Your AI. Your folder. You rule.

Built for long-form work chat — not a system assistant. TeeChat is designed so your chat history stays on your devices — not in our cloud. Download macOS Apple Silicon, Windows, or Linux (.deb) for local folders and optional local models — Intel Mac is coming soon. Hosted confidential AI on desktop or the web is Standard or Pro. OPE and our inference engine are open source.

Web: hosted confidential chat at chat.teechat.ai — Standard or Pro; same seat as desktop. Desktop: macOS Apple Silicon (.dmg), Windows (.exe), and Linux (.deb) available now; Intel Mac coming soon. MobileUpcoming — iOS and Android apps are in development.

Desktop

macOS Apple Silicon, Windows, and Linux are available now — local-first folders you control, optional local models, and the full feature set. Intel Mac is coming soon on the download page.

Your folder. You rule.

We do not operate a server-side archive of your conversations. On the web, threads stay in this browser and auto-delete after 7 days (not synced across devices); desktop apps store Markdown in folders you choose. Hosted inference sends opaque encrypted envelopes — the gateway sees ciphertext only. An open-source inference engine inside a TEE decrypts for the model; verify its attestation in Settings before sending.

Web (hosted, paid)

A Standard or Pro seat can use hosted chat in the browser at chat.teechat.ai. Threads stay on this device in IndexedDB and auto-delete after 7 days (no server-side archive, not synced). Encrypted envelopes to engines; verify attestation in Settings. Not included on Free.

Mobile Upcoming

Native iOS and Android apps are in development — same local folder model and encrypted hosted path as desktop and web. Sign up on web now to keep one account when mobile ships.

How hosted AI works

Hosted without handing over your chat records

Data sovereignty does not mean no cloud — it means your chat history stays yours. When you connect to teechat.ai, messages are encrypted before they leave your device; the gateway routes opaque envelopes and is not designed to persist plaintext. Someone must decrypt to run the model: a dedicated open-source inference engine, inside a measured TEE, does — not the gateway or a generic ops login. When a client or security review asks for evidence, verify attestation in Settings and audit OPE and the engine on GitHub.

Common questions

What is data sovereignty?

Your chat threads live in folders you choose — you rule, you can export, and canceling Pro does not delete your local archive. TeeChat does not operate a server-side chat archive. Using hosted AI on teechat.ai is optional; when you do, messages leave as encrypted envelopes and the routing server forwards scrambled text only. When a review asks for proof, verify the engine in Settings (L3).

Where are my chats stored?

On web today, chats stay in this browser only (IndexedDB) and auto-delete after 7 days — we do not operate a server-side archive. Signing in does not extend retention or sync threads to other devices; clearing browser data removes them immediately. Desktop apps store threads in folders you choose (for example ~/TeeChat on macOS and Windows). Mobile apps are in development.

Who sees my prompt on hosted AI?

Your client encrypts before send. The gateway forwards ciphertext only. A dedicated open-source inference engine inside a TEE decrypts to run the model.

Doesn’t the model have to see plaintext to infer?

Yes — something must decrypt to run the model. TeeChat uses Intel TDX / AMD SEV so guest memory stays encrypted; decryption happens only inside a CPU-protected enclave. The gateway and ops staff cannot read plaintext from memory. Read the deep dive →

Is turning off training enough?

No. Opting out protects training privacy (your chat is not baked into weights), not access privacy (during inference, plaintext may still flow in vendor RAM). TeeChat relies on hardware enforcement, not vendor promises. Read the deep dive →

Is redacted text safe to send?

Redaction is weak against LLM-era inference attacks — jargon, argument structure, and style can re-identify you. The durable fix is environment isolation: put the full document in a hardware TEE instead of stripping fields. Read the deep dive →

Do I need the biggest model for professional work?

Not always. Context richness matters as much as parameter count. Hardware privacy lets you send the full prompt; complete context often beats a frontier model fed sanitized fragments. Read the deep dive →

How do I verify openapi.teechat.ai independently?

A pass proves TLS terminated in a measured TeeChat edge, the hardware quote is fresh for your challenge, and the running build matches open-source GitHub release hashes (code_hash / SHA256SUMS) — optionally bound to your TLS session’s certificate. If GitHub Releases is unreachable, the verifier falls back to TeeChat’s signed www allowlist and tells you how to re-check the GitHub release page. Curling POST /v1/attestation/challenge only fetches a quote-shaped JSON blob; it does not verify Intel/AMD collateral, GitHub hashes, or session SPKI binding. Use teechat-openapi-attest verify https://openapi.teechat.ai, or TeeChat Settings → Inference → OpenAPI verify (desktop full verify / web light preview). Read the deep dive →

How is this different from Apple Private Cloud Compute?

Apple PCC protects assistant requests in Apple’s ecosystem. TeeChat is work chat: you own the thread files, use Standard search (Standard plan+) and Research (Pro), and can verify engine attestation plus audit OPE on GitHub when questionnaires ask for evidence — not confidence alone.

What if my client or employer asks what AI I use?

Offer artifacts: confidential mode, Verify in Settings, trust evidence you can record, and links to open-source OPE and the inference engine.

Why does Windows warn about app security when I install TeeChat?

The current Windows installer is Authenticode-signed with our company OV certificate. The publisher is Shanghai Lightec Technology Co., Ltd. (O=Lightec); the previous personal certificate was revoked. Signing proves who built the file; SmartScreen also checks reputation. Because the publisher string just changed, first installs may still briefly show an “unknown publisher” warning — if the publisher matches Shanghai Lightec Technology Co., Ltd., use More info → Run anyway. Reputation rebuilds as download volume grows.

Which Windows installer should I download?

Use Standard (~10 MB) if you are on Windows 11 or already have Microsoft Edge — the installer will fetch WebView2 from Microsoft if needed. Use the WebView2-included installer (~210 MB) if the Standard setup says it failed to install WebView2, if this PC cannot reach Microsoft download servers, or if you are not sure. In-app updates keep using the small installer.

Why does Chrome on older Windows say the TeeChat allowlist signature is unverified?

On Windows 7, 8, and 8.1, Google capped Chrome at version 109 — that build cannot verify Ed25519 signatures in the browser (Web Crypto added Ed25519 in Chrome 113). TeeChat's web client uses Ed25519 to check the published binaries allowlist. When the browser cannot run that check, the UI incorrectly reports that the allowlist lacks a valid signature. The published files are signed; this browser cannot verify them. Use a current Chrome, Edge, Firefox, or Safari on a supported OS, or the TeeChat desktop app.

The Standard Windows installer failed to install WebView2 — what should I do?

Older Windows often does not ship Microsoft WebView2 (unlike Windows 11 or a PC that already has Edge). The Standard installer (~10 MB) then tries to download WebView2 from Microsoft; some networks cannot reach those servers, so setup aborts. Download the WebView2-included installer from the download page instead. It is much larger (~210 MB) because the runtime is inside the file, but it does not need Microsoft’s download. In-app updates still use the small installer afterward.

Open standard

We build and contribute OPE

Open Privacy Envelope (OPE) is the open-source encryption layer behind TeeChat's hosted path — envelope format, hybrid E2E crypto, attestation hooks, and reference implementations. It is evidence for L3 verification, not a substitute for owning your local folder.

  • Protocol specs and test vectors — github.com/Lightec-AI/OPE
  • Open-source Rust crates, ope-ffi, and ope-wasm used by TeeChat clients and engines
  • Pairs with the open Inference engine for attested, decrypt-inside-TEE inference