Why privacy is the whole point
What "free" actually costs, in numbers you can check.
Fred runs on your own hardware. That decision only makes sense if the alternative is genuinely worse, so this page sets out what the alternative is. Not opinions about it. The findings of competition regulators, the contents of court orders, declassified intelligence reports, and in several cases what the companies say about themselves.
Every claim below links to its source. If you only read three numbers, read these.
1. The scale is not "some analytics"
In September 2024 the US Federal Trade Commission published the results of a formal study of nine companies, among them Facebook, YouTube, Amazon, TikTok, Snap, Reddit, Discord and WhatsApp. It did not use careful language. The companies had engaged in "vast surveillance" of their users, their data practices were "woefully inadequate", and the business model itself rewards collecting as much as possible, because advertising is where most of the revenue comes from. The full report runs to a few hundred pages and is worth an evening.
The advertising machine underneath is bigger than most people picture. The Irish Council for Civil Liberties measured how often the real-time bidding system broadcasts a person's activity and location to potential advertisers: 376 times a day for the average person in Europe, 747 in the United States, 178 trillion times a year in total. Those broadcasts go to firms all over the world, including in countries where no European or American law reaches, and once a broadcast is out there is no recalling it. The ICCL calls it the biggest data breach ever recorded, and the word breach is doing real work there: nothing was hacked. This is the system operating normally.
2. Governments do not need to break in. They ask, or they buy
The first route is simply asking. Google publishes the count itself in its transparency report: tens of thousands of government demands for user information every six months, worldwide, rising nearly every reporting period. Every large cloud provider publishes a similar number. This is not a scandal, it is the routine operation of holding other people's data on someone else's computers. If a company has your data, that data has a legal address, and the address can be served.
The second route is asking about a place instead of a person. A geofence warrant asks a company to name every device that was inside an area during a window of time. Google received 982 of these in 2018, 8,396 in 2019 and 11,554 in 2020, and said they had grown into roughly a quarter of all the legal demands it received in the United States. Courts are still working out whether they are constitutional at all, and the Congressional Research Service has written up the mess. In the meantime, the thing that puts you in the result set is having been nearby.
The third route skips the warrant entirely. In June 2023 the US Office of the Director of National Intelligence declassified an internal report confirming that intelligence agencies buy large quantities of Americans' personal data, including location data, on the open market from commercial brokers. The report also conceded that the agencies do not know how much they hold, what kinds, or what is being done with it. The Brennan Center and EPIC have both written on what that means: data a warrant would be needed to compel can instead be purchased with a credit card.
That market is not careful about who it sells to. In late 2024, journalists and a privacy startup were given access to Locate X, a location tool sold to law enforcement, essentially by saying they might work with police one day. They used it to identify devices that had visited abortion clinics. Around the same time it emerged that officials inside the US Secret Service had argued no warrant was needed to track people this way, on the reasoning that you had agreed to it when you accepted an app's terms of service.
3. An AI chat is not a private conversation
This is the part that matters most for a product like Fred, because of what people actually type into these things: health worries, money trouble, their marriage, their work.
In July 2025 Sam Altman, OpenAI's chief executive, said plainly that there is no legal confidentiality when you use ChatGPT as a therapist. Talk to a doctor, a lawyer or a therapist and the law protects what you said. Type the same words into a chatbot and it is a business record, producible in discovery like any other. He was arguing that the law should change. It has not.
That is not hypothetical, and the delete button does not settle it. In May 2025 a court in the New York Times case ordered OpenAI to preserve output logs it would otherwise have deleted, including conversations users had already deleted, overriding the company's own retention policy. Around twenty million conversations fell in scope. The order was narrowed later in the year, but what had already been preserved stayed preserved. Your data was governed by a court docket, not by the setting you chose.
And the terms move under you. Meta began training its models on European users' public Facebook and Instagram posts in May 2025. LinkedIn switched users in the EU, Switzerland, Canada and elsewhere on by default from 3 November 2025, covering years of posts written long before anyone was asked. Both are opt-out, both are retroactive, and both were announced to people who had already handed the material over.
4. "Stored in Europe" is not the protection people think it is
The US CLOUD Act lets American authorities compel American providers to produce data regardless of which country the servers sit in. That conflict is precisely why the EU's top court struck down the Privacy Shield arrangement in the Schrems II ruling, and why, in May 2023, the Irish Data Protection Commission fined Meta 1.2 billion euros, the largest GDPR penalty ever issued, for sending European users' data to the United States.
A European data centre owned by an American company is a legal question, not a technical one, and the question has been answered more than once. Data that never leaves your house is not a legal question at all.
5. Your data outlives the company you gave it to
You do not consent once. You consent to whoever ends up holding it.
- Bankruptcy sells it. 23andMe filed for Chapter 11 in March 2025, and the genetic data of about 15 million customers became an asset in the estate, eventually going for 305 million dollars. Twenty eight state attorneys general went to court to try to stop the transfer, arguing the company had no right to treat genomes as freely saleable property. Lawfare, Public Citizen
- "Deleted" is a policy, not a fact. In 2023 Amazon paid 30.8 million dollars to settle FTC and Department of Justice complaints that it kept children's Alexa voice recordings indefinitely, kept transcripts even after deleting the audio, and undermined parents' deletion requests. The same action covered Ring, where one employee viewed thousands of videos belonging to at least 81 women, inside their homes. FTC, NPR
- Health and therapy are not exempt. The FTC found that GoodRx sent users' prescriptions and health conditions to Facebook and Google for advertising, and that BetterHelp shared the health data of therapy clients with advertisers. BetterHelp paid 7.8 million dollars back to consumers. Summary of both actions
- Brokers resell it. The FTC moved against the data broker Kochava for selling precise location data that exposed people's visits to health facilities and places of worship, and has now banned it from selling sensitive location data without real consent. FTC
- Even the car. Mozilla reviewed 25 car brands in 2023 and every single one failed its privacy test, a first in the guide's history. 84% admitted sharing or selling personal data. One brand's policy claimed the right to collect information about sexual activity and genetics. Mozilla
6. What it costs even if nothing bad ever happens to you
The usual answer to all of this is "I have nothing to hide". The interesting finding is that people behave as though they do, whether or not they think they do.
After the Snowden revelations in June 2013, traffic to Wikipedia articles on privacy-sensitive subjects fell by roughly 30 percent, and stayed down. Nobody was arrested for reading an encyclopedia. People simply stopped looking things up. That is a peer-reviewed measurement, in the Berkeley Technology Law Journal, of the price of being watched: not punishment, just a quiet narrowing of what people are willing to be curious about.
And the discomfort is already widespread. Pew found in 2023 that 73% of people feel they have little or no control over what companies collect, 79% say the same about government, 81% worry about how companies use it, and the share who say they do not understand what is being done with their data rose from 59% in 2019 to 67% in 2023. That is not apathy. That is resignation, which is what happens when there is nothing else on offer.
What Fred does instead
Fred is an AI that runs on a computer you own. The model runs on your machine, your conversations are files on your disk, and your memory, documents and photos stay where they already are. There is no account to log into to reach your own data, no retention policy that can change next quarter, and nothing to subpoena from us because we do not have it. Unplug the internet and Fred still works.
Being specific about the edges, because a privacy page that overclaims is just marketing:
- When your phone talks to Fred from outside your home, it goes through a small relay so the two can find each other. Message bodies are encrypted with a key made on your own machine, so the relay only ever handles ciphertext, and it keeps none of your content. It does see that two devices are talking, when, and from which IP addresses. It runs in Chur, Switzerland, on our own hardware. The privacy policy takes that apart line by line, including the one caveat we would rather not have.
- This website collects an email address if you join the waitlist, and nothing else. Payments, if you ever choose to support the project, are handled by Stripe and your card details never reach us.
- If you connect Fred to an outside service on purpose, your email, your calendar, a smart home hub, then Fred talks to that service, because that is what you asked for. You choose which agents exist, and you can see what each one touches.
- The full detail is in the privacy policy, which is short, and boring, on purpose.
The point is not that you have something to hide
It is that none of the above asked you first, and none of it is reversible once it has happened. A local AI is not paranoia. It is the ordinary expectation that a machine you paid for works for you, which is how computers worked for about forty years before we agreed to rent them back. Fred is free, it runs on hardware you already own, and nothing it learns about you leaves the building.