The desktop computing landscape is getting noisier by the day. Just as Perplexity threw open the doors to its Mac-resident AI agent earlier this month, a Y Combinator-backed startup called jo has entered the fray with a proposition that sounds almost quaint in its ambition: an AI assistant that knows you intimately but keeps your secrets.
The pitch hinges on a technical split. Half of jo runs on your Mac, handling personal data—photos, browser history, local files. The other half lives on a dedicated cloud machine, yours alone, where the computational heavy lifting happens. No pooled infrastructure. No model training on your documents. Just you and a server that acts, in the company's telling, like a private extension of your desktop.
It's a middle path in a market increasingly divided between the fully local purists and the cloud-everything pragmatists. Whether that middle holds depends on execution, trust, and timing—three variables that rarely align neatly in the startup world.
Two Places at Once
The architecture itself is straightforward, if unusual. Your Mac handles the sensitive stuff. Screen content, messaging apps, files tucked away in Finder—all of it stays put unless you explicitly approve otherwise. The dedicated cloud instance, mounted as a drive on your machine, taps into commercial models from OpenAI, Anthropic, Grok, and Kimi. There's also a local model for those who prefer to keep everything on-device, though that route limits what the system can handle.
According to the company's March launch materials, cloud inference providers are contractually prohibited from training on user data. It's a claim that echoes broader industry anxiety about who learns what from our interactions with AI. The system also auto-escalates to a "reasoning" model when it encounters a particularly thorny query, though the mechanics of that handoff remain somewhat opaque.
Apple's Private Cloud Compute, introduced in June 2024, promised something similar—privacy-preserving cloud inference for demanding tasks. But Apple controls that infrastructure end-to-end. Jo's twist is handing you the keys to your own machine, a gesture that's either empowering or a logistical liability, depending on how you look at it.
Less Chatbot, More Butler

Jo doesn't present itself as a conversational novelty. It plugs into Safari, Chrome, Apple Notes, Slack, Messages, Photos, Gmail, Google Calendar, and a handful of other daily-use apps. It groups your browsing sessions and message threads into what it calls "clips," which it can later reference. Speech gets transcribed locally. Every night, it runs something the company describes as a "reflection loop," building up a running file of preferences and patterns.
You can interact with it through a native macOS app or via Telegram and WhatsApp—voice or text. The promise is continuity across channels: same memory, same understanding of what you meant three days ago.
Morning briefings, task scheduling, price comparisons, research queries—jo aims to handle the connective tissue of digital life. It can spin up a browser on a remote machine with anti-fingerprinting measures for tasks that might otherwise leave a trail. But here's the guardrail: it won't send emails or messages autonomously. It drafts them in Gmail, suggests phrasing, then waits for you to hit send. That's by design, and probably wise given the operational missteps that have plagued more aggressive desktop agents in recent months.
The Trust Proposition
Privacy isn't just a feature for jo; it's the entire narrative. The company's website—last updated this week—repeats the mantra: no data sharing, no model training, full transparency. Personal data remains on your Mac. The cloud machine is yours. Inference providers are contractually walled off from your queries. The architecture leans on open-source components, and users are invited to audit the system themselves. Fire up Activity Monitor, read the privacy documentation, send questions to the team if something doesn't sit right.
It's a strong positioning in an environment where trust in AI platforms has taken a beating. But strong claims invite scrutiny. Privacy guarantees are easy to make in a launch post and harder to maintain under the pressures of scale, investor expectations, and inevitable competitive threats. Jo is offering transparency as a form of accountability. Whether users take the invitation seriously—or even know how to—remains an open question.
A Very Crowded Room

The timing is both opportune and treacherous. Perplexity's Personal Computer went broadly available just days ago, offering an always-on agent with local app hooks and remote approval mechanisms via iPhone. A cluster of fully local Mac assistants—Mochi, Nova, BonsAI, Dottie, TARX, Haye, NORA—have all staked out similar territory in recent weeks, each one emphasizing zero-cloud or local-first architecture.
Then there's OpenClaw, the open-source, self-hosted agent that captured attention in March and April for its capabilities and the operational chaos it sometimes enabled. Security incidents involving agents that control real browsers and desktop environments have left the industry skittish. Jo's approach—running a real browser with anti-fingerprinting but refusing to send messages without explicit approval—reads like a direct response to those concerns.
An Intel and LLMWare solution brief from March pointed to cost, latency, and privacy considerations driving organizations toward local and private cloud deployments. Infrastructure is maturing. User demand, sharpened by recent privacy scandals, is rising. The conditions for a breakout product are arguably present. So is the competition.
The Team Behind It
Jo was founded by Pradeep Elankumaran and Kevin Li, who previously co-founded Farmstead, a Y Combinator company from the Summer 2016 cohort. Elankumaran's resume includes Kicksend (YC Summer 2011), Yahoo, and Lyft. Li worked at Kabam and Yahoo before Farmstead.
The team appears small—Y Combinator lists jo's team size as two, though the company's LinkedIn profile indicates 2–10 employees. The company operates out of Menlo Park. No public funding amounts beyond the YC backing have been disclosed, which is either a sign of bootstrapped discipline or an indication that more announcements are pending.
There's a small wrinkle in the public record: Y Combinator's directory lists the batch as Spring 2026, while founder bios on the same page reference W24. The company's legal entity, Jo, Inc., last updated its Terms of Service in late February. Minor inconsistencies, perhaps, but the kind that invite questions about how quickly the company has moved from conception to launch.
Beta, For Now

Jo is currently free to use and doesn't require a credit card. The system needs an M-series Mac—M1 through M4—with at least 16GB of RAM, which should cover most machines from 2020 forward. Pricing post-beta hasn't been announced, which means the business model remains unclear. Subscription? Per-query? Enterprise licensing? All of the above?
The real test won't be technical ingenuity or privacy architecture. It'll be whether jo can build trust at the same speed its competitors are building feature sets. The desktop AI market is no longer speculative—it's operational, and the stakes are higher than they were even six months ago. For a two-person team (or ten, depending on who's counting), that's a daunting prospect.
But then again, most good bets are.
