Pickle's personal AI app connects users through agent-to-agent chat
Released on iPhone in August, Pickle lets personal agents talk and coordinate plans under owner-set rules; its premium tier costs $8.99 monthly.
By Ryan Merket · Published
Primary source: X
Why it matters
Pickle is turning personal AI into a social product: its agents coordinate with one another, so usefulness depends on both user trust and enough shared context. The published enclave code addresses one part of that trust problem; the app's adoption and economics remain untested in the available figures.

Pickle is building a social app around personal AI agents that talk to one another and introduce their owners. CEO Daniel Park (@danifesto) described the product in an October 1st post on X, using group dinner planning as an example: tell one Pickle what you want, and it talks with friends' Pickles to work out a time and place and prepare a booking.
https://x.com/danifesto/status/2105721921623232995
The post calls Pickle an introduction, but Apple's App Store listing dates version 1.0 to August 10th. It describes an iPhone app where users can chat with their own AI, add friends, and start group conversations that include both people and their agents. The listing offers the app for free with optional Pickle Plus subscriptions at $8.99 a month or $59.99 a year. Park's post is therefore a new public explanation of the product's social premise, rather than its first appearance in Apple's store.
The product extends the assistant beyond a private exchange. Pickle's App Store description says an agent can talk to nearby Pickles and introduce their owners, while group chats let people and their agents speak together. Park's dinner example suggests the practical pitch: an agent handles the negotiation and planning overhead, while people remain part of the conversation. The post says the agents prepare everything needed to book; it does not claim the app completes a reservation without approval.
That design also makes delegation and disclosure central to the product. Park says Pickle keeps account tokens in an isolated credential enclave, with a key generated on the user's iPhone. The AI gets access to an email account, for example, without receiving the underlying token. For passwords and payment details, a separate tool fills forms rather than passing those secrets through the model. Park says payments use Stripe Link to provide a one-time card limited to a transaction the user approves.
When two Pickles communicate, Park says, the system sends a restricted clone of the user's agent. It can read and talk but cannot book, pay, or change files. Owners set sharing rules by person and choose which connected apps an agent may use in each relationship; those app permissions are off by default, according to the thread. Park says both participants can read the agents' exchange.

The credential-enclave source code on GitHub gives those claims a concrete, inspectable component. Its documentation describes credentials held inside an AWS Nitro Enclave, user keys that stay off the operator's systems, and an encrypted, tamper-evident log written before an action. The repository says log entries are retained for 365 days and describes a verification tool for comparing the running enclave's attestation with a build of the published source. That is evidence of a published design and a way to check code measurements; it is not, by itself, an independent audit of the whole service or proof that every part of the app follows the same guarantees. The thread links a privacy architecture explainer and says Pickle plans to open-source its iOS app so users can inspect the path from phone to enclave.
There is a tradeoff behind the social feature: a personal agent can only make useful introductions if it knows enough about its owner to share relevant context. Pickle's controls are meant to let users decide what travels and with whom. Apple's App Store page also lists developer-disclosed data categories that may include precise location, contacts, photos or videos, and other user content. Apple says those disclosures come from the developer and are not verified by Apple. The permissions and data involved matter for an app that describes neighborhood discovery and conversation between agents.
Park's background helps explain the consumer focus. Y Combinator identifies him as Pickle's co-founder and CEO and says he built an e-commerce business generating $2 million a year at age 22 while in medical school. Pickle joined YC's Winter 2025 batch. Its earlier product was an AI body double for video calls, a response Park traced to long days of online medical-school classes. YC's current profile describes Pickle as a personal-memory system spanning software and AR glasses, while the company's website now promotes its iPhone AI and says refunds for Pickle 1's first hardware batch are being processed. Park also wrote in the thread that Pickle had refunded everyone who pre-ordered, without specifying the product in that reply.
The change in emphasis is clear: Pickle is presenting an AI agent as both a personal assistant and a participant in users' social lives. Its published security work addresses how an agent can act on private accounts; its next test is whether people will let those agents share enough context to make their social coordination useful. The app is available on iPhone, but the October post and App Store listing provide no usage or revenue figures for this product.