Privacy

What can be seen, and by whom.

No single party can both identify you and read what you asked. Including us. Here is who sees what, in full.

Never collected

Nothing to leak.

A request for your conversations has nowhere to land. There is no central party to ask.

No email, no phoneYou sign in with a passkey. No password, no name, no card on file.
No chat history on a serverConversations stay encrypted on your device. Nothing syncs anywhere unless you choose to.
No profile of what you askPrompts are encrypted before they leave your device. Nobody in the middle can read them, so nobody can build on them.
Who sees what

Blind is the default.

Every exposure is deliberate and bounded. No party gets two columns.

Full threat model in the docs ↗
The relayforwards your envelope
Who you areyour IP address
Your prompt
Your payments
The operatorruns the model, briefly
Who you are
Your promptthe prompt
Your payments
The ledgerpublic, by design
Who you are
Your prompt
Your paymentsaddress + amount
Frontier labsonly if you pick one
Who you are
Your promptthe text, unattributed
Your payments
ZeroSignalthe people who built this
Who you are
Your prompt
Your payments
Compared

What the others need from you.

Their defaults, as published. Ours, as built.

ZeroSignalChatGPTClaudeGemini
Account to startZeroSignalPasskey onlyChatGPTEmail or phoneClaudeEmail + phoneGeminiGoogle account
Who can read promptsZeroSignalOne operator, unattributedChatGPTStaff and contractorsClaudeTrust & Safety, if flaggedGeminiHuman reviewers
History stored off-deviceZeroSignalNoneChatGPTDefault onClaudeDefault onGeminiDefault on
PaymentZeroSignalPer message, any addressChatGPTCard, on the accountClaudeCard, on the accountGeminiGoogle Play, on the account

Don’t take our word for it.

Free to start. Everything above is architecture, not policy.