Privacy has boundaries. We show them.
Hosted beta B1 does NOT cryptographically protect content from the operator. An administrator can technically read server data, including text during inference. A policy against reading is not a technical inability to read. B2 TEE and remote attestation do not exist yet.
What can be checked today
Source code describes data flow, network allowlists and authorization. HTTP tests check organization isolation and quotas. These pages use no trackers, third-party scripts or webfonts. The threat model explicitly includes administrators, malicious documents and compromised clients.
Local access uses HTTPS with a local certificate. Documents are not encrypted by the application in this release; disk and backup encryption are the administrator’s responsibility. Passwords use scrypt hashes. TLS and disk encryption do not prevent an administrator from reading content at runtime.
The application does not send content to operational logs. Documents, comments and AI answers are stored as your working data. The local email mock stores messages in a protected file, not on the internet. Inference-server logging has separate configuration that must be checked.
B2 still needs a verified TEE stack, runtime attestation and key release after verification. EU hosting, model zero-logging and release signing are neither deployed nor audited by this local release.
Subscription and billing
Account email is required from registration and used for recovery. A paid account is not fully anonymous: in a future live gateway, the payment provider processes card details and payment identifiers; the operator receives status, payment IDs and billing details, not the full card number. Today only a local mock without card entry works. Bank transfer or another less identifying method: TODO — RB decision.