dusken. Hold your place
The promise, in one sentence

Privacy, in plain words.

We don't keep your chats, and the copy we do hold is locked with a key only you have.

Everything else exists to make that sentence true, testable, and safe to say out loud.

The architecture We built the room, not the microphone.

We can't see your chats — but the moment you hit send, the message does travel to our computers to get answered. We don't keep it. But “never touches our servers” would be a lie, so we don't say it.

Messages travel from your device through Dusken servers, which relay without storing, to the model, and stream back the same way. Nothing is kept.

The four rooms

  • Burner every tier

    The AI that doesn’t remember you. One tap — no vault writes, no sync, no local history, nothing server-side. There never is.

    On every tier, every model, including free.

    When this chat ends, it never happened. Gone means gone.

  • Vault default

    Everything Dusken remembers is encrypted on your device before it syncs; the server stores only the encrypted form. Internally tested over enumerated surfaces, not independently audited.

    Your AI remembers you. Our servers never do — no intentional plaintext persistence after inference, internally tested over enumerated surfaces.

    Lose your key and even we can’t bring it back. That’s the deal that makes it private.

  • TEE-verified core

    Chats are answered inside a sealed room in the computer — special hardware that even the people running the machine can’t see into. Before your app sends anything, it checks the room’s seal.

    Wrong seal, no chat, no exceptions.

    If sealed rooms are full, Core asks before falling back — and the indicator changes state.

  • TEE-only pro

    Top-tier users never get quietly moved to an unsealed room — if sealed rooms are full, the session refuses to start rather than pretend.

    Fail closed; no waiver.

    A session can refuse to start rather than run unsealed.

self-tested Tested by us, not audited by outsiders. We never say “proven” or “audited” — we say “internally tested.” If we ever pay for a real audit, the language upgrades.

The four rooms

Pick your room for every conversation

select a room to see how it protects you

Burner

  1. Your device no trace

    The lamp dims

    No vault writes, no sync, no local history. The UI visibly shifts so you always know which room you’re in.

  2. Dusken servers self-tested

    Nothing server-side

    There never is. Plaintext is not intentionally persisted — inference memory only, internally canary-tested.

  3. The model open weights

    Answered, then gone

    Open models on GPUs we control — no frontier-lab APIs anywhere in the serving path.

FAQ

Privacy questions, answered plainly

The promise, the architecture, the keys, the limits — in the same plain words the specs use.

What is Dusken’s privacy promise?

We don’t keep your chats, and the copy we do hold is locked with a key only you have. Everything else exists to make that sentence true, testable, and safe to say out loud.

Do my messages touch Dusken’s servers?

We can’t see your chats — but the moment you hit send, the message does travel to our computers to get answered. We don’t keep it. But “never touches our servers” would be a lie, so we don’t say it.

What does Dusken actually store?

There is a complete receipts list — every scrap of data we hold, why we hold it, and the date it self-destructs. Chats aren’t on the list because we don’t keep them; what IS on the list (locked history boxes, account info, billing records, short-lived security counters) is published for anyone to read.

If a court ever demands “everything,” this list is everything.

Has any of this been audited?

Tested by us, not audited by outsiders. We cancelled the expensive outside audit. So we never say “proven” or “audited” — we say “internally tested.” If we ever pay for a real audit, the language upgrades.

An independent review is a possible future step, not a booked one. Nothing on this site says “audited” until it has happened.

What is Burner Mode?

The AI that doesn’t remember you. One tap: no vault writes, no sync, no local history, nothing server-side — there never is. On every tier, every model, including free.

“Burner is on. When this chat ends, it never happened.”

What is the Memory Vault?

Everything Dusken remembers is encrypted on your device before it syncs; the server stores only the encrypted form. Internally tested over enumerated surfaces, not independently audited.

Every memory is a human-readable card — read, edit, delete each one. Per-conversation toggle, global pause, one-click export, “forget this conversation” on every thread. Free forever, all tiers.

What happens if I lose my key?

Your chat history is stored encrypted under a key derived from your password (or a printed recovery sheet). Dusken is designed never to hold a copy of that key — internally tested, not independently audited. Lose both the password and the sheet, and it’s gone forever; that’s the deal that makes it private.

No reset button exists. That’s not a bug — a reset button would be a back door. If a phone is stolen, you kick it out and the locks change.

How can I check any of this myself?

The trust page carries a live architecture diagram, a TEE attestation viewer anyone can run, the “verify us” packet-capture guide, and a transparency report with a warrant canary — including its limits: verification tools reduce trust in us, they can’t eliminate it.

The web client is open-source on GitHub from launch — the community can inspect the source and independently reproduce the builds. The bar we hold ourselves to: a skeptical stranger goes from homepage to independently verifying a claim in under ten minutes.

What are the hard lines?

There’s a short, published list of hard lines — nothing involving minors, nothing illegal, and when someone seems to be in crisis the AI responds with care and real resources instead of a canned lecture. All of it happens live, in the moment: with no intentional plaintext persistence after inference, there is nothing stored to police afterwards.

Do I need to hand over an email or ID?

Accounts are email-optional — a username and passphrase works — alias-friendly, and no phone numbers, ever.

Adults only. Age assurance is planned to be privacy-preserving; the vendor and method are not chosen yet, so we make no promise about it today.

Pricing

Privacy is free. Proof is the upgrade.

Memory is the moat, not the upsell.

never paywalled Memory, chat history, export, basic model choice, sampler controls.

paid Speed, best models, verified-enclave routing, volume — TEE-verified inference on Core, TEE-only routing on Pro.