Private by design.
Useful by default.
Nupick is built so your most sensitive context can stay local. When a cloud model genuinely helps, only the right, sanitized slice is routed out — and you stay in control.
Deterministic, not a model's best guess.
The boundary doesn't ask an AI to “please remove the sensitive parts.” Redaction is rule-based and deterministic: names, emails, and figures are stripped, identifiers are tokenized, and anything that could single out a person is suppressed — before a single byte crosses to the cloud.
- Tokenized identifiers. Quasi- and direct-identifiers become opaque tokens (
CAT_007) the cloud never resolves; your machine rehydrates the real labels locally. - Secrets stay blocked. API keys, passwords, and credentials are kept out of anything sent to a model.
- Two transcripts. The cloud sees the tokenized, suppressed projection; your device keeps the full-fidelity copy.
- Auditable. Every crossing is logged with a hash and manifest — raw payload bodies are never stored.
Question a database with a cloud model — without the rows ever leaving.
Connect a SQL database and ask analytical questions in plain language. Instead of letting a cloud model write SQL against your raw data, Nupick compiles a validated, privacy-safe plan locally and sends only the aggregate result outward. Here's every step it passes through:
You should never have to choose between capable AI and your own privacy.
Most tools force the trade. Nupick is designed so local-first privacy and cloud-grade reasoning live in the same workspace — with you holding the controls.
Start building your
private AI workspace.
Local-first, privacy-first, and built for people who want powerful AI without handing over everything.