I gave the same caregiver prompt to my app three times and got three very different answers.

"What's the plan for tomorrow's clinic visit?"

Answer 1 — No Memory. Safe, and useless. It can't tell me the appointment time, who's driving, or what to bring, because it knows nothing about this family.

Answer 2 — Raw Memory. Detailed, and unsafe. I dumped every stored note into the prompt, so the model happily surfaced a routine we dropped weeks ago, let contradictions slip through, and echoed a private insurance ID straight into the reply.

Answer 3 — ERINYS + Qwen. Detailed and safe. Only governed context reached the model, every memory that made it in came with a stated reason, and the three private identifiers I planted never appeared.