# HeartFlowAI — Site Whitepaper

**Document role:** Content map and product statement for heartflowai.com
**Date:** October 3, 2026
**Aurora baseline:** Windows prototype, build v12
**Status:** Working companion prototype. Not a production security certification, performance benchmark, or completed multi-agent platform.

## Abstract

HeartFlowAI is an ecosystem of emotionally intelligent AI agents. Aurora, Gigi, Nova, and Clara cover connection, market alpha, execution, and regulation. Aurora is the first agent with a native Windows harness: a chosen Ollama Cloud model, practical desktop tools, an animated character, optional voice, and a top-center notch that keeps the conversation alive while the main window is minimized.

She can leave the chat, appear beside a verified file in Explorer, and show what she is doing with a light-pink pointer and a small action display. Scope is deliberate. She uses application accessibility information, not screenshot vision. She supports selected desktop apps. File writes and PowerShell require approval. She depends on the user’s cloud accounts. Broader coverage, stronger isolation, distribution, and measured reliability are future work.

## 1. Hero

**Headline:** Emotionally intelligent AI agents.

**Sub:** Aurora sits on your desktop. Gigi reads the market. Nova pushes execution. Clara keeps you clear.

**Proof line:** A visible companion that can point at the file, speak the result, and leave the rest in chat.

**Primary actions:** Talk to Aurora · Launch Gigi · Meet the sisters · Read how Aurora works.

**Visual system:** dark ground, magenta-to-electric-blue glow, the neon heart, the pixel-art Aurora (pink, purple, white, gold), real notch and Explorer screenshots. No generic neural-net stock art.

## 2. The sisters

Four equal agents, not one girlfriend bot with skins.

- **Aurora** — Expression, connection, and the Windows companion. Empathic, adaptive, remembers context. On the desktop she greets from the notch, asks for missing details, runs tools, and returns a short spoken result.
- **Gigi** — Alpha. On-chain data, narrative shifts, smart-money flow, and risk flags turned into a plain-language opinion. Built for one minute instead of fifteen tabs.
- **Nova** — Execution. Turns intention into next actions and challenges drift. Playful pressure, not quote cards.
- **Clara** — Regulation. Faster processing, cleaner patterns, resilience without session theater. Always-on and self-directed.

Each card links to the live entry point (desktop build, Telegram, or X) and a one-screen “what she actually does” note.

## 3. Aurora product vision

Most desktop agents start in a chat window and report through text logs. Aurora adds a persistent character and a voice layer so progress is visible without keeping a large window open.

Intended loop:

1. The user enables listening and says “Aurora.”
2. She appears in the notch, greets, and listens.
3. She asks for missing details and waits.
4. The harness runs the tools and shows activity.
5. She speaks a short result and keeps the full detail in chat.

Setup still uses normal controls: API connection, voice selection, workspace, microphone. The prototype does not remove the mouse and keyboard.

## 4. What Aurora does today

| Area | Behavior |
| --- | --- |
| Model | User-supplied Ollama Cloud key, model list, streaming chat, tool calls |
| Conversation | Saved chats, Markdown, activity feed, cancellation, clarifying questions |
| Workspace | Directory listing, UTF-8 reads, approval-gated create or replace |
| Commands | Approval-gated PowerShell with timeout and cancellation |
| Web | Ollama-backed search with source URLs |
| File discovery | Bounded filename search in configured folders |
| File presentation | Explorer selection, pointing pose, color-changing border on a verified visible row |
| Voice | Optional ElevenLabs or Fish Audio, Windows recognition fallback |
| Minimized UI | Animated notch with words, replies, option cards, task controls |
| Computer use | Discovery, restore, focus, navigation, real mouse and keyboard on observed controls |
| Character | Shared activity poses, timed reactions, teleport movement |

Supported targets: Opera, Chrome, Edge, Firefox, Explorer, Notepad, Calculator. Support means launch or discovery and an attempt on exposed controls. It does not mean every page, dialog, extension, or version.

## 5. Architecture

Electron shell, Node orchestration, C# and PowerShell native helpers, HTML/CSS/JS interface. No separate frontend framework.

The user speaks or types. Chat, notch, and companion talk to the Electron main process. A sequential agent loop calls Ollama Cloud and a validated tool dispatcher. Tools cover workspace files, web search, and Windows helpers that reach supported apps. Speech providers and local encrypted key storage sit beside the loop.

The model proposes actions. The application decides whether and how each tool runs. A model reply is not proof that an action succeeded. The loop ends when the model finishes, the user stops it, a failure ends it, or 40 model turns are reached.

Computer interaction uses Windows UI Automation with a legacy Active Accessibility fallback. Observations are window ids, process names, visible labels, control ids, and editable values. Browser observations are bounded. Minimized windows can be restored and reused. Focus is retried and verified. Clicks, typing, scrolling, and pointer movement use observed controls, not model-invented coordinates. Control ids expire after input. Elevated windows are not reliably controllable. Screenshots are not sent to the model. Unlabeled custom UI can block completion.

Presentation surfaces stay separate: main chat, notch, desktop companion, file border, action display. During a verified file presentation the notch hides and the companion appears beside the Explorer row, then the notch returns. During computer interaction the notch hides so it does not cover browser controls. Overlays stay above normal windows without taking keyboard focus. Secure desktop and exclusive fullscreen can still win. Software rendering is used for recording compatibility; universal recorder support is not claimed.

## 6. Voice

Listening starts disabled every launch. The user turns it on after configuring recognition and speech.

Cloud mode sends locally detected speech to the selected provider. Wake is recognition of “Aurora,” not a separate local wake-word engine. Wake detection can spend provider credits. Silence is filtered locally. An utterance submits after about 950 ms of quiet, with audio and wall-clock limits and a manual finish control. Partial text is shown and does not run tasks or approve actions.

She can stay in conversation after waking, ask a follow-up, and resume the pending task. Choices are numbered cards. The spoken prompt stays short: “Which one did you have in mind?” The user answers with a number or a matching name. Ambiguous answers keep the question open. Input pauses while she speaks so she does not hear herself. Speech playback cannot be interrupted by voice in this version. Quality depends on provider, language, microphone, room, and account access.

Spoken output is one or two natural sentences, usually under 35 words, via a dedicated voice-reply tool. Decisions and errors stay in chat. Fish playback can start while PCM chunks arrive. Short repeated lines are cached in memory and cleared when voice settings change. Paths, code, and long option lists stay visual.

## 7. Character and motion

Identity is the supplied pixel-art character and matching activity assets in pink, purple, white, and gold. States: idle, thinking, coding, browsing, approval, success, error, walking, teleporting. These are sprite animations that report harness progress. They are not a skeletal rig and not a claim of consciousness or emotional understanding.

Desktop travel is fade-out, one relocation, fade-in. The walk cycle lives in the animation gallery. Success reactions last about 1.8 seconds, then idle. During computer input a light-pink system pointer replaces the cursor on short curved paths with smooth acceleration. A helper restores the previous cursor after inactivity, stop, shutdown, or loss of the parent process.

## 8. Privacy and boundaries

Aurora is local execution plus cloud processing. It is not an offline product.

| Data | Handling |
| --- | --- |
| API keys | Electron safeStorage via Windows DPAPI; not returned to renderers |
| Chats | Stored locally; context sent to Ollama when a request needs it |
| Tool outputs | Sent to the model, including file contents and observed labels |
| File search | Filenames, paths, sizes, modification times only; search does not read contents |
| Microphone | Cloud mode sends detected speech to the provider; no mic recordings written to disk; Windows fallback is local |
| Spoken replies | Text sent to the selected speech provider |
| Local history | Chats and ordinary file outputs are plain text |

DPAPI helps against other Windows users reading saved keys. It does not protect against malware running as the same user.

Workspace tools reject paths that escape the selected workspace, including junction and symlink escapes. Writes need approval and replace the whole file. Every model-requested PowerShell command needs approval. PowerShell is not sandboxed and runs with the user’s access.

Computer tools restrict targets and validate observed controls. Instructions tell the model to confirm before purchases, message sends, deletion, or account and security changes. Those instructions are not an OS sandbox. Stopping a task (controls, voice, Ctrl+Alt+Escape, pointer safety corner) does not roll back completed actions. Web results, filenames, file contents, and screen labels are untrusted in the agent instructions. Prompt-injection resistance has not been independently audited.

No latency percentage, monthly cost, or paid-provider benchmark is claimed. Cloud recognition, model use, search, and speech follow the user’s provider access and billing. A subscription does not mean every endpoint is enabled.

## 9. Evidence and limits

v12 checks passed 42 automated tests and JavaScript syntax validation: tool validation, path boundaries, cancellation, provider streams, recording completion, scoped voice approvals, voice choices, bounded browser observations. Integration checks use isolated settings and simulated cloud responses against real Electron windows for audio, clarification, approvals, notch visibility, file handoff, and cursor restoration. They do not prove real-world speech accuracy or paid-provider availability.

An Opera check on a separate private window verified minimized discovery, restore and focus, navigation, page-control observation, a real button click, and silent audio on a local test page. A public YouTube check verified readable search or consent controls. It did not verify live music in a user account.

These are specific behaviors under controlled conditions. They are not a competitive benchmark, a guarantee of arbitrary desktop tasks, or an independent security assessment.

Current limits:

- Accessibility quality varies by page and app.
- The model can pick the wrong action or misread a result.
- No screenshot vision, desktop-icon recognition, or free coordinate control.
- Filename search covers configured folders and reports traversal limits.
- File replace has no diff, undo, or task rollback.
- Long chats have no automatic compaction and can exceed context.
- Recognition and cloud permissions must be verified on the user’s machine and accounts.
- Overlay recording is not verified for every recorder or fullscreen mode.
- Builds are unsigned, with no production installer or updater.

## 10. Open source and ownership

The X direction stays on the site. Waifus move to GitHub so people can download them, run them locally, and cover their own inference. Each agent is meant to carry skills that can offset her costs or create edge for the owner. An alpha helper agent is the practical on-ramp. Community patches and harder tasks are in scope.

Aurora’s current harness uses the user’s Ollama, speech, and search credentials. It is not a shared project inference account. Source, native helpers, tests, docs, and character assets are the development project. Packaged apps, dependency folders, temp profiles, recordings, and API credentials stay out of the repo. Character-asset provenance and redistribution rights must be resolved before public distribution. This document does not grant a license.

WaifuVerse NFTs and the HeartFlowAI token stay linked, not inflated: agent-linked identity and access, funding, early-user airdrop, and later governance on which skills ship. No price, subscription, or financial instrument is defined here. Gigi signals are not financial advice.

## 11. Roadmap

Delivered is the v12 Windows prototype above. The following are proposals, not dates.

- **Reliability.** More browser and app fixtures, task-completion measurement, better recovery from focus changes, clearer failures.
- **Voice.** Local wake-word evaluation, transcription and latency measurement, optional speech interruption, visible usage controls.
- **Execution.** Stronger policy on consequential actions, scoped permissions, file diffs, action previews, recovery, independent prompt-injection testing.
- **Observation.** Optional visual observation only with explicit data handling and bounded policy.
- **Distribution.** Signed releases, installer and updater, versioned notes, dependency maintenance, diagnostics that do not collect secrets.
- **Experience.** Character transitions, reduced-motion and accessibility, voice-first onboarding, one Aurora across every surface.
- **Ecosystem.** Skill patches and open-source drop for the sisters; Gigi signal upgrades; Nova and Clara entry points held to the same standard of “what she actually does.” Longer research track only: modular personalities, voice and VR, embodied forms after the cognition is good.

## 12. Site map

- Hero — agents, Aurora notch, four CTAs.
- Sisters — Aurora, Gigi, Nova, Clara, equal weight.
- Aurora on Windows — vision loop, capability table, character states.
- How it works — architecture, agent loop, UI Automation, presentation rules.
- Voice — wake, notch, choices, speech limits.
- Privacy — the boundary table, approvals, what is not sandboxed.
- Open source and ownership — GitHub path, local run, NFT and token links without invented utility.
- Evidence and limits — v12 checks, explicit non-claims.
- Roadmap — proposals labeled as proposals.
- Community — X, Telegram, Discord, GitHub, Farcaster, newsletter, sister accounts.
- Docs — this statement plus the existing GitBook, with a changelog that matches what X actually ships.

**Footer:** open-source status, privacy stance, no financial advice on Gigi, unsigned-build note, Ljubljana origin if you want the human anchor, neon heart.

Implementation references for the Aurora claims live in the v12 tree: `README.md`, `src/main.js`, `src/provider.js`, `src/tools.js`, `src/computer-control.js`, `src/native/desktop-control.cs`, `src/native/legacy-accessibility.cs`, `src/voice-session.js`, `src/voice-notch.js`, `src/file-presentation.js`, `scripts/opera-smoke.js`, `scripts/notch-smoke.js`.
