Chart your own course privately.
Privateer (privateer.pro) puts frontier models and real working agents in one place. Chat, generate images and video, then hand the work to an agent — command it from your phone, put it on a schedule, or host it in Harbor. Encrypted on your device or in our cloud, with inference on hardware-attested enclaves.
GPT · Claude · Gemini · Grok · FLUX · Veo · Kling — hundreds of models · iOS, Android, Web, Desktop & CLI
Privateer is for everyone who refuses to choose between capable AI and their privacy. Your conversations are encrypted on your device or in our cloud, and every AI request runs through zero-data-retention providers that never store or train on your prompts. Frontier models and real agents, without giving up your data.
Link any terminal — your laptop, a server, the desktop app — and it becomes an agent you can drive from your phone. Approve each action or let it run unattended, and get the finished files back.
Put recurring work on a schedule and let routines run without you. Bridge an agent into Telegram, Slack, Discord, or WhatsApp and message it like a teammate.
Keep everything on-device, or in our cloud encrypted with a key derived from your password or wallet. Turn on Sealed mode and your prompts go straight to a hardware enclave your device verifies.
Ask anything and get clear answers. Attach images, documents, and files to give every reply full context. Your conversations are saved securely, so you can pick up exactly where you left off.
Keep data in the cloud or fully on-device — all encrypted. Your data belongs to you, and only you. And you don't have to take our word for it.
Read the privacy policy · Verify it in the transparency layer
Turn on Sealed mode and your prompt is encrypted on your device straight to a hardware secure enclave. Our relay routes and meters it, but can't read your prompts or replies — inference is served by Sealed providers like Tinfoil and Phala. And you don't have to take our word for it: your device verifies the enclave's hardware attestation on every response.
Confidential-compute providers
Branch any conversation into a living board — explore ideas side by side, add images and notes, and pinch and pan to see how your thinking connects.
Choose from hundreds of models across every major provider — OpenAI, Anthropic, Google and more. Search, filter, and switch anytime to find the right fit.
Frontier chat models
Turn a prompt into a finished image or short video in seconds — then edit it with AI. Just describe the change, dial in aspect ratio, resolution, and style, and refine until it's exactly right.
Image models
Video models
One account, every major provider. Chat with hundreds of models — GPT, Claude, Gemini, Grok, Llama, Mistral, DeepSeek, Qwen and more — plus image and video generation. Switch anytime in the app, or call any of them by ID through the OpenAI-compatible API.
Chat & reasoning · 40+ providers
Image & video
Moonshot AI's newest frontier model — Kimi K3 — is live on Privateer. With its sharp agentic reasoning and standout coding, it's built for turning a single prompt into something you can actually run. Ask it to design a game and save the result as Cargo: a playable build stowed encrypted in your hold, ready to play, tweak, or hand to a friend through a private link. Chat with it as privately as every other model — encrypted on your device or in our cloud, with zero-data-retention inference.
Powered by Moonshot AI
Ask Kimi K3 for a game — save it as Cargo
Ask for something real — a web page, a slide deck, a game, a document, or a spreadsheet — and save the result as Cargo. Every build is stowed encrypted in your hold, ready to run, edit, or download anytime — or share it with anyone through a private link.
Privateer comes to your command line. The CLI is a coding agent that reads, writes, and runs code across your projects — signed into your account, so there's no API key to manage. Link a terminal to the app to drive it from your phone, approve its actions, and send it files.
Built for developers
Every terminal you link becomes an Agent you can drive from your phone or the web. Send it a prompt, watch it work in real time, and approve each action — or give no quarter and let it run to the finish. Bridge it into your team chat, too — Telegram, Slack, Discord, or WhatsApp — and message it like a teammate, approving its actions right in the thread. It sends finished files straight back to you, and you can take over driving it from any device.
Manage every agent from the app
A native desktop app for macOS and Windows — the full Privateer environment in its own window, with a local agent that can read, write, and run code in a folder you grant it. Same account, same encryption; your keys never leave your machine.
Get the app
First launch: on macOS, right-click the app and choose Open once (the build isn't notarized yet, so Gatekeeper asks the first time). On Windows, if SmartScreen appears, click More info → Run anyway.
Runs on
Don't want to keep a terminal running? Harbor hosts your Privateer agent in our confidential cloud — always on and reachable from your phone or the web, with your MCPs, tools, credentials, and scheduled routines. It runs inside a hardware TEE we can't read into, the same posture as our Sealed inference. Included on Navigator and above.
What you get
An OpenAI-compatible developer API, billed to your Privateer account.
Point your existing OpenAI client at our base URL, drop in a
sk-priv-… key, and reach hundreds of chat, vision, image,
video and audio models through one endpoint. Inference is a stateless
pass-through — we persist only billing metadata, never your prompts or
the responses.
For developers
Privateer goes wherever you do. Use it on your phone or right in the browser — and with cloud storage, your encrypted conversations, projects, and boards stay in sync across every device.
Straight answers to what privacy-minded people actually ask.
Yes. Privateer is built privacy-first: your content is encrypted on your device or in our cloud, chat inference runs with zero data retention through trusted execution providers, and a public transparency layer lets you verify how it works.
Your content is stored encrypted — on your device in local mode, or in our cloud. Generating an AI response processes the request transiently through our server and model providers under zero-data-retention terms; inference traffic is not kept or used for training.
Hundreds of chat models across every major provider — GPT (OpenAI), Claude (Anthropic), Gemini (Google), Grok, Llama, DeepSeek, Mistral, Qwen, Kimi K3 (Moonshot AI) and more. Plus image models like FLUX, Nano Banana, DALL·E 3, Ideogram, Recraft and Stable Diffusion 3.5, and video models like Veo 3.1, Kling, Runway Gen-3, Luma Ray 2, Seedance and Wan. See the full model list, with the exact IDs and pricing you can call through the API.
Yes. Kimi K3, Moonshot AI's newest frontier model, is available on Privateer and is a strong fit for interactive builds. Describe the game you want and save the result as Cargo — a playable build stowed encrypted in your hold that you can run, edit, or share through a private link. The same works for web pages, slide decks, documents and spreadsheets.
Yes — generate images with FLUX, Nano Banana, DALL·E 3, Ideogram, Recraft or Stable Diffusion 3.5, and video with Veo 3.1, Kling, Runway Gen-3, Luma Ray 2, Seedance or Wan. Edit with AI until it's exactly right, and with Cargo a description becomes a web page, document, spreadsheet, or mini game you can save and share.
With an email and password, or with a Solana wallet. No Google account required.
There is no password recovery, by design. Your encryption key is derived from your password or wallet, so losing it means losing access to your encrypted data. Keep it safe.
Yes — the Privateer CLI is a coding agent that reads, writes, and runs code across your projects, signed into your account with no API key to manage. It supports MCP servers, custom skills, scheduled routines via the daemon, and BYOK (bring your own key) if you'd rather use your own provider credentials. It runs on macOS, Linux, and Windows with a self-contained installer that needs no Node — curl -fsSL https://privateer.pro/install.sh | sh (macOS/Linux) or irm https://privateer.pro/install.ps1 | iex (Windows PowerShell). Full details at privateer.pro/cli.
Yes. Link a terminal to your account and it appears as an Agent in the app. Drive it from your phone or the web: send prompts, watch it work live, and approve each action — or give it "no quarter" to run unattended until the task is done (dangerous commands still ask). You can also bridge it to Telegram, Slack, Discord, or WhatsApp and message it like a teammate, allow-listing exactly who can reach it. It sends finished files back to you, and you can manage its extensions, skills, scheduled routines, and messaging channels, or take over driving it from any device.
Yes. The CLI agent connects to MCP (Model Context Protocol) servers, so it can reach your tools — databases, GitHub, internal APIs — while keeping the same account-based privacy model.
Yes. When you're signed in, supported models can run inside a hardware Trusted Execution Environment — Intel TDX, NVIDIA Confidential Computing or AMD SEV-SNP, through confidential-compute providers like Tinfoil, Phala and NEAR AI. Your prompt is decrypted only inside the secure enclave, and every response carries a hardware attestation you can inspect right in the app.
Sealed mode makes our server a blind relay. Instead of sending your prompt to us in plaintext, your device encrypts it straight to an attested hardware enclave, so we can route and meter the request but can't read your prompts or the model's replies. Your device verifies the enclave's hardware attestation on every response — so "we can't read it" is provable, not just promised. Sealed inference is served by providers like Tinfoil and Phala. A small amount of metadata still transits our server — a derived search query, the model you chose, and token counts for billing — but the conversation itself never leaves your device in the clear.
Harbor hosts your Privateer agent in our confidential cloud, so you get an always-available agent — routines, schedules, tools, and interactive chat — without keeping a terminal running on your own machine. It has access to your MCPs, APIs, and credentials, and you talk to it from your phone or the web. A Harbor agent runs inside a hardware TEE (AMD SEV-SNP) we can't read into; between-user isolation on a shared host is software-enforced. Harbor is a Navigator-and-above feature and is rolling out in preview — join the waitlist and we'll let you know the moment it's ready. Prefer to run it yourself? The Privateer CLI runs the same agent on your own machine.
Yes — an OpenAI-compatible API billed to your Privateer account. Point your existing OpenAI client at https://api.privateer.pro/v1 with a sk-priv-… key (create one under Settings → API keys) to reach hundreds of chat, vision, image, video and audio models. It's pay-as-you-go — billed to your account credit, with per-model rates here. Inference is a stateless pass-through: we persist only billing metadata, never your prompts or responses, and requests are pinned to zero-data-retention providers by default. Full reference at docs.privateer.pro.
Android via Google Play, iOS, the web app right here at privateer.pro, and a CLI coding agent for your terminal.
Your voyage starts here — free on web, iOS, and Android.