Tonight I spent about three hours discovering that a single backtick character in a configuration value had quietly broken my server. Not loudly. Not with an error message pointing at the problem. The app started, reported itself healthy, and lied to me about where it was storing my data — because the hosting panel builds your settings into a shell script, and one stray character ended that script early, so every setting after it simply never existed. The app didn't know they were missing. It just shrugged and used a fallback.
The equivalent product from a company that does this for a living would have taken four minutes. Sign up, click connect, done. No backtick. No shell script. No evening.
I want to talk about why I keep choosing the evening.
What I Was Actually Building
The thing itself is unglamorous. I ramble — genuinely, at length, and usually about products I'm in the middle of testing. Those rambles are where my articles come from, and for a long time I had no good way to catch them.
I tried dictating into the Notes app. Horrible experience. It kept cutting off after what felt like thirty seconds or a minute, and since I ramble a lot, it just kept stopping and I'd have to start it again. Then I used Voice Memos, which records fine, but then I'd have to take the recording, ask something to transcribe it, ship the transcript to my Mac, and handle it from there. By the time I'd done all that it was the weekend anyway, which is exactly when I used to sit down and try to remember what I'd meant two weeks earlier.
So I built a pipeline. Transcription happens on the phone, on the device, using a local model — nothing is uploaded to be turned into text. A shortcut posts the transcript to a small server I run. That server gives it a title, tags it, counts the words, and files it in a database. I can open a web page later, read everything I've said, and export it.
Every single piece of that is something you could buy, already assembled, for a few dollars a month. And every single piece of that would then live on somebody else's computer.
The Trade Nobody Puts on the Box
Here's the thing I keep running into, and it's the reason I'm writing this instead of just filing a bug report with myself.
When you assemble something out of piecemeal parts, you personally absorb every seam. The parts don't know about each other. Nobody tested this exact arrangement. The failures you hit aren't interesting failures — they're not "the algorithm is wrong," they're "a backtick ended a shell script." Noise, not insight. And there's a lot of it.
When you buy the assembled version, all of that disappears. It just works. But you pay for it, and not only in money. You have to trade your quote-unquote privacy.
- Four minutes to working
- Somebody else fixes the seams
- Someone to call when it breaks
- Your data on their servers
- Their breach is your breach
- An evening, sometimes several
- Every seam is yours to eat
- You are the support desk
- Your data on your hardware
- Your breach requires someone to care about you
I want to be fair to the left column, because it isn't a scam. It's genuinely better engineering than I'm doing. The people building those products are good at this and I'm one guy with a hosting account. What I'm disputing isn't their competence. It's that the second cost — the one at the bottom of the column — never appears on the pricing page, and it's the one that compounds.
You have to trade your quote-unquote privacy. That line is never on the box, and it's the only line that gets more expensive over time.
— The actual price comparisonBlast Radius
The argument I'd make to anyone who thinks this is paranoia is not about trust. I'm not claiming the big providers are careless or malicious. Most of them are neither. The argument is about geometry.
When you use the convenient version, you're not just trusting that company. You're trusting that they'll keep their databases safe, that the traffic between you and them stays safe, that every vendor they in turn depend on holds up, and — this is the part people skip — that nobody, ever, progresses faster than the protections currently in place. That last one isn't a question about their intentions. It's a bet on the future, made on your behalf, with your data as the stake.
And a big provider is a big target, precisely because they succeeded. All that data in one place is worth an enormous amount of somebody's time. Which gets you to the thing I actually believe:
The more centralized the data gets, the more potent the results of that breach will be.
— Not a claim about who's careful. A claim about arithmetic.My server is not a big target. I'd guess most attackers won't even find it, and the ones who do are largely the people who don't have the tools to be dangerous. And if they are dangerous, they still have to get through Cloudflare — whose entire reason for existing is defending data and, you know, selling you domains.
That isn't security through obscurity as a strategy. It's just an honest description of blast radius. When a large service is breached, millions of people are in the dump. When mine is breached, one person is: me. I'd rather be the one-person incident, and I'd rather it be my own fault.
The Oopsie Economy
What pushed me from "mildly prefer" to "willing to spend evenings" was watching what happens after a breach.
A company loses everything about you. And what do they go? Oopsie. Here, let me give you access to this thing that will watch and see if your data comes online. And then you get to go and ask the people who are buying batches of stolen information off the dark web — who I'm quite sure have very high morals — whether they'd kindly remove your data from their listings.
And say they do. Great. Now you wait for the next person who buys the same file. So to stay on top of it, you pay someone a monthly fee, forever, to do the thing that should never have happened in the first place. Meanwhile the company that leaked it calls the fine the price of doing business, and everyone moves on.
The harm is permanent, so the remedy is a subscription. A leaked Social Security number cannot be un-leaked. A credit-monitoring service doesn't fix it — it notices it happening again. The business model is not remediation, it's surveillance of your own compromised data, billed monthly, indefinitely.
Once you see it laid out that way, it stops being a consumer-protection product and starts looking like a toll booth on a road somebody else broke.
I don't like that. That's the whole objection, and it isn't complicated. I don't accept a system where the leak is a line item for them and a recurring bill for me.
"You're one guy. You're going to lose that data yourself." This is the good argument, and I have to sit with it. A professional provider has redundant backups, staff who do nothing but security, audits, and a business that dies if they get it wrong. I have a hosting account and a habit of debugging tired. Realistically, self-inflicted data loss is a far more likely outcome for me than a targeted attack.
"And you're not actually more private — you're just more obscure." Also fair. My server sits on somebody else's hardware, behind somebody else's network, running somebody else's operating system. I've reduced the number of parties who hold my data. I haven't reduced it to one.
Both of those are true, and neither one changes my answer — but they do change what I'm claiming. I'm not claiming self-hosting is safe. I'm claiming it's small. Those are different virtues, and only the second one is actually mine.
Why I Keep Circling Local Models
This is also the reason I keep coming back to running AI locally, which I wrote about at length recently. It isn't performance. The hosted models are better, and they're getting better faster than anything I could run at home.
It's that a local model can't go anywhere. To get at what it's read, you have to get at my machine. To get at my machine, you basically have to be standing here. And if you've made it into my house, I have considerably bigger problems than a transcript of me rambling about a voice-memo app.
That's not a technical argument. It's a physical one, and I find physical arguments restful in a way that terms-of-service arguments never are. A promise can be revised. A locked door in a room I'm sitting in cannot be revised from a boardroom.
Is It Worth It?
Honestly? For most people, most of the time, probably not. I want to say that plainly rather than pretend everyone should be doing what I'm doing.
If an evening lost to a config file sounds like a nightmare rather than a mild irritation, buy the assembled thing. Read what it does with your data, pick the one that does the least, and get on with your life. That's a legitimate choice made by an adult, and the person who tells you otherwise is usually selling something too.
But I'd ask one thing of anyone taking that route: notice that you're making a trade. Not a purchase — a trade. The four minutes are real, and so is the thing you handed over to get them. The industry has worked very hard to make the second half of that sentence invisible, and it mostly succeeded.
For me, the calculus is different for a specific reason: what goes into this pipeline is unfinished thinking. Half-formed opinions, things I'd never publish, me talking myself out of positions. If I'm going to transcribe that locally so it never leaves my phone, then shipping the text straight to a cloud service so it can generate a title would defeat the entire point. So my server does the titles itself, badly, with word-frequency counting and some rules about how people start sentences. It's worse than what a model would produce. It's mine.
Self-hosting is not elegant and I won't pretend it is. It's a pile of parts that don't know about each other, held together by someone who'd rather be writing. Tonight it cost me an evening because of a punctuation mark, and there will be more evenings like it.
But that's the payment. That's the whole trade. You either pay in time and frustration, or you pay by adding your life to a pile large enough to be worth stealing — and then, when it's inevitably stolen, you pay again, monthly, to be told about it.
I'd rather pay in evenings. At least when I'm the one who breaks it, I'm also the one who can fix it — and nobody has to send me an oopsie.
I'll keep you posted on the journey. This pipeline is a few days old and already needs rework; I'll write up what breaks, what turns out to be unnecessary, and whether I'm still doing this in six months or quietly signing up for something with a nice onboarding flow. If you're building something similar, or you think I've got this wrong, tell me — I'd genuinely like to be argued with on this one.