SHADOWLINKGet access →
shadow-link — session://private
$ shadowlink –connect
Private AI · Real tools · Encrypted by you

An AI that answers anything —
and can actually do the work.

Shadow Link AI is a private, uncensored AI service with something the privacy-first chat apps don’t have: hands. It doesn’t just talk about the job — it runs the commands, reads the output, fixes its own mistakes, reaches the machines you point it at, and comes back with the result — words, code, or the picture the job called for.

Sign in and start. No filter deciding which questions you’re allowed to ask, no company mining your conversations, and a vault that encrypts your history with a passphrase we do not hold and cannot recover. And when a job needs more horsepower than one model has, one toggle lets Shadow quietly consult a frontier model and fold the answer in — or summon a whole council of them.

256Ktoken context
Toolsnot just a text box
Zerochats we can read
Nonerefusals by policy
01 · The idea

Three things every mainstream AI asks you to accept. We reject all three.

You’re asked to accept a content filter that decides which questions are permitted, a company that can read everything you type, and an assistant that can only ever produce text. Shadow Link AI removes the filter, removes the ability to read your data, and replaces the text box with something that can act.

🔓
Unfiltered

An AI that answers

Built on Shadow v4.5, our open, uncensored model. No refusals, no lectures, no topics quietly walled off. It works for you, not for a policy team.

🛠
Capable

It has hands

Real tools: run commands, read and write files, execute code, connect out to the machines you point it at. Give it a task, get an outcome — not a suggestion.

🛡
Private

A vault we can’t open

Your history is encrypted with a passphrase only you know. What sits on the server is ciphertext — unreadable to us, to staff, and to anyone who seizes it.

The one-line version The privacy crowd gave you an AI that won’t betray you. The big labs gave you an AI that can do things. Shadow Link AI is the first that does both at once.
02 · Capabilities

Everything it does, and every one of them is built today.

This is not a roadmap. Each item below is running in production and in daily use.

Agency

Give it a job, not a prompt

It plans, runs real commands, reads what came back, corrects itself, and reports what actually happened — the difference between an assistant that drafts instructions and one that finishes the task.

Reach

Out to the wider internet

It can fetch, call APIs, clone a repository and talk to the servers you give it. Every task gets its own clean workspace, and the network path it uses is governed and rate-limited rather than wide open.

Memory

A 256K-token working memory

Feed it whole codebases, long documents or a sprawling multi-day thread and it keeps the plot. When a thread grows toward the window, older context is compacted automatically — long work stays coherent instead of falling apart halfway through.

Files

Attach anything, ask about it

Drop in documents, code, logs, spreadsheets, PDFs or images. They land in the task’s own workspace where the AI can open them, run them and take them apart — not just skim a preview of them. It can look at pictures too: screenshots, scans and photos are read, described, and their text transcribed.

Images

It paints, too

Ask for a picture in any house-model conversation and it generates into the chat’s Files drawer — anime or photoreal, no mode to switch. Titles are set in real fonts and rendered into the scene with the spelling checked, and flat text edits are free forever. A section of its own →

Flow

Type ahead, stop anything

Queue your next message while the current one is still running and it starts the moment a lane frees. Press stop and it stops — immediately, cleanly, with the partial work still on screen.

Continuity

Nothing lost mid-thought

Long jobs survive dropped connections, flaky networks and closed laptops. Come back later and the work is there — finished, not abandoned.

Bring your own frontier

Consult Mode

On genuinely hard problems, Shadow can open a discreet consult with a frontier model — Claude, GPT, GLM, DeepSeek — on your own API key. It writes the question itself, folds the answer in, and keeps working as one conversation. It gets a section of its own →

Interface

A client with a spine

A distraction-free terminal aesthetic that works the same on a desktop and a phone. Conversations in a tree, notes alongside them, syntax highlighting, keyboard shortcuts, answers that stream live and reconnect on their own.

Teams

An admin console that tells the truth

Seats, plans and per-person limits, plus 30 days of real usage per person and optional automatic limits that step in before one runaway task spoils the day for everybody else.

03 · The gap we fill

Private AI exists. Capable AI exists. Nobody ships both.

The market split in two. The big assistants are powerful but filtered and surveilled. The privacy-first chat apps fixed the surveillance and stayed a text box — no tools, no ability to act, and often a history stranded in one browser. Shadow Link AI is the overlap.

  Mainstream AI assistants Privacy-first chat apps Shadow Link AI
Answers without a policy filter ✕ Refuses by design ✓ ✓
Real tools — can do the work, not just describe it ~ Limited, sandboxed ✕ Text only ✓ Full agent tooling
Operator cannot read your conversations ✕ Stored and reviewable ~ Varies; often browser-only ✓ Zero-knowledge vault
Attach files the AI can actually open and run ~ Preview and summarise ✕ ✓ Into the workspace
History follows you across devices ✓ ~ Often trapped locally ✓ Encrypted, synced
Consult a frontier model on demand ✕ Walled garden ✕ ✓ Consult Mode — any provider, your key
Generate images without a content filter ~ Filtered and logged ✕ Rarely offered ✓ Built in — titles rendered in, spelled right
Context window ~ Varies by tier ~ Typically modest 256K tokens
04 · Image generation

Ask for the picture. Get the picture.

House-model conversations now generate images natively. There is no mode to switch, no separate app, no different client: the model recognizes when the job needs a visual and fills the request itself, right in the thread where you were already working. The result lands in the chat’s Files drawer beside your code and documents — newest first, downloadable one or all — and the conversation simply carries on. Uncensored, encrypted like everything else, and bounded by honest published numbers instead of mystery.

Uncensored

No filter between you and the canvas

The same philosophy that governs the chat, now for pictures: no banned-prompt list, no classifier deciding which images you are allowed to make. Adults making art for adults is your business, not ours. The ordinary limits of the law still apply — drawn by the Terms of Service, not by a keyword.

Two engines, and edits

Anime, photo, and changes to either

Two purpose-picked engines: anime for illustration, and photo for everything else — realistic people, posters, product shots, painting — written in plain natural language, no tag dialect to learn. It edits too: point it at any picture in the chat and say what to change — make it night, swap the background, add a hat — and the composition stays. Eight sizes from square to wide banner to phone story, up to two images per request.

Words on the image

Titles that belong in the picture

Photo-style images letter themselves: quote the words and they are painted into the scene — a shop sign, a poster headline, a neon tube. On anime it sets them in a real font — 53 typefaces across poster, brand, script, serif, tech, horror, retro, gothic and western — then renders the letters into the scene as a material: neon tubes, chalk on a wall, molten gold, carved wood. Either way a vision model reads the result back and checks the spelling; a miss gets one retry, then the crisp flat version on anime or a plain note of what it read on photo — never a silent typo. Prefer clean type? A flat title with a contrast band is still there, up to 64 characters, and changing the words that way costs nothing and takes no time — no GPU involved.

Private like the rest

Sealed when you step away

On a vaulted account, generated images are sealed under your own vault key whenever no reply is being written in that chat — file names included — and sit on our disks as ciphertext, unreadable while your vault is locked. They are opened in the chat’s walled-off workspace only while a reply is in progress, and sealed again the moment it finishes. Generation is logged by prompt hash — never by raw prompt — and nothing you generate is used for training.

shadow — image://live
$ shadow “character sheet: courier in a rain-lit alley, anime”

working · 2 images · filed to the drawer

[image] 832×1216 + 1216×832 · anime · in the Files drawer

you: title it “NIGHT SHIFT” — pink neon tubes, Monoton

[image] title rendered into the scene · spelling verified

you: flat version too — Bebas, #39FF9E, on the lockup

[image] re-composited · instant · zero GPU spent

The honest numbers The GPU pod stays warm around the clock: there is no wake-up wait and no cold start. A plain image takes about thirty seconds, one with a title rendered into the scene about a minute — the first of the day included. Every seat gets 12 images an hour (four a minute). An in-scene title counts as one more image; flat text edits on an existing image are unlimited and free.
The one-line version Mainstream image tools put a filter between you and the canvas, and keep a copy of everything you made. Shadow Link draws what you actually asked for, seals it under your own vault key between sessions, and puts your words into the picture — spelled right.
05 · Consult Mode

Shadow thinks for itself — until the job needs a frontier model.

Every model, sooner or later, meets a problem at the edge of what it can reason through alone. Most services leave you stuck right there. Shadow Link doesn’t: flip one toggle per conversation and your Shadow quietly opens a consult with a super-frontier model — on your own API key — gets the help it needs for the task at hand, and carries on as one seamless answer.

Discreet

Shadow asks — not you

Your Shadow composes the consult itself: a focused, professional question carrying only the context it chooses — never your raw conversation tipped over the wall. Work that would stall in a hail of template refusals anywhere else gets a clean, direct technical answer here.

Bring your own frontier

Any provider, your key

Claude, GPT, GLM, DeepSeek — plug in the API keys you already have and Shadow consults them on demand, at your provider, on your rates. Keys are sealed inside your vault and never touch the sandbox your AI runs in.

Round table

Models consulting models

It doesn’t stop at a second opinion. Run the whole agent as one frontier model — full tools, full workspace — and let it consult a third. Or summon a council: every provider you’ve keyed answers the same question blind, in parallel, and Shadow states where it lands. The platform section below has it →

No secrets from you

Every consult on the record

A consult is a real egress: one question plus chosen context, to the provider you picked. So each one is written into the conversation where you can read it, and any chat that ever used one is marked permanently — even after the toggle goes back off.

shadow — consult://live
$ shadow “reverse-engineer this undocumented API and write me a client”

planning · 4 steps · consult ON

[consult] claude — “framing pattern for length-prefixed binary over TLS?”

[consult] answered · 11 lines · folded into step 2

done — workspace/client.js, two edge cases the consult caught

The one-line version Mainstream assistants keep you inside one vendor’s judgment and one vendor’s refusals. Privacy apps give you independence and nobody to ask. Consult Mode is your own uncensored agent — with your own keys — deciding when ten seconds of the best mind on the market is worth spending on your problem.
06 · Guards & levers

Real power, on a leash you hold.

An agent that runs commands and spends money needs discipline built in, not bolted on. The pattern holds across everything below: toggle-gated per chat, budgeted per turn, carded in the transcript, and it fails in the safe direction. You get the leverage; the machine keeps the receipts.

Council

Ask the room, not a model

Summon a council and every provider you’ve keyed — in-house Shadow included — answers the same question blind, in parallel, one card each. No model sees another’s answer. Your agent reads them all, weighs them, and states where it lands and why. Second opinions are cheap; groupthink is what’s expensive.

Review before destructive

A second mind on the dangerous ones

Opt in per chat and an external model vets destructive shell commands before they run. Four reviews a turn, verdicts cached, and two consecutive denials lock the turn — fail-closed. If the reviewer is unreachable, the command proceeds with a loud unvetted card, so visibility never depends on the reviewer being up. The concerns are shown verbatim.

Delegate

Read wide, think narrow

Spawn a subagent on our own GPU pod and the bulk reading burns the child’s context, not yours — the parent grows only by the capped result. Each child gets its own scratch directory, inherits the egress gate and the review hook, and comes back as one collapsed line. Two per turn, two concurrent, 240 seconds each.

Handoff

Pass the work, not the summary

Move a job to another chat in your account and the conversation compiles the complete brief itself — goal, state, paths, constraints. On the far side it waits as a card with one button; nothing runs until someone presses it, and both transcripts keep the record. Your account, your continuity.

shadow — review://destructive
$ shadow “clean up the staging tree and rebuild”

working · review ON · 4 reviews / turn

[review] rm -rf /staging/current — DENY — “current is a live symlink into prod; the tree you want is /staging/v3”

[review] rm -rf /staging/v3/build — PASS · circuit 1/2

rebuilt — /staging/v3/build, the live tree untouched

The one-line version Other platforms either cage the agent so it can’t do damage, or let it loose and hope. Shadow Link hands the agent real leverage and makes every use of it gated, budgeted and written down — power with a paper trail, by design.
07 · Privacy posture

Privacy that survives a subpoena.

Most “we don’t log” promises are policy — a company choosing not to look, which it can reverse and a court can override. Ours is architecture: what sits on our servers is mathematically unreadable to us.

  • ▸
    Zero-knowledge vault. Your passphrase never crosses the wire. History is encrypted under a key derived from it; the server holds only ciphertext.
  • ▸
    Two independent secrets. A login password and a separate vault passphrase — stealing one does not unlock the other.
  • ▸
    Hard account isolation. Every account’s chats, notes, files and workspace are walled off at the kernel level, and it is tested that way: one account’s task cannot see another’s data at all.
  • ▸
    Sandboxed execution. When the AI runs tools it does so inside a throwaway, per-task view of the system. Powerful inside its own workspace; unable to reach the host or anybody else’s.
  • ▸
    One exception, stated plainly. The vault seals your conversation history, attachments and generated images. Other files the AI creates in a chat’s workspace — scripts, code, documents — are walled off per account but not vault-encrypted, and anything a reply is working on is readable to the tools while it runs, because they have to read it.
  • ▸
    No training on your data. We could not build a dataset out of your conversations if we wanted to. We cannot read them.
  • ▸
    Total transparency on outside calls. Any conversation that ever consulted an external model is flagged permanently — even after the feature is switched back off.
Design tradeoff, stated plainly True zero-knowledge means no backdoor and no recovery. Lose your passphrase and that history is gone, for good. That isn’t a flaw waiting to be patched — it is the proof the guarantee is real. Privacy you can’t lose is privacy somebody else can open.
Privacy is not a tier The vault, the isolation, the sandbox, the absence of a policy filter and the full 256K context are identical on every plan, including the cheapest one. Plans differ on throughput and nothing else. We will not sell your privacy back to you one upgrade at a time.
08 · Plans

One platform. Pick a seat.

Shadow Link AI is a hosted service — you sign in and use it; the model, the tools and the capacity are ours to run. Seats are how it is sold: one for yourself, or a pool for a team.

Context doubled on every plan, same price — Shadow v4.5 runs a true 256K context window.

Core
$50/month
One person who wants private, unfiltered AI that can actually do the work.
Lanes
2
Tokens / day
18M
GPU output time / day
2.4 h
Requests / min
40
Context
256K
  • ▸
    Two lanes — two tasks running at once
  • ▸
    Full tool access: commands, files, code, remote machines
  • ▸
    256K context and the encrypted vault
  • ▸
    File attachments, notes and a searchable history
Get Core →
OperatorFlagship
$100/month
The person who lives in it all day and runs long, real work through it.
Lanes
4
Tokens / day
48M
GPU output time / day
7.2 h
Requests / min
90
Context
256K
  • ▸
    Four lanes — four tasks at once, all day
  • ▸
    Long jobs measured in hours, not minutes
  • ▸
    The highest ceiling on the platform
  • ▸
    Everything in Core, on well over twice the allowance
Get Operator →
Team3-seat minimum
$195/mo for 3 seats · $65/seat
A group that wants one account, one invoice, and nobody starving anybody else. The price buys three seats — there is no single-seat Team.
Seats
3 minimum
Lanes
2 / seat, pooled
Tokens / day
28M / seat
GPU output time / day
3.2 h
Requests / min
60
Context
256K
  • ▸
    Everything in Core, per seat
  • ▸
    Pooled lanes — a quiet seat lends its lane to a busy one
  • ▸
    Admin console: per-person usage, limits and 30 days of history
  • ▸
    One bill; seats added or removed any month
Get Team — 3 seats →
Never a paid extra, on any plan: the zero-knowledge vault, kernel-level isolation, sandboxed tool execution, answers without a policy filter, the full 256K context, file attachments, image generation and editing — both styles, in-scene titles included — Consult Mode — discreet frontier consultation on your own API key — and the full set of guards and levers: councils, destructive-command review, delegates and handoffs.
What a lane is, and what the allowance means A lane is one task running at once: Core has two, Operator has four. The daily allowance is the honest version of “fair use” — a published number instead of a vague promise and a surprise later. For scale: the heaviest customer day we have measured so far used about 6 million tokens and about an hour of GPU time — a third of Core’s token allowance. The ceilings are there to stop automation running around the clock, not to ration your day.

“GPU output time” is not how long you are allowed to use it. There is no clock on your day and no session limit. It is the time the graphics card spends actually generating your answers — the seconds it is working, not the minutes you spend reading, thinking or typing. Core allows 2.4 hours of it a day and Operator 7.2 hours, against about an hour on the heaviest customer day measured so far. Which ceiling a workload hits first now depends on what it is: token-heavy reading drains the token allowance, generation-heavy work spends GPU seconds. A person working normally will touch neither.

There is no credit meter, no per-message billing and no overage charge. The allowance resets daily at 00:00 UTC.
Which one you want Take Core if AI is a tool you reach for a few times a day. Take Operator if it is where you work — several things running at once, jobs that last hours, and an allowance well over twice Core’s. Take Team when more than one person needs a seat and you want a single bill, shared lanes and a console that shows you who is using what.
Where these prices sit in the market Private, uncensored chat starts around $18/month and stops at text. AI that actually does the work runs $100 to $200/month across the major vendors, with real heavy-user spend reported at $150–250/month. Our entry seat sits a little above private chat and hands you tools none of those have; our full seat lands at the bottom of the tier it genuinely competes in, privacy guarantees included.
09 · Straight answers

The questions worth asking first.

Can you read my conversations?

No, and not as a promise — as arithmetic. Your history is encrypted under a key derived from a passphrase that never leaves your control. We hold ciphertext. A subpoena gets the same ciphertext.

What happens if I forget the passphrase?

That history is gone. There is no reset link and no support ticket that recovers it. That is the cost of the guarantee being real, and we would rather say so on the pricing page than in an apology email.

Is it really uncensored?

There is no policy filter sitting between you and the model, and no topic list. What remains are the ordinary limits of any hosted service — you are still responsible for what you do with it, and abuse of the platform’s own resources is bounded.

What can the AI actually reach?

Its own per-task workspace, the files you attach, and the outside network. It cannot touch the host, other accounts, or anything on your own machines unless you deliberately give it the way in.

How does Consult Mode work, exactly?

One toggle per conversation. When it’s on, your Shadow may — at its own judgment — send a focused question to a frontier provider you configured, on your API key, and fold the answer back into its work. What leaves is the question and the context Shadow chose, not your whole transcript. Every consult is visible in the conversation, any chat that ever used one stays marked, and with the toggle off, nothing leaves at all.

What stops it running something destructive?

Optionally, a second opinion. Review-before-destructive is a per-chat toggle: when it’s on, an external model vets destructive shell commands before they run and its concerns are shown verbatim. Two consecutive denials lock the turn outright. If the reviewer can’t be reached, the command proceeds — but the transcript gets a loud unvetted card, so you are never quietly trusting a service that was down.

Is image generation uncensored too?

Yes, with the same shape as the chat: no banned-prompt list and no classifier between you and the canvas, and the ordinary limits of the law still applying. The platform’s own resources are protected the honest way — published numbers, not mystery: twelve images per seat per hour, four per minute, with flat text edits unlimited and free. The GPU pod stays warm around the clock, so an image takes about thirty seconds and one with an in-scene title about a minute — the first of the day included.

What happens when I hit the daily allowance?

You keep working. Past the line, the seat drops to a single lane at a reduced request rate until the daily reset at 00:00 UTC — requests wait their turn rather than fail. Only at three times the allowance, which is automation running around the clock rather than a person, does a seat pause until the reset. Nothing is deleted, nothing is billed as overage, and you can watch the number all day rather than discovering it at the end of the month.

Can I move up or down a plan?

Any month, both directions — write to [email protected] and it is done on your account. Team seats are added or removed the same way. Capacity changes take effect immediately, not at the next billing cycle.

Do I need to be technical?

To chat, no. To get the most out of the tools, it helps — this is a product for people who want the AI to finish the job, and finishing the job usually means touching real systems.

Do you train on what I type?

No. We could not if we wanted to.

SHADOW LINK AI · Private AI, real tools · v3
Plans and allowances current as of 2026-10-03; the Store page always shows the live figures.