How can I let Claude or ChatGPT answer questions about my own documents without uploading them?
How can I let Claude or ChatGPT answer questions about my own documents without uploading them?
Choose a document app that ships its own MCP server and runs it on your machine. The assistant starts it locally and it reads the vault already unlocked in front of you, so nothing is uploaded and no network port is opened. Before it answers anything, a person unlocks the vault and grants a scope: one document, one category, or everything. It should be read-only, never hand over the file itself, and write every read into an audit log you can check.
People have started asking their assistants the questions a document vault exists to answer. When does my visa expire? What is my policy number? Is there anything I need to renew before the trip? The assistant cannot answer any of them, because the documents are in an app and the assistant is not.
The obvious fix is the wrong one: upload the documents. Then a chat provider holds your passport, your assistant's context window holds it, and the transcript holds it after that. For a product whose whole claim is that it cannot read your documents, handing them to a third party to make a feature work would end the claim rather than extend it.
So Keepsake does the opposite. The assistant comes to the documents. A small program that ships with the app speaks the Model Context Protocol on your machine, and answers — carefully, narrowly, and only what a person has just granted — out of the vault that is already open in front of you.
What actually runs, and what does not
Two processes on one machine, and no server anywhere.
KeepsakeMcp.exesits next to the app. Your assistant starts it and talks to it over its standard input and output — the ordinary way MCP servers are run locally. It holds no documents, no key and no state.- It hands each request to the running copy of Keepsake over a Windows named pipe, and hands the answer back. Keepsake is the only process that has your master key, your grant and your audit log, and it never leaves it.
There is no port. Nothing listens on localhost:8080, so nothing on your network — or in a browser tab, which is how "localhost is safe" usually goes wrong — can reach it. A pipe is addressed by name and by the account it belongs to, not by a socket anyone can open.
If Keepsake is not running, the launcher still answers the handshake and lists its tools, then refuses every read with a sentence rather than a crash: "Keepsake is not running on this machine, so there is nothing to read." That is deliberate. An MCP server that fails to start makes an assistant say the server is broken; one that starts and explains itself makes it say the vault is locked, which is the truth and is actionable.
A person grants a scope, and no tool can widen it
Nothing is readable until somebody opens Keepsake, unlocks the vault, and starts a session under Settings → Assistant access. That screen asks one question — what may it see — and tells you the answer in documents before you agree to it: "This session would be able to read 4 documents, for 30 minutes, up to 200 questions."
| Scope | What it is |
|---|---|
| One document | A single document you picked. The narrowest useful grant, and the one to reach for first. |
| One category | Every document of one type — the passports, or the policies. Wide enough for a trip; a will is not in it. |
| The identity documents | The identity shelf: the passport and what is kept with it. It answers nearly every question anyone asks an assistant in passing, and it contains no will, no deed and no bank statement. |
| The whole vault | Everything. Offered, because you may want it. Never the default. |
The scope is arithmetic, not a policy someone has to enforce correctly. At the moment you grant it, Keepsake works out the exact set of documents it covers and holds that list; every tool intersects with it. A document outside the set does not come back as forbidden — it comes back as absent, from search, from what expires soon, from a lookup by id, and from Ask. The test suite checks all four doors on the same document, because a scope that holds for three of them holds for none.
A session lasts 30 minutes and 200 calls, whichever ends first, and it ends the moment the vault locks — a deliberate lock, an auto-lock or a logout all close it. A grant that outlived the vault being open would be a grant nobody remembers making.
The five tools, and what each one will not do
The list is the whole surface. There is no sixth tool, and asking for one is refused by name.
| Tool | Answers | Will not |
|---|---|---|
keepsake_status | Is the vault unlocked, what was granted, how many documents, how long left. | Return any document content. It answers while the vault is locked, on purpose — that is how an assistant learns to ask you rather than concluding the vault is empty. |
keepsake_search | Matching documents in scope: title, type, dates, issuing authority, tags, your own fields. | Return document text. One broad query must not drain a vault. |
keepsake_document | One document by id, with a capped extract of its recognised text. | Return the file. Not the PDF, not a page image, not a thumbnail. An assistant can be told what a document says; it cannot be handed the document. |
keepsake_ask | The same retrieval the app's own Ask uses, quoting the field or the sentence the answer came from. | Compose an answer. When the vault does not hold it, it says so. |
keepsake_expiring | What expires within N days, soonest first, with the days left on each. | Look past a year, or outside the scope. |
The ceilings are ceilings rather than preferences: 20 results a call, 300 characters of snippet, 2,000 characters of document text, 365 days of lookahead. An assistant that can ask for ten thousand results is one that can copy a vault into a transcript with a single tool call.
Read-only by construction
There is no tool that changes, moves, shares or deletes anything in the vault — not disabled, not gated, absent. The same sentence is what an assistant is told if it tries: the server refuses subscriptions, filesystem roots and requests to borrow your model budget by name, before anything looks at a document.
The end-to-end test suite proves the negative the only way it can be proved: it grants a session, lets an assistant make every kind of call the tools allow, and then checks that the document count is unchanged and every document still says what it said.
Every question is in your audit log
The grant, each read, each refusal and the end of the session are written into the vault's hash-chained audit log — the same chain that records your own logins and imports, where each entry is hashed over the one before it, so an entry cannot be removed or edited later without the chain saying so.
That means "what did the assistant look at last Tuesday" has an answer, and the answer is in your vault rather than in somebody's transcript. A refusal is logged too: a grant that was used and blocked is its own fact, and worth being able to see.
Setting it up
Open Settings → Assistant access. The screen prints the configuration block for you, with the correct absolute path already filled in, and a button to copy it:
{
"mcpServers": {
"keepsake": {
"command": "C:\\Program Files\\Keepsake\\KeepsakeMcp.exe",
"args": [],
"env": {}
}
}
}Paste it into your assistant's MCP configuration — for Claude Desktop that is claude_desktop_config.json — and restart the assistant. Nothing else is configured: there is no key to paste, no account to link and no address to choose, because there is nothing on the other end but the app on your own machine.
Step by step
- Have Keepsake installed and running. KeepsakeMcp.exe is installed with the app and updated with it. There is nothing separate to download.
- Copy the configuration block into your assistant. Settings → Assistant access prints it with the right path already in it. Restart the assistant afterwards so it picks the server up.
- Unlock the vault, at the machine. Keepsake will not unlock for an assistant. A person opens the vault with their password or their key — that is not a workflow gap, it is the boundary.
- Start a session and choose what it may see. The screen tells you how many documents that is before you agree. Start with one document or one category; the whole vault is there if you want it.
- Ask your assistant about your documents. "When does my passport expire?" "Anything to renew before March?" The answers are quoted from your documents, with the document named.
- End the session, or just lock the vault. Either closes the door. Sessions also end themselves after 30 minutes, and everything that happened is in your audit log.
Questions
Does this upload my documents to Claude or OpenAI?
Not to us and not by us. The server runs on your machine and reads your local vault; nothing is sent to any server of ours, and none exists in this path. What your assistant then does with an answer is between you and your assistant — if you ask a cloud assistant a question, the answer it reads travels to that provider the same way anything you type does. That is why the grant is narrow, short and yours to make: the honest control here is deciding what may be read, not pretending the assistant is local when it is not.
Is there a port open on my computer?
No. The launcher talks over standard input and output, and reaches the app over a Windows named pipe addressed by name and account. Nothing listens on a network interface, so nothing on your network or in a browser tab can reach it — which is the failure mode of the usual "just bind to localhost" design.
Can an assistant delete or change a document?
No, and not because we turned it off. There is no such tool on the server at all. Methods that would let a client subscribe, roam your filesystem or borrow your model budget are refused by name before anything looks at a document.
What if my assistant asks for a document I did not grant?
It is told the document is not in this session's scope, and that widening it is your decision to make in the app. The document does not appear in search, in what expires soon, or in an Ask answer either — the scope is a fixed set of documents computed when you granted it, and every tool intersects with it.
Does it work with ChatGPT, Copilot or a local model?
With anything that speaks MCP over stdio and lets you add a local server — Claude Desktop is the common case today, and the protocol is an open standard rather than one vendor's. The configuration is the same block for all of them.
What about Android, the web app or a Mac?
Windows only today, and the omission is a decision rather than a gap. A browser cannot open a pipe to a process, so a web version would mean routing your documents through a server of ours — the one thing this feature exists to avoid. On the phone, the assistant and the vault are not on speaking terms in the same way.
Does the assistant get my file itself?
Never. It can be told what a document says — a capped extract of the recognised text, the dates, the number, the fields — and it cannot be handed the PDF, a page image or a thumbnail. The tool that returns a document says so in its own answer.
Where Keepsake fits
Keepsake is our product, so read this part with that in mind. Everything above is true whether or not you use it, and most of it you can do with a folder and an afternoon.
The retrieval behind keepsake_ask is the app's own Ask your vault, unchanged: the answer is quoted from a field or a sentence, and when the vault does not hold it, it says so. The expiry answers come from the same dates behind renewal reminders. Nothing here is a second, looser copy of either.
What decides all of it lives in one file, shared/mcp-server.json — the tool list, the scopes, the ceilings and the exact words of every refusal. This page is a copy of that file, which is why the wording here is the wording your assistant sees.