Private intelligence / browser-firsthow privacy works

Your thoughts.
Kept yours.

Umbra puts a clear boundary between your words and helpful models. Redact in your browser, get an answer, restore your context.

zero retentionno accountno training on your databrowser-only memory
Umbra AutoNova 4Sage SonnetReasoning R1Gemini FlashQwen CoderLlama OpenMistral SmallSmart Privacybrowser-only memoryMCP connectorsOpenAI-compatible API
The real thing

This is the actual app.

One prompt with a name, an email, and a city. Watch the receipt: the provider only ever saw placeholders.

useumbra.org/apprecorded session
YOUR DEVICEPLACEHOLDERSMODELS

See the boundary before you trust it.

Umbra turns recognizable details into reversible placeholders in your browser before a provider sees the request.

WHAT YOU WROTE

Hi, my name is John Smith, my email is john@example.com, my wallet is 0x1234567890123456789012345678901234567890 and I live in Lisbon.

WHAT THE MODEL SAW

Hi, my name is [PERSON_1], my email is [EMAIL_1], my wallet is [WALLET_1] and I live in [LOCATION_1].

LOCAL RECEIPT

4 details protected in this example.

  • PERSON[PERSON_1]
  • EMAIL[EMAIL_1]
  • EVM_ADDRESS[WALLET_1]
  • LOCATION[LOCATION_1]

A quiet boundary around every conversation.

Nothing private needs to leave your device as readable text. The browser handles the sensitive part before a provider sees a request.

01 / LOCAL

Redact

Identity anchors become reversible placeholders on your device.

02 / PRIVATE

Send

Only the protected version travels to the selected model.

03 / CONTEXT

Restore

Your browser puts your original context back into the answer.

UMBRACHAT

Ask anything,
privately.

Route across frontier and open models, keep every conversation in this browser, and watch Smart Privacy hide your identity anchors before a provider sees them.

Open UmbraChat

redact in the browser → answer → restore your context

UMBRACODE

Describe an idea.
See it running.

Give UmbraCode a product idea and it writes the files, then serves them straight into a sandboxed browser preview you can keep refining.

Build with UmbraCode

one prompt → working files → live browser preview

One private layer

One boundary across every model.

Most apps hand you a single model. Umbra keeps one browser-side boundary in front of many models, tools, and surfaces.

umbra
  • UmbraChat
  • UmbraCode
  • Umbra API
  • Smart Privacy
  • Umbra Auto
  • Nova 4
  • Sage Sonnet
  • Reasoning R1
  • Gemini Flash
  • Qwen Coder
  • Llama Open
  • Mistral Small

One boundary. Many ways to make.

Bring the same browser-first boundary to conversations, media, projects, and your own tools.

LIVE NOW

UmbraChat

A private workspace for everyday questions.

DEMO · STUB

UmbraImage

Local image stub until a FAL_KEY provider is configured.

DEMO · STUB

UmbraVideo

Local video frame stub until a FAL_KEY provider is configured.

DEMO · STUB

UmbraCode

A local project demo until an OpenRouter key is configured.

LIVE NOW

Umbra API

OpenAI-compatible model access for builders. Read the API guide →

LIVE NOW

Umbra Connectors

Bring your own MCP endpoints. Open Connectors →

Model shelf

8 models, including Umbra Auto, Nova 4, Sage Sonnet.

See all models and rates →