Updated September 1, 2026

If you're searching for a Fidaro.ai review or wondering whether Fidaro is a scam, you're researching one of the more technically interesting new AI chatbots we've encountered.

Fidaro isn't primarily trying to beat ChatGPT, Claude or Gemini by promising a smarter chatbot.

Its pitch is privacy.

More specifically, Fidaro says its system has been engineered so that even Fidaro itself cannot read your AI conversations.

That's a substantially stronger claim than simply publishing a privacy policy promising employees won't look at your chats.

And there's enough technical substance behind the concept that we think Fidaro deserves attention.

What Is Fidaro.ai?

Fidaro is a privacy-focused AI assistant currently available free while the service remains in beta.

Users can have ordinary AI conversations, maintain encrypted conversation history, create Projects with their own instructions and upload images or documents for temporary analysis.

The major difference is what supposedly happens between your browser and the AI model.

Fidaro describes itself as a zero-knowledge AI service. Your conversations are encrypted on your device, processed inside protected hardware and stored in encrypted form using keys Fidaro says it never possesses.

Our Fidaro Review Methodology

Because Fidaro is primarily selling trust and privacy, we're evaluating it differently from an ordinary AI chatbot.

For this review we examined:

  • Fidaro's published technical architecture
  • Its encryption and attestation design
  • Its current privacy policy
  • What information Fidaro still collects
  • The people publicly identified as building the company
  • The team's previous privacy and security experience
  • Current product capabilities
  • Current beta limitations
  • Fidaro's terms of service
  • Corporate transparency
  • Available independent third-party information
  • What Fidaro's architecture can and cannot reasonably protect against

There's an important limitation to our review: we haven't independently audited Fidaro's cryptography, source code, hardware configuration or deployment environment.

Therefore, when describing how the security system works, we're reporting Fidaro's documented architecture, not certifying that every security claim has been independently proven.

Is Fidaro a Scam?

Based on what we found, we see no obvious reason to characterize Fidaro as a scam.

There's an identifiable development team, a functioning AI product, detailed technical documentation, published privacy and legal policies, and people behind the project with substantial previous experience building privacy technology.

Fidaro is also currently free during beta, which makes the immediate consumer-risk question rather different from evaluating a website demanding thousands of dollars before revealing its product.

However, “not an obvious scam” and “every security claim has been independently verified” are not the same conclusion.

Fidaro is young.

That's where we think the caution belongs.

How Does Fidaro Keep AI Conversations Private?

This is where Fidaro becomes considerably more interesting.

With many online services, encryption protects your information while it travels across the internet. Once it reaches the company's servers, however, the service needs to decrypt it to process it.

Fidaro is attempting to remove that conventional trust requirement.

According to its technical documentation, the process works approximately like this:

  1. You enter a message in your browser.
  2. Your browser verifies the protected computing environment.
  3. Your device establishes a temporary encrypted channel directly with that environment.
  4. Your message is encrypted before leaving your device.
  5. The encrypted message passes through Fidaro's surrounding infrastructure.
  6. It is decrypted only inside a hardware-protected confidential virtual machine.
  7. The AI model processes the request inside that environment.
  8. The response is encrypted again before leaving.
  9. Your browser receives and decrypts the response.

If the system works exactly as documented, ordinary Fidaro web infrastructure never needs access to the readable conversation.

Intel TDX and the Confidential Computer

At the center of the architecture is Intel's Trust Domain Extensions, or TDX.

Fidaro says its AI backend operates inside a Confidential Virtual Machine whose memory is protected by the processor itself.

The objective is to prevent the host operating system, infrastructure provider and even Fidaro administrators from simply examining what's happening inside the protected environment.

The AI model itself runs within that protected boundary.

That's significant because encrypting a message during transmission doesn't solve much if the message is simply handed to an ordinary readable AI server afterward.

Attestation May Be the Most Important Part

There's another problem with confidential computing: how does your computer know it's sending information to the correct protected environment?

Fidaro's answer is cryptographic attestation.

Before establishing the private channel, the user's device checks a hardware-generated attestation report. Fidaro says the browser verifies Intel's signature and compares measurements of the running software with expected measurements.

If those measurements don't match, the browser is supposed to refuse to establish the conversation.

This matters because the system isn't merely saying:

“Trust us, your conversation is running somewhere secure.”

The architecture is designed to provide cryptographic evidence about the environment receiving the information.

Temporary Encryption Keys Add Another Layer

Fidaro says every conversation establishes a fresh encrypted channel using the Noise protocol.

The session keys last approximately 15 minutes, aren't reused and aren't permanently stored.

This provides forward secrecy: compromising a future session key shouldn't automatically allow an attacker to decrypt previously recorded conversations protected by different temporary keys.

Your Saved Conversations Are Also Encrypted

Fidaro can synchronize conversation history across devices, but the company says those conversations are encrypted before they're stored.

The key required to decrypt that history is derived locally using your Passkey.

According to Fidaro, the company stores the encrypted data but doesn't possess the key needed to turn it back into readable conversation history.

That's a meaningful distinction from simply encrypting a database while the service provider also controls the decryption keys.

Who Is Behind Fidaro?

The team is one reason we're taking this project more seriously than we would an anonymous AI startup making similar claims.

Fidaro publicly identifies:

  • Dan Pomerantz — Founder & Investor
  • Peter Burchhardt — Founder & Investor
  • Shaun Smith — CTO
  • Kayan Lim — CMO
  • Andrew Parker — Founding Engineer

Pomerantz and Burchhardt co-founded ExpressVPN.

Fidaro says CTO Shaun Smith created ExpressVPN's TrustedServer technology, an architecture designed around running servers from volatile memory rather than relying on traditional persistent server installations.

That doesn't automatically prove Fidaro is secure.

But it does establish that people associated with the company have previous experience building privacy-focused infrastructure at substantial scale.

What Can Fidaro Actually Do?

Privacy doesn't matter very much if the chatbot isn't useful.

The current product supports more than simple text conversations.

Fidaro currently advertises:

  • General AI conversations
  • Encrypted synchronized chat history
  • Projects for organizing related conversations
  • Project-specific instructions
  • Image and screenshot analysis
  • Chart analysis
  • Document uploads
  • Mobile-browser access
  • Passkey protection
  • Recovery codes
  • Automatic model selection

Fidaro says it uses several leading open-weight AI models and automatically selects an appropriate model for the task.

The models run on Fidaro's own protected hardware rather than sending prompts to the companies that originally created those models.

Which AI Models Does Fidaro Use?

This is one area where we'd like greater transparency.

Fidaro currently says it uses several leading open models, but doesn't publicly identify the precise models used for particular requests.

Automatic routing is convenient for ordinary users.

But if you're trying to evaluate Fidaro against ChatGPT, Claude, Gemini or another AI system, not knowing exactly which model generated a response makes rigorous comparisons difficult.

Privacy may be Fidaro's primary differentiator, but answer quality still matters.

What Happens to Uploaded Files?

Fidaro currently supports images, screenshots, charts and documents.

However, uploads aren't yet permanently stored with your encrypted conversation history.

The company says uploaded files currently last only for the working session. Refreshing the page clears them, meaning you'll need to upload the file again if you return later.

Encrypted permanent file storage is planned.

We actually prefer that Fidaro clearly acknowledges this limitation rather than pretending the beta already does everything.

Private Doesn't Mean Fidaro Collects Nothing

This distinction is extremely important.

Fidaro isn't claiming that no information whatsoever exists about your account or usage.

Its privacy policy says the company can collect information including:

  • Email address
  • Sign-in method
  • Subscription tier
  • Encrypted conversation data
  • Features used
  • Selected AI model
  • Response latency
  • Anonymous operational metrics
  • Broad conversation categories such as travel or news
  • Billing status
  • Support messages you voluntarily send
  • Website and referral information

Fidaro says product analytics use a one-way hashed identifier rather than being directly associated with your email address.

It also says broad conversation categories leave the protected environment only as aggregated operational information rather than readable conversation content.

Fidaro Still Uses Outside Service Providers

No modern online service exists entirely by itself.

Fidaro's privacy policy identifies outside providers involved in operating different parts of the service, including companies involved with web hosting, encrypted data storage, confidential computing, analytics, email and billing.

Fidaro says those providers don't receive readable AI conversations because the conversation contents remain protected by its encryption architecture.

Again, that's the architectural claim. It's stronger than simply saying third parties promise not to read your conversations, but we'd still welcome independent verification of the complete implementation.

The Biggest Issue: Where Is the Independent Security Audit?

This is probably our largest reservation.

Fidaro provides considerably more technical explanation than many consumer AI companies.

That's good.

But attestation isn't the same thing as an independent security audit of the entire service.

Attestation can provide evidence about what is running inside the confidential environment.

An independent audit can examine a broader collection of questions:

  • Is the browser-side cryptography implemented correctly?
  • Are expected measurements distributed securely?
  • Are recovery mechanisms safe?
  • Can metadata unexpectedly expose users?
  • Are software updates securely deployed?
  • Are there weaknesses outside the confidential VM?
  • Are dependencies and build pipelines secure?
  • Can the claimed architecture be bypassed elsewhere?

As of this review, we couldn't locate a published independent security-audit report or recognized certification covering Fidaro's complete system.

For an ordinary consumer beta, that may not prevent us from experimenting with the product.

For lawyers, healthcare organizations, financial institutions or companies handling regulated information, we'd want considerably more assurance.

“Not Governments, Not Hackers” Is Too Absolute for Us

Fidaro's privacy policy uses exceptionally strong language, saying conversations can't be seen by Fidaro, network operators, governments or hackers.

We understand what the company means within its architectural threat model.

But we'd be more conservative.

No server-side encryption architecture can protect text that has already been captured before encryption on a compromised user's device.

If malware records your keyboard, a malicious browser extension reads the webpage, screen-recording software captures the conversation, or someone gains access to an unlocked device, the confidential server architecture isn't necessarily the problem anymore.

The readable information exists at the endpoints because you need to be able to type and read it.

That's not a criticism unique to Fidaro. It's a limitation of secure communications generally.

We simply wouldn't translate “our infrastructure can't read your messages” into “nobody under any circumstances can ever obtain your messages.”

Corporate Transparency Could Be Better

Fidaro's team transparency is unusually good.

Its legal transparency is less complete.

The current Terms of Service identify the service as “Fidaro,” provide a support email address and explain the basic rules governing use.

What we don't see clearly stated in those short terms is a full legal company name, physical business address or governing jurisdiction.

That doesn't make Fidaro fraudulent.

But a privacy product specifically marketing itself toward journalists, doctors, lawyers and other professionals should eventually make contractual identity and jurisdiction exceptionally clear.

If an organization is considering putting regulated or commercially sensitive information into a service, knowing precisely which legal entity it's contracting with matters.

Fidaro Is Not Automatically HIPAA, PIPEDA or Professional-Privilege Compliance

This deserves emphasis.

Encryption does not automatically equal regulatory compliance.

A technically impressive security architecture is only one part of legal and professional obligations involving confidential information.

Organizations may need contracts, data-processing agreements, jurisdictional assurances, retention controls, access policies, audit documentation and other safeguards depending on their industry and country.

Likewise, using an encrypted AI service doesn't automatically establish attorney-client privilege or satisfy every professional confidentiality requirement.

Businesses handling regulated information should evaluate Fidaro against their actual legal and contractual obligations rather than assuming the word “encrypted” settles the question.

Fidaro Also Warns You Not to Blindly Trust Its Answers

Privacy and accuracy are two separate issues.

Fidaro's Terms of Service explicitly state that AI outputs can be inaccurate, incomplete or unsuitable for a particular situation.

The company also says Fidaro isn't a substitute for professional legal, medical, financial, tax or other specialist advice.

That's important because privacy could make users more comfortable discussing sensitive topics with an AI.

Confidentiality doesn't make an AI answer correct.

What We Like About Fidaro

The biggest positive is obvious: Fidaro is trying to solve privacy technically rather than simply contractually.

We like:

  • Encryption before messages leave the device
  • Hardware-isolated AI processing
  • Cryptographic attestation
  • Short-lived session keys
  • Encrypted synchronized history
  • Passkey-derived encryption
  • No conversation training according to Fidaro's policy
  • Open-weight models running on Fidaro-controlled infrastructure
  • An identifiable team with substantial privacy-industry experience
  • Clear documentation explaining the security architecture
  • Free access while the service remains in beta

The architecture is meaningfully different from an ordinary chatbot whose privacy ultimately depends on trusting company policy.

The Practical Privacy Tradeoffs

Fidaro's privacy architecture is impressive, but privacy technology always involves tradeoffs. Understanding those tradeoffs is more useful than simply seeing the word encrypted and assuming every privacy problem has been solved.

1. Your Conversations Can Be Private While Metadata Still Exists

Fidaro is designed to prevent the company and its ordinary infrastructure from reading the contents of your conversations.

That doesn't mean Fidaro knows absolutely nothing about your use of the service.

As discussed earlier, its privacy policy says the company can collect account information, subscription status, features used, selected models, response latency, token and usage information, and broad conversation categories.

The practical distinction is important:

Conversation content can be protected while metadata about your use of the service still exists.

That's considerably different from complete anonymity.

2. Fidaro Can't Protect a Compromised Computer

Your message has to exist somewhere in readable form before it's encrypted.

In Fidaro's architecture, that's your browser and device.

If your computer contains malware, a malicious browser extension, a keylogger, remote-access software or screen-recording software, an attacker could potentially capture what you're typing before Fidaro encrypts it.

The same problem exists after the response returns. Your browser must decrypt the answer so you can read it.

Confidential computing can therefore provide strong protection for the journey between those endpoints without making compromised endpoints magically secure.

3. Stronger Privacy Can Make Support and Debugging Harder

There's an interesting consequence to building a system whose employees supposedly can't read customer conversations.

The employees can't simply read customer conversations.

That's excellent when privacy is the objective, but it can complicate troubleshooting.

Imagine telling support:

“The AI gave me a terrible answer during an important conversation yesterday.”

An ordinary AI provider may have systems that allow authorized personnel to investigate stored conversation data under its applicable policies.

If Fidaro's architecture works as described, its employees shouldn't be able to simply open your encrypted conversation history and inspect everything you said.

That's not necessarily a weakness. It's a consequence of choosing technical privacy over operational visibility.

4. Privacy Doesn't Automatically Mean the Best AI Model

Fidaro's approach also creates an interesting performance question.

The company says it runs open-weight AI models inside its protected infrastructure rather than simply forwarding your private prompt to another major commercial AI provider.

That's important for the privacy model.

But the most private AI isn't automatically the most capable AI for every task.

ChatGPT, Claude, Gemini and other major AI services continue competing aggressively on reasoning, research, multimodal capabilities, integrations and model quality.

If one of those systems substantially outperforms Fidaro for a particular task, users will have to decide how much additional privacy is worth relative to any difference in capability.

Fidaro's decision not to publicly identify the exact models handling particular requests currently makes that comparison more difficult.

5. Encrypted History Gives the User More Responsibility

There's another unavoidable issue with systems designed so that the provider doesn't possess your decryption keys:

What happens when you lose access?

If a company genuinely can't decrypt your information, it shouldn't be able to magically bypass that protection simply because you forgot your credentials.

That's why Fidaro's Passkey and recovery mechanisms matter.

The privacy benefit comes with additional responsibility for the user. Protecting recovery information becomes more important because a genuine zero-knowledge system may have fewer ways to rescue data when the user loses the credentials required to decrypt it.

6. Confidential Doesn't Automatically Mean Compliant

A company shouldn't conclude:

“Fidaro can't read our conversations, therefore we can safely put anything into it.”

That's too broad.

Encryption and confidential computing are technical safeguards. Regulatory and professional compliance can additionally involve:

  • Data residency
  • Data-processing agreements
  • Legal jurisdiction
  • Retention requirements
  • Audit logging
  • Access controls
  • Subprocessor agreements
  • Breach procedures
  • Records-management requirements
  • Industry-specific regulations

A technically excellent privacy architecture therefore doesn't automatically establish compliance for healthcare organizations, financial institutions, Canadian businesses subject to privacy requirements, lawyers or other regulated professionals.

7. Fidaro Still Requires Trust—Just Less of a Particular Kind

This may be the most important distinction in the entire Fidaro review.

Fidaro's proposition isn't really:

“You don't have to trust anyone.”

It's closer to:

“You shouldn't have to trust Fidaro with the plaintext contents of your AI conversations.”

You still have to trust—or independently verify—that the browser application is delivered correctly, the attestation implementation works as documented, recovery mechanisms are secure, software updates aren't compromised and the published architecture accurately represents the production service.

This is another reason we'd like to see a comprehensive independent security audit.

Who Actually Benefits From This Level of Privacy?

For an ordinary question such as “Give me ten dinner ideas”, Fidaro's additional privacy architecture may not materially change your life.

The value becomes easier to understand when the information is something you genuinely don't want an AI provider itself to inspect.

Potential examples include:

  • Early business strategy
  • Unreleased product ideas
  • Confidential internal discussions
  • Intellectual-property brainstorming
  • Sensitive drafts
  • Documents that have already been appropriately anonymized
  • Private personal brainstorming

Even then, we'd maintain a simple rule:

Privacy technology reduces risk. It doesn't make sensitive information risk-free.

Highly sensitive source code, irreplaceable documents, regulated records and information whose disclosure could cause serious harm still deserve careful handling regardless of how strong an AI provider's encryption architecture appears.

Why Fidaro's Approach Is Still Important

Despite those tradeoffs, we think Fidaro is pursuing an important idea.

Almost every technology company can write:

“We care about your privacy.”

That's ultimately a promise.

Fidaro is attempting something stronger: designing an architecture where the company has less technical ability to violate that privacy in the first place.

That's the difference that makes Fidaro worth watching.

What We'd Like to See Improved

Fidaro is promising, but there are several areas where we'd like to see the company provide greater transparency and independent verification as the platform moves beyond beta.

Publish an Independent Security Audit

This is at the top of our list.

Fidaro has done a better job than many technology companies of explaining how its privacy architecture is supposed to work. The documentation around confidential computing, encryption and attestation gives technically inclined users something meaningful to evaluate.

But ultimately, Fidaro is still describing Fidaro's own system.

We'd like to see a respected independent security firm examine the complete implementation and publish enough of its findings for customers to understand what was tested, what vulnerabilities were discovered and what was corrected.

That wouldn't prove Fidaro could never be compromised. No legitimate security audit can make that promise.

It would provide independent evidence that the architecture has been examined by specialists who weren't responsible for building it.

Identify the AI Models

We'd also like greater transparency about the actual AI models being used.

Automatic model selection is convenient, particularly for users who don't care whether Model A or Model B answers their question.

But sophisticated users increasingly do care.

If Fidaro wants people to compare its product with ChatGPT, Claude, Gemini and other AI assistants, identifying the available open-weight models would make comparisons of reasoning, context limits, coding ability, document analysis and overall answer quality considerably easier.

Ideally, users would be able to see which model handled a particular conversation even if Fidaro continues automatically selecting the model by default.

Make the Corporate Legal Identity Clearer

The people behind Fidaro are publicly identified, which is a major positive.

We'd now like the legal documentation to reach the same standard.

The Terms of Service should clearly identify the contracting corporate entity, its jurisdiction and appropriate business contact information.

This becomes increasingly important if Fidaro intends to attract businesses and professionals rather than remaining primarily a consumer chatbot.

Permanent Encrypted File Storage

The current temporary upload system is understandable for a beta product, but it limits Fidaro's usefulness for document-heavy workflows.

If you're analyzing a lengthy report or working on a project containing multiple documents, having to upload those files again after refreshing or returning later becomes inconvenient.

Fidaro says encrypted permanent file storage is planned.

If the company can implement that while maintaining the same zero-knowledge philosophy used for conversation history, it would make Projects considerably more useful.

More Independent Testing and Third-Party Coverage

Fidaro is still very new.

We'd like to see security researchers, privacy specialists and technically sophisticated users independently examine the product over time.

That matters because one of the strongest tests of security technology is exposure.

The more qualified people examine an architecture, challenge assumptions and attempt to identify weaknesses, the more confidence users can eventually place in the system—assuming discovered problems are handled responsibly.

Fidaro Pros and Cons

Pros Cons
Privacy architecture attempts to prevent Fidaro itself from reading conversations Still an early beta product
Browser-side encryption before prompts are transmitted No comprehensive independent security audit we could locate
Intel TDX confidential-computing environment Exact AI models aren't currently disclosed
Cryptographic attestation verifies the protected environment Uploaded files are currently temporary
Short-lived encryption keys Corporate legal identity and jurisdiction could be stated more clearly
Encrypted synchronized conversation history Zero-knowledge design can make certain support and debugging tasks more difficult
Open-weight models run within Fidaro's protected infrastructure Privacy advantages don't automatically establish regulatory compliance
Team includes people with substantial ExpressVPN privacy-technology experience Protected servers can't secure an already compromised user's device
Currently free during beta Long-term pricing and business model remain to be established

Who Should Consider Trying Fidaro?

Fidaro is particularly interesting for people who like using generative AI but are uncomfortable with an AI provider potentially having technical access to their conversations.

That could include entrepreneurs, developers, researchers, writers, journalists and ordinary consumers who simply place a higher value on privacy.

It's also interesting for people brainstorming ideas they don't necessarily want incorporated into another company's model-training pipeline.

Because Fidaro is currently free during beta, curious users can evaluate its answer quality and interface without making a significant financial commitment.

Who Should Be More Cautious?

Organizations handling regulated or exceptionally sensitive information should apply a higher standard.

If your organization deals with healthcare records, privileged legal information, regulated financial information, confidential customer records or other material subject to specific contractual or legal requirements, don't adopt Fidaro solely because its technical architecture sounds impressive.

Determine whether the service satisfies the actual compliance requirements applying to your organization.

Likewise, we wouldn't use any young beta AI platform as the only repository for irreplaceable information.

Keep appropriate backups and retain original documents independently.

How Does Fidaro Compare With ChatGPT, Claude and Gemini?

We wouldn't frame the comparison as simply asking which chatbot is “best.”

Fidaro is currently competing on a different axis.

ChatGPT, Claude and Gemini are mature AI platforms backed by some of the largest technology companies in the world. Their ecosystems, integrations and model capabilities are considerably easier to evaluate because millions of people use them and their models receive constant public testing.

Fidaro's differentiator is its attempt to minimize the trust users must place in the company operating the AI infrastructure.

That creates a different purchasing—or currently, usage—decision.

If maximum AI capability is your priority, compare the actual quality of the answers.

If preventing the AI service provider from being technically capable of reading your conversations is particularly important, Fidaro deserves a closer look.

Some users may ultimately use both approaches: mainstream AI for ordinary work and a privacy-oriented service for conversations where confidentiality matters more.

Our Fidaro.ai 2026 Verdict

Fidaro is one of the more interesting privacy-focused AI products we've reviewed because its central proposition isn't merely:

“Please trust our privacy policy.”

It's attempting to build a system where readable conversations exist only at the user's endpoint and inside an attested confidential-computing environment.

That's a meaningful architectural distinction.

The people behind the company also give the project credibility. Having ExpressVPN co-founders and people with previous experience building privacy infrastructure doesn't prove that Fidaro's implementation is flawless, but it's considerably more reassuring than an anonymous startup making extraordinary security claims without explaining its technology.

At the same time, we wouldn't treat Fidaro's strongest privacy claims as conclusively proven yet.

The product only launched publicly in 2026. It's still in beta. We couldn't locate a comprehensive published independent security audit, the exact AI models aren't disclosed, permanent encrypted file storage is still being developed and the company's legal identity could be communicated more clearly.

Our verdict is therefore:

Credible team. Impressive privacy architecture. Useful working product. Very young company. More independent verification needed.

That's not a negative verdict.

In fact, we'd argue that Fidaro is approaching one of generative AI's biggest unresolved problems in the right way.

AI systems are becoming increasingly useful, which naturally encourages people to give them increasingly sensitive information.

The long-term solution can't simply be asking users to trust every AI company indefinitely.

Technology that reduces how much information the provider is technically capable of accessing could become increasingly important.

Whether Fidaro ultimately becomes a major AI platform remains to be seen.

But the underlying question it's asking is important:

Why should an AI company need to be capable of reading your private conversations in the first place?

Sources & Further Reading