Everything the home page sums up, limits included. Full technical details are in llms.txt.
What it doesn’t do yet
No release and no installers yet; the app has only been used on macOS with Apple silicon, never on Windows, Linux or an Intel Mac.
Not signed by Apple or Microsoft: macOS will say it’s damaged and Windows will show SmartScreen (see “The first time you open it”).
Updates have not yet been tried end to end.
The AI does two things: rewriting, and checking continuity, which reasons over chapter titles and the codex, not the prose. There is no chat, search by meaning, dictation or “Continue chapter” (the button is there, but disabled).
A local OpenAI-compatible server (LM Studio, llama-server) can be saved and tested, but generates nothing.
The built-in AI runs inside the app: if its engine fails, Versorium closes with it; autosave and snapshots limit what you can lose.
GPU: Metal tried on Apple silicon (M4 Max), with about 15 s of compiling the first time; Vulkan, for Windows and Linux, builds but has never run on a real GPU; there is no CUDA.
Going back to an old snapshot or recovering a deleted chapter is done with git, outside the app; the change log can’t be browsed from it.
↩ Restore reaches back to the start of the current session, up to 1000 edits.
Opening Settings rebuilds the editor, which loses its undo history.
Backups are made by hand; nothing is scheduled.
The GitHub repository and remote are set up outside the app, and pulling doesn’t merge diverged histories.
DOCX and Scrivener drop scene titles, with a warning; the PDF prints them, except the first scene’s in each chapter, which it drops without one. The PDF is US Letter in Times-Roman and replaces emoji and non-Latin scripts, with a warning. The cover is a typographic title page, not an image.
Importing DOCX, EPUB or Scrivener loses bold, italics and scenes; images, DOCX footnotes and comments are not imported. Imported novels are created as English, and a novel’s language can’t be changed.
Spell checking uses the system’s checker: it works on macOS; on Linux it underlines nothing yet; on Windows it hasn’t been tried.
No built-in editors for the codex, plot or research; chapters are reordered with Move earlier / Move later, not by dragging; no downloadable fonts.
Privacy
Your novel stays on your computer unless you ask otherwise. It’s a folder on your disk, and Versorium has no analytics or telemetry.
On its own, the app does one thing over the network: it checks GitHub for updates at launch, with nothing from your novel, and you can turn that off in Settings → Application. Everything else happens when you ask for it: downloading a model from Hugging Face, sending the novel to GitHub or bringing it back, or rewriting with Claude Code, Codex or OpenCode, which send the passage to their own service; that is why the Rewrite dialog labels every provider Local or CLI. If you choose a synced folder such as iCloud Drive or Dropbox as a backup destination, the app tells you that copy leaves the machine. Crash reports are kept on your machine, without prose, and leave only if you press Report.
Crash reports without prose
Kept on your machine with no paths, email addresses or tokens, and no prose: any run of six or more words is removed. They leave only if you press Report, which opens a GitHub issue in your browser.
Credentials in the keychain
Tokens go to your system's credential store (Keychain, Credential Manager or Secret Service), never to a settings file.
This page keeps the theme you pick in this browser (localStorage) and nowhere else. It uses no cookies.
History and snapshots
Every change in the editor is written down as an operation (what was typed or deleted, where, and by whom: you or an AI) in an append-only log kept inside the novel. Every 200 operations the whole chapter is saved as well. Assistants connected through MCP can read the log.
On top of that, every novel is a git repository. Versorium takes a snapshot every minute when something changed, before an AI writes and before a chapter is deleted, and you can save your own with a description.
↩ Restore, in the status bar, puts back the previous text of the selection, or of the word under the cursor.
Quitting with Cmd+Q, the app menu or the Dock waits for the last save; if the save fails, the app stays open and says why.
Four lines of the log: a word deleted, and the first three letters of the one that replaces it.
AI
Versorium ships with no AI switched on. If you want one, you choose where it comes from: a model that runs inside the app with llama.cpp, Ollama if you already use it, or the tools already in your terminal: Claude Code, Codex or OpenCode.
For the built-in AI there is a catalogue of 11 writing models in four sizes, from 0.58 to 17.4 GB. The app recommends the largest size that fits your machine with room to spare, downloads only when you press Download, resumes what was cut off and checks every file against SHA-256.
To rewrite, you select a passage and see the difference before applying it; Versorium takes a snapshot first and records the change under the AI's name. Each provider is labelled Local or CLI, because a CLI tool sends the passage to its own service.
Assistants connected through MCP (Claude Code, Claude Desktop, Codex and OpenCode set up in one click; Cursor and VS Code by hand) can only read, unless you grant write access to one in particular. Even then, every write first returns the diff and is applied only by a second call that confirms it, after a snapshot.
Today The AI only rewrites and checks continuity. The other limits are under “What it doesn’t do yet”.
Files, export and import
Every chapter is a .md file with a YAML header. The header belongs to the app (title, status, word count) and the rest is your text, in no proprietary format. Renaming a chapter changes its title, not its file; the order lives in versorium.json.
You do not need to install git: it is built into the app. If you already use it, the folder is an ordinary repository.
It exports Markdown, DOCX in standard manuscript format, EPUB 3 (it passes epubcheck 5.2.1 with no errors or warnings), PDF and a Scrivener 3 project. DOCX, EPUB and PDF get a typographic title page and a colophon, and you can turn off either one per project. It imports Markdown, DOCX, EPUB and Scrivener projects, and shows you a preview, with its warnings, before creating the project.
You can send the novel to a GitHub repository and bring it back. The token lives in your system's credential store and only ever travels to github.com.
Today Importing from Word, EPUB or Scrivener loses bold, italics and scenes. The other limits are under “What it doesn’t do yet”.
A novel on disk, exactly as Versorium creates it: versorium.json holds the title, the language and the order; .versorium/ops/, every change; .git/, the snapshots. Any text editor opens all of it.
manuscript/ch-02-the-needle.md---
id: ch-02
title: "The Needle"
pov: null
status: "revised"
words: 282
---
She counted the steps on the way up and again on the way down, because the first count came to forty-three and she did not trust herself after the boat. There were forty-two. The extra one was the threshold of the lamp room, higher than the rest, worn in the middle by a hundred years of boots.
Up there, the lens took up all the air. …
The chapter from the capture, as it sits on disk.
The first time you open it
macOS
macOS will say the app is damaged. It is not.
The bundle will carry no Developer ID signature, so macOS will quarantine it and Gatekeeper will report the most misleading message it has. Clear the quarantine flag once, in Terminal:
Only do this with a copy downloaded from the releases page: that flag is the check that protects you from a tampered download.
Windows
SmartScreen will interrupt the installer.
The installer will be unsigned, for the same reason as the macOS bundle, so Windows will show the blue “Windows protected your PC” screen. Choose More info, then Run anyway. Signed builds need Apple and Microsoft certificates, which do not exist yet, plus changes to the release workflow.
Updates are signed with minisign: the app installs one only if its signature matches the public key built into it and its SHA-256 matches the release's SHA256SUMS. It checks for them once at launch, with no account and no token; you can turn that off in Settings → Application. A GitHub token is optional: it is only needed to read a private repository, or to get past GitHub's limit of 60 requests an hour without one. With no release out yet, this path has not been tried end to end.
Platforms
macOS
The first release will have two .dmg downloads: one for Apple silicon and one for Intel.
The app has run on an Apple silicon Mac (an M4 Max), where the built-in AI uses Metal: the first run takes about 15 s to compile, and the app does that ahead of time at launch. It has not been tried on an Intel Mac.
Windows
The first release will have x64 installers in two formats, MSI and NSIS.
The app has not been run on Windows yet. The built-in AI will use Vulkan (NVIDIA, AMD, Intel); there will be no CUDA, on purpose. It will need an x86-64-v2 processor (SSE4.2).
Linux
The first release will have x64 .deb, .rpm and AppImage packages, built on Ubuntu 22.04 (webkit2gtk-4.1).
The app has not been run on Linux yet: only the automated tests run there, and the built-in AI is compiled with Vulkan, but no real GPU has used it. The .deb will declare libvulkan1 and libssl3. It will need an x86-64-v2 processor (SSE4.2). Saving a token will need Secret Service; without it, the app will say so.
Credits
Headings use Aguja Display, a modified version of Adobe’s Source Serif 4, under the SIL Open Font License 1.1 (assets/fonts/OFL.txt). The page loads nothing from other servers and uses no third-party libraries. Other names on this site belong to their owners and only describe compatibility.