What is Talorys, and when did it ship?

Talorys is a single-user personal AI assistant that a developer using the handle rociiu (Roc Yu) released as open source. It chats with streaming responses, stores durable memories you can view and edit, manages tasks, notes and projects, and runs one-time and recurring automations such as reminders and daily task digests. The pitch is ownership: there is no server, database or account operated by the Talorys developers, because every piece runs inside your own Cloudflare account.

The dated objects line up on 10 October 2026. GitHub's API object for rociiu/talorys reports created_at 2026-10-10T09:46:56Z, and the npm registry shows the installer package create-talorys publishing version 0.1.0 at 2026-10-10T09:57:15Z, moving to 0.1.4 by 11 October. A Hacker News thread, “Talorys – A self-hosted personal AI agent on Cloudflare's free tier,” was posted the same day and climbed the front page. The repository is licensed MIT.

This is a self-hosting pattern rather than a hosted product, so the comparison that matters is not another chatbot but where your data and compute sit. For context on building agents that retain information, see our explainer on what an AI agent should remember and forget, and for Cloudflare's own recent AI moves see our coverage of Clef-omni, Cloudflare's audio-video decision model.

Talorys chat screen: a left sidebar with Chat, Memory, Tasks, Notes and Automations, and a conversation adding a task from a chat message.
Talorys chat interface from the project's README (docs/screenshots/chat.png in rociiu/talorys, MIT License), inspected 11 October 2026. The screenshot shows the app adding a task from a chat message; it is the maintainer's own UI capture. Photo: rociiu/talorys contributors. MIT License · Cropped and resized.

How does the one-command install work?

Installation is a single command, `npx create-talorys@latest`. According to the README, the installer checks for Node.js 22+, verifies your Cloudflare login (or opens Cloudflare's authorization page in the browser), lets you pick an account and an agent name, and asks for an owner password that is hashed locally with PBKDF2-SHA256 and stored only as a Cloudflare secret. It then generates a session secret, deploys the private Worker and its Durable Object, stores secrets, and creates and deploys the Pages project wired to the Worker through a service binding.

The installer is designed to be resumable and idempotent: re-running the same command reconciles what already exists without creating duplicate resources, re-prompting for a password, or deleting data. It writes a local `talorys/` directory holding a `talorys.json` with the installation id, account id, resource names and URL—explicitly no secrets—plus the deployable artifacts, which you keep for later updates. A non-interactive path exists for CI using environment variables.

Browser login uses Wrangler's standard OAuth flow rather than a global API key. If you use a scoped API token instead, the README lists the permissions it needs: edit access to Workers Scripts and Cloudflare Pages, read access to Workers AI and account settings, and optional read access to user details.

How is Talorys architected on Cloudflare?

The data path is deliberately narrow. The browser only ever talks to your Cloudflare Pages site; `/api` requests run a Pages Function that forwards them over a service binding to the agent Worker, which is deployed with workers_dev and preview URLs disabled so it has no public URL of its own. Authentication and authorization happen in the Worker, not the frontend, and chat responses stream as Server-Sent Events end to end.

State lives in a single SQLite-backed Durable Object named personal-agent, which the README says holds conversations, memories, tasks, notes, projects, automations, sessions, settings and usage. Scheduling is handled by Durable Object alarms, so reminders and recurring routines fire without anything having to stay online. Chat inference runs on Cloudflare Workers AI using the @cf/zai-org/glm-4.7-flash model; Cloudflare documents that model with a 131,072-token context window and function calling.

An optional, off-by-default semantic-recall module finds memories by meaning using a Workers AI embedding model (default @cf/baai/bge-m3), with configurable cosine floors and a daily embedding cap. Treating stored notes, memories and tool output as data rather than instructions is a sensible default; it echoes the separation we described in our piece on agent sandboxing and least privilege.

Talorys automations screen listing recurring schedules such as a morning task digest, a plant-watering reminder and a stretch break, each with a next-run time.
Talorys automations view from the README (docs/screenshots/automations.png in rociiu/talorys, MIT License), inspected 11 October 2026. Recurring reminders run on Durable Object alarms; the note that times use UTC is the app's own label. Photo: rociiu/talorys contributors. MIT License · Cropped and resized.

What does the free tier actually cover?

Talorys is built to fit the Cloudflare Workers Free plan and, the README stresses, never enables paid features on its own. It provisions Pages, Workers, Durable Objects and Workers AI, and explicitly avoids R2, D1, KV, Vectorize, AI Search and Workflows. That is what makes the “free tier” claim defensible—but it is bounded by Cloudflare's quotas, not by Talorys.

The binding constraint is Workers AI. Cloudflare's pricing documentation says the free allocation is 10,000 Neurons per day, after which you need the Workers Paid plan at $0.011 per 1,000 Neurons. In Talorys, when the daily allocation is exhausted, chat shows a message and resumes after the reset, while tasks, notes, memories and reminders keep working; simple reminders and digests never call the model at all. Adjustable guardrails in Settings cap output and context tokens, tool calls, reasoning steps, and daily AI runs.

Cloudflare services Talorys uses, per its README
ServiceUsed forOn the free plan
Cloudflare PagesReact frontend plus the /api Pages FunctionYes
Cloudflare WorkersPrivate API Worker (no public URL)Yes
Durable Objects (SQLite)All data and scheduling alarmsYes
Workers AIChat model @cf/zai-org/glm-4.7-flashYes, within a daily Neuron allocation

What are the security and privacy claims?

Talorys describes a single-user threat model: the internet can reach your pages.dev URL, but only the owner should read or change data. The owner password is hashed on the installer's machine with PBKDF2-HMAC-SHA256 at 100,000 iterations and a random salt and stored as a Worker secret; the database keeps only an HMAC of session tokens, so a storage leak cannot be replayed. Sessions are HttpOnly, Secure, SameSite=Strict cookies that expire after 30 days or 14 days of inactivity, and changing the password signs out other devices.

The security doc also lists brute-force lockouts, a CSRF scheme requiring a custom header and same-origin checks, a strict content-security policy, and a build check that no secrets or bindings end up in browser code. Destructive agent tools—deleting a task or note, forgetting a memory, cancelling an automation—require an explicit confirmation in the owner's latest message, enforced in code and not just in the prompt, and scheduled AI runs get read-only tools plus a notify action. The README adds that Talorys has no telemetry, analytics, tracking or advertising and sends nothing to its developers, while noting that Cloudflare still processes your data to run inference.

What should you check before relying on it?

The project is one day old at the time of writing, with releases moving quickly (0.1.0 through 0.1.4 within about 18 hours) and several merged community fixes around automations, backups and deployment verification. That pace is a strength and a caution: the code is active, but it has not had time to accumulate independent security review or long-running production use. Nothing here is a tested endorsement—we read the repository, README, security and semantic-recall docs, the npm metadata and the Hacker News thread; we did not deploy an instance or audit the code.

Two claims deserve your own verification. First, “free” depends entirely on staying inside Cloudflare's daily Workers AI allocation and other account quotas, which Cloudflare sets and can change; a busy assistant can exhaust the chat budget before the day is out. Second, the quality of answers is the quality of @cf/zai-org/glm-4.7-flash, a compact flash model, not a frontier system—useful for personal notes, reminders and light reasoning, but not a drop-in for heavy coding or analysis.

Common questions

Is Talorys really free to run?

It is free to install and is built to fit the Cloudflare Workers Free plan, but chat uses Cloudflare Workers AI, whose free allocation is 10,000 Neurons per day. Beyond that you need the Workers Paid plan. Talorys itself has no paid tier and provisions no paid Cloudflare services.

Where does my data live?

In a single SQLite-backed Durable Object in your own Cloudflare account. Talorys sends nothing to its developers and has no telemetry, though Cloudflare processes your messages and included memories when it runs Workers AI inference.

Which model does it use for chat?

Cloudflare Workers AI's @cf/zai-org/glm-4.7-flash, a multilingual flash model with a 131,072-token context window and function calling. An optional semantic-recall module uses a Workers AI embedding model, @cf/baai/bge-m3 by default.

THE TAKEAWAY

What to remember

If you want a private, self-hosted assistant you fully own on infrastructure you control, Talorys is a clean MIT-licensed way to get one on Cloudflare in a single command—just size your expectations to a flash chat model and a daily free Neuron budget.

Sources & further reading

  1. rociiu/talorys repository (GitHub API object) ↗
  2. Talorys README ↗
  3. Talorys security documentation ↗
  4. create-talorys on npm (registry metadata) ↗
  5. Workers AI pricing (Neuron allocation) ↗
  6. glm-4.7-flash model documentation ↗
How this story was made

Written by Kristian Kostov with AI assistance and checked against the linked sources. Company performance claims are attributed to the company. Analysis reflects AiLookout’s interpretation; we have not independently tested the products discussed. Cover photography is illustrative and does not depict the specific announcement or product.

Our editorial standards
Back to all stories