Iva: a personal assistant with memory, running on your server
Iva is a personal assistant that runs on your own server and communicates through Telegram. It remembers what you discussed in previous conversations. Before you send real work data its way, it is worth understanding how it is built and where the limits are.
Iva is Majento's own open-source project, built by our team. This breakdown is based on the public code of the smixs/iva-agent project, tag v0.4.10, checked on September 29, 2026. This is an analysis of code and documentation only. No load testing or security audit was performed.
How Iva receives messages and where data goes
Messages arrive through Telegram. The bot checks the messenger on its own schedule, asking whether there is anything new. You do not need a public web address, a domain name, or a security certificate for your server. Iva reaches out for messages instead of waiting for incoming traffic.
That does not make it fully isolated. Your requests and any attachments travel to the external AI models and services you configure. Running on your own server gives you control over where data is stored and how the system is set up. It does not guarantee that nothing leaves your network.
Iva runs on a Linux server, including a rented virtual private server (VPS, a remote computer you lease by the month). It starts automatically as a background service when the server turns on. Installation is documented at iva-agent.com and in deploy.md. Do not expect a ten-minute setup without preparation. Some steps require careful attention.
How Iva stores and updates memory
Iva's memory lives in plain text files in markdown, a simple formatting style that any text editor can open. The core records are ordinary files on disk. You can open them, read them, copy them.

The structure is straightforward. Daily notes sit at the bottom, then summaries rolled up by day, week, month, and year. Separate cards cover people, projects, and decisions. A short CORE file holds working rules that the assistant re-reads at the start of every conversation.
Each night an automated process runs. It reads new notes, asks the AI model to suggest edits to existing cards, reviews those suggestions, and writes them in. Facts are appended with a date and a source. The current description of a card may be updated while the previous version is preserved.
If you edited a card manually at the same time, the automatic update is held back. That reduces the risk of overwriting your changes. Still, the model's conclusions are not guaranteed to be accurate. It can make mistakes, and that is worth keeping in mind.
Memory search works two ways: by keywords, using SQLite FTS5, a built-in text search engine, and by connections between cards. Semantic search, where you write something like "that conversation about the supplier deal" rather than an exact phrase, is available but requires separate configuration. Git, a system that saves versions of files, records significant changes in a dedicated memory repository. Not every message, but meaningful updates are tracked.
All memory files can be read, copied, and backed up by you directly. They belong to you.
What you can ask Iva to do: text, voice, images
The primary mode is text. You write in Telegram, for example: "draft a short note to our partner about moving the meeting to Friday - he usually prefers a formal tone." The card for that person can give the assistant the context it needs to write something appropriate.
Voice messages work too. An external speech-recognition service converts the audio to text, then normal processing takes over. Quality depends on the provider, and not every language is supported equally well.
Images are a separate case. You can send a picture directly to the model if that model supports image input, or route it through a dedicated description service. Both options may carry their own costs. Images sent directly to the model bypass the text filter applied to incoming messages. Worth keeping in mind.
What you can configure with a file, and what requires code
A skill file is a rules document the AI reads before handling a specific type of task. Think of formatting rules for outgoing emails or a template for processing incoming requests. Skill files are written in markdown and take effect with the next message. No restart needed.
Adding a new tool or an MCP connection, a protocol for linking external services to an AI agent, requires programming work and a rebuild. You cannot add an integration with a markdown file alone.
On the external integrations side: web search is enabled by configuring a provider. Google Mail, Calendar, and Drive require a separate authorization step. Personal accounts are not connected automatically. Full details are in extending.md.
How to build skill files for repeating tasks is covered in our article on reusable AI agent skills. The difference between an agent and a regular chatbot is explained here.
Who has access and where the risks are

Access is controlled by a list of permitted Telegram accounts. Each account is identified by a numeric user ID. An empty list blocks all access.
Iva is a personal assistant with one shared memory per installed instance. There are no built-in isolated spaces for different employees or clients. Give several people access and all of them will read from and write to the same memory.
The shell tool, which runs commands directly on the server, operates with the permissions of the user account running the process. Passwords and keys stored in the .env configuration file may be passed to programs it launches. The recommendations in security.md are: restrict system-level permissions, connect only the accounts you actually need, and test on non-sensitive data first.
The software includes filters on incoming text and some protection against secrets leaking outward. Detection of harmful instructions is limited.
How to structure access controls in AI systems for a team is covered in a separate article. The topic of a shared team agent has its own breakdown.
What the costs look like
Iva's code is released under the MIT license. The software itself is free.
You will pay for three things: server rental, AI model usage, and any external services you choose to connect (speech recognition, image processing, search, and so on). Whether you pay a flat subscription or per request depends on the provider and the volume of work.
Specific numbers are left out on purpose. They change, and your real budget depends entirely on what you use it for. The practical way to estimate costs is to measure them on your own tasks: run the system on a small workload and check the usage figures after a week.
How to get started
The starting point is iva-agent.com and the deployment documentation. All installation steps are described there.
A few practical notes before you begin. Read each installation command before running it, and limit the system permissions of the process. Keep a separate backup of the memory folder. Connect external integrations one at a time, confirming the basics work before adding more.
If you want to understand how an AI agent fits into a small company's workflows more broadly, start here.
Common questions
Does installation require a technical specialist?
Installation involves working with a Linux server and a command line. If you have never done that before, you will likely need help. The documentation is detailed but written for someone who has at least basic familiarity with servers.
Does data stay only with me?
Memory files are stored on your server. Requests sent to the AI model and any attachments go to the external providers you choose during setup. There is no complete isolation. What you do have is control over which services are connected.
Can I give my team access?
Technically yes, through the list of permitted Telegram accounts. This is a single instance with shared memory. There are no isolated spaces per person. For team use, read the team agent breakdown first.
How do I figure out what it will cost?
Costs come from server rental, AI model usage, and external services if you connect speech recognition, image processing, or search. Many providers charge based on tokens, small fragments of text that the model breaks requests and responses into when processing them. The clearest picture comes from practice: run your typical work tasks for a week and check the usage counters in your provider dashboard.
Questions about implementation, or want to talk through whether Iva fits your situation - reach out on Telegram @shimaoz or at hello@majento.ai.