push.tt / Features
Partly shipping

AI you switch on, in one conversation, on purpose

Every AI feature here is off by default, quarantined to a clearly-labelled conversation, and gated behind a consent step the server actually enforces.

Partly shipping. The assistant conversation, the consent gate and the in-app labelling all ship today. The model behind it is a stub provider — connecting a real one, and AI digests, are in development.

The boundary is cryptographic, not a checkbox

The assistant is a real account with an empty public key. Your device therefore cannot derive a key to encrypt to it. Talking to the assistant is not "encryption turned off" — it is a conversation that was never encryptable in the first place, and the client knows it.

  • A separate internal gate keeps voice out of that conversation entirely, so no plaintext audio can be sent to a keyless party
  • The app shows an open-lock badge wherever end-to-end encryption is absent by design
  • A green padlock on an unencrypted conversation is worse than no padlock at all

How this differs from the category

The usual arrangement is that AI features require server-side plaintext across your whole account. Ours is opt-in and confined to one conversation you can point at.

  • On-device transcription is the AI feature we lead with, and it preserves end-to-end encryption entirely
  • The assistant is the one place content is readable, and it is labelled everywhere it appears
  • We do not currently offer AI summaries of your channels, and we will not add them silently