Private by design

Your chats run inside a locked room.

When you use a normal AI chat, your messages arrive at a server where the provider can read them. Privasys Chat is different: the AI runs inside a sealed area of the processor that nothing outside can look into. Not the cloud company that owns the machine, not the network in between, and not Privasys.

The locked room, briefly.

The technology is called confidential computing. Modern processors can set aside a protected area, often called an enclave, whose memory is encrypted by the chip itself. Software inside the enclave can work on your data; anyone outside, including the machine's own administrators, sees only scrambled bytes.

Privasys Chat runs the entire AI model inside such an enclave, on processors and graphics cards built for it (Intel TDX and NVIDIA H100 confidential computing, for the technically curious). The result is simple to state: the only places your conversation ever exists in readable form are your own screen and the inside of that sealed hardware.

Who can see what.

PartyWhat they see
YouYour conversation, on your device.
The networkEncrypted traffic only. Messages are sealed in your browser and opened only inside the enclave.
The cloud providerAn encrypted virtual machine it cannot look inside, even with physical access to the hardware.
PrivasysOperational signals only (is the service up, how loaded is it). Never your prompts, never the replies.

The journey of a message.

From the moment you press send, your message is encrypted for one specific, verified enclave, and nothing else can open it.

  1. 1

    Sealed in your browser

    Your message is encrypted on your device, addressed to the exact enclave your wallet verified. Gateways and networks in between relay ciphertext they cannot open.

  2. 2

    Opened only inside

    The enclave decrypts your message in protected memory, runs the model, and encrypts the reply the same way. Nothing readable ever touches a disk or leaves the sealed area.

  3. 3

    Back to you, signed

    The reply arrives with a signature from the hardware that produced it, so you can later prove what answered you and with which model.

Where your conversations live.

Your chat history is stored on your device, in your browser. It is not kept on Privasys servers, it is not read by anyone, and it is never used to train or improve any model. Delete a conversation and it is gone.

There is no advertising and no profiling anywhere in the product: the business model is providing private AI, not monetising conversations.

Why you sign in with the Privasys Wallet.

The wallet is not a login box. It is the piece that checks the hardware on your behalf.

Before you authenticate, the Privasys Wallet on your phone independently verifies the enclave's credentials: that it is genuine confidential hardware, running exactly the software it claims. Only then does it approve the sign-in and set up the sealed channel. If the hardware or software ever changes, the wallet notices and asks you to verify again. You can sign in with an ordinary identity provider instead, but then this verification step is not performed for you, so the wallet is the recommended way to get the experience the product is built around. See the privacy model in the documentation for the details.

Go deeper

The full technical detail, from architecture to APIs, lives in the documentation:

Private by hardware, not by promise.

Sign in with the Privasys Wallet for the full verified experience, or contact us if you have specific requirements.