Privacy
What can be seen, and by whom.
No single party can both identify you and read what you asked. Including us. Here is who sees what, in full.
Relay
who203.0.113.42
prompt
paid
Operator
who
promptIs this rash something I should see a doctor about?
paid
Ledger
whoZS7Q…K4MD
prompt
paid$0.0032
ZeroSignal
who
prompt
paid
Never collected
Nothing to leak.
A request for your conversations has nowhere to land. There is no central party to ask.
No email, no phoneYou sign in with a passkey. No password, no name, no card on file.
No chat history on a serverConversations stay encrypted on your device. Nothing syncs anywhere unless you choose to.
No profile of what you askPrompts are encrypted before they leave your device. Nobody in the middle can read them, so nobody can build on them.
Who sees what
Blind is the default.
Every exposure is deliberate and bounded. No party gets two columns.
Full threat model in the docs ↗The relayforwards your envelope
Who you areyour IP address
Your prompt
Your payments
The operatorruns the model, briefly
Who you are
Your promptthe prompt
Your payments
The ledgerpublic, by design
Who you are
Your prompt
Your paymentsaddress + amount
Frontier labsonly if you pick one
Who you are
Your promptthe text, unattributed
Your payments
ZeroSignalthe people who built this
Who you are
Your prompt
Your payments
Compared
What the others need from you.
Their defaults, as published. Ours, as built.
Account to start
ZeroSignalPasskey only
ChatGPTEmail or phone
ClaudeEmail + phone
GeminiGoogle account
Who can read prompts
ZeroSignalOne operator, unattributed
ChatGPTStaff and contractors
ClaudeTrust & Safety, if flagged
GeminiHuman reviewers
History stored off-device
ZeroSignalNone
ChatGPTDefault on
ClaudeDefault on
GeminiDefault on
Payment
ZeroSignalPer message, any address
ChatGPTCard, on the account
ClaudeCard, on the account
GeminiGoogle Play, on the account
Don’t take our word for it.
Free to start. Everything above is architecture, not policy.