Agents & /goal
State a goal and the agent works in steps; a separate evaluator decides when it is actually
met. It keeps running as a background job with the browser closed. There is no spend ceiling
per run on any plan — a goal may spend whatever your balance covers. A wall clock set by
your plan still applies, enforced on our side, not in your browser. On your own Anthropic
account we can report that limit, but not enforce it.
Containers you own
Real Linux workspaces on our container hosts — create, resize, pause, resume, share. Your
agent runs in the container the chat has selected, so what it edits is exactly what
you see in the Containers page. Paused workspaces move to the NAS and come back on resume.
Pick the operating system
Every container runs Linux, and you choose which Linux when you create it: the ZeroLog
toolchain image by default, or a plain Ubuntu 24.04, Debian 12 with Node.js 22, Alpine
3.20, or Alpine with Python 3.12. The choice is fixed once the container exists — your
files stay, but software installed inside them would not survive a swap. It costs nothing
extra: a container counts against the vCPU, memory and disk your plan allows, the same way
whichever base you pick. Windows is on the list but cannot be selected, and the picker says
why — a container shares the kernel of the machine it runs on, so a Windows container
needs a Windows machine, and ours run Linux.
Snapshots & rollback
Take a snapshot of a workspace before a risky change, and put back a single file or the
whole thing. A full rollback snapshots the current state first, so the undo has an undo.
Retention follows your plan, and an automatic snapshot never deletes one you took on
purpose.
Import from Claude, ChatGPT & Gemini
Export files from all three are parsed locally — preview first, then import. An imported
history can be continued as a chat. Export back out as Markdown, JSON, HTML or text, with
vault content and network names redacted whether you remember to ask or not.
Claude Code, Codex & Gemini CLI
The real binaries, in your container, pointed at whichever model you picked — Kimi K3, GLM,
DeepSeek — with no Anthropic or OpenAI account involved. The chat's Manual / Automatic /
Skip-all setting becomes the CLI's own permission mode, so one choice governs both.
Voice
Speak instead of typing, answers read back — per account, with push-to-talk or automatic
end-of-speech detection. Recognition and speech happen in your browser: no audio reaches
this server and it costs nothing to run. The trade is that your browser vendor processes
the speech, and the interface says so.
What the name means
Registration takes a username and a password: there is no field for an email, a phone
number or a name, and your IP is never stored — it is held in memory long enough to
rate-limit sign-ins and nothing else.
This is not anonymity, and we will not claim it is. The moment you
top up credit, your payment provider knows exactly who you are: card payments and Google
Pay carry your name and billing address, and the operator can see them in Stripe. What the
name means is that we do not ask for, need, or keep more than the service requires.
Turn on anonymous chats and content is encrypted in your browser: the
server keeps ciphertext and the billing counters, so there is no operator read path to the STORED chat. What you ask is still sent to the model provider to be answered — encryption protects storage here, not the fact that a model has to see the prompt.
You can make that the default for every new chat in one switch.
Ordinary chats are stored, so your history is there when you come
back — we say so rather than let the name imply otherwise. Credentials always sit in an
AES-256-GCM vault, and the moment a chat uses one the request is pinned to providers that
retain nothing, or it fails rather than falling back to one that does.
Your own key
Every account has its own spending limit, enforced per request — nobody ever
touches the shared one. Or bring your own provider key: those requests run on it, cost no
balance, and are marked in the chat as yours. Tokens still count, so the statistics stay
honest.
Multiplayer
Share a container by invite link, from Pro. You decide when creating the link whether the
person may read or also write; it expires and can be revoked. Opening one shows whose
container it is and what access it grants before accepting.
Models that use other models
Ask the model in your chat to hand part of the job to a different one — a vision model
to read the screenshot you just uploaded, a stronger model for the hard part — and the
answer comes back into the same conversation. Your uploaded files and images go along with
the question. The chat shows which model was asked and what it cost: a second model working
under the first one's name would be a lie by omission. It is billed to your balance like any
other message, bounded to one hand-off deep with a few calls and a spend ceiling per message,
and you can switch it off for your account.
Generating images runs on Leonardo AI and is off until you turn
it on: it needs the Leonardo connector enabled for your account, and every picture
costs credit — without the balance to pay for it, the request is refused rather than run.
Connectors
Leonardo AI as an agent tool, enabled per account, every call routed through the egress
broker and logged. A connector may only reach the hosts it declared — anything else is
refused, not merely recorded.
Legal research
Questions about Swiss, EU, US and Canadian law, answered only from official sources with
every statement linked to its citation. Where the corpus does not cover something, the
answer says so instead of filling the gap from memory.
Not legal advice — it does not replace a lawyer, and the interface says
that with every answer.