I Built WorkMemory AI Because I Was Tired of Forgetting What I Shipped
The problem Every year, review season shows up and I sit there staring at a blank doc trying to remember what I actually did in March. Was that the sprint where I fixed the outage, or was that April? What was that migr
The problem
Every year, review season shows up and I sit there staring at a blank doc trying to remember what I actually did in March. Was that the sprint where I fixed the outage, or was that April? What was that migration script for again?
Six months of Slack messages, half-finished tickets, and closed PRs later, and none of it is in any usable shape. I'm not bad at my job β I'm just bad at remembering my job, because nothing captures it in the moment.
So I built WorkMemory AI: a place to log work as it happens, so I never have to reconstruct a year from memory again.
π Live app: https://work-memory-ai-navy.vercel.app/
(Heads up β it's on a free Vercel tier, so the first load can take 30-40 seconds while it spins up. Give it a minute.)
What it actually does
At its core, it's a daily/weekly work log. But the useful part isn't the logging β it's what happens after.
Project tagging that doesn't get in your way
You can manually tag a log entry with a project, or just write naturally and let the AI extract project names, tech, and metrics from the text itself. Manual and AI-extracted tags get merged case-insensitively, so you don't end up with duplicate Project-X / project-x tags cluttering the dashboard.
Chat with your own logs
This is the feature I use the most. Instead of scrolling back through weeks of entries, I can just ask:
"What did I ship in week 31?"
"When did I deploy the encryption module?"
The answers are generated strictly from your own log data β if it's not in your logs, the AI says so instead of inventing an answer. No hallucinated accomplishments.
On-demand summaries
Need a recap for a 1:1, a sprint retro, or your annual review? Generate an AI summary for any week, month, or year, pulled directly from what you actually logged β not what you vaguely remember logging.
Review prep that writes itself (mostly)
When it's actually review time, WorkMemory can draft:
- Self-Appraisals structured by theme
- STAR examples (Situation, Task, Action, Result) for behavioral interviews or promo packets
- Manager One-Pagers β a tight executive summary of your highest-impact work
All generated from real logged data, not a scramble through your memory the night before the deadline.
Export everything
Once you've got a summary, a self-appraisal draft, or a STAR example built out, you're not stuck reading it inside the app. You can export it as PDF or plain text/Markdown β useful whether you're pasting it into a review portal, sending it to your manager, or just keeping an offline copy for yourself.
Bring your own key
I didn't want to lock anyone into a specific AI provider (including me). You can plug in:
- OpenRouter
- Groq
- OpenAI
- Or a custom OpenAI-compatible endpoint URL if you're self-hosting a model
Your key, your model, your data.
The stack
Frontend
- React 18/19 + TypeScript + Vite
- Material UI (MUI v6)
- React Router v7
- Axios with
withCredentials: true
Backend
- FastAPI (Python 3.12)
- SQLAlchemy 2.0 + PostgreSQL (Neon)
-
python-josefor JWT,passlibfor bcrypt hashing -
cryptography(Fernet) for AES-256 encryption at rest
A few technical decisions worth mentioning
HttpOnly cookie auth over localStorage tokens. Session tokens live in HttpOnly, SameSite=None, Secure cookies. Frontend JS never touches the token, which kills the usual XSS-token-theft vector outright.
Encryption at rest for every log entry. Raw log text is encrypted with Fernet (AES-256) before it ever hits Postgres, and decrypted on the way out. If the database were ever compromised, the actual log content is unreadable without the key.
Timezone-aware scheduling. Calendar reminders and daily logging windows respect the user's configured timezone (defaults to IST) instead of assuming UTC or the server's local time β which matters a lot once reminder emails are involved.
CI that actually gates on security, not just tests. Every push runs Semgrep (SAST), Trivy (dependency/container scanning), and Snyk Code, with all GitHub Actions pinned to immutable commit SHAs to reduce supply-chain risk.
What's next
This is still very much in progress. There's an in-app tracking feature (create/delete) where I'm logging bugs and feature requests as they come in, and I'm actively working through that list.
If you try it and something feels off, or you have ideas for what would make this more useful β I'd genuinely like to hear it. The whole point of this project was "stop losing your own work to memory," so feedback that comes from actually using it is the most valuable kind I can get.
The code is currently in a private repo, but happy to share access if you're curious about the implementation details β especially the encryption wrapper or the AI extraction pipeline.
Built with React, TypeScript, FastAPI, and a mild obsession with not forgetting things.
Originally published by Dev.to WebDev. Aggregated on AIWithGhost for educational purposes β full credit and traffic to the original publisher.





