i
News
News · 2026-09-22

Confer shows what stricter AI privacy costs

@neuronium_ai @neuronium_ai

Most consumer AI services offer privacy as a policy, not a technical guarantee. OpenAI, Anthropic and Google provide zero data retention for some paid corporate and developer accounts, while ordinary users generally get weaker promises. More private options do exist—from trusted hardware environments to models running on a laptop—but they narrow model choice, reduce capability or raise the price. The trade-off is no longer abstract: Confer’s cheapest paid plan costs $34.99 a month.

Cover: Confer shows what stricter AI privacy costs

What “private” actually means

When you type into ChatGPT, Claude or Gemini, the safest assumption is that the conversation can be obtained if the service owner, advertisers, contractors, law enforcement or civil litigants have a lawful way to request it.

The clearest exception is a contract between a user—or more often, their employer—and an AI provider. A zero data retention policy, or ZDR, requires the provider to delete interaction records after processing.

OpenAI, Anthropic and Google offer ZDR for corporate versions of their services. But the protection has important limits:

It is generally restricted to paid corporate and developer accounts.
Anthropic does not offer ZDR for its most capable “Mythos-class” models, including Fable 5.1.
OpenAI’s version can analyze user activity before deletion through a system called Private Safety Processing.
Google says it retains some Gemini prompts for abuse monitoring, even with ZDR enabled.

Anthropic cites the risk of fraud, hacking and “autonomous improper behavior” as reasons for excluding some models. OpenAI says its checks happen in the customer’s systems rather than at OpenAI. If abuse is detected, the system can send a warning to the organization. In some cases, Private Safety Processing may notify OpenAI employees without revealing the conversation’s contents.

Google removes the user’s Google identifier and IP address from retained prompts. That is useful, but not the same as anonymity: a prompt can identify someone through details contained in the text itself.

Policies, promises and proxies

Most people cannot obtain corporate-grade ZDR. Consumer services tend to offer a softer commitment: they will not log conversations.

Proton’s Lumo is an example. Proton describes every conversation as private, but Lumo does not have the end-to-end encryption guarantees associated with Proton Mail and Proton Drive. Users are relying on Proton to follow its own privacy policy. The company’s long-standing reputation in private services makes that promise more credible, but it remains a promise.

As Jan puts it, a mathematical guarantee is stronger than a promise. A promise from a company that can be trusted still matters, though.

Venice.ai and Duck.ai take a similar approach. Both say they do not store conversation logs, but both send prompts to other platforms, including Claude and ChatGPT. They function as proxies, limiting how much information the underlying model can collect about the user.

Duck.ai lets the user choose the third-party model.
Venice.ai appears to route conversations to different services depending on the request.
Venice.ai does not always disclose which model it is using.
In some cases, Venice.ai answers with a model hosted on its own infrastructure.

Venice.ai also advertises trusted execution environments that are supposed to prevent conversations from being recorded cryptographically. When WIRED asked the company’s employees for more details, its AI chatbot repeatedly sent reporters to an email address that did not work.

An anonymous proxy can offer more privacy than using ChatGPT or Claude directly. But once those services receive the text, the proxy’s retention policy becomes less decisive. Johns Hopkins University professor Matt Green points out that the underlying model can still collect the message itself.

Removing identifying metadata does not remove identifying information. A request for the best coffee shops in your neighborhood reveals where you live, and enough such details can form what Green calls a kind of personal fingerprint.

Hardware is stronger than policy

The most reliable protection is a technical barrier that prevents a service from reading the conversation at all. That requires cryptography, but current AI models cannot process prompts under genuine end-to-end encryption like Signal or WhatsApp messages. They need plaintext to generate an answer.

Trusted execution environments, or TEEs, are the practical compromise. An AI server runs on isolated hardware, often using Nvidia Confidential Computing. The system processes the request inside a separate hardware-protected area and can cryptographically prove that the rest of the server cannot access its secrets.

Confer, the private AI chatbot created by Signal founder Moxie Marlinspike, uses a Nvidia-based TEE, passkey authentication and open-source code. Its creators describe the combination as one of the strictest privacy options available in a consumer AI chatbot.

Meta uses a TEE in a more private version of Meta AI inside WhatsApp. To access it, users start typing in the “Ask Meta AI or search” field, select the “Ask” button, then choose the speech-bubble icon with a lock in the upper-right corner of the Meta AI chat. Meta calls the protected mode Incognito and says it prevents conversation records from being saved.

Incognito is not genuine end-to-end encryption. It is Meta’s attempt to bring AI closer to the privacy level it promises for person-to-person WhatsApp conversations.

Meta’s Muse agent does not yet support TEE protection. It runs in a separate virtual machine in the cloud. Meta says its advertising systems cannot access user data and that users can opt out of having their data used to train Meta’s AI. The company says it plans to release Muse Confidential VM later this year, with a cryptographically verifiable guarantee that Meta cannot access data inside a user’s Muse virtual machine.

Apple’s equivalent is Private Cloud Compute, or PCC. When Apple Intelligence or Siri sends a request to Apple’s servers, the user’s device cryptographically verifies that the server is running an unchanged version of PCC code. That code is not supposed to retain logs and is designed to isolate data from remote access.

PCC protection ends when Apple Intelligence or Siri sends a request to ChatGPT or another outside AI service. Apple says it will ask for permission first.

For simpler requests, Apple uses a more limited model directly on the device. Other local tools include:

Ollama — runs AI models on your own computer.
LM Studio — runs local models without sending data to the cloud.
LocalAI — another tool for hosting AI on a device.

Local processing keeps data from leaving the computer, but it comes with a capability penalty. Green says local AI can run on almost any laptop, yet it is intellectually much weaker than modern cloud models and produces fabricated information more often.

The price of not being watched

Confer offers roughly 20–25 free requests per day. After that, its cheapest paid plan costs $34.99 a month, compared with $20 a month for the minimum paid plans from Claude and ChatGPT.

Confer free20–25 requests/day
Confer paid$34.99/month

Marlinspike argues that the price reflects the real cost of operating an AI model without depending on future profits from data collection or advertising. Green adds that advanced models already require substantial spending on electricity and equipment.

My guess is that privacy will keep separating into tiers: policy-based privacy for most users, hardware-backed privacy for those willing to pay, and local models for those willing to accept weaker answers. The open issue is whether services that refuse to monetize user data can remain affordable without eventually weakening the promise they sold.

Daily AI news

Every day we pick what actually matters in AI and explain it plainly — no hype, no filler. Subscribe if you want to follow where the industry is going.

Only what matters — every day

Follow on X