Privacy by design

    How DreamFort keeps you private.

    Chat with ChatGPT, Claude, Gemini and Grok without revealing who you are. Every request is routed through an OHTTP relay to strip your network identity, then through a TEE-isolated gateway that talks to the provider on your behalf. No single party can correlate who you are with what you asked. Your saved history stays locally in your browser or mobile app, and the app asks for permission before its first AI request.

    The privacy model

    Two independent layers, in series. Each layer eliminates one piece of correlation. Together, they leave no party with both.

    OHTTP relay

    Splits the network transport. The relay sees your IP but only an encrypted blob. The downstream gateway sees the plaintext request but never your IP.

    TEE-isolated gateway

    Runs inside a sealed trusted execution environment (TEE) with remote attestation. The operator can't see or log any of the prompts or requests, or build a profile across requests.

    How a request flows

    Four hops, two trust boundaries. Each party only sees what it strictly needs to do its job.

    01Your device

    Encrypts the request content with the gateway's public key. The ciphertext is wrapped in an OHTTP envelope and sent to the relay.

    02OHTTP relay

    Sees your IP and an opaque ciphertext blob. Forwards the blob to the TEE gateway from its own infrastructure. Never sees the request content.

    03TEE gatewayattested

    Inside a TEE — decrypts the request, calls the model provider, and re-encrypts the response. Sees the request content but not your IP. Memory is sealed; the operator can't read it.

    04Model provider

    Receives an anonymous request from our gateway. Sees the content needed to return your result but no identifying information about you.

    What each party sees

    A summary of the information each hop has access to.

    PartySees your IP?Sees request content?
    OHTTP relayYesNo
    TEE gatewayNoYes (in sealed memory)
    Model providerNoYes (anonymized)
    OpenGradient operatorNoNo

    What's not private

    Be honest about the limits.

    • The model provider still sees the request content needed to return your result - but the sender is anonymized.
    • Account-level data (email, plan, billing) is held by OpenGradient under standard data protection.
    • Coarse timing and traffic volume aren't hidden. An adversary watching both ends of the network could still correlate. Mitigated with batching, not eliminated.

    FAQ

    Why combine OHTTP and a TEE? Isn't one enough?

    OHTTP alone hides your network identity from the operator that talks to the provider — but the operator still sees your prompts. A TEE alone protects the prompt content from the operator, but the operator still sees your network identity. Putting them in series means neither layer can correlate identity to content, even if compromised independently.

    How is the TEE attested?

    Before any prompt is decrypted, the client verifies a remote attestation from the gateway's TEE. The attestation cryptographically proves the gateway is running the expected binary on genuine TEE hardware. The attestation is rechecked periodically - when it's stale, the indicator in your composer shows a warning.

    What does the model provider see?

    An anonymous request from our gateway's infrastructure. The provider sees the request content needed to return your result and our gateway's IP - but no identifying information about you. From their side, every DreamFort user looks the same.

    Are my chats stored on DreamFort's servers?

    No - your saved chat history lives locally in your browser or mobile app. Relevant context is transmitted only when needed for a request, and is not kept as a remotely stored conversation history.