Skip to main content
Live
Main content

Signal creator Marlinspike launches Confer to fix AI chatbot privacy problem

A wave of privacy-focused AI tools — Confer, Lumo, Duck.ai, Venice.ai — is racing to shield chatbot conversations from logging, subpoenas, and training pipelines.

Jaeden Schafer
Editor in Chief · · 6 min read
Signal creator Marlinspike launches Confer to fix AI chatbot privacy problem

A new category of privacy-focused AI chatbots is emerging to solve a problem the industry created: conversations with ChatGPT, Claude, and Gemini are logged by default, with few restrictions on how that data is shared, sold, used for further training, or handed to law enforcement and civil litigants who subpoena it. The most technically ambitious entrant is Confer, launched earlier this year by Moxie Marlinspike, the cryptographer who built Signal in 2014 and now counts well over a hundred million users on that end-to-end encrypted messenger. Confer uses Nvidia's Confidential Computing hardware to cryptographically prevent its own servers from reading user conversations — a guarantee that goes beyond the pinky-swear no-log policies offered by most competitors.

The stakes have shifted. A decade ago, text messages were the most sensitive data most people transmitted from their devices. Now people route their finances, health concerns, relationships, and deepest insecurities through chatbots that were built as data-collection systems first and confidants second.

You have this intelligent thing staring back at you, and you're basically telling it, one question at a time, every possible thing there is to know about your life.
Matt Green, Computer science professor at Johns Hopkins University

Matt Green, a privacy and security researcher at Johns Hopkins University, frames the problem in blunt terms: users are handing frontier labs a comprehensive personal profile, one query at a time, in exchange for conversational convenience. That profile sits on servers governed by terms of service that reserve broad rights to retain, analyze, and disclose the content.

Key facts

  • 01Moxie Marlinspike, the cryptographer who built Signal in 2014, launched Confer, an AI chatbot that uses Nvidia Confidential Computing to prevent its own server from logging conversations.
  • 02OpenAI, Anthropic, and Google offer zero data retention (ZDR) only for paid enterprise and developer accounts, not consumer users of ChatGPT, Claude, or Gemini.
  • 03Anthropic excludes its most capable 'Mythos-class' models, including Fable 5.1, from ZDR coverage, citing misuse risk and 'autonomous misbehavior' by agents.
  • 04OpenAI's Private Safety Processing, announced last month, scans user activity for abuse before deletion even under ZDR and can flag content to customer organizations.
  • 05Proton's Lumo, DuckDuckGo's Duck.ai, and Venice.ai rely on no-log promises rather than end-to-end encryption; Duck.ai and Venice.ai proxy requests to third-party models like ChatGPT and Claude.

Marlinspike, who introduced Confer in a blog post describing it as "a service where you can explore ideas without your own thoughts potentially conspiring against you someday," argues that the AI privacy gap dwarfs the messaging privacy gap that prompted him to build Signal.

Those same things I was concerned about with messaging are happening in the AI space, but several orders of magnitude more significantly.
Moxie Marlinspike, Signal creator and cryptographer

The strongest available protection for corporate users is a contractual provision known as zero data retention, or ZDR. OpenAI, Anthropic, and Google all offer ZDR on their enterprise and developer tiers, requiring the provider to delete conversation records as soon as they are processed. Consumer users of ChatGPT, Claude, and Gemini do not qualify.

Even ZDR has holes. Anthropic excludes its most capable Mythos-class models — including Fable 5.1 — from ZDR coverage, citing risks of misuse for scams, hacking, and "autonomous misbehavior" by agents. OpenAI announced last month that its new Private Safety Processing system will analyze user activity for abuse before deletion, alert customer organizations when it detects problems, and in some cases flag content to OpenAI staff without exposing the underlying conversation. Google similarly logs some Gemini prompts for abuse monitoring under ZDR, stripping user IDs and IP addresses, though the company acknowledges the sanitized data can still identify a user when the prompt itself contains identifying information.

For everyone outside a corporate contract, the market has produced a second tier of tools that lean on policy rather than cryptography. Proton offers Lumo, marketed as an AI chatbot where "every conversation is private," but the privacy rests on Proton's promise not to log rather than on the end-to-end encryption that underpins Proton Mail and Proton Drive. DuckDuckGo's Duck.ai and Venice.ai make similar no-log commitments while relaying user prompts to third-party providers such as OpenAI and Anthropic, effectively acting as anonymizing proxies.

Green points out the limitation of the proxy approach: even when the relay service keeps no logs, the underlying model still receives the prompt content. Ask a chatbot for the best coffee shops in your neighborhood and you have disclosed where you live. Strip the metadata and the message itself can still fingerprint a user through accumulated context. Duck.ai lets users choose which underlying model receives their queries. Venice.ai routes queries automatically across providers without always disclosing which model is answering, and did not respond to questions sent through the working channels Wired could identify.

Related · from this week
Signal's Whittaker: AI chatbots are not your friends, and Copilot shopping is a backdoor
Jaeden Schafer · 4 min read →

The technically stronger path is a trusted execution environment, or TEE. In a TEE setup, the AI model runs on isolated hardware — most commonly Nvidia's Confidential Computing platform — and the server can produce cryptographic proof that the rest of the system cannot access the enclave where prompts are processed. Confer combines that Nvidia-based TEE with passkey authentication and open-source code that outside auditors can inspect. Meta uses a similar TEE approach to power a more private version of its Meta AI assistant inside WhatsApp. On-device models, which never send prompts off the user's hardware at all, remain the theoretical gold standard but are limited by the size and capability of models that fit on consumer devices.

Skeptics will note that TEE-based protection depends on the integrity of Nvidia's hardware and the honesty of the operator's attestation. A confidential computing enclave that ships with an undisclosed bug or a compromised firmware update loses much of its guarantee. The open-source code Confer publishes only covers the software layer; the silicon underneath is proprietary. For most users the practical choice is not between perfect privacy and none, but between a promise backed by a company's reputation and a promise backed by hardware most people cannot personally audit.

The commercial pressure here is real and growing. Frontier labs are monetizing enterprise contracts partly on the strength of ZDR guarantees, which suggests they understand the retention default is a liability for the highest-value customers. Confer, Lumo, and the rest are pricing signals that consumers may soon demand the same. The lab that offers a genuine cryptographic guarantee at the consumer tier — rather than a policy footnote buried in enterprise terms — will have a durable differentiator in a market where every other capability gap closes within a quarter.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

Signal's Whittaker: AI chatbots are not your friends, and Copilot shopping is a backdoor
Security

Signal's Whittaker: AI chatbots are not your friends, and Copilot shopping is a backdoor

The Signal president pushes back on the agentic-AI pitch from Microsoft's Mustafa Suleyman, calling pervasive app access a privacy backdoor.

Jaeden Schafer4 min read
DuckDuckGo ships browser extensions to default users into its no-AI search
News

DuckDuckGo ships browser extensions to default users into its no-AI search

Traffic to the AI-free search page tripled on May 28, with U.S. iOS installs up 69.9% week-over-week after Google's AI Overviews push.

Jaeden Schafer4 min read
Box's Aaron Levie says CEOs are 'uniquely prone to AI psychosis'
Analysis

Box's Aaron Levie says CEOs are 'uniquely prone to AI psychosis'

DuckDuckGo installs jumped 30% after Google's AI search push, and one CEO is calling out his peers for losing touch with the work.

Jaeden Schafer5 min read