A judgment · not an inventory
Open it. It has
already decided.
Every other task app is storage. The list grows, the important thing sinks, and eventually you stop opening it. Control’s home screen is a judgment about what matters right now — at this hour, on this day, in the timezone you actually woke up in.
PRIVATE BETAAccounts are opening gradually. Sign in if you already have one.
Illustration · NOW is capped at seven
The guilt museum
A list that only grows is a list you stop opening.
Todoist, Things, Reminders, Notion — all excellent storage, and none of them decide. So the list grows. The important thing sinks under the trivial one. Eventually you open it and feel bad, which is the moment it stops being a tool.
The failure is not the interface and it is not your discipline. It is that storage was never the hard part. Deciding is. Control is built the other way round: the list is still there, complete and intact, but it is not what you are shown.
One bar · no forms · no confirmation step
Say it. That is the whole interface.
One input takes everything: a new thing, a change to an old thing, a note, a question. Type it or speak it. There is no date picker, no project, no tags to maintain and no “is this right?” step — Control commits instantly from a parse that runs on your device, then refines it in the background.
Illustration of behaviour that ships today, not a live parser.
0.45 urgency · 0.30 heat · 0.15 context · −0.10 fatigue
It can always tell you why.
The ordering takes no model call. It is four weighted terms of arithmetic, run on your device over your own data — deterministic, testable and inspectable. When the order looks wrong you can find out exactly why, and that is not something a list ranked by a language model can offer you.
Because it is arithmetic, it also works with the network off, and it changes through the day on an explicit rule rather than a mood: open Control at ten at night and tomorrow’s nine o’clock is at the top, because the rule says the horizon moves forward after seven.
7 of 9 shown · cap 7
14:00 — Neutral, with actionable tasks lifted ×1.05 over passive events. Tap a row to see the arithmetic behind its position.
- urgency ×0.45+0.425due today = 0.900 · working hours · tasks ×1.05heat ×0.3+0.222heat 74 / 100context fit ×0.15+0.075routine, place and day alignment = 0.50fatigue ×-0.1−0.010shown and skipped = 0.10total0.712at or above the 0.25 threshold
Held back · below 0.25
Nine open items, one screen, four hours of the same day. Nothing above was generated — it is the same four terms every time, and it runs on your device with no network and no model call.
Three things that do not bend
Capture never fails
Network down, model down, allowance gone — the thought still saves, on the device, immediately. Running out of quota degrades the intelligence, never the data. It is the single most important rule in the system.
Nothing is deleted on a clock
A task is something you decided, and it does not become less true because a fortnight passed. Control escalates, then asks, and only lets something go dormant when you have ignored it after being shown it. Never silently, never on a timer.
It travels with you
Where you live, where you are today and where a particular meeting happens are three different questions. Control keeps them apart, ranks against the timezone you are actually in, and asks before adopting a new one — it never reshuffles your day behind your back.
0.5 ^ (t / half-life)
It forgets the way a person does.
Control learns as you use it — your people, your hours, the project that is eating this month. The rule that governs all of it is one line: confidence fades in what Control guessed, never in what you decided.
So a guess about this month’s context is worth almost nothing a fortnight later, a guess about how you work holds for a season, and anything you told it outright never fades at all. Every one of those beliefs is visible, editable, and will show you the sentence it came from.
What Control will not claim
Control is not end-to-end encrypted.
It cannot be. An assistant that reads your sentences has to be able to read your sentences, and a product claiming both end-to-end encryption and server-side AI is claiming something that is not possible. We would rather lose you here than be caught later.
- Who reads itOur servers can read your content, in order to process it. Not zero knowledge, not end-to-end encrypted, and we will not use either phrase.
- Who elseYour sentences are processed by a third-party AI provider. Every outside company that touches your data is listed on the subprocessor page — a page of its own, not a clause, and the complete list rather than a selection.
- DictationSpeaking to Control uses your browser’s own speech recognition, which means the audio goes to the company that made your browser — Google or Apple — and not to us. We will not call that private, and Control says so the first time you press the microphone.
- How muchNever your whole history. A single request carries your sentence, at most about twenty facts, and a handful of relevant items. That ceiling is what makes the receipt short enough to actually read.
- At restSensitive fields are encrypted with a key scoped to your account, on top of full-disk encryption, so a stolen database dump is not enough on its own. Separation between accounts is enforced by Postgres itself, not by application code — a bug in our query layer must not be able to become a data breach.
- LeavingAsk for deletion and everything you wrote is purged within 30 days, and out of backups within 35 — captures and receipts included. What survives is a content-free billing record, kept only as long as tax law requires.
Data receipt · specimenrecorded on every model call
- You said
- “call joseph about the contract”
- Control sent
- your sentence
- 4 facts, by name only — timezone · employer · manager.name · workday_end
- 2 upcoming items, titles only
- Not sent
- your history, your other items, the values behind those fact names
- Provider and retention
- recorded per call · listed on the subprocessor page
Every model call writes one of these, from the same rows that meter your usage — so what Control tells you and what actually happened cannot drift apart. Fact names, never fact values.
Free · $4.99 · $9.99
Pay for the thinking, not the storage.
Storing your items costs us almost nothing, so it is unlimited on every plan and it is never metered. What the plans buy is the expensive part: how many times a day Control reasons about what you wrote, and how often it reaches for the stronger model to do it.
Free
$0
The whole product, with a smaller allowance of the expensive part.
- Items storedUnlimited
- CaptureUnlimited, never metered
- AI interactions a day25
- Handled by the strong model10%
Control
$4.99/ month
For a real week: twenty to thirty things open, several with dates.
- Items storedUnlimited
- CaptureUnlimited, never metered
- AI interactions a day150
- Handled by the strong model25%
Control+
$9.99/ month
For the heaviest use — long research projects and dense calendars.
- Items storedUnlimited
- CaptureUnlimited, never metered
- AI interactions a day500
- Handled by the strong model50%
Running out of an allowance never costs you a thought. Control drops to the local parser, the item still saves, still appears and is still searchable, and it is enriched automatically when the allowance resets. Quota degrades the intelligence, never the data. Control is in private beta — nothing is charged today, and every limit above is adjustable.
One screen
Stop reading your list.
Start with what it decided.
Control is in private beta. Sign in if you already have an account.