Skip to content

Comparisons

How SELF compares with other privacy, messaging, and communication tools. By SELF we mean both Celestial (the protocol) and the SELF App (the product most people actually touch). Each section looks at the same things: architecture, jurisdiction, delivery, authentication, recovery, and purpose. We will add more comparisons over time. None of this is legal, investment, or security advice.


Signal

Signal (signal.org) is widely regarded as the benchmark for private messaging. This is the friendliest comparison in the list, because Signal and SELF agree on more than they disagree.

Sources reviewed (Signal, 2025 to 2026 public materials):

What each one actually is

Signal is a single thing done extremely well: end-to-end encrypted messaging. It is run by a US non-profit (the Signal Foundation), is fully open source, and uses the Signal Protocol, the Double Ratchet design that most other serious apps license or imitate. Every chat, call, and group is end-to-end encrypted by default, and its Sealed Sender work hides much of the who-talks-to-whom metadata too. By design it is a messenger and nothing else.

SELF is broader by design. It is a protocol (Celestial) and a client (the SELF App) spanning messaging, mail, calendar, encrypted storage, an AI assistant, office tools, wallet functions, and browser validation under one user-held key hierarchy. Protected content is encrypted on the client, with clear boundaries for operational metadata and services that must process readable data. Signal versus SELF is best-in-class single-purpose messaging compared with a broad privacy platform plus chain. The dividing lines are scope, the identity anchor, jurisdiction, and delivery.

Where Signal is genuinely right

Default end-to-end encryption for everything, fully open source, repeatedly audited, run by a non-profit rather than an advertising business, and unusually disciplined about metadata. When Signal has been subpoenaed (the 2021 and 2024 Santa Clara County cases), the most it could produce was account-creation and last-connection timestamps. SELF shares the emphasis on user-held keys and client-side encryption for protected content. Its services retain the routing, timing, account, and service metadata needed to operate the wider platform.

The phone number you cannot avoid

Signal still requires a phone number to register. Usernames (introduced in 2024) let you hide that number from the people you chat with, and discovery can be set to "Nobody", but your account remains anchored to a phone number internally, used for anti-spam and recovery. That is a real identity hook: a number tied to a SIM and a carrier. SELF requires no phone number. Encryption keys are derived on the user's device from a recovery phrase. An account email is required for contact and recovery, is encrypted at rest with a server-held key, and can be decrypted by SELF.

Delivery and notifications

The same structural point applies as elsewhere on this page. Signal ships as native iOS and Android apps, so the install is bound to an Apple ID or Google account, and push notifications travel through Apple's APNs and Google's FCM. Signal handles this about as carefully as anyone can, but the app-store identity and the platform relay still exist. The SELF App runs as a PWA in the browser with Web Push payloads encrypted to the browser, so it is not anchored to the two store gatekeepers in the same way.

Jurisdiction and infrastructure

Signal is a US non-profit running centralized servers on US cloud infrastructure. Its data minimization is excellent, so there is very little to compel, but it still sits under US legal process. SELF places core SELF App content and core application infrastructure in the EU, across Germany and France. External mail, optional web search, payment processing and static frontend delivery retain their documented processor boundaries. The PWA also lets users participate in network validation from the browser, while backend, inference, mail, call, signaling, orchestration, and coordinator services remain part of the production architecture.

Scope

Signal is a messenger. SELF combines messenger, mail, calendar, AI, vault, office, wallet, and browser validation under one user-held key hierarchy. Signal is superb for stand-alone secure chat. SELF is built for people who want a broader set of privacy tools, with client-side encryption applied to the protected content each service stores.

Philosophies (different directions)

LensSELF (Celestial + App)Signal
Core goalBroad privacy platform with user-held encryption keysBest-in-class private messaging
EncryptionClient-side encryption for protected contentE2E by default (Signal Protocol)
Identity anchorUser-held keys, no phone number; account email requiredPhone number required to register
MetadataRouting, timing, account, and service metadata remain visibleMinimal; Sealed Sender
JurisdictionAustralian operator; core app content and infrastructure in the EU, with documented external processorsUS non-profit, US legal process
DeliveryProgressive web appNative iOS and Android, store-gated
InfrastructureCore EU application services plus browser validationCentralised US-hosted servers
ScopeAI, vault, messenger, mail, calendar, office, wallet, chainMessaging and calls

In one sentence. Signal is a best-in-class stand-alone private messenger, while SELF removes the phone-number requirement and delivers a broader PWA suite with user-held keys, protected content encrypted on the client, core EU application infrastructure, and browser validation.


Proton

Proton (proton.me) is a Swiss privacy suite: encrypted mail, VPN, calendar, drive, and a password manager. It is the closest comparison to SELF on breadth, and its Swiss base is a genuine strength worth stating plainly.

Sources reviewed (Proton, 2021 to 2026 public materials):

What each one actually is

Proton is a centralized provider of privacy products, run by Proton AG in Switzerland, with end-to-end encryption for its mail product. The model is that you trust a well-run Swiss company to hold your encrypted data and behave well, backed by strong Swiss law. SELF is a PWA plus a chain: encryption keys are derived on the user's device, protected content is encrypted on the client, and users can participate in validation from the browser. SELF services can access the account and operational data identified below.

Where Proton is genuinely right

Switzerland is a meaningfully better home than the United States. Proton cannot be forced to hand over message content, because it does not hold the keys; it does not answer foreign governments directly (Article 271 of the Swiss Criminal Code, so foreign agencies must use the slower Mutual Legal Assistance Treaty process); and it actively fights data requests. SELF places core SELF App content and core application infrastructure in the EU, with application, database, mail, and call infrastructure in Germany and inference and object storage in France. External processors remain at the documented boundaries for optional search, payments, external mail and static frontend delivery.

The limits of "trust a good company"

Proton's model still leaves identifying metadata in the provider's hands, and real cases show it. Content stays encrypted, but Proton can be compelled by a Swiss court to begin logging a specific account's IP address (the 2021 climate-activist case), and it holds account metadata such as recovery email addresses and payment identifiers that have been used to identify people (a 2024 Catalan independence case, and the Stop Cop City matter where payment data reached the FBI through the Swiss MLAT process). Email itself also exposes sender, recipient, and timestamps by the nature of SMTP. None of this is bad faith. It is the structural cost of a centralized provider that holds your account.

SELF uses user-held encryption keys and requires no phone number. It also has a central account and billing path: SELF can decrypt the required account email, payment providers process billing data, and services retain operational metadata. Mail between SELF accounts is encrypted on the client. Inbound external mail arrives in readable form before being encrypted to the user's key, and outbound external mail leaves readable under TLS. Mail timestamps, sizes, and folders remain visible to the service.

Architecture

Proton stores your encrypted private key on its servers and unlocks it with your account password. SELF derives encryption keys on the client from a recovery phrase the user holds. SELF runs its core application services on dedicated EU infrastructure, uses documented external processors at defined service boundaries, and supports browser-based network validation through its PWA.

Philosophies (different directions)

LensSELF (Celestial + App)Proton
Core goalBroad platform with user-held encryption keysTrusted Swiss custodian of encrypted data
JurisdictionAustralian operator; core app content and infrastructure in the EU, with documented external processorsSwitzerland (strong; MLAT, Article 271)
ContentClient-side encryption for protected content; external mail follows SMTP boundariesE2E mail; provider cannot read content
Metadata and identityUser-held keys; required account email and operational metadataRecovery email, payment, court-ordered IP logging
Key custodyKeys derived on your device from a recovery phraseEncrypted private key stored on Proton servers
InfrastructureDedicated core EU application services plus browser validationCentralised Proton servers
ScopeAI, vault, messenger, mail, calendar, office, wallet, chainMail, VPN, calendar, drive, pass

In one sentence. Proton is a privacy suite run by a Swiss provider, while SELF combines user-held encryption keys, client-side encrypted protected content, core EU application infrastructure, no phone-number requirement, and browser validation across a broader production platform.


Telegram

Telegram (telegram.org) is a popular, feature-rich messaging and broadcasting platform. It is also the clearest contrast in this list, because on the thing that matters most for privacy it works very differently from how most users assume.

Sources reviewed (Telegram, 2024 to 2026 public materials):

What each one actually is

Most people think of Telegram as an encrypted messenger. By default it is not end-to-end encrypted. Ordinary "cloud chats", the default for every one-to-one conversation and the only option for groups and channels, are encrypted between your device and Telegram's servers, where Telegram holds the keys and can read the content. End-to-end encryption exists only in "Secret Chats", which are manual, one-to-one only, tied to a single device, and by most estimates used in well under 5% of conversations. SELF encrypts direct and group message content and attachments on the client by default. Its delivery services still see sender and room identifiers and timing.

Where Telegram is genuinely good

Credit where it is due. Telegram is fast, polished, and excellent for large communities, channels, and bots, and its voice and video calls are end-to-end encrypted. As a public broadcast and community tool it is genuinely strong. The problem is narrower than "Telegram is bad": its reputation as a private messenger simply outruns its default behavior.

Who can read your messages, and who they will tell

Because default chats are readable by Telegram, the provider holds both the content and the metadata around it: phone number, IP address, usernames, and timestamps. That started to matter more after August 2024, when founder Pavel Durov was arrested in France and Telegram reversed its long-standing stance. It now discloses IP addresses and phone numbers to authorities in response to valid legal requests across a broad range of crimes, not just terrorism. Telegram also requires a phone number, runs a custom protocol (MTProto) that has been criticised for lacking the peer review of open standards, and operates through a corporate structure spread across Dubai and the British Virgin Islands.

SELF's messenger content is encrypted on the client, requires no phone number, and uses keys derived on the user's device. SELF can decrypt the required account email and can see message routing and timing data. Core messenger content and core application infrastructure are hosted in the EU, with documented external processor boundaries.

Philosophies (different directions)

LensSELF (Celestial + App)Telegram
Default encryptionDirect and group message content encrypted on the clientClient-server; provider can read cloud chats
E2E coverageMessenger content and attachments; routing and timing remain visibleSecret Chats only (manual, 1:1, one device)
Groups and channelsGroup message content encryptedNever end-to-end encrypted
Identity anchorUser-held keys, no phone number; account email requiredPhone number required
Provider accessAccount email and delivery metadata; no key for stored message contentHolds content and metadata
Data locationCore app content and infrastructure in the EU; documented external processorsDiscloses IP and phone on broad legal requests (since 2024)
ProtocolStandard, well-studied primitivesCustom MTProto, limited peer review
ScopeAI, vault, messenger, mail, calendar, office, wallet, chainMessaging and broadcasting

In one sentence. Telegram is a strong broadcasting platform whose default cloud chats are readable by its provider, while SELF encrypts direct and group messenger content on the client, keeps encryption keys with the user, and requires no phone number.


WhatsApp

WhatsApp (whatsapp.com) is the most widely used messenger on earth, and unlike Telegram it does encrypt message content end-to-end by default. The catch is everything around the message, and who owns it.

Sources reviewed (WhatsApp, 2021 to 2026 public materials):

What each one actually is

WhatsApp uses the Signal Protocol for message content. SELF Messenger uses a separate NaCl-based client-side design implemented with TweetNaCl: X25519-derived shared secrets protect conversation keys, and message content is encrypted in the browser with authenticated encryption. SELF does not implement or claim equivalence with the Signal Protocol. WhatsApp is owned by Meta, an advertising company, and the product is built around a phone number, an uploaded contact list, and metadata that flows to the wider Meta group. SELF has no advertising model or phone-number requirement. Routing and timing data and the required account email remain available to SELF services.

Where WhatsApp is genuinely right

The underlying protocol is sound. WhatsApp licensed the Signal Protocol, turned it on by default for personal chats, calls, and media, and in doing so brought real transit encryption to billions of people who would never install a niche app. That is a genuine good, worth saying before the caveats. It is also worth being precise about who earned it: the cryptography is Signal's design, not Meta's.

How strong is the encryption, really?

Calling WhatsApp's encryption "strong" without caveats overstates it, because the end-to-end guarantee is narrower than the impression it gives.

The biggest gaps are the carve-outs. Default cloud backups to iCloud or Google Drive are not end-to-end encrypted unless you switch it on, and the way restore works indicates WhatsApp can recover the backup key, so your history (and the half of any conversation that the other person backs up) can be readable off-device. Messages you send to business accounts can be hosted and processed on Meta's servers, which removes the end-to-end protection on that conversation entirely. Conversations with Meta AI are not end-to-end encrypted at all. The "everything is encrypted" impression is doing more work than the defaults support.

There is also the question of who inside the company can reach the data it does hold. A former WhatsApp security chief has alleged that roughly 1,500 engineers could access user data without proper controls or audit trails. Meta disputes the claim. SELF derives keys on the user's device and stores protected content such as messenger history, AI conversations and memory, vault content, and calendar event content as client-side encrypted ciphertext. AI content is processed live on SELF-controlled inference infrastructure, and operational account and service data sits outside that encrypted-content boundary.

The metadata is the product

End-to-end encryption protects what you say, not the fact that you said it. WhatsApp still collects who you talk to, how often, your group memberships, timestamps, IP addresses, device identifiers, and your uploaded address book, and Meta's own policy says this information is shared across Meta companies to operate and market its services. Relationship and timing metadata like this is enough to map a person's life even when the content is sealed, and for an advertising company that metadata is not exhaust, it is the asset. In 2021 the Irish Data Protection Commission fined WhatsApp €225 million for failing to be transparent about exactly this kind of data processing, including data about non-users pulled in through contact uploads.

SELF has no advertising model, requires no phone number, and does not depend on an uploaded address book as the identity anchor. Encryption keys come from a user-held recovery phrase. SELF retains the account, billing, routing, timing, and other service data needed to provide the platform.

Delivery, notifications, and jurisdiction

As with the other native apps here, WhatsApp installs through the App Store or Google Play and pushes notifications through APNs and FCM, so the install is bound to an Apple or Google identity and previews transit those platforms. Meta is a US company, which places WhatsApp under US legal process and the CLOUD Act. The SELF App runs as a PWA with Web Push payloads encrypted to the browser. Core SELF App content and core application infrastructure are hosted in the EU, with documented external processor boundaries.

Philosophies (different directions)

LensSELF (Celestial + App)WhatsApp
Content encryptionClient-side encryption for protected contentE2E for personal chats only (Signal Protocol)
Operator accessNo key for stored protected content; account and service data remain accessibleHolds metadata; broad internal access alleged
Encryption boundariesExternal mail, metadata, billing, live AI processing, and optional web search sit outside stored-content encryptionDefault backups, business chats, Meta AI
MetadataRouting, timing, account, mail envelope, reminder, and public wallet data remain visibleHarvested and shared across Meta
Business modelSubscription model, no advertisingAdvertising and profiling (Meta)
Identity anchorUser-held keys, no phone number; account email requiredPhone number plus uploaded contacts
Stored historyProtected content encrypted with user-held keysCloud backup not E2E unless enabled
In-app AIEncrypted storage; live inference on SELF-controlled GPUsMeta AI not end-to-end encrypted
DeliveryProgressive web appNative iOS and Android, store-gated
JurisdictionAustralian operator; core app content and infrastructure in the EU, with documented external processorsUS (Meta), under US Cloud Act
ScopeAI, vault, messenger, mail, calendar, office, wallet, chainMessaging and calls

In one sentence. WhatsApp protects personal chats with the Signal Protocol while retaining a phone-number and advertising model; SELF requires no phone number, derives encryption keys on the user's device, uses NaCl-based client-side encryption for messenger content, and runs a broader subscription-funded PWA on core EU application infrastructure.


PRVC

PRVC (prvc.app) is an identity-free secure messenger. This section looks at how it differs from SELF across identity, jurisdiction, delivery, authentication, recovery, and purpose.

Sources reviewed (PRVC, 2026 public materials):

What each one actually is

PRVC is a single feature done with conviction: identity-free messaging. Its pitch is that true privacy protects both what you say and the identity behind it. So it removes phone numbers, emails, and accounts; your identity becomes a random string tied to one device, connections happen through one-time 64-character invite codes, and messages are sharded, scattered across servers as decoy "haystacks", and erased within roughly a day. It adds a Panic PIN that wipes local keys under duress. It is a US-patented product (US11516192B2) shipped as a native mobile app, with terms governed by the laws of Delaware.

SELF is bigger than any single app, and that is the point. Celestial is the participatory protocol described in Natural Technology, and the SELF App is its first live Constellation. The PWA spans messaging, mail, calendar, AI, vault, office, wallet, and browser validation. Keys are derived on the client from a BIP39 recovery phrase, and protected content is encrypted before storage. Account email, operational metadata, external mail boundaries, billing, live AI processing, optional web search, and coordinator services remain explicit parts of the architecture.

So the honest framing is not "messenger vs messenger." It is a narrow, deliberately disposable privacy tool against a philosophy, a protocol, and a product: SELF's worldview, Celestial as the foundation beneath it, and the SELF App as the client people use. PRVC is the part that meets a messenger head on, but the SELF App matters precisely because of what sits beneath it.

Where PRVC is genuinely right

It helps to be fair about this, because the strongest part of PRVC's case is true. Most "secure" apps still hang your whole social graph off a phone number, and that identity hook has caused real harm: large phone-number leaks, scaled enumeration of who uses which app, and, as the explainer notes, the use of registration numbers to locate and target people. Encrypting message content while leaving identity exposed is a real gap, and removing the phone number genuinely shrinks what an attacker or a data broker can grab.

SELF answers that diagnosis differently. PRVC's answer is to erase identity. SELF's answer is to make identity user-held and durable, with encryption keys derived from a recovery phrase and no phone-number requirement. SELF also requires an account email that the service can decrypt for contact and recovery. One approach optimizes for deniability in a single app. The other optimizes for continuity across a broad platform.

Jurisdiction: the US Cloud Act follows the company, not the server map

PRVC presents itself as stateless and serverless in spirit, but it is a US-domiciled product. Its terms are governed by the laws of Delaware, its protection rests on a US patent, and its export language invokes US encryption-export law. That places PRVC squarely under US jurisdiction, and therefore under the CLOUD Act (2018).

The CLOUD Act lets US authorities compel a provider subject to US jurisdiction to produce data in its possession, custody, or control, regardless of which country the servers sit in. "Our shards are scattered on servers around the world" does not move the company outside that reach, and it can come with non-disclosure obligations so the user is never told. PRVC's identity-free design does reduce how much stored content there is to hand over, which is a real mitigation. But two things survive it. First, compelled assistance can be forward-looking: a US order can require a provider to assist with collection going forward, while messages are still transiting and before they evaporate. Second, the company itself, its keys, its infrastructure relationships, and its update pipeline all remain reachable by US process.

Core SELF App content is processed and stored on core application infrastructure in the European Union. Application, database, mail, and call infrastructure runs in Germany, with GPU inference and object storage in France. The public application bundle and DNS are served by a US provider; the bundle contains no personal data. Optional search, payment processing and external mail retain their documented processor boundaries.

The phone in your pocket: app stores and plaintext notifications

This is where PRVC's own delivery choice undercuts its central promise. PRVC ships as a native iOS and Android app. That has two consequences the marketing does not address.

The install is tied to a real identity that Apple and Google hold. You download PRVC through the App Store or Google Play, which means the install is bound to your Apple ID or your Google account. Apple and Google therefore both know that this specific, identified person has PRVC on their device. PRVC may not know who you are. The two companies that control the operating system, the store, and the device still know the identified install. The "who" that PRVC works so hard to remove is reintroduced one layer down, at the platform it cannot see or control.

Notification text routes through Apple and Google in the clear. Push notifications on iOS and Android are delivered through Apple's APNs and Google's FCM. When a message preview appears on your lock screen, that notification payload has passed through Apple's or Google's servers, and unless every payload is treated as opaque ciphertext, the visible text is readable by the relaying platform. So the plaintext you see on your phone is plaintext that also existed on a US-based provider's infrastructure, attached to an account that identifies you. For a tool whose entire thesis is "if we do not know who you are, there is nothing to share," depending on two US platforms that do know who you are, and that do see notification content, is the weakest link in the chain.

The SELF App is a PWA running in the browser, so its primary delivery path does not require a native app-store install. Its notifications use the Web Push standard, where the payload is encrypted to the user's browser and the push service relays ciphertext rather than readable previews. Browser validation is available to users, while SELF continues to operate the backend, signaling, orchestration, coordinator, mail, call, and inference services needed by the product.

Authentication: a memorised PIN versus phishing-resistant passkeys

PRVC authenticates with a memorised PIN and adds a Panic PIN for duress. It deliberately rejects biometrics, arguing that a PIN you keep in your head has stronger US legal protection than a face or fingerprint a court can compel you to present. As a legal-deniability argument for a specific threat model, that is coherent.

The SELF App uses WebAuthn passkeys as the primary method: domain-bound, biometric-backed, and phishing-resistant by design. Email with a one-time code is the secondary authentication path, and the recovery phrase derives encryption keys. The honest summary: PRVC optimizes authentication for courtroom deniability in one app, while the SELF App prioritizes phishing-resistant authentication for ongoing account use.

Recovery and continuity: erased forever versus sovereign and durable

PRVC treats no recovery as a feature. Lose your phone and your identity and history are gone, because "if you cannot recover it, neither can an adversary." For a burner-style, high-risk, short-conversation use case, that is defensible.

It is the wrong default for a platform people spend ongoing time within. SELF's model gives the user continuity without surrendering control: the recovery phrase reconstructs encryption keys on any device, an optional recovery password enables cross-device recovery without re-entering the phrase, and the server still never sees the keys. Sovereignty includes the freedom to leave and the ability to keep what is yours across a lost phone, a new device, and the years of a real relationship with a health, finance, or family service.

The AI question, and what privacy rests on

PRVC markets "No AI, ever" as a core virtue. SELF takes a different view: AI conversations and memory can be encrypted on the client for storage while inference runs on dedicated GPUs SELF controls. Prompts are processed in readable form during live inference. Optional web search and URL reading send the user's search text to a third-party data provider after an explicit action.

Underneath that, the two protect users in different ways. PRVC reaches a low-data position by erasing identity outright and provides no recovery. SELF keeps encryption keys on the user's device and stores protected content as ciphertext, while retaining the readable account and service data needed to operate and recover a durable account.

Purpose and scope

PRVC is a tool: one screen, one job, ephemeral by design, aimed at a narrow high-risk threat model. There is a real place for that. SELF is a broader platform spanning AI, vault, messenger, mail, calendar, office, wallet, and a chain with browser validation. Its account and recovery model is designed for durable use across those services.

Philosophies (different directions)

LensSELF (Celestial + App)PRVC (public narrative)
Core goalDurable account across a broad privacy platformErase identity; leave no trace
Identity modelRecovery phrase-derived keys; account email requiredNo identity; random per-device string
JurisdictionAustralian operator; core app content and infrastructure in the EU, with documented external processorsDelaware law, US patent, under US Cloud Act
DeliveryProgressive web app with browser validationNative iOS and Android, store-gated
NotificationsWeb Push, payload encrypted to the browserAPNs / FCM, preview text via Apple and Google
Account pathNo phone required; account email requiredNo account, email, or phone number
AuthenticationPasskeys primary; email one-time code secondaryMemorised PIN + Panic PIN, no biometrics
RecoveryRecovery phrase + optional cross-device recoveryNone; lose the phone, lose everything
AIClient-encrypted storage; SELF-hosted live inferenceNone ("No AI, ever")
ScopePlatform and chain across many life domainsSingle-purpose ephemeral messenger

In one sentence. PRVC is designed around disposable, account-free messaging, while SELF offers durable recovery, user-held encryption keys, no phone-number requirement, a broad PWA suite, and core EU application infrastructure.


Vant Chat

Vant Chat (vant.chat) is, in shape, very close to PRVC: an identity-free, no-sign-up messenger built for people who want zero traceability, aimed at journalists, activists, and similar high-risk users. Because the model is almost the same, most of the PRVC comparison applies directly, so this section is shorter and focuses on what is shared and the few things that differ.

Sources reviewed (Vant Chat, 2026 public materials):

The same model, the same limitations

Vant shares PRVC's core design: no phone number, no email, no account or user ID (it uses temporary pairwise connection links per contact), end-to-end encryption by default, a "no servers, zero data stored" claim, and post-quantum cryptography. Because the model is the same, the structural limitations from the PRVC section above apply here too.

  • Native iOS and Android delivery. Vant ships through the App Store and Google Play, so the install is bound to an Apple ID or Google account, and those platforms know that an identified person has it. Vant does also offer a direct Android APK that avoids the Play account, which is a genuine point in its favor, but iOS still goes through Apple.
  • Push notifications still travel through Apple and Google. Vant promotes push notifications even when the app is closed. On iOS and Android those are delivered through APNs and FCM, so notification content and delivery transit Apple's and Google's servers, exactly the weak link described under PRVC. An identity-free app whose alerts depend on the two companies that know your device identity has quietly reintroduced the "who" at the platform layer.
  • No recovery. With no account, a lost phone means lost contacts and history. That is fine for a throwaway tool and the wrong default for something you live in. SELF gives you recovery without surrendering control: a recovery phrase, optional cross-device recovery, and keys the server never sees.
  • Identity and continuity. Like PRVC, Vant removes the account entirely. SELF uses recovery phrase-derived keys and a required account email to support durable use without requiring a phone number.

What is a little different

Two things set Vant apart from PRVC, one better and one worse. On the better side, Vant has resisted data-localisation pressure: it was removed from Apple's China App Store in 2024 for refusing to comply with national-security data demands, which at least signals a posture against handing data over. On the worse side, where PRVC is openly US-domiciled (so you can at least reason about the CLOUD Act), Vant's operator and governing jurisdiction are not clearly stated. "We do not have your data" is harder to weigh when you do not know who is making the promise or which law they answer to.

Where this leaves SELF

The same place as the PRVC comparison. Vant is a single-purpose tool for deniable, throwaway conversations. SELF is built for continuity across messaging, mail, calendar, AI, vault, office, wallet, and browser validation. Encryption keys stay with the user and protected content is encrypted on the client. SELF also maintains a recoverable account, visible operational metadata, and core production services on EU infrastructure, with documented external processors at defined boundaries.

Philosophies (different directions)

LensSELF (Celestial + App)Vant Chat
Core goalDurable account across a broad privacy platformErase identity; zero traceability
IdentityUser-held keys, no phone number; account email requiredNo account or IDs; pairwise links
DeliveryProgressive web app with browser validationNative iOS and Android (plus Android APK)
NotificationsWeb Push, encrypted to the browserAPNs / FCM via Apple and Google
RecoveryRecovery phrase + optional cross-deviceNone; lose the phone, lose everything
JurisdictionAustralian operator; core app content and infrastructure in the EU, with documented external processorsOperator and jurisdiction unstated
ScopeAI, vault, messenger, mail, calendar, office, wallet, chainSingle-purpose messaging

In one sentence. Vant Chat is a no-account messenger built for ephemeral use, while SELF provides a recoverable account, user-held encryption keys, client-side encrypted protected content, no phone-number requirement, and PWA delivery.


Duck.ai

Duck.ai (duck.ai) is DuckDuckGo's free, account-optional AI chat: a privacy-minded proxy to third-party models such as GPT, Claude, and Mistral. It is the closest comparison on this page to SELF on the AI axis, because both answer the question of how to use an assistant without an advertising company building a profile around you. The architectures diverge from there.

Sources reviewed (Duck.ai, 2025 to 2026 public materials):

What each one actually is

Duck.ai is a privacy proxy, not a private model. DuckDuckGo sits between you and providers such as OpenAI, Anthropic, Azure OpenAI, and together.ai. It reads your prompt, strips your IP address, attaches contextual metadata (date, timezone, units, and global region derived from a GEO::IP lookup), and forwards the text to the provider. Chats save locally in your browser by default; optional Sync & Backup stores encrypted copies on DuckDuckGo's servers with keys held only on your devices. The provider receives the full text of what you typed. DuckDuckGo receives it too.

SELF is a broad privacy suite with its own AI stack. AI conversations and memory are encrypted on the client for storage. SELF AI performs live inference on dedicated GPUs SELF controls and does not use external model APIs for ordinary conversation. Optional web search and URL reading send the user's search text to a third-party data provider after an explicit action. Duck.ai versus SELF is a comparison between a privacy proxy to third-party models and a self-hosted AI service integrated with a wider PWA platform.

Where Duck.ai is genuinely right

Credit where it is due. Using a model provider directly exposes your IP, account identity, and usage history. Duck.ai improves on that materially: no account is required for basic chat, your IP is stripped before the request reaches the model company, DuckDuckGo has contractual limits on provider retention and training, and some models offer stronger tiers such as Zero Data Retention or Zero Provider Visibility (described per session in Duck.ai's privacy dialogue). Local-by-default chat storage, optional encrypted Sync & Backup with client-held keys, and no advertising profile built from your prompts are real strengths. For someone who wants hosted AI without signing into another Big Tech account, Duck.ai is a thoughtful step up from the default.

Three parties, two of them reading your words

The structural gap is who sees the content of your prompts.

The model provider reads everything. Duck.ai anonymizes the sender while the message remains readable. Your prompt arrives at OpenAI or Anthropic as readable text. They cannot easily tie it to your IP. They still process it, apply their usage policies, and retain it under their agreements with DuckDuckGo (typically deleted within 30 days, with safety and legal exceptions). Even models labelled Zero Data Retention are read at inference time; the guarantee is about retention afterward, not about secrecy during processing.

DuckDuckGo reads everything too. To strip metadata and forward the request, the proxy must see the prompt in plaintext. The privacy win is that the provider does not know it was you. It is not that nobody saw what you typed.

SELF keeps ordinary AI inference on infrastructure it operates. AI content is processed live by SELF's model service on dedicated hardware, then prompts and responses are retained as client-side encrypted content. Ordinary conversations do not become external model API traffic. When a user explicitly invokes optional web search or URL reading, the search text is sent to a third-party data provider.

Metadata: stripped IP, not stripped context

Duck.ai's privacy policy says metadata containing personal information is removed before prompts reach model providers. That is true for the IP address itself, but not for everything inferred from it. By default, requests to most providers include today's date, your timezone, your preferred unit system, and a global region guessed from GEO::IP. Optional "Use Approximate Location" (off by default) can add city-level location for locally relevant answers.

When users asked models where they were, some got back their city, which clashed with a plain reading of "all personal information removed" and sparked community pushback in mid-2025. DuckDuckGo's response, including from CEO Gabriel Weinberg in that thread, is that the IP is stripped and never sent, while region or city is inferred separately, similar to DuckDuckGo Search. That may be technically accurate and still leave the policy sounding broader than the behaviour users expected.

SELF does not use a third-party model API for ordinary AI conversations. Optional web search and URL reading are separate, explicit actions that send search text to a third-party data provider.

Voice, jurisdiction, and what sits beyond chat

Duck.ai's voice chat and dictation send audio to the model provider (through an encrypted relay DuckDuckGo cannot decrypt); only the text transcript is saved locally by default. That is another path where your words reach a US model company even when the proxy behaves well.

DuckDuckGo is a US company routing traffic to US-governed model APIs. The main compulsion surface is prompt content processed as plaintext on a third party's infrastructure, subject to that provider's policies and legal environment. The location of optional encrypted backups does not change that live-processing boundary.

SELF places core SELF App content and core application infrastructure in the EU and runs inference on dedicated GPUs it controls. Its assistant is integrated with messaging, mail, calendar, vault, office, wallet, and browser validation under one recoverable account. External model APIs are not used for ordinary conversation; optional search and URL reading use a third-party data provider.

Philosophies (different directions)

LensSELF (Celestial + App)Duck.ai
Core goalBroad privacy suite with self-hosted AIPrivacy-oriented access to third-party AI models
Who reads your promptSELF-hosted model processes it during live inferenceDuckDuckGo proxy and external model provider
Prompt to third partiesNo external model API for ordinary chat; optional search text goes to a data providerFull text forwarded; IP stripped
Provider retentionAI conversations stored client-side encrypted; search provider receives explicit queriesContractual no-training; deleted within ~30 days (ZDR on some models)
Chat storageClient-side encrypted prompts, responses, and memoryLocal browser by default; optional encrypted server sync
Location in requestsNo location added to ordinary model inference; search is a separate external serviceGEO::IP region by default; optional city-level
IdentityUser-held keys, recovery phrase, passkeys, and account emailNo account required; optional encrypted Sync & Backup
ScopeAI, vault, messenger, mail, calendar, office, wallet, chainAI chat and dictation only

In one sentence. Duck.ai provides privacy-oriented access to third-party models, while SELF stores AI conversations client-side encrypted, runs live inference on dedicated hardware it controls, and integrates the assistant into a broader PWA suite, with optional external search clearly separated from ordinary conversation.