You work through a hard problem with your AI on the phone during the commute; back at your desk you want to continue on the PC - and today that means scrolling history, copy-pasting, and re-explaining everything. Cloud full-sync is heavy and often unacceptable for privacy; RAG is passive retrieval that only kicks in after you switch; mainstream memory systems are effectively device-locked. MemoryBridge (jiabaobei, MIT) takes a different position: a cross-device, cross-platform shared semantic memory layer - the official engineering implementation of what it calls CDSMP, Cross-Device Semantic Memory Persistence. Version 0.30 is a pure-stdlib Python package distributed also as a portable membridge.exe.

Three architectural commitments separate it from the memory-tool crowd. Memory follows the person, not the app: devices share one semantic memory graph synchronized with incremental delta packets, never full dumps. Edge preloading pushes hot memories to a device before you even open it, so switching is continuous instead of switch-then-wait. And content freezing is an architectural constraint, not a policy: MemoryBridge only extracts associations and tunes structural parameters, it never rewrites your raw memory content - because letting an LLM auto-abstract memory inevitably injects hallucinated distortion. Writes are explicit (memory_add), so there is no path by which a hallucination becomes a memory.

Three recall routes, one fusion

Retrieval in src/membridge/retrieval.py fuses three routes with Reciprocal Rank Fusion (k=60): vector similarity, keyword matching for exact-literal hits, and a one-hop walk over the SAN - the semantic association network in src/membridge/san.py whose edge weight is w_ij = lambda*co-occurrence + (1-lambda)*cosine. Every edge carries a type (semantic, cooccur, entity) plus a small evidence note, so each link answers “why are these two related?”; entity-anchor edges come from zero-dependency regex extraction of code symbols, file paths, repos, and tags, which links memories across mixed Chinese-English phrasing without relying on literal coincidence. Each injected line is annotated with the route that hit it - vector, keyword, or graph - so you can judge at a glance whether to trust it. v0.30 adds Hindsight-style temporal filtering (at:7d, at:2026-09, at:2026-09-01..2026-09-20) applied before fusion, and an evidence count - how many distinct memories reference a node - used as the RRF tie-breaker but deliberately kept out of the injected block, where every character is recurring token cost.

Injection obeys a budget and a silence contract. The context block must fit a token budget; the first over-budget entry is truncated as a prefix of the original text (truncation, not rewriting - content freezing intact); and when nothing passes the quality bar, the tool says “no intervention this turn” instead of padding weak hits. Since v0.26, overflow recalls degrade to one-line pointers (mb:#id snippet) that a later search can expand, with stable-prefix section ordering and byte-identical output for identical input - explicitly tuned to hit the host’s KV cache.

Deltas over a cloud folder you already have

The sync layer is the most opinionated part. src/membridge/dss.py builds delta packets from semantic fingerprints with epsilon quantization and an embedder-consistency handshake; each packet carries a monotonically increasing sequence number, and receivers track a per-device sync watermark so duplicate or out-of-order packets converge idempotently through content-fingerprint dedup. The transport, though, is deliberately boring: a folder on a cloud drive. src/membridge/channel.py and src/membridge/netdisk_sync.py wire a channel folder through Jianguoyun/Nutstore WebDAV (primary) or OneDrive (backup) via rclone for headless ends, or simply detect a local drive folder on PC and Mac. Everything on the drive is ciphertext - end-to-end encryption with Fernet plus PBKDF2 - and since v0.17 the channel key travels inside the channel folder itself, so a new device needs no passphrase transfer at all. A wiring.json descriptor is written exactly once by a single designated writer (every other device is read-only), so the classic wiring (1).json conflict copy can never appear; every other end’s init reads it and wires itself up automatically, credentials encrypted as one block with the same chain as the deltas.

Container consistency solves the schema-drift problem that kills cross-device stores: src/membridge/schema.py emits a device identity card (schema version, node and edge fields, kind enum, storage planes, migration registry); membridge schema --peer reconciles two cards in both directions and auto-ALTERs missing columns, and delta packets carry a five-tuple edge format reconciled before apply - so typed edges from v0.14 no longer degrade across devices.

A phone as a base station, a handover card as a workbench

For phones and tablets, membridge gateway turns one always-on home device into a token-protected HTTP base station: mobile clients Add, Search, and Preload against that device’s store without holding a copy, a built-in pocket-note web page works with add-to-home-screen, iOS Shortcuts or any HTTP client works out of the box, and /health plus an IP allowlist make it observable. The mobile guide’s suggestion that a retired phone makes a fine 5-10 watt 24/7 base station pairs naturally with a local Ollama-class model into a zero-cloud personal stack.

The v0.15 handover mechanism is the sleeper feature. A third memory kind, handover, follows a line-prefix convention - goal:, done:, failed:, next:, refs: - where the failed line has a hard format: “tried X; failed because Y; don’t retry unless Z”. The newest non-stale card becomes the workbench, injected every turn as a state declaration that skips relevance ranking entirely; a new card automatically supersedes the old one by derivation (zero new state - every device converges on the same card after sync), cards older than seven days silently demote to ordinary memory, and edges touched by handover cards get structural weight decay so no card becomes a super-hub.

The rest of the discipline

membridge init walks a wizard (src/membridge/wizard.py) that auto-configures ZCode, Claude Code, Claude Desktop, Cursor, Cline, Windsurf, VS Code Copilot, Gemini CLI, and Qwen Code, installs a WorkBuddy skill, auto-generates and vaults the sync passphrase (Windows DPAPI, or a permission-600 file bound to the local user), and schedules auto-sync every fifteen minutes. The sync agent uploads important memories immediately and batches routine ones, while local-tagged memories never leave the device - part of the PAMS privacy gates (L1 migration tags, L2 scene domains, L3 deferred). membridge doctor warns about split stores, temp-directory databases, and logs zero-hit queries as gap discovery; membridge export renders the whole store as a read-only, git-friendly Markdown view; and the MCP surface stays deliberately tiny - three tools with one-line descriptions, because descriptions live in every client session and that is where token savings start.

Against alternatives the positioning is candid: OpenMemory and MemGPT/Letta are device-locked or cloud-hosted; memU gets explicit credit for its zero-LLM backend but is called out for letting the LLM generate memory content. MemoryBridge’s bet is that a memory you can audit, freeze, export, and carry - with the cloud drive seeing only ciphertext - is the version you will actually trust with your work.

Watch PyShine on YouTube

Contents