Comparisons
How SELF compares with other privacy, messaging, and communication tools. By SELF we mean both Celestial (the protocol) and the SELF App (the product most people actually touch). Each section looks at the same things: architecture, jurisdiction, delivery, authentication, recovery, and purpose. We will add more comparisons over time. None of this is legal, investment, or security advice.
Signal
Signal (signal.org) is widely regarded as the benchmark for private messaging. This is the friendliest comparison in the list, because Signal and SELF agree on more than they disagree.
Sources reviewed (Signal, 2025 to 2026 public materials):
What each one actually is
Signal is a single thing done extremely well: end-to-end encrypted messaging. It is run by a US non-profit (the Signal Foundation), is fully open source, and uses the Signal Protocol, the Double Ratchet design that most other serious apps license or imitate. Every chat, call, and group is end-to-end encrypted by default, and its Sealed Sender work hides much of the who-talks-to-whom metadata too. By design it is a messenger and nothing else.
SELF is broader by design. It is a protocol (Celestial) and a client (the SELF App) spanning messaging, mail, calendar, encrypted storage, an AI assistant, office tools, wallet functions, and browser validation under one user-held key hierarchy. Protected content is encrypted on the client, with clear boundaries for operational metadata and services that must process readable data. Signal versus SELF is best-in-class single-purpose messaging compared with a broad privacy platform plus chain. The dividing lines are scope, the identity anchor, jurisdiction, and delivery.
Where Signal is genuinely right
Default end-to-end encryption for everything, fully open source, repeatedly audited, run by a non-profit rather than an advertising business, and unusually disciplined about metadata. When Signal has been subpoenaed (the 2021 and 2024 Santa Clara County cases), the most it could produce was account-creation and last-connection timestamps. SELF shares the emphasis on user-held keys and client-side encryption for protected content. Its services retain the routing, timing, account, and service metadata needed to operate the wider platform.
The phone number you cannot avoid
Signal still requires a phone number to register. Usernames (introduced in 2024) let you hide that number from the people you chat with, and discovery can be set to "Nobody", but your account remains anchored to a phone number internally, used for anti-spam and recovery. That is a real identity hook: a number tied to a SIM and a carrier. SELF requires no phone number. Encryption keys are derived on the user's device from a recovery phrase. An account email is required for contact and recovery, is encrypted at rest with a server-held key, and can be decrypted by SELF.
Delivery and notifications
The same structural point applies as elsewhere on this page. Signal ships as native iOS and Android apps, so the install is bound to an Apple ID or Google account, and push notifications travel through Apple's APNs and Google's FCM. Signal handles this about as carefully as anyone can, but the app-store identity and the platform relay still exist. The SELF App runs as a PWA in the browser with Web Push payloads encrypted to the browser, so it is not anchored to the two store gatekeepers in the same way.
Jurisdiction and infrastructure
Signal is a US non-profit running centralized servers on US cloud infrastructure. Its data minimization is excellent, so there is very little to compel, but it still sits under US legal process. SELF places core SELF App content and core application infrastructure in the EU, across Germany and France. External mail, optional web search, payment processing and static frontend delivery retain their documented processor boundaries. The PWA also lets users participate in network validation from the browser, while backend, inference, mail, call, signaling, orchestration, and coordinator services remain part of the production architecture.
Scope
Signal is a messenger. SELF combines messenger, mail, calendar, AI, vault, office, wallet, and browser validation under one user-held key hierarchy. Signal is superb for stand-alone secure chat. SELF is built for people who want a broader set of privacy tools, with client-side encryption applied to the protected content each service stores.
Philosophies (different directions)
| Lens | SELF (Celestial + App) | Signal |
|---|---|---|
| Core goal | Broad privacy platform with user-held encryption keys | Best-in-class private messaging |
| Encryption | Client-side encryption for protected content | E2E by default (Signal Protocol) |
| Identity anchor | User-held keys, no phone number; account email required | Phone number required to register |
| Metadata | Routing, timing, account, and service metadata remain visible | Minimal; Sealed Sender |
| Jurisdiction | Australian operator; core app content and infrastructure in the EU, with documented external processors | US non-profit, US legal process |
| Delivery | Progressive web app | Native iOS and Android, store-gated |
| Infrastructure | Core EU application services plus browser validation | Centralised US-hosted servers |
| Scope | AI, vault, messenger, mail, calendar, office, wallet, chain | Messaging and calls |
In one sentence. Signal is a best-in-class stand-alone private messenger, while SELF removes the phone-number requirement and delivers a broader PWA suite with user-held keys, protected content encrypted on the client, core EU application infrastructure, and browser validation.
Proton
Proton (proton.me) is a Swiss privacy suite: encrypted mail, VPN, calendar, drive, and a password manager. It is the closest comparison to SELF on breadth, and its Swiss base is a genuine strength worth stating plainly.
Sources reviewed (Proton, 2021 to 2026 public materials):
- Information for law enforcement
- Clarifications regarding arrest of a climate activist
- ProtonMail provided a user's IP address to authorities (Ars Technica)
What each one actually is
Proton is a centralized provider of privacy products, run by Proton AG in Switzerland, with end-to-end encryption for its mail product. The model is that you trust a well-run Swiss company to hold your encrypted data and behave well, backed by strong Swiss law. SELF is a PWA plus a chain: encryption keys are derived on the user's device, protected content is encrypted on the client, and users can participate in validation from the browser. SELF services can access the account and operational data identified below.
Where Proton is genuinely right
Switzerland is a meaningfully better home than the United States. Proton cannot be forced to hand over message content, because it does not hold the keys; it does not answer foreign governments directly (Article 271 of the Swiss Criminal Code, so foreign agencies must use the slower Mutual Legal Assistance Treaty process); and it actively fights data requests. SELF places core SELF App content and core application infrastructure in the EU, with application, database, mail, and call infrastructure in Germany and inference and object storage in France. External processors remain at the documented boundaries for optional search, payments, external mail and static frontend delivery.
The limits of "trust a good company"
Proton's model still leaves identifying metadata in the provider's hands, and real cases show it. Content stays encrypted, but Proton can be compelled by a Swiss court to begin logging a specific account's IP address (the 2021 climate-activist case), and it holds account metadata such as recovery email addresses and payment identifiers that have been used to identify people (a 2024 Catalan independence case, and the Stop Cop City matter where payment data reached the FBI through the Swiss MLAT process). Email itself also exposes sender, recipient, and timestamps by the nature of SMTP. None of this is bad faith. It is the structural cost of a centralized provider that holds your account.
SELF uses user-held encryption keys and requires no phone number. It also has a central account and billing path: SELF can decrypt the required account email, payment providers process billing data, and services retain operational metadata. Mail between SELF accounts is encrypted on the client. Inbound external mail arrives in readable form before being encrypted to the user's key, and outbound external mail leaves readable under TLS. Mail timestamps, sizes, and folders remain visible to the service.
Architecture
Proton stores your encrypted private key on its servers and unlocks it with your account password. SELF derives encryption keys on the client from a recovery phrase the user holds. SELF runs its core application services on dedicated EU infrastructure, uses documented external processors at defined service boundaries, and supports browser-based network validation through its PWA.
Philosophies (different directions)
| Lens | SELF (Celestial + App) | Proton |
|---|---|---|
| Core goal | Broad platform with user-held encryption keys | Trusted Swiss custodian of encrypted data |
| Jurisdiction | Australian operator; core app content and infrastructure in the EU, with documented external processors | Switzerland (strong; MLAT, Article 271) |
| Content | Client-side encryption for protected content; external mail follows SMTP boundaries | E2E mail; provider cannot read content |
| Metadata and identity | User-held keys; required account email and operational metadata | Recovery email, payment, court-ordered IP logging |
| Key custody | Keys derived on your device from a recovery phrase | Encrypted private key stored on Proton servers |
| Infrastructure | Dedicated core EU application services plus browser validation | Centralised Proton servers |
| Scope | AI, vault, messenger, mail, calendar, office, wallet, chain | Mail, VPN, calendar, drive, pass |
In one sentence. Proton is a privacy suite run by a Swiss provider, while SELF combines user-held encryption keys, client-side encrypted protected content, core EU application infrastructure, no phone-number requirement, and browser validation across a broader production platform.
Telegram
Telegram (telegram.org) is a popular, feature-rich messaging and broadcasting platform. It is also the clearest contrast in this list, because on the thing that matters most for privacy it works very differently from how most users assume.
Sources reviewed (Telegram, 2024 to 2026 public materials):
- Telegram privacy explained (ESET)
- Telegram's privacy policy reversal after the Durov arrest (The Droid Guy)
What each one actually is
Most people think of Telegram as an encrypted messenger. By default it is not end-to-end encrypted. Ordinary "cloud chats", the default for every one-to-one conversation and the only option for groups and channels, are encrypted between your device and Telegram's servers, where Telegram holds the keys and can read the content. End-to-end encryption exists only in "Secret Chats", which are manual, one-to-one only, tied to a single device, and by most estimates used in well under 5% of conversations. SELF encrypts direct and group message content and attachments on the client by default. Its delivery services still see sender and room identifiers and timing.
Where Telegram is genuinely good
Credit where it is due. Telegram is fast, polished, and excellent for large communities, channels, and bots, and its voice and video calls are end-to-end encrypted. As a public broadcast and community tool it is genuinely strong. The problem is narrower than "Telegram is bad": its reputation as a private messenger simply outruns its default behavior.
Who can read your messages, and who they will tell
Because default chats are readable by Telegram, the provider holds both the content and the metadata around it: phone number, IP address, usernames, and timestamps. That started to matter more after August 2024, when founder Pavel Durov was arrested in France and Telegram reversed its long-standing stance. It now discloses IP addresses and phone numbers to authorities in response to valid legal requests across a broad range of crimes, not just terrorism. Telegram also requires a phone number, runs a custom protocol (MTProto) that has been criticised for lacking the peer review of open standards, and operates through a corporate structure spread across Dubai and the British Virgin Islands.
SELF's messenger content is encrypted on the client, requires no phone number, and uses keys derived on the user's device. SELF can decrypt the required account email and can see message routing and timing data. Core messenger content and core application infrastructure are hosted in the EU, with documented external processor boundaries.
Philosophies (different directions)
| Lens | SELF (Celestial + App) | Telegram |
|---|---|---|
| Default encryption | Direct and group message content encrypted on the client | Client-server; provider can read cloud chats |
| E2E coverage | Messenger content and attachments; routing and timing remain visible | Secret Chats only (manual, 1:1, one device) |
| Groups and channels | Group message content encrypted | Never end-to-end encrypted |
| Identity anchor | User-held keys, no phone number; account email required | Phone number required |
| Provider access | Account email and delivery metadata; no key for stored message content | Holds content and metadata |
| Data location | Core app content and infrastructure in the EU; documented external processors | Discloses IP and phone on broad legal requests (since 2024) |
| Protocol | Standard, well-studied primitives | Custom MTProto, limited peer review |
| Scope | AI, vault, messenger, mail, calendar, office, wallet, chain | Messaging and broadcasting |
In one sentence. Telegram is a strong broadcasting platform whose default cloud chats are readable by its provider, while SELF encrypts direct and group messenger content on the client, keeps encryption keys with the user, and requires no phone number.
WhatsApp
WhatsApp (whatsapp.com) is the most widely used messenger on earth, and unlike Telegram it does encrypt message content end-to-end by default. The catch is everything around the message, and who owns it.
Sources reviewed (WhatsApp, 2021 to 2026 public materials):
- WhatsApp Privacy Review (Mozilla Foundation, 2025)
- Irish DPC WhatsApp decision (IAPP)
- WhatsApp and data privacy in 2025 (heyData)
What each one actually is
WhatsApp uses the Signal Protocol for message content. SELF Messenger uses a separate NaCl-based client-side design implemented with TweetNaCl: X25519-derived shared secrets protect conversation keys, and message content is encrypted in the browser with authenticated encryption. SELF does not implement or claim equivalence with the Signal Protocol. WhatsApp is owned by Meta, an advertising company, and the product is built around a phone number, an uploaded contact list, and metadata that flows to the wider Meta group. SELF has no advertising model or phone-number requirement. Routing and timing data and the required account email remain available to SELF services.
Where WhatsApp is genuinely right
The underlying protocol is sound. WhatsApp licensed the Signal Protocol, turned it on by default for personal chats, calls, and media, and in doing so brought real transit encryption to billions of people who would never install a niche app. That is a genuine good, worth saying before the caveats. It is also worth being precise about who earned it: the cryptography is Signal's design, not Meta's.
How strong is the encryption, really?
Calling WhatsApp's encryption "strong" without caveats overstates it, because the end-to-end guarantee is narrower than the impression it gives.
The biggest gaps are the carve-outs. Default cloud backups to iCloud or Google Drive are not end-to-end encrypted unless you switch it on, and the way restore works indicates WhatsApp can recover the backup key, so your history (and the half of any conversation that the other person backs up) can be readable off-device. Messages you send to business accounts can be hosted and processed on Meta's servers, which removes the end-to-end protection on that conversation entirely. Conversations with Meta AI are not end-to-end encrypted at all. The "everything is encrypted" impression is doing more work than the defaults support.
There is also the question of who inside the company can reach the data it does hold. A former WhatsApp security chief has alleged that roughly 1,500 engineers could access user data without proper controls or audit trails. Meta disputes the claim. SELF derives keys on the user's device and stores protected content such as messenger history, AI conversations and memory, vault content, and calendar event content as client-side encrypted ciphertext. AI content is processed live on SELF-controlled inference infrastructure, and operational account and service data sits outside that encrypted-content boundary.
The metadata is the product
End-to-end encryption protects what you say, not the fact that you said it. WhatsApp still collects who you talk to, how often, your group memberships, timestamps, IP addresses, device identifiers, and your uploaded address book, and Meta's own policy says this information is shared across Meta companies to operate and market its services. Relationship and timing metadata like this is enough to map a person's life even when the content is sealed, and for an advertising company that metadata is not exhaust, it is the asset. In 2021 the Irish Data Protection Commission fined WhatsApp €225 million for failing to be transparent about exactly this kind of data processing, including data about non-users pulled in through contact uploads.
SELF has no advertising model, requires no phone number, and does not depend on an uploaded address book as the identity anchor. Encryption keys come from a user-held recovery phrase. SELF retains the account, billing, routing, timing, and other service data needed to provide the platform.
Delivery, notifications, and jurisdiction
As with the other native apps here, WhatsApp installs through the App Store or Google Play and pushes notifications through APNs and FCM, so the install is bound to an Apple or Google identity and previews transit those platforms. Meta is a US company, which places WhatsApp under US legal process and the CLOUD Act. The SELF App runs as a PWA with Web Push payloads encrypted to the browser. Core SELF App content and core application infrastructure are hosted in the EU, with documented external processor boundaries.
Philosophies (different directions)
| Lens | SELF (Celestial + App) | |
|---|---|---|
| Content encryption | Client-side encryption for protected content | E2E for personal chats only (Signal Protocol) |
| Operator access | No key for stored protected content; account and service data remain accessible | Holds metadata; broad internal access alleged |
| Encryption boundaries | External mail, metadata, billing, live AI processing, and optional web search sit outside stored-content encryption | Default backups, business chats, Meta AI |
| Metadata | Routing, timing, account, mail envelope, reminder, and public wallet data remain visible | Harvested and shared across Meta |
| Business model | Subscription model, no advertising | Advertising and profiling (Meta) |
| Identity anchor | User-held keys, no phone number; account email required | Phone number plus uploaded contacts |
| Stored history | Protected content encrypted with user-held keys | Cloud backup not E2E unless enabled |
| In-app AI | Encrypted storage; live inference on SELF-controlled GPUs | Meta AI not end-to-end encrypted |
| Delivery | Progressive web app | Native iOS and Android, store-gated |
| Jurisdiction | Australian operator; core app content and infrastructure in the EU, with documented external processors | US (Meta), under US Cloud Act |
| Scope | AI, vault, messenger, mail, calendar, office, wallet, chain | Messaging and calls |
In one sentence. WhatsApp protects personal chats with the Signal Protocol while retaining a phone-number and advertising model; SELF requires no phone number, derives encryption keys on the user's device, uses NaCl-based client-side encryption for messenger content, and runs a broader subscription-funded PWA on core EU application infrastructure.
PRVC
PRVC (prvc.app) is an identity-free secure messenger. This section looks at how it differs from SELF across identity, jurisdiction, delivery, authentication, recovery, and purpose.
Sources reviewed (PRVC, 2026 public materials):
- prvc.app (home, architecture, FAQ, privacy policy, terms)
- How prvc.app works: a non-technical explainer
What each one actually is
PRVC is a single feature done with conviction: identity-free messaging. Its pitch is that true privacy protects both what you say and the identity behind it. So it removes phone numbers, emails, and accounts; your identity becomes a random string tied to one device, connections happen through one-time 64-character invite codes, and messages are sharded, scattered across servers as decoy "haystacks", and erased within roughly a day. It adds a Panic PIN that wipes local keys under duress. It is a US-patented product (US11516192B2) shipped as a native mobile app, with terms governed by the laws of Delaware.
SELF is bigger than any single app, and that is the point. Celestial is the participatory protocol described in Natural Technology, and the SELF App is its first live Constellation. The PWA spans messaging, mail, calendar, AI, vault, office, wallet, and browser validation. Keys are derived on the client from a BIP39 recovery phrase, and protected content is encrypted before storage. Account email, operational metadata, external mail boundaries, billing, live AI processing, optional web search, and coordinator services remain explicit parts of the architecture.
So the honest framing is not "messenger vs messenger." It is a narrow, deliberately disposable privacy tool against a philosophy, a protocol, and a product: SELF's worldview, Celestial as the foundation beneath it, and the SELF App as the client people use. PRVC is the part that meets a messenger head on, but the SELF App matters precisely because of what sits beneath it.
Where PRVC is genuinely right
It helps to be fair about this, because the strongest part of PRVC's case is true. Most "secure" apps still hang your whole social graph off a phone number, and that identity hook has caused real harm: large phone-number leaks, scaled enumeration of who uses which app, and, as the explainer notes, the use of registration numbers to locate and target people. Encrypting message content while leaving identity exposed is a real gap, and removing the phone number genuinely shrinks what an attacker or a data broker can grab.
SELF answers that diagnosis differently. PRVC's answer is to erase identity. SELF's answer is to make identity user-held and durable, with encryption keys derived from a recovery phrase and no phone-number requirement. SELF also requires an account email that the service can decrypt for contact and recovery. One approach optimizes for deniability in a single app. The other optimizes for continuity across a broad platform.
Jurisdiction: the US Cloud Act follows the company, not the server map
PRVC presents itself as stateless and serverless in spirit, but it is a US-domiciled product. Its terms are governed by the laws of Delaware, its protection rests on a US patent, and its export language invokes US encryption-export law. That places PRVC squarely under US jurisdiction, and therefore under the CLOUD Act (2018).
The CLOUD Act lets US authorities compel a provider subject to US jurisdiction to produce data in its possession, custody, or control, regardless of which country the servers sit in. "Our shards are scattered on servers around the world" does not move the company outside that reach, and it can come with non-disclosure obligations so the user is never told. PRVC's identity-free design does reduce how much stored content there is to hand over, which is a real mitigation. But two things survive it. First, compelled assistance can be forward-looking: a US order can require a provider to assist with collection going forward, while messages are still transiting and before they evaporate. Second, the company itself, its keys, its infrastructure relationships, and its update pipeline all remain reachable by US process.
Core SELF App content is processed and stored on core application infrastructure in the European Union. Application, database, mail, and call infrastructure runs in Germany, with GPU inference and object storage in France. The public application bundle and DNS are served by a US provider; the bundle contains no personal data. Optional search, payment processing and external mail retain their documented processor boundaries.
The phone in your pocket: app stores and plaintext notifications
This is where PRVC's own delivery choice undercuts its central promise. PRVC ships as a native iOS and Android app. That has two consequences the marketing does not address.
The install is tied to a real identity that Apple and Google hold. You download PRVC through the App Store or Google Play, which means the install is bound to your Apple ID or your Google account. Apple and Google therefore both know that this specific, identified person has PRVC on their device. PRVC may not know who you are. The two companies that control the operating system, the store, and the device still know the identified install. The "who" that PRVC works so hard to remove is reintroduced one layer down, at the platform it cannot see or control.
Notification text routes through Apple and Google in the clear. Push notifications on iOS and Android are delivered through Apple's APNs and Google's FCM. When a message preview appears on your lock screen, that notification payload has passed through Apple's or Google's servers, and unless every payload is treated as opaque ciphertext, the visible text is readable by the relaying platform. So the plaintext you see on your phone is plaintext that also existed on a US-based provider's infrastructure, attached to an account that identifies you. For a tool whose entire thesis is "if we do not know who you are, there is nothing to share," depending on two US platforms that do know who you are, and that do see notification content, is the weakest link in the chain.
The SELF App is a PWA running in the browser, so its primary delivery path does not require a native app-store install. Its notifications use the Web Push standard, where the payload is encrypted to the user's browser and the push service relays ciphertext rather than readable previews. Browser validation is available to users, while SELF continues to operate the backend, signaling, orchestration, coordinator, mail, call, and inference services needed by the product.
Authentication: a memorised PIN versus phishing-resistant passkeys
PRVC authenticates with a memorised PIN and adds a Panic PIN for duress. It deliberately rejects biometrics, arguing that a PIN you keep in your head has stronger US legal protection than a face or fingerprint a court can compel you to present. As a legal-deniability argument for a specific threat model, that is coherent.
The SELF App uses WebAuthn passkeys as the primary method: domain-bound, biometric-backed, and phishing-resistant by design. Email with a one-time code is the secondary authentication path, and the recovery phrase derives encryption keys. The honest summary: PRVC optimizes authentication for courtroom deniability in one app, while the SELF App prioritizes phishing-resistant authentication for ongoing account use.
Recovery and continuity: erased forever versus sovereign and durable
PRVC treats no recovery as a feature. Lose your phone and your identity and history are gone, because "if you cannot recover it, neither can an adversary." For a burner-style, high-risk, short-conversation use case, that is defensible.
It is the wrong default for a platform people spend ongoing time within. SELF's model gives the user continuity without surrendering control: the recovery phrase reconstructs encryption keys on any device, an optional recovery password enables cross-device recovery without re-entering the phrase, and the server still never sees the keys. Sovereignty includes the freedom to leave and the ability to keep what is yours across a lost phone, a new device, and the years of a real relationship with a health, finance, or family service.
The AI question, and what privacy rests on
PRVC markets "No AI, ever" as a core virtue. SELF takes a different view: AI conversations and memory can be encrypted on the client for storage while inference runs on dedicated GPUs SELF controls. Prompts are processed in readable form during live inference. Optional web search and URL reading send the user's search text to a third-party data provider after an explicit action.
Underneath that, the two protect users in different ways. PRVC reaches a low-data position by erasing identity outright and provides no recovery. SELF keeps encryption keys on the user's device and stores protected content as ciphertext, while retaining the readable account and service data needed to operate and recover a durable account.
Purpose and scope
PRVC is a tool: one screen, one job, ephemeral by design, aimed at a narrow high-risk threat model. There is a real place for that. SELF is a broader platform spanning AI, vault, messenger, mail, calendar, office, wallet, and a chain with browser validation. Its account and recovery model is designed for durable use across those services.
Philosophies (different directions)
| Lens | SELF (Celestial + App) | PRVC (public narrative) |
|---|---|---|
| Core goal | Durable account across a broad privacy platform | Erase identity; leave no trace |
| Identity model | Recovery phrase-derived keys; account email required | No identity; random per-device string |
| Jurisdiction | Australian operator; core app content and infrastructure in the EU, with documented external processors | Delaware law, US patent, under US Cloud Act |
| Delivery | Progressive web app with browser validation | Native iOS and Android, store-gated |
| Notifications | Web Push, payload encrypted to the browser | APNs / FCM, preview text via Apple and Google |
| Account path | No phone required; account email required | No account, email, or phone number |
| Authentication | Passkeys primary; email one-time code secondary | Memorised PIN + Panic PIN, no biometrics |
| Recovery | Recovery phrase + optional cross-device recovery | None; lose the phone, lose everything |
| AI | Client-encrypted storage; SELF-hosted live inference | None ("No AI, ever") |
| Scope | Platform and chain across many life domains | Single-purpose ephemeral messenger |
In one sentence. PRVC is designed around disposable, account-free messaging, while SELF offers durable recovery, user-held encryption keys, no phone-number requirement, a broad PWA suite, and core EU application infrastructure.
Vant Chat
Vant Chat (vant.chat) is, in shape, very close to PRVC: an identity-free, no-sign-up messenger built for people who want zero traceability, aimed at journalists, activists, and similar high-risk users. Because the model is almost the same, most of the PRVC comparison applies directly, so this section is shorter and focuses on what is shared and the few things that differ.
Sources reviewed (Vant Chat, 2026 public materials):
- vant.chat (home, features, mission)
The same model, the same limitations
Vant shares PRVC's core design: no phone number, no email, no account or user ID (it uses temporary pairwise connection links per contact), end-to-end encryption by default, a "no servers, zero data stored" claim, and post-quantum cryptography. Because the model is the same, the structural limitations from the PRVC section above apply here too.
- Native iOS and Android delivery. Vant ships through the App Store and Google Play, so the install is bound to an Apple ID or Google account, and those platforms know that an identified person has it. Vant does also offer a direct Android APK that avoids the Play account, which is a genuine point in its favor, but iOS still goes through Apple.
- Push notifications still travel through Apple and Google. Vant promotes push notifications even when the app is closed. On iOS and Android those are delivered through APNs and FCM, so notification content and delivery transit Apple's and Google's servers, exactly the weak link described under PRVC. An identity-free app whose alerts depend on the two companies that know your device identity has quietly reintroduced the "who" at the platform layer.
- No recovery. With no account, a lost phone means lost contacts and history. That is fine for a throwaway tool and the wrong default for something you live in. SELF gives you recovery without surrendering control: a recovery phrase, optional cross-device recovery, and keys the server never sees.
- Identity and continuity. Like PRVC, Vant removes the account entirely. SELF uses recovery phrase-derived keys and a required account email to support durable use without requiring a phone number.
What is a little different
Two things set Vant apart from PRVC, one better and one worse. On the better side, Vant has resisted data-localisation pressure: it was removed from Apple's China App Store in 2024 for refusing to comply with national-security data demands, which at least signals a posture against handing data over. On the worse side, where PRVC is openly US-domiciled (so you can at least reason about the CLOUD Act), Vant's operator and governing jurisdiction are not clearly stated. "We do not have your data" is harder to weigh when you do not know who is making the promise or which law they answer to.
Where this leaves SELF
The same place as the PRVC comparison. Vant is a single-purpose tool for deniable, throwaway conversations. SELF is built for continuity across messaging, mail, calendar, AI, vault, office, wallet, and browser validation. Encryption keys stay with the user and protected content is encrypted on the client. SELF also maintains a recoverable account, visible operational metadata, and core production services on EU infrastructure, with documented external processors at defined boundaries.
Philosophies (different directions)
| Lens | SELF (Celestial + App) | Vant Chat |
|---|---|---|
| Core goal | Durable account across a broad privacy platform | Erase identity; zero traceability |
| Identity | User-held keys, no phone number; account email required | No account or IDs; pairwise links |
| Delivery | Progressive web app with browser validation | Native iOS and Android (plus Android APK) |
| Notifications | Web Push, encrypted to the browser | APNs / FCM via Apple and Google |
| Recovery | Recovery phrase + optional cross-device | None; lose the phone, lose everything |
| Jurisdiction | Australian operator; core app content and infrastructure in the EU, with documented external processors | Operator and jurisdiction unstated |
| Scope | AI, vault, messenger, mail, calendar, office, wallet, chain | Single-purpose messaging |
In one sentence. Vant Chat is a no-account messenger built for ephemeral use, while SELF provides a recoverable account, user-held encryption keys, client-side encrypted protected content, no phone-number requirement, and PWA delivery.
Duck.ai
Duck.ai (duck.ai) is DuckDuckGo's free, account-optional AI chat: a privacy-minded proxy to third-party models such as GPT, Claude, and Mistral. It is the closest comparison on this page to SELF on the AI axis, because both answer the question of how to use an assistant without an advertising company building a profile around you. The architectures diverge from there.
Sources reviewed (Duck.ai, 2025 to 2026 public materials):
- Duck.ai Privacy Policy and Terms of Use
- What information does Duck.ai share with model providers?
- Reddit: Duck.ai's privacy policy is lying to us (community discussion, June 2025)
What each one actually is
Duck.ai is a privacy proxy, not a private model. DuckDuckGo sits between you and providers such as OpenAI, Anthropic, Azure OpenAI, and together.ai. It reads your prompt, strips your IP address, attaches contextual metadata (date, timezone, units, and global region derived from a GEO::IP lookup), and forwards the text to the provider. Chats save locally in your browser by default; optional Sync & Backup stores encrypted copies on DuckDuckGo's servers with keys held only on your devices. The provider receives the full text of what you typed. DuckDuckGo receives it too.
SELF is a broad privacy suite with its own AI stack. AI conversations and memory are encrypted on the client for storage. SELF AI performs live inference on dedicated GPUs SELF controls and does not use external model APIs for ordinary conversation. Optional web search and URL reading send the user's search text to a third-party data provider after an explicit action. Duck.ai versus SELF is a comparison between a privacy proxy to third-party models and a self-hosted AI service integrated with a wider PWA platform.
Where Duck.ai is genuinely right
Credit where it is due. Using a model provider directly exposes your IP, account identity, and usage history. Duck.ai improves on that materially: no account is required for basic chat, your IP is stripped before the request reaches the model company, DuckDuckGo has contractual limits on provider retention and training, and some models offer stronger tiers such as Zero Data Retention or Zero Provider Visibility (described per session in Duck.ai's privacy dialogue). Local-by-default chat storage, optional encrypted Sync & Backup with client-held keys, and no advertising profile built from your prompts are real strengths. For someone who wants hosted AI without signing into another Big Tech account, Duck.ai is a thoughtful step up from the default.
Three parties, two of them reading your words
The structural gap is who sees the content of your prompts.
The model provider reads everything. Duck.ai anonymizes the sender while the message remains readable. Your prompt arrives at OpenAI or Anthropic as readable text. They cannot easily tie it to your IP. They still process it, apply their usage policies, and retain it under their agreements with DuckDuckGo (typically deleted within 30 days, with safety and legal exceptions). Even models labelled Zero Data Retention are read at inference time; the guarantee is about retention afterward, not about secrecy during processing.
DuckDuckGo reads everything too. To strip metadata and forward the request, the proxy must see the prompt in plaintext. The privacy win is that the provider does not know it was you. It is not that nobody saw what you typed.
SELF keeps ordinary AI inference on infrastructure it operates. AI content is processed live by SELF's model service on dedicated hardware, then prompts and responses are retained as client-side encrypted content. Ordinary conversations do not become external model API traffic. When a user explicitly invokes optional web search or URL reading, the search text is sent to a third-party data provider.
Metadata: stripped IP, not stripped context
Duck.ai's privacy policy says metadata containing personal information is removed before prompts reach model providers. That is true for the IP address itself, but not for everything inferred from it. By default, requests to most providers include today's date, your timezone, your preferred unit system, and a global region guessed from GEO::IP. Optional "Use Approximate Location" (off by default) can add city-level location for locally relevant answers.
When users asked models where they were, some got back their city, which clashed with a plain reading of "all personal information removed" and sparked community pushback in mid-2025. DuckDuckGo's response, including from CEO Gabriel Weinberg in that thread, is that the IP is stripped and never sent, while region or city is inferred separately, similar to DuckDuckGo Search. That may be technically accurate and still leave the policy sounding broader than the behaviour users expected.
SELF does not use a third-party model API for ordinary AI conversations. Optional web search and URL reading are separate, explicit actions that send search text to a third-party data provider.
Voice, jurisdiction, and what sits beyond chat
Duck.ai's voice chat and dictation send audio to the model provider (through an encrypted relay DuckDuckGo cannot decrypt); only the text transcript is saved locally by default. That is another path where your words reach a US model company even when the proxy behaves well.
DuckDuckGo is a US company routing traffic to US-governed model APIs. The main compulsion surface is prompt content processed as plaintext on a third party's infrastructure, subject to that provider's policies and legal environment. The location of optional encrypted backups does not change that live-processing boundary.
SELF places core SELF App content and core application infrastructure in the EU and runs inference on dedicated GPUs it controls. Its assistant is integrated with messaging, mail, calendar, vault, office, wallet, and browser validation under one recoverable account. External model APIs are not used for ordinary conversation; optional search and URL reading use a third-party data provider.
Philosophies (different directions)
| Lens | SELF (Celestial + App) | Duck.ai |
|---|---|---|
| Core goal | Broad privacy suite with self-hosted AI | Privacy-oriented access to third-party AI models |
| Who reads your prompt | SELF-hosted model processes it during live inference | DuckDuckGo proxy and external model provider |
| Prompt to third parties | No external model API for ordinary chat; optional search text goes to a data provider | Full text forwarded; IP stripped |
| Provider retention | AI conversations stored client-side encrypted; search provider receives explicit queries | Contractual no-training; deleted within ~30 days (ZDR on some models) |
| Chat storage | Client-side encrypted prompts, responses, and memory | Local browser by default; optional encrypted server sync |
| Location in requests | No location added to ordinary model inference; search is a separate external service | GEO::IP region by default; optional city-level |
| Identity | User-held keys, recovery phrase, passkeys, and account email | No account required; optional encrypted Sync & Backup |
| Scope | AI, vault, messenger, mail, calendar, office, wallet, chain | AI chat and dictation only |
In one sentence. Duck.ai provides privacy-oriented access to third-party models, while SELF stores AI conversations client-side encrypted, runs live inference on dedicated hardware it controls, and integrates the assistant into a broader PWA suite, with optional external search clearly separated from ordinary conversation.

