Talorys is an open-source personal AI agent built for Cloudflare's free plan

Talorys is a free, open-source personal AI assistant that, according to its GitHub README, runs entirely inside the user's own Cloudflare account. It chats with you, remembers what matters, manages tasks, notes and projects, and runs reminders and routines on a schedule, all without any server, database or account operated by the Talorys developers. The pitch is four short lines: one person, one Cloudflare account, one command, one personal AI agent. The command is npx create-talorys@latest.
The feature list is compact. Chat streams responses and shows Markdown and tool activity indicators. Memory holds durable personal facts and preferences that you can view, edit and delete, and only the most relevant memories are sent to the model on each turn. Tasks, notes and projects have full create, read, update and delete in the UI, and can also be driven from chat, for example 'Add a task to review my project tomorrow'. Automations cover one-time and recurring reminders, daily task digests and optional AI routines, delivered to an in-app notification center; they run on Durable Object alarms, so nothing has to stay online. The tool is single-user by design: no signup, no accounts, no teams, and the installer sets the owner password. Tasks, notes, memories and reminders keep working if Workers AI is unavailable or the free quota is used up.
The architecture is a short chain. The browser talks to a Cloudflare Pages site (a React app plus an /api Pages Function). The Function forwards requests over a service binding to a private Worker built on the Hono router, which calls TalorysAgent, a Cloudflare Agents SDK Durable Object. That object keeps conversations, memories, tasks, notes, projects, automations, sessions, settings and usage in SQLite, calls the Workers AI model @cf/zai-org/glm-4.7-flash for streaming and tool calling, and uses alarms for reminders and recurring schedules. The agent Worker is deployed with workers_dev set to false and preview_urls set to false, so it has no public URL. Authentication and authorization happen in the Worker, not the frontend, and chat responses stream as Server-Sent Events end to end. Talorys does not provision R2, D1, KV, Vectorize, AI Search, Workflows or any paid service.
The installer does most of the work. It checks for Node.js 22 or newer and uses its bundled Wrangler CLI, verifies your Cloudflare login or opens Cloudflare's authorization page, and lets you pick an account and an agent name. It asks for an owner password (hidden input, strength-checked), hashes it locally with PBKDF2-SHA256 and stores it only as a Cloudflare secret. It generates a 256-bit session secret and unique resource names (talorys-
On cost, the README is explicit that this is not unlimited free. Talorys is designed to fit the Cloudflare Workers Free plan and never enables paid features on its own, but free plans carry account-level quotas (requests, Durable Object usage, a daily Workers AI Neuron allocation) that Cloudflare sets and can change. When the AI allocation runs out, chat shows a clear message and resumes after the daily reset while everything else keeps working. If the account is on a paid plan, usage beyond included amounts is billed by Cloudflare under that plan. Built-in guardrails, adjustable in Settings β AI, cap max output tokens, max context tokens (older history is summarized), max tool calls and reasoning steps per request, max AI requests per day and max scheduled AI runs per day. Simple reminders and task digests never use AI, and a Usage panel shows local estimates with links to the Cloudflare dashboard for exact Neuron usage.
On privacy, all data sits in a single SQLite-backed Durable Object named personal-agent in the user's Cloudflare account. The README says Talorys has no telemetry, analytics, tracking or advertising code and sends nothing to its developers, while noting that Cloudflare processes the data to provide its services, including Workers AI inference on chat messages and the relevant memories included in each prompt. Settings β Privacy β Download backup produces talorys-backup.json with conversations, memories, tasks, notes, projects, settings and automations, never sessions or credentials; import validates the file and merges it in one transaction, and importing the same backup twice is harmless.
Day-two operations are one-liners too. npx create-talorys@latest update redeploys the latest Worker and frontend to the same resources; the Durable Object namespace is never recreated (migrations are append-only), the owner password and sessions are kept, and schema migrations run automatically and transactionally on first request. status and doctor commands exist, and reset-password replaces the password secret and signs out every device. For development, git clone, npm install and npm run dev start the agent Worker (port 8787), the Pages Function proxy (port 8788) and the Vite UI (localhost:5173) in one terminal, with a deterministic mock AI provider and a local dev password, so no Cloudflare login is needed. The repository is a monorepo with apps/agent, apps/web, packages/shared, packages/create-talorys, Playwright end-to-end tests and docs.
Key facts
- Talorys is a free, open-source, single-user personal AI assistant installed with npx create-talorys@latest into the user's own Cloudflare account, with no server or account run by its developers.
- It runs as a SQLite-backed Cloudflare Agents SDK Durable Object that stores conversations, memories, tasks, notes, projects and automations, and uses the Workers AI model @cf/zai-org/glm-4.7-flash for chat and tool calling.
- It is designed to fit the Cloudflare Workers Free plan and never enables paid features itself, but the README says it is not unlimited free: Cloudflare's quotas, including a daily Workers AI Neuron allocation, still apply.
- Tasks, notes, memories and reminders keep working when Workers AI is unavailable or the free quota is used up; chat resumes after the daily reset.
- The installer hashes the owner password locally with PBKDF2-SHA256, generates a 256-bit session secret, and deploys a private Worker with no public URL behind a Pages Function.
Why it matters
Most personal AI assistants are hosted services, which means your notes, tasks and chat history live in someone else's account. Talorys takes the opposite route: everything is deployed into a Cloudflare account you control, and the README states that the Talorys developers operate no server, database or account and receive nothing from installations. It also targets the Cloudflare Workers Free plan, so the barrier to running a private agent is one npx command and a free account rather than a monthly subscription. The design choice to keep non-AI features (tasks, notes, memories, reminders) working when the AI quota is exhausted is a practical answer to the free tier's main limit.
Who it affects
Individual developers and technically comfortable users who already have, or are willing to create, a Cloudflare account and want a private assistant they own. The tool is single-user by design, with no signup, accounts or teams, so it is not aimed at groups or organisations that need shared workspaces. Installation needs Node.js 22 or newer.
How to use it
Run npx create-talorys@latest and follow the prompts: confirm your Cloudflare login, choose an account and agent name, and set an owner password. The installer deploys the Worker and Pages project and prints the pages.dev URL; open it, sign in with the password and start chatting. Keep the generated talorys/ directory, because updates, status checks and password resets run from it (npx create-talorys@latest update, status, doctor, reset-password). For unattended installs, set TALORYS_OWNER_PASSWORD and pass --yes and --account-id, with CLOUDFLARE_API_TOKEN if you are not logged in. Usage limits can be tuned under Settings β AI, and Settings β Privacy β Download backup exports your data. To try it without touching Cloudflare, clone the repo and run npm run dev, which uses a mock AI provider.
How solid is it
The evidence is the project's own README, which describes the design, installer steps and guardrails in concrete detail, including a test suite (unit, Playwright end-to-end and an optional real-account smoke test) in the repository layout. The README names no author beyond the rociiu account in the clone URL. It gives no release date, version number or license name (it is only called open-source), and no benchmarks, performance figures, user counts or GitHub stars. Security is described only in docs/security.md, which is not part of the README, and no independent security audit is mentioned. Treat the privacy and no-telemetry statements as the project's claims, not as verified findings.
Risks and caveats
Free does not mean unlimited: quotas on requests, Durable Object usage and the daily Workers AI Neuron allocation are set by Cloudflare and can change, and the README gives no numeric figures for them. Accounts on a paid plan are billed by Cloudflare for usage beyond included amounts. Your chat messages and the relevant memories included in each prompt are processed by Cloudflare through Workers AI, so the data is in the user's account but not hidden from the platform. The README documents a single Workers AI model in its architecture and mentions no support for other models. The owner password is the single gate to the agent; if it is lost, reset-password replaces it and signs out every device.
βOne person. One Cloudflare account. One command. One personal AI agent.β
β Talorys README