goaldrift
Back

Bring your own key: the case for it

12 February 2026 By goaldrift 5 min read

An old brass padlock lying open on a wooden table.

Most apps with an AI feature in them work the same way. The company holds an account with a model provider, your request goes through their servers, and you pay them a monthly fee that covers the cost with something on top.

Bring-your-own-key inverts it. You hold the account, the key sits in your browser, and requests go from your machine to the provider. The app in the middle never handles the money and never sees the text.

It's a less convenient arrangement and it's worth the inconvenience for a few specific reasons.

What changes about your data

The main one, and it isn't a promise about privacy — it's a change in what's possible.

In the usual arrangement, your notes pass through the company's servers. Any assurance about what happens to them is a policy, and policies are things a company chooses and can change, particularly under new ownership.

With your own key, your notes go from your browser to the model provider you chose. There's no third party to trust about it, because there's no third party in the path. That's a structural difference rather than a stronger promise, and structural differences survive changes of management.

It also means the answer to how much of my data do you hold is zero. Not encrypted, not anonymised, not retained for thirty days. Absent.

What changes about the money

You pay the provider directly, at cost, for what you use.

For most people that's very little. The kind of request this app makes — a goal, a few notes, a blocker, back with three suggestions — costs a fraction of a penny. Someone using it a few times a week is spending pennies a month, against a subscription that would be several pounds regardless of use.

The heavier consequence is on the other side. An app that resells model access has to charge a subscription, and once there's a subscription there's a business that needs retention, and retention is where a lot of bad product decisions come from. Notifications you didn't ask for. Features designed to be sticky rather than useful. A gentle pressure to make the thing you look at for thirty seconds into something you look at for twenty minutes.

Taking the money out of the middle removes that incentive entirely. There's nothing to retain you for.

That's an unusual thing for a product to want, and worth being plain about. An app you open for thirty seconds and close is a bad business and a good tool, and those two things are usually in tension. Removing the subscription is one of the few ways to resolve it in the tool's favour.

What it costs you

The honest part, because this arrangement is genuinely worse in several ways.

Setting it up is a hurdle. You need an account with a provider, a payment card on it, and a key pasted into a settings box. That's five minutes and a small amount of unfamiliarity, and it will lose a fair number of people at the door. Anyone comparing this to an app where AI simply works is comparing correctly.

You're exposed to the provider's pricing and availability. If they raise prices or change models, that's between you and them.

And key handling is your responsibility. It lives in your browser, which is safer than a lot of alternatives and not the same as a vault. Clearing site data removes it, and pasting it into the wrong box would be your problem.

Worth knowing too that a key can be revoked and replaced in about a minute at the provider's end, and that most providers let you set a spending cap on it. Doing both when you first set it up removes nearly all of the risk people worry about.

There's also a fairness point worth making. Bring-your-own-key suits people who are comfortable getting an API account, and that isn't everyone. An app built this way is quietly selecting for a certain kind of user, and it's better to say so than to pretend the setup is trivial.

When the usual model is right

The counter-argument in full, because it isn't weak.

If AI is the core of a product rather than a small feature, doing it properly requires work the user shouldn't have to think about — routing between models, handling failures, caching, adjusting to provider changes. Hiding that is worth paying for, and a company that does it well is earning the subscription.

Volume matters too. A heavy user of a genuinely AI-centred product may well spend more on their own key than a subscription would cost, because the company's bulk pricing beats retail.

And for most people, five minutes of setup is a genuine barrier to a feature they'd otherwise use. There's no honest way around that.

The case here is narrower. When AI is one button on one goal, used occasionally, on notes that are personal — the setup cost is small, the running cost is negligible, and the data question is the one that actually matters.

One button, one goal

What the feature does is deliberately limited. You press unstick on a goal that's gone quiet. It reads that goal's notes, steps and blocker, and comes back with three moves of thirty minutes or less, plus a line quoted from your own notes so you can tell it read them.

Then it's finished. No conversation, no follow-up, no checking in tomorrow. It's a tool you pick up and put down.

For a request that size, the cost through your own key is fractions of a penny, and the text involved — a few lines about a goal you're avoiding — is exactly the sort of thing there's no good reason to route through anyone else's server.

The key stays in your browser. It isn't included when you export your goals to a file, which is deliberate, because a backup that quietly contains your credentials is a bad backup.

Where this fits with the rest

It's the same argument as the local storage, applied to a different part of the system.

Your goals live on your machine because that's where a personal record ought to live. The model key is yours for the same reason, and the effect in both cases is that this app can stop existing without taking anything of yours with it.

That's a low ambition for a product and a reasonable one for a tool. What's left after we're gone should be your file, your key, and your account with a provider you chose — none of which needed us in the first place.


Related: Local-first software, explained · AI can't want it for you · What we left out of goaldrift, and why

Share: