Talorys packages a personal AI assistant into a single deployment command, placing the application, its stored data and its model access inside the user’s Cloudflare account. There is no Talorys-operated backend to sign up for, according to the project’s repository.
The MIT-licensed software combines chat with persistent memory, tasks, notes, projects and scheduled reminders. Its appeal among AI products is the deployment model: a technically capable user can install an assistant without separately assembling a frontend, database, authentication layer and scheduling system.
That convenience has a specific boundary. Talorys is single-user software built around Cloudflare services, not a provider-independent assistant that the documented installer can place on any server. “Free-tier-friendly” describes its intended usage profile, not a guarantee of unlimited inference or permanently free hosting.
One Command Sets Up the Application and Its Storage
The documented starting point is:
npx create-talorys@latest
The installer requires Node.js 20.18 or newer and bundles Cloudflare’s Wrangler command-line tool. A globally installed copy of Wrangler isn’t required.
“One command” doesn’t mean zero interaction. The installer verifies the user’s Cloudflare login or opens Cloudflare’s authorization flow, lets them choose an account and agent name, and asks for an owner password. It then provisions the application and prints the deployed pages.dev address.
The documented stack has four main components:
| Cloudflare service | Role in Talorys |
|---|---|
| Pages | Hosts the React frontend and a Pages Function that forwards API requests |
| Workers | Runs the agent’s API and authentication logic |
| SQLite-backed Durable Objects | Stores application data and runs scheduling alarms |
| Workers AI | Provides chat inference and tool calling through @cf/zai-org/glm-4.7-flash |
The browser communicates with the Pages site. Requests under /api/ pass through a Pages Function to the agent Worker using a service binding, rather than a separate public API address.
According to the README, the Worker disables both its workers.dev address and preview URLs. Authentication and authorization happen in the Worker, not merely in the browser interface. The Pages site remains the entry point; “private Worker” does not mean the whole application is inaccessible from the internet.
Talorys also says it does not provision R2, D1, KV, Vectorize, AI Search or Workflows. Its persistent store is a single SQLite-backed Durable Object, keeping the deployment relatively compact.
The installer checks the frontend, authentication endpoint, rejection of unauthenticated requests and storage health. It deliberately does not run AI inference during those checks. A successful deployment therefore isn’t, by itself, a test of model responsiveness or chat quality.
Memory and Reminders Extend Beyond the Chat Window
Talorys is designed as a personal organizer with an AI interface, rather than just a chat page.
The documented chat interface supports streaming responses, Markdown and indicators showing tool activity. The assistant can manage tasks, notes and projects through conversation, while those same records remain accessible through conventional interface controls.
Its persistent memory stores personal facts and preferences that the owner can view, edit and delete. The project says only the most relevant memories are included in each model turn. That makes memory both an application feature and part of the inference data flow: selected stored information is sent to Workers AI alongside chat content.
Scheduled functionality includes one-time and recurring reminders, daily task digests and optional AI routines. These use Durable Object alarms, so the user’s browser or computer does not need to stay online. Delivery is to an in-app notification center; the supplied documentation does not establish email, SMS or mobile push delivery.
There is also a useful separation between AI and ordinary application functions. Talorys says tasks, notes, memories and reminders remain available when Workers AI is unavailable or its daily allocation is exhausted. Simple reminders and task digests do not use AI.
That design could make the application less disruptive when inference stops. It does not make the non-AI functions independent of Cloudflare: they still depend on the deployed application, storage service and applicable platform limits.
Users Control the Installation, While Cloudflare Runs It
The project’s strongest ownership claim is that the deployment belongs to the user’s Cloudflare account. Talorys says it operates no server, database or user account behind the installation, and includes no telemetry, analytics, tracking or advertising code.
Those are project claims, not the results of an independent privacy or security audit. The supplied evidence establishes the documented architecture and promises, rather than independently verifying every deployed code path.
The distinction matters because “no Talorys backend” does not mean “no third-party processing.” Cloudflare hosts the application and its SQLite-backed data. Workers AI processes chat messages and the relevant memories included in prompts. This is neither local inference nor storage on hardware controlled by the user.
Within the application, the owner can manage memories, adjust AI limits and revoke sessions. The documented password setup hashes the owner password locally with PBKDF2-SHA256 and stores the hash as a Cloudflare secret. A separate session secret is generated during installation.
Access is deliberately simple: there is one owner, with no signup system, team accounts or separate user roles. Signing in from several devices still means accessing the same owner account. That suits an individual assistant, but it is not a documented multi-user collaboration model.
Early Hacker News discussion focused partly on whether this arrangement should be called “self-hosted.” Commenters disagreed over whether managing software in a cloud account qualifies; some also raised billing concerns. These are reactions from one discussion, not representative user research or independent Talorys testing.
“User-managed Cloudflare deployment” is the more precise description. The user controls the installation and application data without a Talorys-operated service in between, while Cloudflare still controls the underlying infrastructure. The MIT license permits modification, but the documented architecture does not make moving to another provider a simple redeployment.
The Free Tier Has a Daily AI Budget
Talorys says it targets Cloudflare’s Workers Free plan and never enables paid features on its own. That is useful deployment behavior, but the bill depends on the Cloudflare account and its usage, not solely on the installer.
Under Cloudflare’s published Workers AI pricing, both Free and Paid Workers plans receive 10,000 Neurons per day at no charge. Usage beyond that allocation requires paid access; on Workers Paid, excess usage costs $0.011 per 1,000 Neurons. The daily allocation resets at 00:00 UTC.

Neurons are Cloudflare’s compute-based accounting unit. They are not a fixed number of messages or tokens, so the allowance cannot honestly be translated into “this many conversations per day” without assumptions about workload.
For Talorys’s configured GLM-4.7-Flash model, Cloudflare lists equivalent rates of $0.060 per million input tokens and $0.400 per million output tokens. Actual consumption depends on the prompts, included history and memories, generated output, and additional inference involved in tool use or scheduled AI routines.
Talorys documents several adjustable guardrails:
- Maximum output and context tokens, with older history summarized.
- Limits on tool calls and reasoning steps per request.
- Maximum AI requests per day.
- Maximum scheduled AI runs per day.
These controls help bound consumption. They do not reserve a separate Cloudflare allowance for Talorys or override account-level quotas. Other workloads in the same account also matter.
The project says chat displays a clear message when the AI allocation runs out and resumes after the daily reset. Its Usage panel shows local estimates and links to Cloudflare’s dashboard for exact Neuron usage. For billing decisions, the provider’s usage records are the relevant reference.
There are separate limits on requests and Durable Object usage as well. The claim that organizer functions keep working after AI exhaustion should not be read as a promise that they survive every platform quota or outage. Cloudflare can also change its pricing and allowances.
A Quick Install Still Leaves Maintenance to the Owner
Talorys’s low-friction deployment does not remove the need for backups, updates and account oversight.
The installer writes a local talorys/ directory containing deployment artifacts and installation metadata, but no secrets. The project instructs users to retain it for maintenance. From that directory, the documented update command is:
npx create-talorys@latest update
The backup and update instructions say updates reuse the existing resources and preserve the Durable Object namespace, owner password and sessions. The interface can export a JSON backup containing conversations, memories, tasks, notes, projects, settings and automations, excluding sessions and credentials.
Those are useful provisions for early-stage software. They should still be treated as documented behavior, not an independently established reliability record.
Developers can also inspect the application locally. The development documentation describes a local stack using a mock AI provider, with a separate option for real Workers AI access. The mock handles selected intents and otherwise returns an echo response, so local testing alone does not establish production model performance.
Talorys offers a concrete starting point for someone who wants a personal assistant under their own cloud account and accepts responsibility for maintaining it. The meaningful advance is packaging: several Cloudflare services become an installable, coherent application. The tradeoff is equally concrete. Removing the agent vendor’s backend leaves the owner with more control, but still dependent on Cloudflare’s infrastructure, quotas and pricing.
Sources
- project’s repositorygithub.com
- Hacker News discussionnews.ycombinator.com
- Cloudflare’s published Workers AI pricingdevelopers.cloudflare.com
- development documentationgithub.com





