Built so the company can't read your data, by design.
01 Mission
Most consumer AI products treat your conversations as training data, ad signal, or both. We're building one that can't. The pieces are open: your phone wraps your data before it leaves, the AI runs in a sealed space your phone can verify, your record of what happened is yours, and the export is offline-readable.
02 How we keep ourselves honest
Every design choice is written down, and every privacy claim on this site has to trace to the record that supports it — an automated check refuses to ship copy that drifts from what the system actually does. Those records are not published yet; until they are, you are taking that part on trust, and we would rather say so. We also publish what we explicitly don't claim to defend against.
03 What we believe
- Trust should be verifiable, not promised. "We don't read your data" is a policy claim. "Our infrastructure can't read your data" is an architecture claim. We build the second kind.
- Privacy isn't a tier. The privacy guarantees that matter are on every plan we'll ever sell.
- Open beats closed for the hard parts. The AI is open-weight. The export format is offline-readable, so your data outlives us. The client source is committed to publication and being prepared for it — it is not public yet, and we would rather say so than imply otherwise.
04 The team
Coming soon. For now we'd rather let the work speak.
05 See how it works
For the under-the-hood details — how the encryption works, how the AI integrity check works, how the audit log works, what we promise and what we don't — read the technical details.