R
Ravenwood

Welcome to Ravenwood.

We run our AI on hardware we control ourselves — deliberately small, not the sprawling data centres the industry is burning power and water on. That means we decide what happens to your information: your chats stay on your phone, we never sell them, and we never use them to teach the AI.

Aerial view of terraced planting on a green roof

Two products, one way of building

01 — Products
Budulai icon Assistant — iPhone & Mac

Budulai

The private AI assistant that actually does things. It runs your Mac from your phone, carries multi-step Flows through to the finish, and compiles cited Deep Research.

Read more →
Techlepathy: live Mac control from your phone
Approve-first plans, reversible actions
Conversations live primarily on your device
Hormone Helper icon Health — iOS, 5.0 rated

Hormone Helper

HRT that does not run out. Seven moving parts — supply, prescription, labs, pharmacy, insurance, paperwork, calendar — collapsed into one number: days of runway.

Read more →
Photograph the label, read on-device
Drafted refills, lab orders and records letters
Discreet mode ships on by default
02 — How it works

Why your question takes a trip, and your life stays home.

An AI model is a very large piece of machinery — far too big and too power-hungry to live inside a phone. So the phone doesn't do the thinking: it sends the question to a machine that can, and gets an answer back. That is true of every AI app you have ever used. The difference is who controls that machine, and how big it has to be. We run modest hardware of our own rather than renting space in a hyperscale data centre — so nobody else sets the rules about your information, and answering your question does not cost a town's worth of power and water.

{{ st.n }}
{{ st.title }}
{{ st.body }}
The whole of it
Your phone
question →
← answer
Our hardware
Stays on the phone
Chat history Health & calendar Photos & files Contacts
Makes the trip
Your words Context to answer them Files you attach
excerpt kept ≤ 30 days, then deleted
Think of a photo lab. You hand over one negative, you get the print back, and they keep a numbered stub for a month in case something went wrong with the order — never the album, and never sold to anyone. The exact retention list.

What we won't do

03 — Principles
{{ pr.title }}

{{ pr.body }}

Research

04 — Research

Running our own inference as a two-person company is a stack of unglamorous problems. We publish what we learn — including the questions still open. All research notes.

{{ r.meta }}
{{ r.title }}
{{ r.body }}

Serious AI, from a company that isn’t selling you.

Privately hosted models, plain-language plans before anything happens, and a retention list we publish in full.

R
Ravenwood

Powerful AI from a company that cares about the environment and leaves your data alone.

© 2026 Ravenwood Tech LLC — privacy-first by design
R
Ravenwood
Budulai logo Budulai
For iPhone & Mac — now in early access

The private AI assistant that actually does things.

Budulai doesn't stop at the answer. It runs your Mac from your phone, carries multi-step work through to the finish, and compiles cited research — on privately hosted models, with your approval at every step.

Free to start · no card required

A man outdoors among tall trees, looking up from his phone

Most assistants stop at the answer. Budulai keeps going until it's done.

{{ p.title }}

{{ p.body }}

Meet Techlepathy

Control your Mac from your phone.

A live view of your desktop in your pocket. Hand Budulai a job and watch it open apps, type, click and finish the work — then tap in to take over whenever you want.

{{ t }}
Techlepathy pairing screen listing file search, remote commands, screenshots and app control
What it can reach
Add Device screen with Budulai Agent, password and SSH key connection methods
Three ways to connect
Autonomy settings with ask, always and never for sending email, controlling the Mac and running shell commands
Ask, always, or never — per capability
You approve, it runs

Nothing happens without your say-so.

Before Budulai touches anything it shows the plan — every step, in plain language. Approve it, change it, or stop it. Risky actions ask twice, and actions can be undone.

Set every capability to ask, always or never — and destructive commands stay blocked even on “always.”

One tap, whole workflows

Flows

Multi-step automations that gather what they need, think it through, and deliver the result where you want it. On a schedule, or with one tap.

Pick one
Ready-made for work, marketing, home and development.

Choose a flow and it configures itself, or describe what you keep forgetting to do and Budulai builds one around it.

Work flows: automate job search, build a resume, write cover letters, send invoices
See it first
Every step is listed before it ever runs.

You see what a flow will read, what it will do, and when it will run — with a switch to turn it off at any point.

AI Fitness Coach flow with four steps, running daily at 6:30 AM

It already knows your day

Budulai works with what's on your iPhone — privately, and only with the permissions you grant.

{{ e.title }}

{{ e.body }}

Connections settings with toggles for phone control, calendar, reminders, notifications, location and Apple Health
Every connection, on your terms
Privacy, stated plainly

Privacy-first, and honest about the difference.

Budulai runs on a model we deploy and maintain on infrastructure Ravenwood operates, so no big-tech platform sees your conversations. We keep a small amount of operational data briefly to keep the service safe and working — and we say exactly what, for how long, on the security page.

{{ pv }}

Start free. Grow when you're ready.

Every tier is private by design. No ads, no data sales — ever.

{{ t.name }}
{{ t.price }} {{ t.per }}
{{ it }}
Join the waitlist

It doesn't just answer. It acts.

Join the waitlist and be among the first with an assistant that finishes what you start.

Join the waitlist
R
Ravenwood

Powerful AI from a company that cares about the environment and leaves your data alone.

© 2026 Ravenwood Tech LLC — privacy-first by design
R
Ravenwood
Hormone Helper icon Hormone Helper
Hormone Helper — iOS, 5.0 on the App Store

Running out is not an option. So it plans.

Seven things decide whether you keep your HRT: what's left, when the prescription ends, blood tests, pharmacy delays, insurance approval, paperwork, and the calendar. Hormone Helper works backwards from your last covered day and turns all seven into one number — days of runway — then drafts the messages that keep it from running down.

Free for three days, then $29.99 / year

A person checking Hormone Helper on their phone outdoors
Hormone Helper daily check-in screen
The daily check-in
Hormone Helper body tab showing a month of logged days
The long record
Photograph the label and the app reads the name, strength and dose
Photograph the label

Other apps record what already happened.

A gap in HRT is not a missed vitamin. Everything in the app computes backwards from never running out — and it warns you about what is about to break, not what already did.

{{ p.n }}
{{ p.title }}

{{ p.body }}

What it does

One number, and the math behind it.

The app opens by telling you how many days of medicine you have, and shows the chain that produced it — no black box. Three drafts wait in a queue: approve, read, or hold. Holding is a first-class choice, and the best empty state is nothing needing you at all.

{{ c }}
Reminder settings for doses, refills before they run out, and blood tests
Refills, before they run out
Setup
Photograph the label. It reads it.

Typing a regimen is where setup dies. Vials, pharmacy stickers and handwritten compounding labels all parse — read on the phone, never uploaded, photo deleted once the fields fill. Every field is flagged read, matched or check, so the one uncertain value is called out instead of buried.

Reconciliation
Nobody adds a med on day one.

People add their medicine on day 41, having taken a dose that morning. Assume day one and every number downstream is wrong — so before saving, the app asks how long you have been on it and what you took today. The count is right from the start.

Paperwork

Nineteen institutions, one identity record.

If the pharmacy still has your old name, they can turn you away even when everything else is in order. The app keeps one record and drafts a letter for every place that has not caught up — starting with the counter that quietly blocks pickups.

Paperwork tab listing eight institutions still holding the old name, pharmacy first
Eight places, pharmacy first
Safe mode

Not everyone is out.

Discreet mode is not a blur or a passcode screen — it is a working notes app. Long-press the title to come back. Safety is a default here, not a premium tier.

Safe tab with discreet mode, unlabeled notifications and on-device label reading
The Safe tab
Support screen listing trans-run and LGBTQ+ helplines
Lines that pick up, trans-run first
Discreet mode showing a working notes app
Discreet mode, in the open
{{ s.title }}

{{ s.body }}

Budulai, inside the app

An assistant that answers from your own logs.

Not a chatbot bolted to the side. Budulai writes the daily brief, drafts every message in the queue, and answers "what breaks first?" with the actual dependency — from your records, not a search engine. Educational support, explicitly not medical advice, and nothing sends itself.

{{ d }}

Never lose your medicine again.

Free for three days, then $29.99 a year — about $2.50 a month.

Get Hormone Helper
R
Ravenwood

Powerful AI from a company that cares about the environment and leaves your data alone.

© 2026 Ravenwood Tech LLC — privacy-first by design
R
Ravenwood
An empty Ravenwood meeting room with a long table and plants
Research & open questions

What we're working on, and what we don't know yet.

A small company running its own inference. We publish the problems as we hit them — including the ones still open — because the honest version is more useful to the people who depend on these apps.

Work in progress

Four threads
{{ t.n }} {{ t.status }}
{{ t.title }}
{{ t.area }}

{{ t.body }}

Note coming
How the work gets decided

Every thread on this page started as somebody's real problem — a prescription that nearly lapsed, a plan that ran without being read. We build from those, not from a roadmap.

A Ravenwood engineer working at a laptop against a slatted wood wall

Open questions we would rather ask out loud

Where we need help
{{ q.n }}
{{ q.title }}

{{ q.body }}

Clinicians, pharmacists and privacy counsel: we would like to hear from you. Get in touch.

Nothing about dose timing ships until a prescriber has checked the math. That is the one rule we will not trade for a release date.

How we handle data
R
Ravenwood

Powerful AI from a company that cares about the environment and leaves your data alone.

© 2026 Ravenwood Tech LLC — privacy-first by design
R
Ravenwood
Security & data handling

Privacy-first, not "zero-retention." Here's the difference.

Your conversations live primarily on your device. The AI runs on hardware we operate ourselves. We keep a small amount of operational data for a short, defined period to keep the service safe and working — and we would rather tell you exactly what that is than round it down to zero.

The life of one request
You send it
Encrypted on your device, TLS 1.2+ with certificate pinning.
Our infrastructure answers
Our model, our hardware. No public AI service, no third-party provider.
A short excerpt is held
A preview plus timestamp and counts, for abuse prevention only.
≤ 30 days
Deleted
Your conversation stays on your device. Never sold, never used for training.

How inference works

{{ i.title }}

{{ i.body }}

What we retain, and for how long

{{ r.what }}
{{ r.detail }}
{{ r.period }}

We do not sell your personal information, and we do not use your conversations to train, fine-tune or improve AI models. Content flagged by automated safety systems or reported by users may be reviewed and held longer where that is necessary to investigate abuse or comply with law.

Processed on your device

Read on the phone and included as context only when relevant. The raw data is not stored on our servers.

{{ d }}

Controls in the app

{{ c }}

Questions about your data?

We answer privacy requests within thirty days.

Contact us
R
Ravenwood

Powerful AI from a company that cares about the environment and leaves your data alone.

© 2026 Ravenwood Tech LLC — privacy-first by design
R
Ravenwood
Contact & early access

Get in, or get in touch.

Budulai is in early access for iPhone and Mac. Hormone Helper is on the App Store today. A person reads everything sent to these addresses.

Waitlist
Join Budulai early access

Send us your name and we'll email you when a spot opens. Free to start, no card required.

{{ statusLine }}

{{ c.label }}
{{ c.address }}

{{ c.body }}

Ravenwood Tech LLC

An Oregon limited liability company.

Privacy requests

Access, correction, deletion and portability requests are answered within thirty days. See the security page.

Sponsorships

Companies and clinics can fund Hormone Helper subscriptions for people who cannot pay. Sponsors never see user data.

R
Ravenwood

Powerful AI from a company that cares about the environment and leaves your data alone.

© 2026 Ravenwood Tech LLC — privacy-first by design
R
Ravenwood
← Research
Inference Shipping

Running our own inference stack as a small company

Renting a hosted model would have been faster and, at our volume, probably cheaper. We chose the harder path because the alternative meant handing every conversation to a company whose business depends on knowing things about people.

The decision

The default for a small team is obvious: call somebody else’s API, ship in a week, worry about it later. The problem is that "later" never comes with leverage. Once your product depends on a provider, their retention policy is your retention policy, their terms of service are your privacy promise, and any change they make lands on your users without your consent.

So we operate the stack ourselves. We deploy the model, tune the serving layer, own the hardware budget, and answer for every byte that touches it. That is a real cost, and it shows up in three places: capacity, latency and the number of hours two people can spend on infrastructure instead of product.

Capacity planning without a hyperscaler

Hosted providers hide the awkward truth that inference capacity is lumpy. A model either fits on the accelerator you have or it does not, and the gap between "comfortable" and "queueing" is much narrower than a dashboard suggests. Our planning is deliberately conservative:

We size for the busy hour, not the daily average — assistants are used in bursts, mostly morning and evening.
We keep headroom for the long requests. Deep Research and multi-step Flows run far longer than a chat turn and will happily consume a queue.
We degrade honestly. When we are saturated the app says so, rather than silently getting slower or falling back to somebody else’s cloud.

The rule we will not break: there is no cloud fallback. If our capacity runs out, the answer is a wait or an apology — never a quiet hop to a third party.

Cost per answer

Owning hardware turns a variable cost into a fixed one, which is uncomfortable early and pleasant later. Below a certain volume we are paying for silicon that idles. Above it, every additional answer is nearly free, and our margin stops being a function of somebody else’s price list.

That shape is why the pricing is what it is. Free tiers are limited not to upsell you but because a free request costs us real electricity on a machine we bought. We would rather be transparent about that than pretend it is magic.

What it cost us

Debuggability, mostly. A managed provider gives you dashboards, traces and someone to page. We gave that up, and we also chose not to keep the transcripts that would make debugging easiest. Diagnosing a bad answer with a thirty-day excerpt and a latency number is slower than reading the full conversation — and that is the trade we accept in exchange for having nothing worth stealing.

What is next

Better batching for long-running Flows, so a background job cannot starve a person waiting on a chat turn, and a clearer capacity signal in the app. We will publish the numbers once they are stable enough to be worth publishing.

All research Get in touch
R
Ravenwood

Powerful AI from a company that cares about the environment and leaves your data alone.

© 2026 Ravenwood Tech LLC — privacy-first by design
R
Ravenwood
← Research
Agent safety Shipping

Approve-first actions, and undo after

Every real-world action Budulai takes is shown as a plain-language plan before it runs. What we learned is that people read the first step, skim the second, and trust the rest — which changes how you have to design the whole thing.

The premise

An assistant that can send email, move files and drive a Mac is only safe if the person stays in the loop. The obvious answer is a confirmation dialog. The obvious answer is also useless, because a dialog that appears every time is a dialog nobody reads.

So we ask a narrower question: what is the smallest number of moments where a human decision genuinely changes the outcome, and how do we make those moments impossible to skim past?

What people actually read

Watching real approvals, the pattern was consistent. The first line gets read carefully. The second gets read. Anything past step three is scanned for a familiar shape — an app name, a file name — and approved on vibes. Length is not the problem; position is.

Plans are ordered by consequence, not chronology. The step that sends, deletes or overwrites is surfaced first, even if it happens last.
Every step names its object in the user’s own words: "Q2 Invoices.pdf from your Desktop", not "the attachment".
Steps that only read something are visually quieter than steps that change something.

A plan that lists ten equally weighted steps is not transparency. It is an invitation to press Approve.

When to ask twice

Some actions cannot be walked back: an email that has left, a file that is gone, a message posted somewhere public. For those, one approval is not enough, and a second identical dialog is just friction. The second prompt has to add information — who exactly is receiving this, what exactly is attached — so that confirming requires reading something new.

Destructive shell commands are handled differently again: they are refused outright by a safety filter before they ever reach an approval screen, even for people who have set that capability to "always".

Undo is a feature, not an apology

Approval is a prediction; undo is a correction. Anything reversible ships with the reversal built in — a draft returns to drafts, a moved file goes back, a scheduled Flow can be unscheduled mid-run. Making undo cheap is what lets us keep the approval flow short: you do not need to interrogate a plan when getting it wrong costs one tap.

Open question

We still do not know the right default for people in their first week. Ask about everything and the app feels bureaucratic; ask about less and you are teaching someone to trust a system they have not yet seen work. Right now we start cautious and let people loosen it. We are not certain that is correct.

All research Get in touch
R
Ravenwood

Powerful AI from a company that cares about the environment and leaves your data alone.

© 2026 Ravenwood Tech LLC — privacy-first by design
R
Ravenwood
← Research
Health planning Prototype

Seven variables, one number

Whether someone keeps their HRT depends on supply, prescription expiry, lab timing, pharmacy delays, insurance approval, paperwork and the calendar. Hormone Helper collapses all seven into a single figure — days of runway — and then shows its work.

Why one number

Ask someone on long-term hormone therapy what they are worried about and the answer is never "my adherence rate". It is "am I going to run out". Every existing tracker answers a different question — what did you take, did you take it on time — which is a record of the past when what people need is a forecast.

So the app opens with a forecast: how many days of medicine you have, given everything currently known. One number, in plain language, on the first screen.

The seven inputs

Supply on hand — counted from doses logged, not estimated from a start date.
Prescription validity — the date your authorisation lapses, which frequently arrives before the vial empties.
Lab timing — a required panel that has not been drawn can block a renewal entirely.
Pharmacy lead time — including compounding, which is measured in days rather than minutes.
Insurance authorisation — the slowest and least predictable link in the chain.
Paperwork — a name or gender marker mismatch that stops a pickup at the counter.
The calendar — weekends, holidays and the appointment you have not booked yet.

The runway is the shortest of the seven, not the average. One blocked dependency is a gap, no matter how healthy the other six look.

Against the black box

A single number is only trustworthy if you can see where it came from. Tap the figure and the app shows the chain: which input is currently binding, what would extend it, and how many days each fix would buy. A prediction people cannot audit is a prediction they will ignore the first time it disagrees with them.

Calm, not alarming

Low supply is an amber flag with a suggested action, never a red alert. The people using this app are frequently already anxious about access, and an interface that panics on their behalf makes the situation worse rather than more manageable. The best empty state here is nothing needing you at all.

Still open

The math needs clinical review before real regimens depend on it, and how much of the chain can be genuinely automated depends on pharmacy and lab integrations we do not have yet. Until then, the app drafts the messages and you send them.

All research Get in touch
R
Ravenwood

Powerful AI from a company that cares about the environment and leaves your data alone.

© 2026 Ravenwood Tech LLC — privacy-first by design
R
Ravenwood
← Research
On-device parsing Prototype

Reading a medication label on the phone

Typing a regimen is where setup dies. Photographing the vial should replace it — but only if the app is honest about which fields it actually read and which ones it guessed.

The setup problem

Every health tracker asks for the same thing up front: medication, dose, concentration, frequency, route. It is five fields of pharmacological detail entered by someone who just wants the app to work, and it is where most people abandon the process entirely.

The label already has all of it. So the first screen is a camera, and everything else is a fallback.

Three kinds of label

Manufacturer vials — printed, consistent, and by far the easiest case.
Pharmacy stickers — variable layout, small type, frequently curved around a bottle and partly obscured by a cap.
Compounding labels — sometimes handwritten, often the ones carrying the most unusual concentrations, and the case where a wrong reading matters most.

Read on the phone, then deleted

Parsing happens on the device. The photo is never uploaded, and it is deleted once the fields are populated — a medication label is an identity document, a diagnosis and a pharmacy record in one image, and there is no version of storing it that we are comfortable with.

The photo exists for as long as it takes to fill in five fields, and not one second longer.

Per-field confidence

The interesting design problem is not accuracy, it is uncertainty. A parser that returns five fields silently is dangerous, because the one it got wrong looks exactly like the four it got right. So every field carries a state — read, matched or check — and the interface pulls the uncertain one to the top rather than burying it in a filled-in form.

In practice concentration is the field that most often needs a human. Handwritten decimals and unfamiliar units are where the parser is least sure, and that is precisely the value that determines every dose calculation downstream.

Reconciliation

Nobody adds a medication on day one. They add it on day forty-one, having taken a dose that morning. Assume day one and every number downstream is wrong — so before saving, the app asks how long you have been on it and what you took today. Two questions, and the count is correct from the start.

Still open

Handwriting remains the weak point, and we have not yet decided how far to push on-device recognition versus simply asking. Asking is unglamorous and always correct; we are inclined to keep asking until the parser earns the benefit of the doubt.

All research Get in touch
R
Ravenwood

Powerful AI from a company that cares about the environment and leaves your data alone.

© 2026 Ravenwood Tech LLC — privacy-first by design