Kagi Assistant
Published September 28, 2026· By Juan Martinez
In This Article
Kagi Assistant is a chat interface bolted onto a paid search engine, and that lineage explains most of what it is. Rather than building or hosting its own model, Kagi Inc. buys API access to more than thirty models from nearly every major lab and resells them under one subscription, with answers optionally grounded in its own ad-free search index. The privacy claim here is contractual and procedural rather than cryptographic: no training on your prompts, no account identifier passed to the model provider, and conversation threads deleted after a day. That is a real design, but it is a different kind of promise from one enforced by encryption, and the difference is worth understanding before paying for it.
Privacy Architecture
The prompts you type go to third-party model providers. That is the structural fact everything else sits on top of: when you pick Claude, GPT, Gemini, Mistral, DeepSeek, Grok or any of the other thirty-odd models on the bench, your text leaves Kagi’s infrastructure and lands at that lab’s API. Kagi’s position is that it acts as an intermediary that strips your identity out of the transaction — its documentation notes for OpenAI-routed requests that “the Assistant does not include a unique user identifier for these requests,” and its per-provider table lists “No” under “Trains on User Data via API” for every provider on the list, backed by the terms of service Kagi signed with each one.
What that buys you is unlinkability rather than invisibility. The model provider sees the prompt; what it does not see is who wrote it or which account it belongs to. Kagi’s documentation does not go further than this — there is no published explanation of how IP addresses are handled at the network layer, no described proxy or header-stripping mechanism, no technical write-up of the anonymization beyond the statement that the identifier is absent. For a product whose entire pitch is “use these models without being tracked,” the mechanism is asserted more than it is documented.
Retention is where the design has actual teeth. Assistant threads are deleted automatically after one day by default, and you can delete one immediately by hand. A thread you report for a bug is kept 30 days for debugging and then removed. Requests to the model backend are not saved or tied to a customer account, though Kagi allows for short-term retention as part of request debugging. On Kagi’s own infrastructure, load balancer and VM logs live 7 days and sampled Sentry error logs 90 days — samples, not full request bodies.
The retention you do not control is on the provider side, and it varies a lot. Google’s Gemini models hold data 24 hours. Some providers, including Cerebras and DeepSeek, store nothing. Anthropic, OpenAI, Mistral and xAI default to 30 days. One case sits outside all of this: prompts that Anthropic’s own safety systems flag are retained for two years under Anthropic’s general API policy. Kagi cannot override that, and to its credit it publishes the fact rather than burying it — but if you send something to a Claude model through Assistant and it trips an abuse classifier, a two-year copy exists somewhere Kagi has no key to and no say over.
There is no zero-access or end-to-end encryption claim for Assistant threads anywhere in Kagi’s documentation, and the absence is honest rather than an oversight. The privacy model here is minimize-then-delete plus contract, not storage the operator is cryptographically unable to read. During the day your thread exists, Kagi could in principle read it; the protection is policy and a short clock, not math. In practice a one-day window is a narrow exposure, and for most people the practical outcome may be similar to an encrypted-at-rest design. But the two are not the same guarantee, and someone whose threat model includes the operator itself — or a legal order served on it inside that window — should know which one they are getting.
Using Assistant at all requires a paid Kagi account, created before any interaction, via email or SSO through Apple, Google, Microsoft or GitHub. There is no anonymous path and no way to try the product without an identity attached to a payment method. Everything unlinkable about the model requests sits downstream of an account Kagi knows exactly who owns.
Trust & Transparency
Kagi Inc. is a Delaware Public Benefit Corporation headquartered in San Francisco, which places it squarely under US jurisdiction and everything that implies for legal process. Founded in 2018 by Vladimir Prelovac, the company ran on roughly $3M of founder capital until 2023, then took about $2.5M from around 93 angel investors across 2023-2024, and converted to PBC status in early 2024. That funding shape matters: it is not venture-scale money demanding venture-scale growth, and the business runs on subscriptions rather than advertising. Kagi has also deliberately declined to build a referral or affiliate program — its founder said so publicly on the company’s own feedback forum in 2023, and the position still stood as of community discussion in 2026 — which means nobody at Kagi has a financial reason to steer you toward one model over another.
The company’s data minimization on its own side is straightforward and, unusually, verifiable by just opening devtools: Kagi holds email and payment information, states that it does not sell data, and loads no analytics or telemetry anywhere on its site or in its products. For a commercial web product this is genuinely rare and it is the kind of claim that would be immediately embarrassing if false.
Open source is where the public story and the shipped reality diverge. The Assistant web client, the core backend and the browser extensions are not published. Kagi’s GitHub organization contains supporting tooling around the edges — an LLM connection library, a vector database tool, an MCP server for Kagi Search, the Privacy Pass extension code, a Small Web initiative repo, a news app, plus assorted forks — but none of it is the product you are paying for. This is a closed-source commercial service with open auxiliary tools, and the no-training and no-identifier claims at the heart of its privacy pitch are claims you take on trust, because there is no code to read and no audit to check them against.
No independent third-party security audit of Kagi Assistant, or of Kagi generally, exists that this review could find. What does exist is a public bug bounty program, scoped explicitly to include Assistant, paying $50 to $1,000 by severity with reports to security@kagi.com — and, more usefully, a public record of things it has caught. Two HIGH-severity access-control failures on Assistant threads have been disclosed and paid at $150 each, one on shared threads and one on thread access generally, alongside a MODERATE authentication issue on threads paid $100-200. That record cuts both ways. It shows the program works and that Kagi publishes its failures rather than hiding them. It also shows that thread access control has broken more than once in a product whose privacy model depends entirely on Kagi’s own code being correct, since nothing cryptographic is standing behind it. A bounty is a real trust signal, but it is a bug-finding mechanism, not a design review, and it is not a substitute for an audit.
No confirmed breach or security incident affecting Kagi has been found.
Features
The model bench is the reason to be here. More than thirty models are available and switchable mid-conversation: Anthropic’s Claude line including Fable 5.1, Opus 5.5, 4.5 Sonnet and 4.5 Haiku; OpenAI’s GPT 5 chat, GPT 6 Astra, Sol and Luna, GPT 5.6 Terra and GPT OSS 120B; Google’s Gemini 2.5 Pro, 3.1 Pro Preview, 3.8 Flash and the Flash Lite and Gemma variants; Mistral’s Small, Medium 3.5, Large 3, Magistral and Pixtral; DeepSeek V4 Pro and V4.1 Flash; Alibaba’s Qwen 3.8 Max and 27B; xAI’s Grok 4.7; Meta’s Muse Spark 1.3; Moonshot’s Kimi K3 and K2.7; MiniMax M3; Z.ai’s GLM models; and Nous Hermes-4. Subscribing to each of those labs separately would cost several times what Kagi charges, and switching between them normally means switching products. Here it is a dropdown.
Web access is the other differentiator, and it is not the usual arrangement. Most chat tools that search the web are querying somebody else’s index behind the scenes. Kagi queries its own — the ad-free index it built for its search product — and you can toggle that grounding on or off per query, apply Kagi’s search lenses to narrow what the model sees, and carry your personalization settings across from search. A “Librarian” tool handles source analysis on the results.
Capability splits by tier rather than by feature flag. Quick mode, available from the entry tier up, returns responses in under five seconds and can use tools, but optimizes for speed over depth. Research mode, exclusive to the top tier, takes 30 seconds or more and runs a distinct planning phase before answering, working through up to five research steps and roughly fifteen tool calls. Research mode also unlocks a Python interpreter for actually executing code, image generation and editing, and Wolfram|Alpha integration, plus the flagship models. The practical consequence is that the entry tier gives you the wide model bench but the shallow reasoning loop.
File handling is competent and unglamorous: up to 30MB per upload covering plain text, PDFs, CSV, XLSX and JSON spreadsheets, JPG, PNG, GIF and WEBP images, and MP3, WAV, FLAC and OGG audio. Pasting a URL pulls in up to 50MB of fetched content.
Usability
Assistant is a web product and only a web product. It runs at assistant.kagi.com, it is embedded in the main Kagi search interface, and it is reachable through Kagi’s bang shortcuts — typing !ai, !chat or !code in the search bar drops you into a conversation. There are no verified native desktop or mobile apps for Assistant. On a phone that means a browser tab, with no share-sheet integration, no offline access to past threads and no system-level assistant hooks.
The bang shortcuts are the genuinely pleasant part of the experience, and they only work because Assistant lives inside a search engine. Starting a search, realizing a model would answer better, and getting there by typing three characters removes a context switch that every standalone chat product forces on you.
The one-day auto-delete is a privacy feature that is also a usability cost, and the review should be blunt that it is both. Threads you would have wanted to come back to are gone by tomorrow unless you copy them out yourself. There is no documented archive, no pinning, no project workspace that survives the clock. If your working pattern involves returning to a long conversation across a week, this product actively fights you.
The tier structure adds its own friction. Someone on the entry plan sees a model picker full of names, some of which they cannot select, and gets responses from a mode explicitly tuned to answer fast rather than think. The gap between what the interface displays and what your subscription reaches is the kind of thing that reads as a paywall rather than a plan.
The free trial is 100 searches and 100 Assistant interactions, and it still requires creating an account first.
Price & Value
There is no free tier. Past the 100-interaction trial, using Assistant means paying, and the entry point is Starter at $5.00 per month, or $4.50 monthly on an annual plan at $54 per year. Starter includes 300 searches per month and Assistant in Quick mode. Professional runs $10.00 per month, or $9.00 annually at $108 per year, and lifts search to unlimited with a larger monthly Assistant allowance. Ultimate is $25.00 per month, or $22.50 annually at $270 per year, and is the only tier with Research mode, the Python interpreter, image generation, Wolfram|Alpha and the flagship models. Annual billing takes 10% off across the board.
Crucially, Assistant is not locked behind the top tier. Five dollars gets you the thirty-model bench with search grounding, which is the core of what makes this product interesting. Set against paying three separate labs twenty dollars a month each for their consumer chat apps, the arithmetic is not close, and you get an ad-free search engine in the same subscription.
Kagi also runs a fair-pricing policy: a month you do not use is credited back automatically against the next cycle. That is the opposite of how most subscription businesses make their margin, and it fits a company funded by subscriptions with no advertising and no affiliate revenue to chase.
The honest counterweight is what the money does not buy. At $25 a month, Ultimate is priced against the top consumer chat subscriptions while giving you no native apps, no persistent conversation history past 24 hours, no published source code and no independent audit. What you are paying for is breadth of model access, an independent search index underneath the answers, and a company whose incentives point away from surveillance. If those are the three things you want, the price is fair. If you wanted a chat assistant that keeps your work, runs on your phone, and can prove its claims in code, this is not that, at any tier.
Pros and Cons
- Over thirty models from Anthropic, OpenAI, Google, Mistral, DeepSeek, xAI, Alibaba, Meta, Moonshot and others are available under a single subscription, switchable mid-conversation.
- Web grounding uses Kagi's own independently operated, ad-free search index rather than proxying queries to a third-party search engine.
- Conversation threads are automatically deleted after one day by default, with manual immediate deletion also available.
- Kagi's contracts with every listed model provider forbid training on user data, and the per-provider documentation table shows "No" for training across the board.
- Requests to model providers omit a unique user identifier, so prompts are not linkable to a Kagi account on the provider's side.
- No analytics or telemetry are loaded anywhere on the site or in the product, a claim anyone can verify from a browser's network tab.
- Assistant starts at the $5/month entry tier rather than being reserved for the top plan, and the full model bench is available there.
- Per-provider retention windows, including Anthropic's two-year retention of safety-flagged prompts, are published rather than glossed over.
- A public bug bounty explicitly covering Assistant has a track record of paid disclosures, including two HIGH-severity access-control fixes.
- The fair-pricing policy automatically credits an unused month against the next billing cycle, and the company runs on subscriptions with no advertising and no affiliate program.
- Prompts are sent to third-party model providers rather than run on infrastructure Kagi controls, so the privacy guarantee is contractual rather than architectural.
- There is no zero-access or end-to-end encryption for stored threads — during the day a thread exists, the operator can read it.
- The anonymization mechanism is asserted but not documented: there is no published explanation of IP handling, header stripping or any network-level proxy.
- The Assistant client, core backend and browser extensions are closed source, so the no-training and no-identifier claims cannot be independently verified.
- No independent third-party security audit of Assistant or of Kagi generally exists.
- Thread access control has broken at least twice in disclosed HIGH-severity bounty reports, in a product whose privacy rests entirely on that code being correct.
- Prompts flagged by Anthropic's own safety systems are retained for two years under Anthropic's API policy, which Kagi cannot override.
- There is no free tier and no anonymous usage path — even the 100-interaction trial requires creating an account.
- The product is web-only, with no verified native desktop or mobile applications.
- The one-day auto-delete means no archive, no pinning and no persistent project history; anything worth keeping must be copied out manually.
- Research mode, the Python interpreter, image generation, Wolfram|Alpha and the flagship models are all locked to the $25/month Ultimate tier.
- Kagi Inc. is a Delaware corporation headquartered in San Francisco, placing it fully within US legal jurisdiction.
Our Rating
Kagi Assistant is the right product for someone who already wants a paid, ad-free search engine and would rather rent thirty models through one honest vendor than subscribe to three labs directly. Its privacy design is coherent on its own terms — strip the identifier, contract away training, delete the thread tomorrow — and the company’s incentives, with no ads, no data sales and no affiliate revenue, point in the right direction. The honest limit is that every one of those protections is a promise you cannot check. The code is closed, no auditor has looked, and the one-day retention window is enforced by Kagi’s own software, which the bug bounty record shows has leaked thread access before. If your threat model stops at “don’t let the model labs build a profile of me,” this does that well and cheaply. If it includes the operator, or if you need your conversations to survive the week, look elsewhere.
- Privacy Architecture6.7/10
Contractual no-training terms with every model provider and no unique account identifier attached to provider-bound requests, but no zero-access or encryption claim for stored threads, no documented IP-anonymization mechanism, and no anonymous usage path — an account is required before any interaction
- Trust & Transparency7.0/10
A subscription-only Public Benefit Corporation with no telemetry, no affiliate program, and a public bug bounty with a real track record of paid disclosures — held back by closed-source implementation, no independent audit, and a jurisdiction offering no special legal protection beyond standard US process
- Features9.0/10
More than thirty switchable models from nearly every major lab under one subscription, web search grounded in Kagi's own independent index rather than a proxied third-party search engine, and broad file upload support — the widest model bench in this vertical
- Usability6.0/10
Bang-shortcut access from the search bar is genuinely fast, but the product is web-only with no native apps, the best reasoning mode and tools are locked to the top tier, and the one-day auto-delete leaves no archive for anything you didn't copy out yourself
- Price & Value7.5/10
No standing free tier, but the $5/month entry price unlocks the full model bench rather than a crippled subset, undercutting the cost of subscribing to multiple labs separately, with a 10% annual discount and an unused-month credit policy
Privacy Architecture 30% · Trust & Transparency 20% · Features 20% · Usability 20% · Price & Value 10%