Privatemode AI processes AI requests without ever decrypting the data outside the user’s own device, using confidential computing to keep it encrypted through the model’s actual computation, not just in transit and at rest. It offers a chat interface, coding-agent integration with Claude Code, VS Code and Zed, an OpenAI-compatible API, and speech-to-text, routing to Kimi, OpenAI, Qwen, Mistral and DeepSeek models. It is built by Edgeless Systems, a German company, and targets insurance, public sector, legal and healthcare use.
Encrypting data through computation rather than only around it is a materially stronger claim than the ‘we don’t train on your data’ privacy language most AI products offer, and the certifications back it up with unusual specificity: BSI C5:2026 at ‘very strong attestation’, ISO 27001, GDPR, and readiness for German penal code Section 203, the professional secrecy standard covering doctors, lawyers and similar regulated professions. That last one is a genuinely narrow, checkable claim rather than a vague compliance gesture, and independent auditing and penetration testing are both stated.
Confidential computing is real technology with real performance and cost overhead compared to unencrypted inference, and usage-based pricing with no published rate means that overhead is not visible until you sign up. For the regulated sectors named, the trade is likely worth it; for a general chat use case, it is worth confirming the latency and cost against a need that actually requires this level of protection rather than assuming more encryption is free.






