bring your own platform.

The Cornelius figurine sitting at a small laptop, both paws on the keyboard