No one sees this conversation. Not us, not anyone.
Zero Witness runs in your browser when your device can handle it, and on hardware we run ourselves when it can't — never a cloud we don't control. Nothing is logged. Nothing stays with us.
How it stays private
The model runs inside your browser
Not a program you install — an open-weight language model that loads into your browser and runs on your own graphics hardware, in the tab. The entire conversation happens there. Nothing is ever sent anywhere, and once it has loaded you can disconnect from the internet and keep talking.
A private machine, if it has to
If your device can't keep up, your message is encrypted before it leaves your browser and processed on our own hardware. Decrypted only in memory. Never written to disk.
Then it's gone
When your conversation ends — the button, closing the tab, or navigating away — the model releases what it was holding as soon as the machine is idle: immediately if it already is, within about a minute if someone else's conversation is still running. There's no separate environment to mark for deletion or queue for cleanup. Releasing that memory is the whole of it.
You can see which of these is running at any moment, and switch between them yourself.
Why we built it this way
Most AI companies ask you to trust a privacy policy. We built Zero Witness so there's less to trust in the first place — your words either never leave your device, or they pass through hardware we own outright, not a cloud provider's servers.
That's a real trade-off, not a marketing line. It means we're smaller and slower than the AI companies with data centers. It means there's a hard limit on how many conversations can happen at once. We think that trade is worth it, and we'd rather tell you than hide it.
Questions worth asking
Both run an open-weight language model, and you choose which on the chat page. The difference is where that model runs — and every row below is written so a tick is the better answer, which means the comparison has to read honestly in both directions. It does: browser mode wins on privacy, ours wins on capability and reach.
On our hardware. Your message is encrypted in your browser before it's sent, and the reply is encrypted on the way back, so nothing on the network in between can read either one. We can: it's decrypted in memory on hardware we own outright, because answering it isn't possible otherwise. It's never written to disk, nothing is kept once the answer is finished, and the keys are made fresh for every message.
In your browser. The model itself runs inside the tab, on your own graphics hardware. It loads into your browser once and stays there — nothing is installed on your computer, and you can remove it whenever you like — but nothing you type is ever sent anywhere, and no second machine takes any part in answering you.
In browser mode, nothing. Our machine sends your browser the page and the model file, and after that it's out of the loop entirely — your messages are never transmitted anywhere.
Server mode exists because browser mode needs a reasonably modern device. If yours can't run a model locally, we run it on our hardware instead, and we tell you clearly which one you're on.
Honestly: not in any normal sense, but we're not going to claim it's mathematically impossible. Your message is encrypted in your browser, decrypted only in memory to be answered, and never written to disk. When your conversation ends, the model releases what it was holding — immediately if the machine is idle, within about a minute if someone else's conversation is still running.
What we can't offer is cryptographic proof of that. Services that make a stronger claim use specialized server hardware that isolates memory even from the machine's operator. We don't use that hardware, because we run our own rather than renting from a cloud provider. If that guarantee matters more to you than anything else, use browser mode — there, the question doesn't arise at all.
For browser mode, you don't have to. Open your browser's network tab and watch: after the page loads, your messages produce no outbound requests. That's verifiable by you, right now, without trusting us.
For server mode, you're trusting how we've built and run our infrastructure. That's a real trust requirement and we'd rather say so than dress it up.
No conversation content, ever — not in either mode.
Like any website, our server sees basic technical information when you connect: an IP address, timestamps, and rough request sizes, used to keep the service running and stop abuse. That's kept briefly and then deleted. We count visits to this page with Plausible: no cookies, no profile, and nothing that follows you between sites. Its script is served from here and its events go through our server, so your browser never talks to theirs — though the visit, and the address it came from, do reach them. Page views of the chat page are counted the same way; nothing about a conversation is — not what you typed, not which model ran, not which mode you used, not whether you sent anything at all. And there's no account to attach any of it to.
No. We use existing open-weight models and don't train or fine-tune on anything you type. There's no dataset being built here — your conversation isn't retained long enough to be one.
In browser mode, speed depends on your device — your own hardware is doing the work.
In server mode, capacity is shared among everyone using it at that moment. That's the honest cost of running on hardware we own rather than renting cloud infrastructure. We'd rather be slower on our own hardware than faster on someone else's.
Open-weight models rather than proprietary ones from a major AI company. In your browser you choose from a library of them — published by Alibaba, Meta, Google, Microsoft and Hugging Face — sized from 198 MB to 2.58 GB, with each one's measured weakness written beside it. On our hardware it's Qwen3.8 27B, larger and more capable than any of them.
Either way, answers here won't match the frontier models on raw capability. You're trading some of that for privacy.
No. There's no sign-up, no email, and nothing to log into — which means there's no account record connecting you to anything you type.
Yes, from the browser you used. A copy of each conversation is kept there, on your device and nowhere else, and the Saved list on the chat page opens it again. Nothing is stored on our side, so there's nothing we could restore. Turn saving off on the chat page and the copy is deleted; export a file, or nominate a folder where your browser supports it, if you want a copy that outlives a browser clean-up.
Zero Witness is early, and small. It isn't backed by a large company, and it isn't funded by advertising or by selling data — and it won't be. If it grows, it grows by charging for the service itself, not by monetizing anything you type here.