Built so the company can't read your data, by design.
01 Mission
Most consumer AI products treat your conversations as training data, ad signal, or both. We're building one that won't. Our vendor's contract forbids training on your data, and we'll never grant the exception it allows. Your phone encrypts your words before they leave it. Before every message, your phone checks the AI's secure front door. The AI itself runs on secure hardware that our vendor checks. And you keep a record of what happened that shows if anyone altered it.
02 How we keep ourselves honest
Every design choice is written down, and every privacy claim on this site has to trace to the record that supports it — an automated check refuses to ship copy that drifts from what the system actually does. Those records are not published yet; until they are, you are taking that part on trust, and we would rather say so. We also publish what we explicitly don't claim to defend against.
03 What we believe
- Trust should be verifiable, not promised. "We don't read your data" is a policy claim. "Our infrastructure can't read your data" is an architecture claim. We build the second kind.
- Privacy isn't an upgrade. Every plan we sell gets the same protections.
- Open beats closed for the hard parts. The AI is open-weight. The app's source code will be published, but it isn't public yet.
04 The team
Coming soon. For now we'd rather let the work speak.
05 See how it works
For the under-the-hood details — how the encryption works, how the AI integrity check works, how the audit log works, what we promise and what we don't — read the technical details.