Venice AI hit unicorn status this morning on the back of a $65M Series A, and the headline everywhere calls it “privacy-first AI.” I read three versions of that story before I noticed none of them said where the prompts actually go. Which is the whole question, and somehow the one part nobody prints.

Because privacy-first is a real thing Venice does. They don’t log conversations. They don’t train on your chats. They route through their own stack instead of reselling OpenAI. If you’re comparing them to ChatGPT’s data-retention defaults, they win, and it’s not close.

But “we don’t keep it” is a different promise than “it never left.” And those two get blurred together on purpose, or at least conveniently, in every launch post I’ve seen today.

What “privacy-first” is quietly doing

Type a prompt into Venice. That text gets serialized, wrapped in TLS, and shipped to a server you don’t own. The model runs there. The response comes back. Somewhere in that round trip your words sat in the RAM of a machine in a datacenter, decrypted, because a GPU can’t do inference on ciphertext.

Venice’s claim is that they don’t do anything bad with that moment. Fine. I mostly believe them. But the moment still exists, and it’s a moment where your data is on someone else’s hardware, subject to their breach surface, their subpoenas, their next pivot, their next investor who wants better margins. A privacy policy is a promise about behavior. It is not a wall.

The unicorn valuation is the tell, honestly. You raise $65M by building infrastructure that scales, and infrastructure that scales is centralized by definition. The business model needs your prompt to arrive at their servers. Privacy-first, in that framing, is the most trustworthy possible version of a fundamentally remote system. It is still remote.

The part that actually stays local

Here’s a different setup, and it’s the one I keep coming back to. An AI agent that runs inside the browser you already have open. It reads the page you’re looking at using the DOM your own Chrome already rendered. It acts on the tab you’re already logged into. The page content never gets packaged up and mailed to a cloud, because the thing reading the page is sitting right there in the page.

That’s the architecture behind dassi. It lives in the side panel. When it drafts a reply to the email you have open, it’s working off the Gmail tab your session already authenticated, not a copy of your inbox uploaded somewhere for processing. Your login state, your page, your machine.

I wrote more about why this distinction matters in local browser vs cloud browser agents, but the short version is that most “browser agents” spin up headless Chrome on a rented server and then can’t see anything you’re logged into. Local execution isn’t a feature they forgot. It’s a thing their business can’t afford.

But it still calls a model, right

Yes. And this is the honest catch, so I’ll sit with it.

A browser agent still needs a language model, and the good models live in the cloud. So when dassi runs GPT-5.2 or Claude Opus 4 to reason about your page, some text does go out over the wire to whatever model you picked. That’s real. I’m not going to pretend the electron stays home.

The difference is what leaves and who you’re trusting with it. With bring-your-own-key, the traffic goes straight from your browser to your model provider on your account. No middleman product in between logging, caching, or reselling. You already trust Anthropic or OpenAI with the prompt the second you use their model at all. What you avoid is a second company sitting in the path, which is exactly the argument for why BYOK matters when everyone in the AI stack is quietly mining everyone else. And the agent decides what’s worth sending. The full page, all your tabs, your session cookies, the DOM tree nobody needs? That stays on your machine. Only the slice the model actually needs to reason about goes anywhere, and it goes to a provider you chose, on a key you hold.

So what did $65M buy

A very good remote AI, run by people who seem to genuinely care about not being creepy with your data. That’s worth something. If your alternative is pasting work into ChatGPT, Venice is a real upgrade and I’d tell a friend to use it.

But privacy-first is a description of intent, not of physics. The prompt still travels. The unicorn still runs in a datacenter. The strongest version of “my data stayed private” isn’t a company promising to be careful with the copy you sent them. It’s never sending the copy. Runs in your browser, on your login, and the page you’re reading never books a flight.