# Open-source personal assistants: comparison

> Self-hostable AI assistants that act on your mail, calendar, docs and chat on your behalf.

Canonical page: https://llms-technical-reviews.com/compare/personal-assistants/

## How is the assistant architected?

The main split is where the agent loop lives: in a long-running gateway process, behind a durable job queue, or in a fixed request pipeline. [Waku](/p/waku-agent/) is the clearest loop to read. [QM](/p/qm/) and [Rakazo](/p/rakazo/) are the most robust when workers crash.

**One always-on process that owns its loop.** [OpenClaw](/p/openclaw/) runs a Gateway on port 18789. Channel plugins feed an embedded runner whose `runLoop` starts tool calls while the stream is still arriving and injects mid-run "steering" messages. [Hermes Agent](/p/hermes-agent/) puts one `AIAgent`, built from 14 mixins, behind its CLI, gateway and API. Tool rounds persist the assistant message before they execute anything. [Agenvoy](/p/agenvoy/) is a Go daemon bound to `127.0.0.1`. A dispatcher LLM picks the model, then `Execute` runs up to 256 rounds. [Leon](/p/leon/) routes Socket.IO utterances to an agent loop or to legacy skills. Each tool runs in its own worker process, and a reviewer call checks that the task is complete. [Waku](/p/waku-agent/) is the small, synchronous version: a 209-line `run_loop` in the Anthropic message shape.

**Durable runs.** [QM](/p/qm/) stores turns as Postgres `runs`, claimed with `FOR UPDATE SKIP LOCKED` and kept in order per thread. It delegates the loop itself to Pi, OpenCode, Codex or Claude Code. [Rakazo](/p/rakazo/) writes a queued run, and a Graphile worker leases it and drives Pi from one 8,000-line executor. [OpenBot](/p/openbot/) runs CopilotKit's runtime, accepts any AG-UI server as a Bot, and sends every computer action through one `ComputerGateway`.

**Pipelines more than loops.** [Khoj](/p/khoj/) makes one LLM call to choose sources, then runs tools in a fixed order. It iterates only in `/research` mode, for up to 5 rounds by default. [Inbox Zero](/p/inbox-zero/) is driven by mail webhooks: static rule conditions run before any model call. Its chat assistant is a separate Vercel AI SDK `ToolLoopAgent`.

Pick: Waku to learn from or fork.
Pick: QM or Rakazo when runs must survive restarts and pause for approval.
Pick: OpenClaw or Hermes Agent for one agent reachable from many surfaces.

Per-project answers: https://llms-technical-reviews.com/personal-assistants/q/architecture/index.md

## How are integrations (email, calendar, chat, docs) implemented?

For email, [Inbox Zero](/p/inbox-zero/) is the only project with deep native Gmail and Outlook clients. To reach the assistant from chat apps, [OpenClaw](/p/openclaw/) and [Hermes Agent](/p/hermes-agent/) cover the most platforms.

**Native mail, calendar and content clients.** [Inbox Zero](/p/inbox-zero/) implements one `EmailProvider` interface for Gmail and Outlook. Pub/Sub or Graph webhooks push new mail, and tokens live in Postgres. MCP servers only add context to drafts. [QM](/p/qm/) stores OAuth tokens in an encrypted keychain for each scope, and the agent mostly uses them from shell commands in its sandbox. The editor confirmed that it also has admin-registered, audited MCP servers and an Inbox loop that rescans Gmail and Slack every 15 minutes. [Leon](/p/leon/) declares Gmail, Notion and TickTick in JSON toolkits, encrypts credentials with AES-256-GCM per profile, and offers a `setup_connection` tool when a call lacks credentials. [Khoj](/p/khoj/) treats Notion (OAuth) and GitHub (token) as content to index, not as services to act on.

**Managed catalogues.** [OpenBot](/p/openbot/) routes Composio, MCP and a Google Drive REST adapter through one `listTools`/`callTool` interface. Its credentials are AES-GCM encrypted and cannot be read back. [Rakazo](/p/rakazo/) stacks Composio, Pipedream Connect, remote MCP and any OpenAPI document. Stdio MCP needs a flag and an allowlist, and tools are discovered when each run starts.

**Chat channels first, MCP for the rest.** [OpenClaw](/p/openclaw/) ships about 28 `ChannelPlugin`s with pairing and group policy. [Hermes Agent](/p/hermes-agent/) reaches about 20 platforms; most adapters are plugins under `plugins/platforms/`, a point the editor corrected. [Agenvoy](/p/agenvoy/) supports only Telegram and Discord and has no first-party mail or calendar tools. MCP tools are named `mcp__<server>__<tool>`, and keys live in the OS keychain. [Waku](/p/waku-agent/) adds Google Calendar OAuth and an MCP OAuth flow on a loopback port. Apple Calendar writes are opt-in.

Pick: Inbox Zero for automated email triage.
Pick: OpenBot or Rakazo for broad SaaS access without writing clients.
Pick: OpenClaw or Hermes Agent to talk to your agent from existing chat apps.

Per-project answers: https://llms-technical-reviews.com/personal-assistants/q/integrations/index.md

## How is memory and user context stored and retrieved?

[Leon](/p/leon/) has the most developed general memory, and [Khoj](/p/khoj/) is best for answering from your own documents. [Waku](/p/waku-agent/) has the cleanest small design. The approaches range from Markdown files placed in the prompt to scored database records.

**Curated Markdown in the prompt.** [Hermes Agent](/p/hermes-agent/) keeps `MEMORY.md` (2,200 characters) and `USER.md` (1,375), frozen at session start to protect the prompt cache. A background review saves new facts every 10 user turns, not after each turn as its answer first said. [QM](/p/qm/) keeps a `MEMORY.md` per scope, with Postgres revisions, and recalls only its last 6,000 characters. The editor confirmed that extraction waits for 3 quiet minutes or 10 turns. There are no embeddings. [OpenClaw](/p/openclaw/) indexes workspace `MEMORY.md` with full-text search plus embeddings (OpenAI by default), and auto-injects only owner- or agent-originated entries.

**Scored records with search.** [Leon](/p/leon/) stores items as `persistent`, `daily` or `discussion`, with importance, expiry and pins. It recalls them with hybrid lexical and vector search, weighted 1.35 for persistent items and 0.65 for discussion. [Khoj](/p/khoj/) extracts facts after every turn into pgvector and recalls the last 7 days plus semantic matches. Users can edit them through `/api/memories`. [Waku](/p/waku-agent/) puts a small-model gate in front of SQLite FTS5 and consolidates every 6 exchanges. [Inbox Zero](/p/inbox-zero/) keeps plain Postgres rows. The editor found that `ReplyMemory`, learned from your edits to drafts, also shapes future replies.

**Session or platform memory.** [Rakazo](/p/rakazo/) keeps versioned Markdown documents and compacts old history into a summary. Semantic recall returns at most 5 items, and only after compaction. [OpenBot](/p/openbot/) injects confirmed personal facts from Postgres, but threads and learned skills live in CopilotKit Intelligence. [Agenvoy](/p/agenvoy/) has no user fact store: only session summaries and tool-error records, and vector search needs an OpenAI key.

Pick: Khoj to search notes and documents.
Pick: Leon or Waku for a personal assistant that learns preferences.
Pick: QM for memory that must stay separate per person and channel.

Per-project answers: https://llms-technical-reviews.com/personal-assistants/q/memory/index.md

## How are actions on the user's behalf gated?

[OpenBot](/p/openbot/) has the strictest gate: no computer action runs before a policy decision and an audit row exist. [QM](/p/qm/) is the strongest choice for a team, and [Agenvoy](/p/agenvoy/) has the most concrete guardrails for one person on a laptop.

**Policy engines in front of every action.** [OpenBot](/p/openbot/) resolves the clicked element from the server's own snapshot, evaluates CEL `deny`/`allow` rules (errors deny, with a `dry-run` mode), then applies approval rules. Credentials, security settings and payments are always handed to the person, and this cannot be configured. [QM](/p/qm/) gives the org a `dangerous`, `auto` or `strict` posture that narrower scopes can only tighten. A regex command floor asks before recursive `rm`, force-push or `DROP TABLE`, and an LLM screen checks tool results for prompt injection.

**Per-tool approval with defaults you must check.** [Rakazo](/p/rakazo/) judges connector tools by name prefix, and unknown names ask. Shell, browser and file tools are exempt, so the sandbox is the boundary. [Hermes Agent](/p/hermes-agent/) blocks hardline patterns and deny globs, sends other dangerous commands to a guardian LLM, and defaults cron runs to `deny`. Its default shell is still the host. [Agenvoy](/p/agenvoy/) asks before side effects, requires the sudo password for paths outside the home directory, runs `run_command` in bubblewrap with no network, and moves `rm` targets to trash. [OpenClaw](/p/openclaw/) has full exec modes, but the editor found the unconfigured default is `security: "full"`, `ask: "off"` with the sandbox off.

**Narrow or no gate.** In [Inbox Zero](/p/inbox-zero/), chat sends, replies and forwards become confirmation cards. The editor found that `manageInbox` (archive, trash, unsubscribe) runs at once, and so do active rules' `REPLY`, `FORWARD` and `DELETE` actions. [Waku](/p/waku-agent/) has no approval step, but `send_message` only writes to a local outbox. [Leon](/p/leon/) relies on prompt rules and allow/deny lists, and its pulse can act every 30 minutes. [Khoj](/p/khoj/) pauses only when its sandboxed operator asks the user.

Pick: OpenBot for audited browser agents in a team.
Pick: QM for shared Slack assistants with per-scope rules.
Pick: Agenvoy or Hermes Agent for a personal machine, after tightening their defaults.

Per-project answers: https://llms-technical-reviews.com/personal-assistants/q/action-safety/index.md

## How are LLM providers selected and configured?

[Hermes Agent](/p/hermes-agent/) supports the most providers. [Inbox Zero](/p/inbox-zero/) and [Khoj](/p/khoj/) have the most useful fallback chains, and [Agenvoy](/p/agenvoy/) is the only one that picks a model for each request on its own.

**Broad catalogues with local models.** [Hermes Agent](/p/hermes-agent/) declares 42 provider overlays, resolves the rest from models.dev, and picks the wire protocol per model: OpenAI chat, Anthropic messages, Codex Responses or Bedrock Converse. [Leon](/p/leon/) lists 13 providers, including local llama.cpp and SGLang. Setup can reuse keys already stored by Codex or Claude Code. [Rakazo](/p/rakazo/) uses Pi with OpenRouter as the default. Users can connect ChatGPT, Claude, Copilot or xAI subscriptions by OAuth, and each bot can pin a model. [OpenClaw](/p/openclaw/) loads providers as plugins and maps `host.docker.internal` in Docker so a container can reach local Ollama or LM Studio.

**Routing and fallback built in.** [Inbox Zero](/p/inbox-zero/) defines model tiers such as `DEFAULT_LLMS` and `NANO_LLMS`. Each is an ordered `provider:model` chain, so later entries are fallbacks, and Ollama works. [Khoj](/p/khoj/) stores models as admin rows of three types. A base URL covers local servers, and a failed call moves to lower-priority settings rows on retryable errors. [Agenvoy](/p/agenvoy/) asks a dispatcher LLM to label each request as code, research, work, chat or fetch. The label sets the model tier and reasoning effort, at the cost of one extra call. The editor found that the optional beta dispatcher sends request text to a hosted third-party classifier.

**Narrow or delegated.** [OpenBot](/p/openbot/) accepts only `openai`, `anthropic` and `google`. A base-URL override is the only way to use a local model. [QM](/p/qm/) delegates model calls to its harness and defaults to `claude-opus-5`. Its answer said there was no local support, but the editor confirmed that admins can register any OpenAI- or Anthropic-compatible endpoint for Pi-based harnesses. [Waku](/p/waku-agent/) turns every provider into the Anthropic message shape, so structured output is not available.

Pick: Hermes Agent or Rakazo to bring your own models and subscriptions.
Pick: Inbox Zero or Khoj when outages must fail over.
Pick: Leon for local models first.

Per-project answers: https://llms-technical-reviews.com/personal-assistants/q/models/index.md

## How is it deployed and self-hosted?

[Agenvoy](/p/agenvoy/) is the lightest install: one Go binary with no database server. [Waku](/p/waku-agent/) and [OpenClaw](/p/openclaw/) are close behind, and [Rakazo](/p/rakazo/) is the simplest full multi-user stack to self-host.

**Local, single-user, no database server.** [Agenvoy](/p/agenvoy/) keeps SQLite and an embedded ToriiDB store under `~/.config/agenvoy` and needs `bubblewrap` on Linux. The editor found that the first boot of each version downloads the dashboard's vendor files, so it needs network access. [Waku](/p/waku-agent/) installs with `pip install waku-agent` (Python 3.11+, not 3.12 as its answer said). Its dashboard has no authentication, so it stays on `127.0.0.1`. [OpenClaw](/p/openclaw/) needs Node 24.16+ for `node:sqlite`. Its compose file runs one gateway with `no-new-privileges`. [Leon](/p/leon/) is bare-metal only: there is no Dockerfile, and `pnpm install` runs a setup pipeline that builds Python and llama.cpp tooling. [Hermes Agent](/p/hermes-agent/) runs a gateway and a dashboard under s6-overlay with host networking, and builds its own SQLite to avoid a WAL bug.

**Postgres-backed servers.** [Rakazo](/p/rakazo/) needs only Postgres 16, Docker and a model key. `install-images.sh` writes secrets and starts five services, and nothing uses Redis. [Khoj](/p/khoj/) requires pgvector, and its compose file adds Terrarium, SearXNG and an optional desktop container. PyTorch makes the image heavy. [Inbox Zero](/p/inbox-zero/) adds Redis, a cron container, and either Google OAuth with Pub/Sub or a Microsoft app registration.

**Platforms with outside dependencies.** [OpenBot](/p/openbot/) refuses to boot without a CopilotKit Intelligence project, managed or self-hosted. It ships a Helm chart. [QM](/p/qm/) keeps sessions in memory unless Postgres is configured. It also needs a sandbox backend and a deployment repository created with `qm init` for Docker, AWS, Fly or Porter.

Pick: Agenvoy or Waku for one person on one machine.
Pick: Rakazo for a self-contained team server.
Pick: QM or OpenBot when you already run cloud infrastructure and need multi-user access control.

Per-project answers: https://llms-technical-reviews.com/personal-assistants/q/deploy/index.md

## Projects

- [openclaw/openclaw](https://llms-technical-reviews.com/p/openclaw/index.md) — Local Gateway that connects ~28 chat channels and companion apps to an embedded tool-calling agent with SQLite state and plugins.
- [NousResearch/hermes-agent](https://llms-technical-reviews.com/p/hermes-agent/index.md) — Python agent core behind a CLI, desktop app and 20-platform chat gateway, with guarded shell tools, curated memory and self-written skills.
- [khoj-ai/khoj](https://llms-technical-reviews.com/p/khoj/index.md) — Self-hosted multi-user chat server that answers from your pgvector-indexed notes, web search, sandboxed code and a computer-use agent.
- [leon-ai/leon](https://llms-technical-reviews.com/p/leon/index.md) — Self-hosted Node.js assistant: a tool-calling agent loop over JSON-declared toolkits, layered SQLite memory and optional remote-device tools.
- [yc-software/qm](https://llms-technical-reviews.com/p/qm/index.md) — Self-hosted agent server for Slack and web that gives every person and channel its own memory, sandbox and keychain.
- [elie222/inbox-zero](https://llms-technical-reviews.com/p/inbox-zero/index.md) — AI email assistant for Gmail and Outlook: plain-English rules triage new mail and pre-draft replies, plus a chat agent for the inbox.
- [CopilotKit/OpenBot](https://llms-technical-reviews.com/p/openbot/index.md) — Self-hosted platform where AG-UI agents get their own browser computer, with every action policy-checked and audited first.
- [elie222/rakazo](https://llms-technical-reviews.com/p/rakazo/index.md) — Self-hosted persistent AI bots on a Pi agent runtime, with Postgres job queue, pluggable sandboxes and rule-based tool approval.
- [ShenSeanChen/waku-agent](https://llms-technical-reviews.com/p/waku-agent/index.md) — Readable Python assistant harness: one Anthropic-shaped tool loop, gated SQLite/FTS5 memory, and built-in traces and evals.
- [agenvoy/Agenvoy](https://llms-technical-reviews.com/p/agenvoy/index.md) — Single-binary Go daemon for a local personal agent, with LLM-routed model choice, sandboxed tools, cron skills and chat bots.