NOT LIVE YETThis site is a preview. Nothing here is running in production.

Savant is raising and speaking with investors now.Get in touch

Savant  //  Tallinn, Estonia

We never see your
chat history because
it does not exist.

Every question is answered in memory and dropped the moment the answer goes back. Nothing touches a disk, and nothing marks two conversations as having come from the same person. A history is something a company has to build on purpose, and we never build one.

No chat history No email needed Pay in crypto
What a question looks like
How it works

Why there is no history to hand over

Most services promise not to look through your conversations. We would rather not be in a position where we could. Your question is locked on your own device, carried by a relay that belongs to someone else, and answered on a machine that writes nothing down.

OnionWhere the name comes from
  1. Step 1

    Your device wraps it in layers

    One layer for each machine the question will pass through, added on your own computer or phone before anything is sent.

  2. Step 2

    A relay we do not own peels one

    It belongs to a separate operator, one of several your device picks from at random. It sees your IP address the way any website would, and its key opens the outer layer only. What is underneath stays shut.

  3. Step 3

    Our machine opens the last one

    This is the only part we run. It reads the question, writes the answer, and seals the reply. Once that is sent the question is gone from memory, and it was never anywhere else.

Who sees what

What each machine can see

What we are talking aboutEntry relay (not ours)RelaySavant
Your IP addressSees itNever sees it
Your questionCannot read itReads it
The answerCannot read itWrites it
Your name or emailNever asked forNever asked for
Earlier turns of this conversationCannot read themReads them, sent by you
Your other conversationsCannot read themNothing is kept
Which balance paid for itCannot see itCannot tell

A chat history only exists if three things are true at once. The questions have to be written down somewhere, they have to be linked to each other, and they have to be linked to a person. Yours are answered in memory and never reach a disk, nothing marks two of them as coming from the same place, and we were never told who you are. Break any one of those and a history cannot be assembled. We break all three.

Our machine does read your question, because something has to in order to answer it. Within one conversation your device sends the earlier turns along with each new question, so for that moment the machine sees them together. It writes none of it down, and when the answer is sent the whole exchange is gone. Across conversations nothing links one to another.

The last row is the one that makes the others hold. When you add credit, your device is issued blind tokens (Privacy Pass): signed by us without us seeing them. Each question spends tokens according to its size. The machine that answers can check the tokens are real, but it cannot tell which balance they came from, so it cannot link the question to you or to your other conversations.

The relay operators will be listed here at launch, so you can check who they are yourself.

What you get

Four promises we cannot break

Not because we are nice, but because of how the thing is built.

1

Nothing that identifies you

No IP address, no email, no name. You get a twenty digit number and that number is the whole account. Pay in crypto and nothing at all points back to you.

2

Pay in crypto

We take Monero, Bitcoin, Lightning, Ethereum, Litecoin and most other coins. Monero is the one we suggest, since it leaves no public trail back to you. Cards work as well if you would rather, though the card processor will know who you are. We will not, because the tokens you spend cannot be traced back to the payment.

3

You always know what firmware runs

Every machine has its firmware and its hash published. Relay and support machines boot coreboot, built with 3mdeb (Dasharo) and Leah Rowe (Libreboot). The EPYC inference boards have no open firmware port yet, so they run vendor firmware, and we say so rather than pretend.

4

Our own machines

The machine that answers you is hardware we bought and rack ourselves. Nothing runs on rented cloud, so there is no landlord who could read it over our shoulder. We tell you which country the rack is in, because that is the country whose courts can reach it.

The hardware

What is actually in the rack

Listed here so you can see what your answers are being generated on.

ProcessorAMD EPYC 9965, 192 cores per socket
BoardGigabyte MZ33-AR1, single socket, full PCIe 5.0 breakout
Memory3 TB of Kingston DDR5 RDIMM in every machine
Accelerators4× AMD Instinct MI350P per machine, liquid cooled, on ROCm
Firmwarecoreboot on relay and support machines. Vendor firmware on the EPYC boards until a port exists. A hash for every machine, published at launch.
LogsNo questions, no answers, no timestamps, no IP addresses. Nothing is written, so there is nothing to keep.
StorageDisks hold the operating system and model weights, encrypted at rest. Questions and answers are never written to them. Swap is off.
JurisdictionCompany registered in Estonia. Machines racked in RACK LOCATION.
SourceApp, relay and server code under a free licence, published at launch
Pricing

Three models, one balance

Named after Estonian weather. You pay per million tokens, in and out, from credit you have already added. Nothing expires and there is no subscription.

Lumisnow

Light and quick. Everyday questions, drafts, summaries, translation.

Udufog

The middle one. Code, analysis, long conversations, most real work.

Tormstorm

The largest model we run. Hard problems, long documents, research.

Prices per million tokens, in and out, are set before launch and will be listed here in euro, with the Monero or Bitcoin amount shown at the moment you pay. Add credit in any coin or by card. On your device the credit becomes blind tokens, and each question spends tokens according to its size.

Your first question is free. The app issues itself one small token before you have added anything, so you can see it work before you pay.

Before you sign up

Jump the trackers

A small game about the things that follow you around the web. Get past fifty of them and there is something in it for you.

Onion runner 0 dodged
Jump the trackers Reach 50 jumps for a lifetime secret surprise

Tap the strip or press space to jump

Secret surprise Fifty jumps clear. takes 10% off your account, for life, from launch.

Start

Your account is a number

Press Generate, keep the number somewhere safe, and that is the sign up finished. There is no password and no email to confirm. Since we never learn who you are, there is nothing about you to hand over later.

Add credit in whichever coin suits you, or by card. The balance belongs to the number, not to a person, and on your device it becomes blind tokens that cannot be traced back to it.

At launch you paste the number into the app or the API and add credit. Until then it is just a number, so generate as many as you like.

Hear about launch without giving us an address: @Savant_ee or the feed. No mailing list, on purpose.

Account number
#### #### #### #### ####
Made in your browser. It does not reach us until you first use it. The last digit is a check digit, so a typo fails instead of quietly becoming someone else's number. Write it down, because we have no way to recover it for you.

Scripts are off in your browser, so nothing can be generated here. At launch the app makes the number for you. It is twenty digits, and the last one is a check digit.