Docs

shadows is private, uncensored AI. Every model runs inside a hardware enclave, your wallet is your account, and you pay with USDG on Robinhood Chain. We never store your prompts or answers.

PartWhat it is
AppThe chat at app.askshadows.com: wallet sign-in, a free trial, every model, saved chats encrypted on your device.
APIAn OpenAI-compatible endpoint at https://api.askshadows.com/v1. Same models, same credits, your own code.
EnclavesModels run in trusted execution environments at Phala, Chutes, NEAR AI or Tinfoil, reached through RedPill's attested gateway.
Robinhood ChainWhere payments happen. Chain id 4663, USDG for credits, gas in ETH.

This page describes what the code does today. Where something isn't built yet, it says so.

How privacy works

  1. You send a message from the app or the API over TLS to our API.
  2. The API checks your credits, and for models in the enclave tier it asks a safety model (in an enclave too) whether the conversation crosses one of the hard limits. This happens in memory.
  3. The API rebuilds the request from a fixed list of fields (messages, sampling settings, stop sequences, response format, tools, reasoning settings) and drops everything else, including the user, metadata and store fields that OpenAI clients fill in on their own. It sends the request to RedPill with one key shared by every shadows user.
  4. RedPill's gateway, itself running in an enclave, checks the model's enclave before forwarding, and signs a receipt for the answer.
  5. The answer streams back the same way. Nothing writes the prompt or the answer to a database, a log or a cache. When the stream ends, they're gone.
Honest limit. Our API runs on an ordinary server (Railway), not yet in an enclave. So for the enclave tier the claim is "never stored", not "nobody but the enclave could read it". With end-to-end encryption the API only relays ciphertext. Moving the API into a confidential VM with a published build hash is planned.

What we keep

KeptWhyHow long
Wallet addressIt is the accountWhile the account exists
Balance and adult-content settingTo run the accountWhile the account exists
Usage per request: model, tokens, cost, timeBilling and your usage page. Never the textWhile the account exists
Payments: transaction, amount, country you gave, time of your express request, sanctions checkConsumer law, VAT and bookkeepingAs bookkeeping law requires (normally 5 years)
Saved chats as ciphertext, with size, random id and timeSync between your devicesUntil you burn them
Sessions and API keys, as hashesTo recognise youSessions: 7 days. Keys: until revoked
Free trial: a hash of the token and today's countThe daily limit30 days
Web pages the agent readsNot kept: fetched, passed to the model, goneNever stored

Server logs have one line per request: method, path, status and duration. No IP addresses, no content. Our hosts (Railway for the API, Vercel for the app) handle IP addresses to deliver traffic, like any host. The app loads no analytics, ads or third-party scripts.

Sign in

Your wallet is your account. The app finds the wallets in your browser (EIP-6963), asks for your address, and has you sign a standard Sign-In with Ethereum message (EIP-4361) for app.askshadows.com. Signing costs nothing and gives no access to your funds. The API then sets a session cookie that scripts can't read; it lasts 7 days.

Works with MetaMask, Rabby, Phantom, Coinbase Wallet and other browser wallets. On a phone, open the app in your wallet's built-in browser. Smart-contract wallets can sign in too, but see saved chats.

Free trial

No wallet needed: 10 messages a day on the Uncensored model, up to 1,024 tokens per answer. Instead of a sign-up, your browser solves a small proof of work (about a second). The trial token stays in your browser; we keep only its hash and today's count, never a wallet or IP address. Trial chats aren't saved. The whole trial has a daily budget, and pauses until midnight UTC if it's used up.

Credits and pricing

  • 1 USDG = 100 credits. Credits are prepaid and can only be used for shadows.
  • Each answer costs what it uses: input and output tokens times the model's price, shown in credits per million tokens in the model table and in the app's model picker.
  • Before a request, the API sets aside an estimate from your balance; afterwards it charges the exact token count from the model's answer and releases the rest. If your balance can't cover the estimate, you get a 402.
  • Credits don't expire. They can't be transferred or turned back into money, except for the refund of unused credit.

Models

Every model runs in a hardware enclave. Prices are in credits per million tokens (1 USDG = 100 credits).

ModelAPI idPrivacyContextInputOutputGood for
Uncensored · Gemma 4 26BuncensoredEnclave262k30140uncensored, fast
Uncensored Pro · Qwen3.8 27Buncensored-proEnclave262k60300uncensored, vision
Code · GLM-5.3 FlashcodeEnclave · E2EE262k30100code
Reasoning · DeepSeek V4 FlashreasoningEnclave · E2EE262k90260reasoning, code
Frontier · Kimi K3kimi-k3Enclave1M6003,000frontier, vision, reasoning
Frontier · GLM-5.3glm-5.3Enclave · E2EE1M280880frontier, code, reasoning
Frontier · Qwen3.5 397Bqwen3.5-397bEnclave262k110700frontier, vision
Frontier · Kimi K2.6kimi-k2.6Enclave · E2EE262k220920frontier, vision
OpenAI gpt-oss 120Bgpt-oss-120bEnclave · E2EE131k30120reasoning
Chat · Gemma 4 31Bgemma-4-31bEnclave · E2EE131k3092fast, vision
  • Uncensored models are retrained by Phala to answer without lectures or refusals. Hard limits still apply.
  • Adult content is off until you confirm you're 18 or older in Account, and then only on Uncensored Pro (Qwen3.8 27B, Apache-2.0). Gemma's licence forbids sexual content.
  • E2EE models are end-to-end encrypted in the app (signed in, Chat) and through the API.

Top-ups

  1. In the app, open your balance and pick an amount. You see what you buy, the price, the refund rules and the seller before paying.
  2. Give your country (for VAT) and tick two boxes: that you want your credits right away, and that you lose the right of withdrawal for credit you use. Norwegian consumer law requires this.
  3. Your wallet sends USDG on Robinhood Chain from the address you signed in with to our treasury. The app switches your wallet to Robinhood Chain if needed. You pay the network fee in ETH.
  4. After 20 confirmations (a few seconds) your credits arrive and you get a confirmation you can download.

A payment is held instead of credited if it comes without the express request, from a wallet on a sanctions list (we screen against the OFAC list, refreshed daily), or above 1,000 USDG per wallet per 30 days. Held payments are reviewed by hand. Our server watches the chain itself; there's no payment processor, and the server holds no key that can move funds.

Refunds

Unused credit from payments in the last 14 days can be refunded: Account → Refund of unused credit. The amount is your unused credit, up to what you paid in those 14 days. It leaves your balance at once, and we pay it back in USDG by hand, only to the wallet that paid, usually within a few days.

Saved chats

Chats can sync between your devices without us being able to read them:

  1. The app asks your wallet to sign this exact text (it never changes):
    shadows: unlock saved chats
    
    Signing this creates the key that encrypts your saved chats on your device. It costs nothing and gives no access to your funds.
    
    Key version: 1
  2. It turns the signature into an AES-256 key with HKDF-SHA256 (salt shadows-chats, info aes-256-gcm v1). The key can't be exported and stays on your device.
  3. Each chat is encrypted with AES-256-GCM under a fresh random 12-byte IV, with the chat's id as additional data, and stored as 0x01 ‖ IV ‖ ciphertext. The server refuses anything that isn't in this format.

The first time, the app asks you to sign twice and checks that both signatures match. Smart-contract and passkey wallets give a different signature each time, so their chats can't be saved. If you lose your wallet, nobody can recover your saved chats. Burn deletes a chat from your device and our database at once. Only sign that text on app.askshadows.com: any site that gets the same signature can derive the key.

Safety

shadows doesn't lecture or refuse legal requests. Three things are always blocked, for everyone: sexual content involving minors; sexual or degrading content depicting a real, identifiable person; and meaningful help creating chemical, biological, radiological or nuclear weapons.

A fast keyword check runs first. Then, for the enclave tier, a guard model (gpt-oss-120b, in an enclave) reads the recent conversation, about the last 12,000 characters including system messages, earlier turns and tool calls, and answers only "safe" or "unsafe". If the guard is down or unclear, the request is refused. On end-to-end encrypted requests our API can't read the prompt, so the guard can't run; those models' own built-in safety applies.

Attestation and receipts

You can check the enclaves yourself, without trusting this page:

  • Model enclave: GET https://api.askshadows.com/v1/attestation?model=<id>&nonce=<64 hex> returns the model enclave's attestation report, including its GPU evidence. No account needed.
  • Gateway: fetch RedPill's gateway attestation directly: GET https://api.redpill.ai/v1/aci/attestation?nonce=<64 hex>. Its Intel TDX quote binds your nonce and the gateway's signing keys, and names the open-source gateway code and commit.
  • Per answer: every answer carries an X-Receipt-Id header. GET /v1/receipts/<id> (with any key or session) returns a receipt signed inside the gateway with ed25519. It names the model, records that the gateway verified the model's enclave, and has the SHA-256 of the exact answer bytes. Answers are passed through unchanged, so the hash matches what you received. Receipts appear a moment after the answer ends.

Verify the TDX quote with Intel's tooling (for example Phala's open-source dcap-qvl).

API

OpenAI-compatible, at https://api.askshadows.com/v1. Create a key in the app under Account → API keys (shown once). Requests are paid from the same credits.

curl https://api.askshadows.com/v1/chat/completions \
  -H "Authorization: Bearer sk-shd-…" \
  -H "Content-Type: application/json" \
  -d '{"model": "uncensored", "messages": [{"role": "user", "content": "Hello"}]}'

With the OpenAI SDK, change only the base URL:

from openai import OpenAI

client = OpenAI(base_url="https://api.askshadows.com/v1", api_key="sk-shd-…")
stream = client.chat.completions.create(
    model="kimi-k3",
    messages=[{"role": "user", "content": "Explain TEEs in two lines."}],
    stream=True,
)
for chunk in stream:
    print(chunk.choices[0].delta.content or "", end="")

Endpoints

Method and pathWhat it does
GET /v1/modelsModels with prices (credits per million tokens), context size and privacy tier. No key needed.
POST /v1/chat/completionsChat, streamed ("stream": true) or not. Tool calling and response formats pass through.
GET /v1/receipts/{id}The signed receipt for an answer.
GET /v1/attestation?model=&nonce=The model enclave's attestation report.
POST /v1/tools/fetchReads a public web page for an agent: {"url": "…"} returns its title and text. Our server fetches it, so the site sees our server, not you. Public internet only, 20 a minute, wallet keys only.

Errors

Statuserror.typeMeaning
400content_blockedA hard limit was hit. error.code says which.
401unauthorizedMissing or wrong key.
402insufficient_fundsNot enough credits for this request.
404invalid_request_errorUnknown model.
429rate_limitedMore than 60 requests a minute.
502upstream_errorThe model provider failed. Safe to retry.
503content_blocked (classifier_unavailable)The safety check is unavailable. Retry in a moment.

End-to-end encryption

On models marked E2EE, your client can encrypt messages to the model's enclave key so our API only relays ciphertext. It uses Phala's ACI E2EE v2 scheme: X25519 key agreement, HKDF-SHA256 and AES-256-GCM, with the request bound to the model, a nonce and a timestamp.

  1. Fetch the gateway attestation and take an X25519 key from its attested key set.
  2. Encrypt each message's content and send the headers X-E2EE-Version: 2, X-Client-Pub-Key, X-Model-Pub-Key, X-E2EE-Nonce and X-E2EE-Timestamp.
  3. The answer comes back encrypted to your key, with X-E2EE-Applied: true.

Billing still works because token counts stay in plaintext.

In the app: when you're signed in and chatting with a model marked E2EE, the app does all of this for you. It fetches the attestation straight from RedPill (so our API can't swap the key), checks that the key is bound into the enclave's report with a fresh nonce, encrypts every message on your device, and decrypts the streamed answer. The model picker shows an E2EE badge, the top bar says Encrypted, and each answer is marked End-to-end encrypted. Not yet done in the browser: checking the Intel signature on the enclave's report, so for now the app claims only that our servers pass on ciphertext.

Uncensored models aren't end-to-end encrypted yet: the safety check that enforces the hard limits has to read the message, and today it runs in our API, outside an enclave. Moving our API into a confidential VM will let the check run inside an enclave too.

Agents

In the app: open Agent in the sidebar and give it a task. The model can read web pages (fetched by our server, so sites see our server, not you), search Wikipedia, calculate exactly and check the date. Each step shows above the answer and can be opened to see what the tool returned. Each step is billed like a message; a task stops after 8 steps. Agents need a wallet.

Point any OpenAI-compatible agent framework at https://api.askshadows.com/v1 with an sk-shd- key. Tool calling passes through to the model: send tools and tool_choice, run the tools yourself, and send the results back as tool messages. The guard reads tool-call arguments too. Every model supports tool calling except Reasoning (DeepSeek V4 Flash).

A short version for agents to read:

base_url: https://api.askshadows.com/v1   (OpenAI-compatible)
auth: Authorization: Bearer sk-shd-…
models: GET /v1/models   (ids, prices in credits per 1M tokens, privacy)
chat: POST /v1/chat/completions   (stream, tools, response_format)
receipt: header X-Receipt-Id, then GET /v1/receipts/{id}
limits: 60 requests/minute; 402 means top up at app.askshadows.com

Not built yet

  • Our API in a confidential VM with a published build hash.
  • The Intel signature check of the enclave report, and the per-answer seal row, in the app.
  • End-to-end encryption for the uncensored models (needs the safety check inside an enclave).
  • Images and video.
  • Full web search for the agent. Today it searches Wikipedia and reads any public page you or it names.
  • Sign-in by QR code (WalletConnect) on phones without a wallet browser.

Updated 5 October 2026 · Terms · Privacy