Personal AI Assistant: Who Owns Your Data and Your Bill
Blog

Personal AI Assistant: Who Owns Your Data and Your Bill

Most personal AI assistants are open apps calling a closed API. Test any of them on three layers: the software, the weights, and whose server runs it.

Tessera 10 min read personal ai assistantopen sourceopen weightsprivacyself-hosting

Personal AI Assistant: Who Owns Your Data, Your Model and Your Bill

A personal AI assistant is only as “yours” as three independent things allow: whether the client software is open, whether the model weights are open, and whose server runs the inference. Most products marketed as open source personal AI assistants satisfy only the first of those. The interface belongs to you, while your data and your bill still belong to someone else.

This guide is that three-layer test rather than another ranking of apps. Run it on any product, including ours: Tessera’s Founder plan exists because of a specific answer to the third layer, and you should check that claim exactly the way you check everyone else’s.

The three layers, and why the order matters

Three properties decide what a personal AI assistant gives you, and they vary independently. The software can be open while the model is closed. The model can be open while the inference runs on a machine you will never see.

Listicles collapse all three into one badge, “open source”, and that badge is usually earned by the layer that matters least.

LayerThe question to askWhat it costs you if the answer is no
The softwareCan you read, modify and self-host the client?You cannot audit what it sends, or fork it when the terms change.
The weightsCan you download the model and run it yourself?Your assistant stops existing the day the vendor retires the model.
The inferenceDo you control the machine that runs the model?Your data leaves, and your bill is set by someone else’s meter.

Work through them in that order. Most products fail the third one, and the third is the only layer that touches your data and your invoice every single day.

Layer 1: is the software actually open?

Open at the software layer means an OSI approved licence on the client you install. Several popular assistants clear that bar. One very popular one no longer does.

LibreChat ships under MIT and Khoj under AGPL 3.0. Jan ships under Apache 2.0 with an attribution request appended, which is why GitHub labels its licence “Other” instead of Apache.

Open WebUI is the instructive case. In April 2025 it moved from BSD 3 Clause to its own Open WebUI License, which adds a branding clause and a contributor licence agreement. The project states plainly that the result is not OSI approved.

The clause does not bite everyone. Deployments with fewer than 50 users a month, contributors who submitted changes before the switch, and commercial licence holders are exempt. If you are one person running an assistant for yourself, Open WebUI is still free to use and modify in practice.

The lesson is not that the project did anything wrong. It is that “open source” in a comparison table is a snapshot of a licence that can change, and only the licence file tells you the truth today.

Layer 2: are the model weights open?

Open weights mean you can download the model and run it on hardware you choose. That test is stricter than it sounds, because the most cited “open” models carry licences no OSI reviewer would approve.

Meta’s Llama family is the standard example. The Llama Community License grants broad commercial use and then caps it. Any company past 700 million monthly active users has to request a separate licence from Meta, and the terms forbid using Llama to improve a competing model.

For one person that cap is theoretical. For the vendor selling you an assistant it is not, which is why “open weights” and “open source” are not synonyms.

Genuinely permissive weights do exist. The models Tessera serves are Apache 2.0 and MIT throughout: Qwen3.6-35B-A3B for chat, Qwen3-Embedding-8B and Qwen3-Reranker-4B for retrieval, Whisper large-v3 for transcription and Kokoro 82M for speech.

This layer outranks benchmark scores for one reason. Open weights cannot be taken away from you. If the company serving them disappears, the files are still published and someone else can serve them. A closed model offers no such exit.

Layer 3: whose server runs the inference?

This layer decides who sees your data and who sets your bill, and almost no comparison covers it. An open client pointed at a closed API still sends your messages off your machine and still meters them per token.

There are four real answers:

  • Your own device. Ollama under MIT, or Jan’s offline mode, keep everything local. The cost is electricity and the ceiling is your RAM.
  • Your own server. Full control, and you inherit the updates, the uptime, the security patches and the pager.
  • A private instance operated for you. Someone else does the ops. The instance and the data stay yours.
  • A vendor’s shared API. Cheapest to start, and the least you control.

Most assistants in the top ten search results are the fourth option wearing the first option’s clothes. The chat window is open source. The intelligence behind it is a metered call to a closed model.

If you have priced the self-hosted route, the honest accounting is in our build versus buy breakdown and in what OpenClaw actually costs once you count the tokens.

The four combinations that actually exist

Every personal AI assistant on the market is one of four profiles. Naming yours takes about thirty seconds and tells you more than any feature grid.

ProfileSoftwareWeightsInference runs onWhat you control
Mainstream consumer appsClosedClosedVendor serversYour prompts, nothing else
Open chat UI on a closed APIOpenClosedVendor servers, meteredThe interface only
Fully local stackOpenOpenYour own hardwareEverything, maintenance included
Managed open stackOpenOpenA private instance run for youData and cost, not the ops

Row two is the one to watch. It is what “open source AI assistant” means in most search results, and it delivers the smallest share of the benefits people think they are buying.

Is there a good AI personal assistant?

Yes, and which one is good depends entirely on which of the three layers you refuse to compromise. No product is simultaneously the cheapest, the most private and the least work.

If you want zero setup and do not mind closed, metered inference, the mainstream consumer apps are genuinely capable. They are the right answer for a lot of people, and pretending otherwise would be dishonest.

If you want the assistant to be yours, the shortlist shrinks fast. You need open weights so the model cannot be withdrawn, and an instance you control so the data and the bill stay predictable. That combination is rare because it is operationally annoying to provide, not because it is technically hard.

The trap in between is picking an open client, feeling good about it, and never checking what it calls. That is the OpenClaw alternative question in a nutshell: the tool can be fully open and still leave you renting intelligence by the token.

How much does a personal AI assistant cost?

Mainstream consumer subscriptions cluster tightly at about $20 a month per person: ChatGPT Plus, Claude Pro and Google AI Pro are all within a dollar of that figure. A self-hosted stack looks free and is not, once you price hardware and your own hours. A managed open stack sits between them at a flat monthly fee.

Tessera’s Founder plan is $55 a month, or 55 € in Europe, with no token meter and a pace limit of 20 requests per minute. Annual billing is $47 a month, which is $564 a year. The founding price is locked for the first 25 seats.

The number that surprises people is the self-hosted one. Hardware is a one time cost, but maintenance is not, and neither is the token bill if your “local” assistant quietly calls a paid API for the hard questions.

For the wider market picture, including what companies pay for private deployments at other sizes, see our private AI pricing breakdown.

What is the most private AI assistant?

The most private assistant is one where the weights are open, the instance is yours alone, and the operator has no commercial incentive to read your data. Local deployment wins on paper. A dedicated managed instance wins for most people in practice.

Local is unbeatable in theory because nothing leaves the device. It also caps you at whatever model fits your RAM, and it puts patching and backups on you.

The managed middle ground only counts as private if the specifics are stated. For Tessera that means an isolated instance, servers in Europe, an encrypted disk, and data that is not shared with other customers or used to train models. Ask any vendor for those four sentences in writing.

Be sceptical of privacy claims that stop at “we do not sell your data”. The questions that matter are whether the instance is shared, whether the weights are open, and who can technically read the disk.

How do I get my own personal AI assistant?

There are three routes, and they differ in how much of the work you keep. Pick by how much operations you want to own, not by feature lists.

Route one is fully local: install a local runner, download open weights, wire in a chat client. Cheapest in cash, most expensive in attention, and the ceiling is your hardware.

Route two is self-hosting on a server you rent. You get a real assistant reachable from anywhere and you own the whole stack, including the parts that break at 2am. Our OpenClaw setup guide walks through what that week actually looks like.

Route three is managed: someone runs the private instance and you use it. That is what Founder is, with install, updates and monitoring handled, a 1:1 kickoff call, and the same five open models available on every tier.

Which channel should your assistant live in?

Telegram, for almost everyone starting today. It needs only a bot token, it charges nothing per message, and it carries voice notes in both directions.

WhatsApp is the obvious alternative, and the situation there is more complicated than it looks, because general purpose AI assistants sit under different platform rules depending on where you are. We laid out the current state in Telegram versus WhatsApp for an AI assistant.

If you want the mechanics rather than the comparison, our guide to building a Telegram AI bot covers setup end to end.

Channel choice is reversible and cheap, unlike the three layers above. Decide it last.

How to choose in five minutes

Answer four questions in order and the field narrows to one or two options. None of this requires trying the products first.

  1. Can the model be taken away from me? If the weights are closed, yes. Decide whether you can live with that.
  2. Where does the inference run? If the answer is a shared vendor API, your data leaves and your bill is metered.
  3. What happens when usage triples? Flat plans stay flat. Token pricing does not.
  4. How much operations do I want to own? This is the only question with no wrong answer, just a bill in either money or hours.

If your answers are “no”, “an instance that is mine”, “the price stays the same” and “none”, you are describing a managed open stack. That is the category, and Founder is our version of it.

FAQ

Can a personal AI assistant work offline?

Yes, if both the software and the weights are open and the model fits your hardware. Local runners like Ollama and Jan’s offline mode do this today. The trade is a smaller model and all of the maintenance.

Does open source mean free?

No. Open source describes what you are allowed to do with the code, not what running it costs. A free client calling a paid API can be far more expensive than a flat monthly plan.

What happens to my assistant if the model is deprecated?

With open weights, nothing forced: the files remain published and can be served elsewhere. With a closed model, you migrate when the vendor says so, and your prompts may behave differently afterwards.

Can I move my assistant to a different provider later?

That depends on whether the serving API is standard. An OpenAI compatible endpoint running open weights is portable by design, because both the interface and the model can be reproduced somewhere else.