Vision
Last updated August 9, 2026
Today we remove the name from the envelope. An AI provider answers your question without being told whose account it came from — no name, no email, no identifier, and nothing linking one question to the next.
That is worth having, and it is not enough. If you write my landlord Sarah Chen is withholding my deposit at 14 Bridge Street, the envelope is anonymous and the letter is not. Everything that actually identifies you is in the part we currently pass through untouched.
The goal is to close that gap. Not to make the product refuse the question, and not to hand the model something so stripped it answers uselessly — but to let you write exactly what you would write to a person you trust, and have the machine on the other side see a version of it with the identity taken out.
Substitute, don't delete
The obvious approach is to cut identifying details out. It breaks the product. Ask for help replying to your landlord with the name removed and you get an answer addressed to [name] throughout, which you then have to repair by hand — so you stop using the feature, and you have traded a real capability for a privacy gain you cannot see.
The approach that works is to swap each identifying detail for a stable placeholder, keep the mapping, and put the real values back in the answer:
The provider gets a coherent question it can actually answer. You get your own words back. The mapping between the two is the only place the real name and the placeholder are connected — and the intent is that it lives on your device and never travels with the request at all.
What that has to cover
Anonymity in the contents of a message is not one problem. It is several, of very different difficulty, and honesty about which is which is the point of this table.
In what you type
In what you upload
Where it runs decides what we may claim
The same feature is worth very different amounts depending on where the work happens, and we would rather explain that than let the strongest-sounding version be assumed.
On our infrastructure. Your message reaches us, we take the identity out, and we forward what is left. This is the version that ships first, because the chokepoint already exists. The honest sentence for it is removed before we forward it — and note what that does not say: the original reached us.
On your device. The identifying detail is replaced before anything leaves your phone, and the mapping never exists anywhere else. The honest sentence becomes identifying details never leave your device, which is a categorically stronger claim — and the destination we are building toward. It costs three separate client implementations and is limited by the least capable phone we support, which is why it is second rather than first.
We will say which one is running. When the second arrives, this page and Security change on the same day.
The order we are building it in
Steps 1 to 5 are a working product on their own, and they are the point at which what we are allowed to say about Secure AI changes. Everything after raises the ceiling.
What we will never claim
Detection of this kind is never complete, and a privacy product that implies otherwise is doing something worse than one that offers nothing. So, in advance of building it:
We will not say all identifying detail is removed. We will not promise that context — the things that identify you without naming you — is caught, because we do not believe it can be. We will not describe a stage as shipped on a platform where it is not running. And if detection cannot be performed on a request, that request will fail rather than quietly go through unprotected.
The strongest thing a company in this position can offer is a precise account of where its protection stops. That is what this page is for, and it is why it exists before the feature does.
Questions, or want to be told when a stage moves? Email privacy@secureai.one.