Is Local AI Actually Private? On-Device LLMs Explained

"Private AI" and "AI at home" get thrown around loosely, so it is worth being exact. The short answer: when the thinking happens on a box in your house, your questions and your files can be handled without ever being sent to somebody else's computer. This article explains what that really means, where the edges are, and how it differs from what happens when you use a rented app.

What "at home" and "private" really mean

At home means the work happens on hardware in your house. What the assistant knows sits on your own drive, and the arithmetic that turns your question into an answer runs on a chip in the room with you, not in a data centre. Private follows from that: if the work does not have to travel over the internet, none of what you said goes to anyone else while it is being answered.

The two ideas are related but not the same. Something can run in your house and still quietly report back about you, and something can run elsewhere with strong promises attached. The reason a box on your shelf is the stronger position is that it removes the need to trust anyone else for the main job. You are not leaning on a policy. You are leaning on the fact that no request was ever made.

How answering at home keeps your work off the internet

Underneath, an assistant is a large set of numbers and a program that runs your words through them to work out what to say back. When that happens on your shelf the sequence is short: your question goes into the box's memory, the chip does the arithmetic, and the answer comes back. Nothing in that loop needs to reach outside the house.

Private out of the box, not after you configure it

The first year is the whole price, and every year after is the service running. The machine stays ours; the model trained on your material is yours alone while the service runs. See what it costs →

Digital Twin Pro — the small box your assistant lives in — is built for exactly this. It arrives fully assembled on professional-grade parts, with your assistant already installed. Your assistant arrives with a name, and you can change it. It handles the everyday work on the box itself: drafting, summarising, chat, listening and speaking, and answering from your own papers. Because the whole thing is already on the shelf, supported local workflows can process content without submitting it to an external model provider. You point your phone's camera at the card in the box, so there is no screen, keyboard or mouse to look after.

For technical readers. NVIDIA Jetson Orin NX 16GB, 1024-core Ampere GPU, 16GB LPDDR5, up to 157 sparse INT8 TOPS (Super Mode). Runs quantized 7–8B-class LLMs, ASR/TTS and small vision models on-device. Ships on JetPack 7.2, assembled in Miami, FL, USA.

What are you actually protecting against?

Privacy questions get much clearer once you name what you are worried about. Here is the plain-language version.

  • The company reading it: With most rented AI, every message you type passes through a company's computers. When the answer comes from your own shelf, no request is sent, so there is nothing for anyone to read.
  • Your words becoming somebody's product: A common worry is that what you type gets used to build the next version. If the box answered you itself, there was nothing to send and nothing to use.
  • Someone listening on the way: Anything crossing the internet can in principle be logged somewhere along the route. If it did not travel, there is nothing to catch.
  • A court order or a breach somewhere else: A company cannot hand over, or leak, what it was given.
  • Someone getting at the box itself: That is the honest flip side. When your work lives in your house, the lock on the door and the state of your Wi-Fi start to matter. A box on your desk is only as private as the room and the network it sits in.

No arrangement is perfectly private. What a box at home does is shrink the list of things you have to trust — from a company, plus its infrastructure, plus the path across the internet, down to hardware you can physically put your hand on.

What does and doesn't leave the box

For the everyday work the answer is simple: nothing about your question or its answer goes anywhere. The box reads what you asked, works it out on the shelf, and hands it back.

There are ordinary exceptions, and being straight about them is the whole point:

  • Software updates: Updates, health checks, and backups are part of the service — we do the tending. That needs a connection for the update itself — not for your questions.
  • Sending a job to an outside service: You can connect an outside model you already pay for and it's optional. You turn it on, and you decide which job goes out. When one does, that one request goes to that company under its terms. Until you turn it on, the work stays home.
  • Anything you send on purpose: Passing an answer to another app, or syncing a file, moves your work because you moved it.

Think of it as a switch you are holding: home by default, outside only when you flip it.

How this differs from what a rented app does with your data

With a typical rented assistant, every message travels to that company and is handled on its systems. How long it is kept, who may look at it, and whether it feeds the next version are all governed by that company's policies, and policies change. Those services are genuinely excellent at the hardest reasoning and at jobs that need to hold an enormous amount of material at once. That is where they still lead.

A box at home flips the default. Instead of "it goes out unless a policy says otherwise," it is "it does not go out unless you send it." You trade a little raw capability for control. A small box will not match the very largest services on the hardest problems, but for private drafting, summarising, transcription and the routines you have asked it to keep, the work stays in your hands. And it is cheap to run — roughly $1 to $3 a month in electricity, assuming about 10W on average at typical U.S. rates.

Who this is a good fit for

It makes the most sense if you handle sensitive material, want less of your life sitting on other people's computers, or simply prefer your work to stay on your own hardware unless you decide otherwise. The first year is the whole price, and every year after is the service running. The machine stays ours; the model trained on your material is yours alone while the service runs. If your work regularly needs the very largest services, open the valve — once, for a while, or always — and the outside model is paid for out of the same fee.

Frequently asked questions

Is AI at home actually private?

For the work the box does itself, yes. Your questions and answers are handled on the box and are not sent anywhere. The honest caveat is that the box lives on your network and in your space, so the lock on the door and the state of your Wi-Fi become your job. Privacy moves from trusting a distant company to looking after your own hardware.

Does any of my work leave the box when I use it?

Not for the work it does itself. Nothing about your question or the answer goes out. Your work only leaves if you send a job to an outside service, install an update, or share something yourself.

What happens if I connect an outside AI service?

You can connect the AI services you already use, signing in with your own account. It's optional, and you choose which jobs go out. When one does, that single request goes to that company under its terms. The rest stays home, and the box shows you when a job went out.

Is privacy part of the paid service, or how the box works?

It is how the box works. The first year is the whole price, and every year after is the service running. The machine stays ours; the model trained on your material is yours alone while the service runs.

Can a box at home do all that a big outside service can?

Not quite. Digital Twin Pro is very good at drafting, summarising, speech, and answering from your own papers, which covers most of what people actually do. The hardest reasoning, and jobs that need to hold an enormous amount of material at once, still go better through a big outside service — which is why you can connect the ones you already use for those moments.

Local AI. Private data. Local training.

$8,995 the first year — everything included. $4,995 each year after. The first year costs more because it contains the Jetson Orin placed and configured, your archive loaded and the first training run; every year after is the service running.

Begin the first year — $8,995

Or add the Archive Assessment first — $1,950, credited in full

You order and pay at checkout; we write back within days — a decline returns every dollar, and until our letter confirms the year you may withdraw in writing. From that letter the year is final, and it arrives on the date the letter names. Prefer to write to us first?

One decision, and then it is handled

One price, and one way to begin.


The same assistant at either address, for the same price. Begin with the first year; if you like, add the Archive Assessment before it — delivered work you keep, credited in full.

The first year

$8,995

Everything included. $4,995 each year after.

Begin the first year — $8,995

Or add the Archive Assessment first — $1,950, credited in full

The first year costs more because it contains the Jetson Orin placed and configured, your archive loaded and the first training run; every year after is the service running. You order and pay at checkout; we write back within days — a decline returns every dollar, and until our letter confirms the year you may withdraw in writing. From that letter the year is final, and it arrives on the date the letter names.

We answer in writing, within one business day — and if we cannot serve you well we say so before our letter confirms a year. Prefer to write to us first?