Chart your own course privately.
Privateer (privateer.pro) puts frontier models and real working agents in one place. Chat — by typing, or out loud and hands-free — generate images, video and 3D models, then hand the work to an agent: command it from your phone, drive it by voice, put it on a schedule, or host it in Harbor. Encrypted on your device or in our cloud, with inference on hardware-attested enclaves.
GPT · Claude · Gemini · Grok · FLUX · Veo · Kling · Hunyuan3D — hundreds of models · type or talk · Android, Web, Desktop & CLI
Privateer is for everyone who refuses to choose between capable AI and their privacy. Your conversations are encrypted on your device or in our cloud, and every AI request runs through zero-data-retention providers that never store or train on your prompts. Frontier models and real agents, without giving up your data.
Link any terminal — your laptop, a server, the desktop app — and it becomes an agent you can drive from your phone, by thumb or by voice. Approve each action or let it run unattended, and get the finished files back.
Put recurring work on a schedule and let routines run without you. Bridge an agent into Telegram, Slack, Discord, WhatsApp, or Buzz and message it like a teammate.
Keep everything on-device, or in our cloud encrypted with a key derived from your password or wallet. Turn on Sealed mode and your prompts go straight to a hardware enclave your device verifies.
Ask anything and get clear answers. Attach images, documents, and files to give every reply full context. Your conversations are saved securely, so you can pick up exactly where you left off.
Tap the mic and have an actual conversation. Privateer hears where your sentence ends — no push-to-talk, no wake word, no button to hold — and starts speaking the answer while the rest of it is still being written. Talk over it and it stops mid-word to listen. It even learns your rhythm: how long a pause means you're thinking versus done, retuned every turn, so it stops cutting you off.
Talk over it to interrupt · tap to send early
Why it feels like a conversation
Exactly what leaves your device, and where it goes. Your microphone audio is transcribed by Whisper Large v3 Turbo, and the line spoken back is synthesized by Deepgram Aura-2 — both under zero-data-retention terms. Live conversation is the one surface that steps outside the attested enclave, and only for speed: 4.3 seconds of silence before every reply makes talking useless. Read-aloud and the Audio studio keep the enclave model. Voice chat is on the Sailor plan and up, or any time you're holding $5+ in credits.
Keep data in the cloud or fully on-device — all encrypted. Your data belongs to you, and only you. And you don't have to take our word for it.
Read the privacy policy · Verify it in the transparency layer
Turn on Sealed mode and your prompt is encrypted on your device straight to a hardware secure enclave. Our relay routes and meters it, but can't read your prompts or replies — inference is served by Sealed providers like Tinfoil and Phala. And you don't have to take our word for it: your device verifies the enclave's hardware attestation on every response.
The whole turn is assembled here — your message, the history, your memories — then sealed to the enclave's own key. Nothing is put together for you on our servers.
Sees a sealed body and where it is going. It routes the traffic and meters it for billing — it cannot open what it is carrying.
Opened and answered inside hardware — Intel TDX, NVIDIA Confidential Computing or AMD SEV-SNP, run by Tinfoil, Phala or NEAR AI. Zero retention: nothing kept, nothing trained on.
And you check the far end yourself. Your device verifies the enclave's hardware attestation on every response — so "sealed" is something it proves to you, not something we tell you.
Confidential-compute providers
Branch any conversation into a living board — explore ideas side by side, add images and notes, and pinch and pan to see how your thinking connects.
Choose from hundreds of models across every major provider — OpenAI, Anthropic, Google and more. Search, filter, and switch anytime to find the right fit.
Frontier chat models
Turn a prompt into a finished image or short video in seconds — then edit it with AI. Just describe the change, dial in aspect ratio, resolution, and style, and refine until it's exactly right. Describe a sound and get that too — a door slam, rain on a window, a distant siren — ready to drop under a cut.
Image models
Video models
Guide a video with pictures
Sound effects
A video doesn't have to start from words alone. Give the model reference pictures — a look, a character, a palette — and it works from them; or pin the first and last frame and let it fill the middle. Made a clip you like? Continue it from its final frame, or alter it: same clip, new direction. Those are separate choices on purpose. A model handed both a pinned frame and reference pictures renders the frame and quietly discards the references — at full price — so Privateer asks which you meant instead of guessing.
Sound effects are the one generator we can't route to a zero-retention provider, so we don't pretend otherwise: they're switched off until you turn on non-ZDR media generation, and your prompt is sent with nothing attached to your account. Everything else here stays on the default.
Hand Privateer an image and get back a real mesh — one you can spin on the screen, keep in your library, and take into a game engine or a 3D app. Give it up to four views of the same object and the model stops inventing the sides it cannot see. Don't have four? Privateer can draw them: it generates the front from your description, then makes every other view an edit of that same picture, so you get one object from four angles instead of four different objects.
Mesh models
What you get
No two of these models take the same options — one is dialled by output resolution, the next by a texture tier, the next by a quality preset — so the studio draws its controls from the model you picked and re-quotes the price the moment you change one. Being straight about the trade, exactly as with sound effects: mesh generation runs on a provider we can't route to zero retention, so it stays switched off until you turn on non-ZDR media generation.
Generating a clip is half the job. Studio is the other half: lay your clips on a timeline, trim them, crossfade between them, put a generated track underneath, and export the result back to your library. Drag in your own footage and it sits on the same timeline as everything the app made.
Project → cut → version
A project holds the media you gathered; a cut is one arrangement of it, and a project can hold several — a long version and a vertical crop off the same shoot. Save a version when a cut is worth keeping, and come back to it later.
The editing itself never leaves your device: the media is decrypted in your browser, cut there, and re-encrypted before it is stored. There is no server-side render — nothing is uploaded to be processed. Generating inside a cut works exactly like generating anywhere else in Privateer, with the same disclosures. Studio needs a real browser engine, so it runs on the web app and the desktop app, not on phones.
One account, every major provider. Chat with hundreds of models — GPT, Claude, Gemini, Grok, Llama, Mistral, DeepSeek, Qwen and more — plus image and video generation. Switch anytime in the app, or call any of them by ID through the OpenAI-compatible API.
Chat & reasoning · 40+ providers
Image & video
The newest frontier models are live on Privateer: Moonshot AI's Kimi K3, Anthropic's Claude Opus 5 and Claude Sonnet 5, and OpenAI's GPT-5.6 line — Luna, Sol and Terra, plus their Pro tiers. All of them are built for sharp agentic reasoning and standout coding, and you can switch between them mid-conversation. Ask one to design a game and save the result as Cargo: a playable build stowed encrypted in your hold, ready to play, tweak, or hand to a friend through a private link. Chat with them as privately as every other model — encrypted on your device or in our cloud, with zero-data-retention inference.
Newest from Moonshot AI, Anthropic and OpenAI
Ask any of them for a game — save it as Cargo
Ask for something real — a web page, a slide deck, a game, a document, or a spreadsheet — and save the result as Cargo. Every build is stowed encrypted in your hold, ready to run, edit, or download anytime — or share it with anyone through a private link. A file you already have can become one too: a spreadsheet or document you attach, or keep in a project, carries an Edit badge that turns it into an artifact you can keep updating, with version history. The conversion runs on your device, so it tells you what a format change would cost before anything is written.
Privateer comes to your command line. The CLI is a coding agent that reads, writes, and runs code across your projects — signed into your account, so there's no API key to manage. Link a terminal to the app to drive it from your phone, approve its actions, and send it files.
Built for developers
Connect your tools
Connectors are yours, not ours. Each one is an MCP server — pick it from the catalog in the app or the desktop client, sign in through your browser or paste a token, and its tools show up in the agent's toolbox behind the same permission gate as everything else. Credentials are write-only from your phone: they're sealed to the machine that runs the connector, so neither our relay nor our servers ever see the value. Local connectors run entirely on your machine; remote ones talk to that vendor's host, and every connector says which it is.
Every terminal you link becomes an Agent you can drive from your phone or the web. Send it a prompt, watch it work in real time, and approve each action — or give no quarter and let it run to the finish. Bridge it into your team chat, too — Telegram, Slack, Discord, or WhatsApp — and message it like a teammate, approving its actions right in the thread. It also speaks the Agent Client Protocol, so an ACP host like Buzz or Zed can drive the same agent — still bound by the tool limits you set and confined to the directory you point it at. It sends finished files straight back to you, and you can take over driving it from any device.
Manage every agent from the app
Work that finishes while you're away lands in your inbox: what the run produced, the files it staged, and a button to have it read to you — long results included, read in full rather than cut off partway. From a result you can follow up, which starts the next task on the machine that produced it and carries that routine's own instructions and working directory with it; if that machine is offline, Privateer asks rather than quietly running it somewhere else. Or ask for a brief: one short read across everything you haven't seen yet, with a line on why each item matters. Briefs are written on your device and stay there.
Voice mode isn't only for chat. Point it at a linked terminal and drive a real coding agent hands-free: hand it the job out loud, hear back its one-line account of what it did, and approve tool calls by saying so. Say allow, or deny. Say "no, don't allow that" — both words in one breath — and deny wins, because a wrongly-denied command costs you a re-ask and a wrongly-allowed one already ran on your machine. Anything it isn't sure it heard, it asks again. It never guesses.
Only that closing line is read aloud — never the diffs, paths, or tool output
Hands-free, and careful about it
Why only the recap. That session carries the contents of your own machine — paths, diffs, tool output. Reading it aloud verbatim would be unusable as speech and would ship far more of your machine to a speech provider than the answer needs. So the app speaks the agent's own closing summary and nothing else, and it tells you so, once, before your first spoken turn. The answer words it listens for come from your language's catalog, not a hardcoded English list.
A native desktop app for macOS and Windows — the full Privateer environment in its own window, with a local agent that can read, write, and run code in a folder you grant it. Same account, same encryption; your keys never leave your machine.
Get the app
First launch: on macOS, right-click the app and choose Open once (the build isn't notarized yet, so Gatekeeper asks the first time). On Windows, if SmartScreen appears, click More info → Run anyway.
The app offers to install the privateer command-line agent the
first time you open it — it's already inside the app, so there's nothing more
to download. By installing you agree to the Terms of Service
and the licence shown by the installer.
More about the desktop app: what it adds, every build, and what still has rough edges →
Rather stay in the browser? The Privateer side panel for Chrome and Edge → chats about the page you're on — and, signed in, acts on it one approved action at a time.
Runs on
Don't want to keep a terminal running? Harbor hosts your Privateer agent in our confidential cloud — always on and reachable from your phone or the web, with your MCPs, tools, credentials, and scheduled routines. It runs inside a hardware TEE we can't read into, the same posture as our Sealed inference. Included on Navigator and above.
What you get
An OpenAI-compatible developer API, billed to your Privateer account.
Point your existing OpenAI client at our base URL, drop in a
sk-priv-… key, and reach hundreds of chat, vision, image,
video and audio models through one endpoint. Inference is a stateless
pass-through — we persist only billing metadata, never your prompts or
the responses.
For developers
Privateer goes wherever you do. Use it on your phone or right in the browser — and with cloud storage, your encrypted conversations, projects, and boards stay in sync across every device.
Straight answers to what privacy-minded people actually ask.
Yes. Privateer is built privacy-first: your content is encrypted on your device or in our cloud, chat inference runs with zero data retention through trusted execution providers, and a public transparency layer lets you verify how it works.
Your content is stored encrypted — on your device in local mode, or in our cloud. Generating an AI response processes the request transiently through our server and model providers under zero-data-retention terms; inference traffic is not kept or used for training.
Hundreds of chat models across every major provider — GPT (OpenAI), Claude (Anthropic), Gemini (Google), Grok, Llama, DeepSeek, Mistral, Qwen, Kimi K3 (Moonshot AI) and more. Plus image models like FLUX, Nano Banana, DALL·E 3, Ideogram, Recraft and Stable Diffusion 3.5, video models like Veo 3.1, Kling, Runway Gen-3, Luma Ray 2, Seedance and Wan, and 3D mesh models like Hunyuan3D, Trellis, Tripo and Meshy. See the full model list, with the exact IDs and pricing you can call through the API.
Yes. Kimi K3, Moonshot AI's newest frontier model, is available on Privateer and is a strong fit for interactive builds. Describe the game you want and save the result as Cargo — a playable build stowed encrypted in your hold that you can run, edit, or share through a private link. The same works for web pages, slide decks, documents and spreadsheets.
Yes — generate images with FLUX, Nano Banana, DALL·E 3, Ideogram, Recraft or Stable Diffusion 3.5, and video with Veo 3.1, Kling, Runway Gen-3, Luma Ray 2, Seedance or Wan. Sound effects come from Stable Audio 3: describe a noise — a door slam, rain on a window — and get an audio clip back. Edit with AI until it's exactly right, and with Cargo a description becomes a web page, document, spreadsheet, or mini game you can save and share. Being straight about the trade: sound effects are the one generator we can't route to a zero-retention provider, so they stay switched off until you enable non-ZDR media generation, and your prompt is sent with nothing attached to your account.
Yes — give it a picture and it generates a 3D mesh you can spin in the app, keep in your library, and download as a GLB (or a textured OBJ, where the model makes one). Ten models from five labs are available — Hunyuan3D, Hyper3D Rodin, Trellis, Tripo and Meshy — and because no two of them take the same options, the studio draws its controls from whichever one you pick and quotes the exact price for your settings before you generate. Up to four views of the same object sharpen the result, and Privateer can draw those views for you: the front from your description, then every other angle as an edit of that same picture, so it stays one object. Being straight about the trade, as with sound effects: mesh generation runs on a provider we can't route to zero retention, so it stays switched off until you enable non-ZDR media generation. It's in the app, available to agents, and on the developer API.
Yes, two different ways, and the difference matters. You can pin the first and last frame and have the model fill the middle, or you can hand it reference pictures — a look, a character, a palette — as guidance on models that read them. You can also carry on from a clip you already made: continue it from its final frame, or alter it in a new direction. Pinned frames and reference pictures can't ride in the same request — a model given both renders the frames and silently ignores the references, at full price — so Privateer asks which one you meant rather than throwing your pictures away.
Yes — Studio is a timeline editor built into the app. Trim clips, crossfade between them, lay a generated track underneath, drag in footage of your own, and export the result back to your library. A project holds the media, a cut is one arrangement of it, and you can save a version of a cut to come back to. The editing happens in your browser: the media is decrypted on your device, cut there, and re-encrypted before it is stored — there is no server-side render. Studio needs a real browser engine, so it runs on the web app and the desktop app, not on phones.
Yes — voice mode is a real spoken conversation, not dictation. Tap the mic and talk: no push-to-talk button, no wake word. Privateer works out where your sentence ends — learning your own pause length turn by turn — and starts speaking the answer while the rest of it is still being generated. Talk over it and it stops mid-word to listen. You pick the voice, and the pick is remembered per device. It runs on Android and the web, on the Sailor plan and up, or any time you're holding $5+ in credits. Being straight about the trade: your microphone audio is transcribed by Whisper Large v3 Turbo and the spoken line is synthesized by Deepgram Aura-2, both under zero-data-retention terms. Live conversation is the one surface that steps outside the attested enclave, and only for speed — read-aloud and the Audio studio keep the enclave model.
Yes. Point voice mode at a terminal you've linked and run the agent hands-free: give it the task out loud, hear back its one-line account of what it did, and approve or refuse tool calls by saying so. If one utterance contains both an allow and a deny phrase — "no, don't allow that" — deny wins, because a wrongly-denied command costs a re-ask and a wrongly-allowed one already ran on your machine. Anything it isn't sure it heard, it asks again rather than guessing, and the answer words come from your language's catalog, not a hardcoded English list. Only the agent's closing summary is read aloud; the paths, diffs and tool output in that session are never sent for speech, and the app tells you so once, before your first spoken turn.
It lands in your inbox — what the run produced, plus any files it staged. You can have a result read aloud (long ones are read in full, not cut off partway), follow up on it — which starts the next task on the machine that produced it, carrying that routine's own instructions and working directory, and asks first if that machine is offline — or ask for a brief: one short read across everything you haven't seen yet, with a line on why each item matters. Briefs are written on your device and stay there.
With an email and password, or with a Solana wallet. No Google account required.
There is no password recovery, by design. Your encryption key is derived from your password or wallet, so losing it means losing access to your encrypted data. Keep it safe.
Yes — a side panel for Chrome 116+, Microsoft Edge, and Chromium browsers like Brave, Vivaldi, Arc and Opera (not Firefox or Safari). It chats about the page you're on, and once you're signed in it can act on that page: click, type, scroll, navigate and open tabs — each one raising an approval row you accept or decline, with no per-site "always allow". No account is needed to start. It ships with access to no website at all: attaching a tab is Chrome asking you about that one site, revocable in your account and in chrome://extensions. Being straight about the trade, as everywhere else: your message and the text of a page you attach go to our server for inference in plaintext, routed to a zero-retention or attested model where the catalogue has one; what gets stored is encrypted on your device first. Full details at privateer.pro/extension.
Yes — the Privateer CLI is a coding agent that reads, writes, and runs code across your projects, signed into your account with no API key to manage. It supports MCP servers, custom skills, scheduled routines via the daemon, and BYOK (bring your own key) if you'd rather use your own provider credentials. It runs on macOS, Linux, and Windows with a self-contained installer that needs no Node — curl -fsSL https://privateer.pro/install.sh | sh (macOS/Linux) or irm https://privateer.pro/install.ps1 | iex (Windows PowerShell). Full details at privateer.pro/cli.
Yes. Link a terminal to your account and it appears as an Agent in the app. Drive it from your phone or the web: send prompts, watch it work live, and approve each action — or give it "no quarter" to run unattended until the task is done — with the flag up, nothing stops to ask, dangerous commands included. You can also bridge it to Telegram, Slack, Discord, or WhatsApp and message it like a teammate, allow-listing exactly who can reach it. It sends finished files back to you, and you can manage its extensions, skills, scheduled routines, and messaging channels, or take over driving it from any device.
Yes. The CLI agent connects to MCP (Model Context Protocol) servers, so it can reach your tools — databases, GitHub, internal APIs — while keeping the same account-based privacy model.
Yes. When you're signed in, supported models can run inside a hardware Trusted Execution Environment — Intel TDX, NVIDIA Confidential Computing or AMD SEV-SNP, through confidential-compute providers like Tinfoil, Phala and NEAR AI. Your prompt is decrypted only inside the secure enclave, and every response carries a hardware attestation you can inspect right in the app.
Sealed mode makes our server a blind relay. Instead of sending your prompt to us in plaintext, your device encrypts it straight to an attested hardware enclave, so we can route and meter the request but can't read your prompts or the model's replies. Your device verifies the enclave's hardware attestation on every response — so "we can't read it" is provable, not just promised. Sealed inference is served by providers like Tinfoil and Phala. A small amount of metadata still transits our server — a derived search query, the model you chose, and token counts for billing — but the conversation itself never leaves your device in the clear.
Harbor hosts your Privateer agent in our confidential cloud, so you get an always-available agent — routines, schedules, tools, and interactive chat — without keeping a terminal running on your own machine. It has access to your MCPs, APIs, and credentials, and you talk to it from your phone or the web. A Harbor agent runs inside a hardware TEE (AMD SEV-SNP) we can't read into; between-user isolation on a shared host is software-enforced. Harbor is a Navigator-and-above feature and is rolling out in preview — read how Harbor works and join the waitlist, and we'll let you know the moment it's ready. Prefer to run it yourself? The Privateer CLI runs the same agent on your own machine.
Yes — an OpenAI-compatible API billed to your Privateer account. Point your existing OpenAI client at https://api.privateer.pro/v1 with a sk-priv-… key (create one under Settings → API keys) to reach hundreds of chat, vision, image, video and audio models. It's pay-as-you-go — billed to your account credit, with per-model rates here. Inference is a stateless pass-through: we persist only billing metadata, never your prompts or responses, and requests are pinned to zero-data-retention providers by default. Full reference at docs.privateer.pro.
Android via Google Play, the web app right here at privateer.pro, a desktop app for macOS and Windows, and a CLI coding agent for your terminal. The app is available in 14 languages, including Hindi, Bengali, Tamil, Arabic and Hebrew — pick one in the app or let it follow your device.
Your voyage starts here — free on web and Android.