the weights you can verify if the env is fully reproducible
the local attack vectors are a problem, ideally you have a secure data center + tamper proof hardware.
its not a panacea but theres a huge difference between "i'm using random llm api provider (or a proxy to have even more hops that you dont control)" and "i'm using a fully reproducible remotely attested confidential inference api" , even if the latter is not perfect for all threat models
yes it does fall into private ai category.
based on the claims (i havent read the source) it provides anonymization of traffic to the providers, but that addresses a very specific issue - attribution of the conversation to specific identity.
it does not protect the privacy of the conversation itself, at least not from the provider. So if you upload sensitive documents or prompt it with releaving data your identity might not be tied to the account, but the data can still get out.
thats where the confidential inference and confidential computing part comes in, you can get much better assurances there provided that its implemented right and you can attest to a reproducible stack that is not leaking your data somewhere.