Saturday, September 5, 2026
Not all privacy tools are the same — here is how to actually check
"We take your privacy seriously" is printed at the bottom of nearly every app's privacy policy, including the ones that read every note you write to train a model or serve you ads. The word "privacy" has been stretched thin enough that it no longer tells you much on its own. What actually separates a genuinely private tool from a company that simply says the word "private" a lot is whether its architecture can be checked, not just believed.
Four questions worth asking any app that claims to be private
Is your data encrypted before it leaves your device, or only in transit and at rest on their server? The second version still means the company can read your data — "encrypted at rest" just means it's locked in a drawer they hold the key to.
Can the company reset your password and get you back in? If yes, they hold a key of their own, which means "zero-knowledge" is marketing language, not an accurate description.
Does the AI processing happen on a server or on your device? If any AI feature runs in the cloud, your content is being read there, however briefly, regardless of what the encryption looks like the rest of the time.
Is the security architecture documented well enough for an outside researcher to actually verify the claims? A privacy claim nobody can check is a promise. A privacy claim backed by a documented, auditable architecture is closer to a guarantee.
Prevon is built to answer all four of those the hard way: local encryption before anything is sent anywhere, no password reset because there is no company-held key, an on-device AI with no network access at all, and a published, documented architecture that welcomes outside security review rather than avoiding it. Not every tool that calls itself private needs to fail these questions — but it is worth actually asking them instead of taking the word "private" at face value.
