← back to chat

Your privacy, itemized

What is proven, what is architecture, and what still needs your trust. We list all three, because anyone who claims everything is proven is lying.

Encrypted channel to confidential hardware

by design

Checking the live connection...

Chats live only on this device

verified live

This browser currently holds 0 chats with 0 messages in local storage. We have no database for your conversations. Clear your browser data and they are gone forever, even we could not bring them back.

AI runs inside sealed hardware

by design

Inference runs on NVIDIA H100 GPUs in confidential-computing mode inside AMD SEV-SNP encrypted VMs, operated by Privatemode (Edgeless Systems, Germany). The hardware signs a measurement of the exact code it runs; the encryption proxy rejects the connection unless that signature chain verifies against AMD and NVIDIA root certificates. Neither the operator nor the datacenter can read prompts, and nothing is retained after the response.

No account, no tracking

by design

No sign-up, no cookies for tracking, no analytics scripts on the chat. There is nothing to link your conversations to you.

Our relay server

you trust us

Your message passes through our server on its way to the encrypted channel, and today you have to trust that we do not log it. We do not, and our code is public, but honesty requires the label. The fix is already on our roadmap: verification moves into the app on your device, so our server becomes a blind pipe. The upcoming native app closes this gap completely.

Want to check the deep claims yourself? Privatemode's attestation flow, manifests, and source are public: docs.privatemode.ai