The model is hosted inside of a special hardware instance with code that verifiably doesn't log. Thus, one can know that it isn't being spied upon, even by the AI provider.
Most is explained in our blog post:


Introducing Private AI Models - End-to-End Encrypted Inference on PayPerQ
PayPerQ now offers AI models running inside Trusted Execution Environments with end-to-end encryption. Your prompts are encrypted in your browser ...