index · all work
03 · desktop app

A private, encrypted desktop app for auditing your days as a founder, student, and human. Claude can read and write all of it.

Year2026
Statusshipped
RoleSolo · design + engineering
Built withReact 19 · TypeScript 5.9 · Electron 41 · Vite 8 · Tailwind CSS v4 · +7
cortex · founder dashboardopen ↗

Live demo. Click Run to load the real app and use it right here, or open it full-screen.

01Overview

I built Cortex to keep my days, coursework, money, and contacts in one private place. The macOS app brings habits, focus sprints, reading, CRM, calendar, finances, and founder metrics into the same dashboard. Data is encrypted locally with AES-256-GCM; Electron safeStorage protects the master key through the macOS Keychain. The local server on port 3456 also serves the dashboard to my phone over Tailscale.

The MCP server gives agents access to the same local API. They can read study material, log a sprint, update a calendar event, or work with the dashboard's other records. Opportunity Radar collects and scores opportunities against an editable profile. Cloud Spend reads AWS and Google billing data into a local ledger, so I can check usage alongside the rest of my finances.

02The problem

Founders and students juggle habits, revenue, deploys, coursework, contacts, and a firehose of opportunities across a dozen disconnected tools, with no single private place to see and audit it all. Cortex is a local-first, encrypted desktop dashboard that unifies those signals and exposes them to an AI agent.

03Highlights
  • Encrypts every data file at rest with AES-256-GCM in a custom binary container (4-byte magic, 2-byte version, per-write 12-byte IV, 16-byte GCM auth tag). The 32-byte master key is sealed with Electron safeStorage (Keychain-backed on macOS), and a one-time migration rewrites any plaintext JSON to ciphertext behind a sentinel guard.
  • The MCP server in mcp-server/src/index.ts proxies the localhost:3456 API for habits, books, CRM, calendar, finance, coursework, and founder metrics. It supports stdio and an optional HTTP transport.
  • Three-tier persistence hook: Electron IPC to encrypted JSON, then the HTTP web API, then localStorage, with size-adaptive debounce (150/500/1000ms) and batched queueMicrotask writes. The web server socket is IP-gated to localhost and the Tailscale CGNAT range (100.64.0.0/10).
  • Opportunity Radar runs from scripts/ on a launchd schedule. Native feed collectors supply candidates to a classifier with no tool access; hunt orders steer the search, and normalized application URLs, titles, and hosts prevent duplicate records.
  • A KeepAlive watcher daemon turns a 'Run radar' button press into a full pipeline run by polling a runStatus flag over the HTTP API every 5 seconds. It is decoupled from Electron and self-heals stale runs after 45 minutes, so it needs zero app-code changes.
  • Cloud Spend keeps 13 months of AWS Cost Explorer and Google BigQuery billing data in an encrypted local ledger. Usage, credits, budgets, service totals, and source health stay visible together.
04By the numbers
256-bit authenticated encryption
3
persistence paths
13
months of cloud cost history
2
MCP transports
◆What's inside6 parts
  • cortexapp

    The Electron 41 + React 19 macOS desktop app: around 20 feature modules (daily, habits, founder, CRM, finances, courses, GTM) on an OLED-black Tailwind v4 UI, persisted through Electron IPC, then the HTTP API, then localStorage.

  • cortex-mcp-servermcp

    MCP access to the app's local API for study, habits, journal, contacts, calendar, GTM, and founder metrics over stdio or HTTP.

  • opportunity-radarworker

    Native feed collectors, a classifier with no tool access, an editable profile, and deduplication before opportunities enter the app.

  • electron main (:3456 web server)service

    The Electron main process owns the encrypted data directory, the tray, and context-isolated preload IPC, and runs a Tailscale-gated HTTP server on port 3456 that serves the same dashboard as a PWA to the phone.

  • crypto container (electron/crypto.ts)library

    Encrypts every data file with AES-256-GCM in a custom binary format (CTX1 magic, version byte, 12-byte per-write IV, 16-byte auth tag), keyed by a 32-byte master key held behind Electron safeStorage and the macOS Keychain.

  • integrations (electron/integrations)library

    Founder-metric clients for GitHub, Lemon Squeezy (MRR), Vercel, Supabase, the Mars Obsidian journal vault, and Paperclip, feeding the weekly-audit rollup shown in the UI and over MCP.

·Tags
desktop appMCPlocal-firstpersonal dashboardencryptionautomation
Full tech stack 12
React 19TypeScript 5.9Electron 41Vite 8Tailwind CSS v4shadcn/uiRechartsZustandModel Context Protocol SDKNode.jslaunchdSupabase