PrivacyPick
Maple logo

Maple

Open Source
7.6
out of 10
Visit Maple →
IP AnonymizationUndisclosed
Storage ModelZero-access encrypted
RetentionSession-only by default
Provider TrainingContractual no-train
JurisdictionUnited States
Free TierLimited free tier
Telemetryopt-out
Established2025
WebWindowsmacOSLinuxAndroidiOS
GLMKimiDeepSeekGPT-OSSGemmaLlama
Pro (individual, monthly)
$20.00/mo
Max (individual, monthly)
$100.00/mo
Team (per user, monthly)
$30.00/mo

Published September 30, 2026By Juan Martinez

In This Article

Maple is an AI chat and research workspace from Maple Privacy Labs Inc., a two-person-founded company in Austin, Texas that launched the product in January 2025. Its distinguishing claim is architectural rather than contractual: messages are encrypted on the user’s device, and the only place they are ever decrypted is inside a hardware-isolated enclave whose running code can be cryptographically matched against public source. The models are open-weight releases deployed by Maple itself, so no request is forwarded to an outside model vendor. What the product does not have is an independent security audit, a track record longer than roughly eighteen months, or an annual billing discount.

Privacy Architecture

The design starts one step earlier than most privacy-positioned AI products. Messages are encrypted locally before they leave the device, so what arrives at Maple’s servers is ciphertext rather than a prompt. Decryption happens inside AWS Nitro Enclaves — a trusted execution environment that, in Maple’s own description of the properties it relies on, provides CPU and memory isolation, ephemeral storage, and no external network connectivity, with outbound traffic forced over a vsock channel to a proxy on the parent instance. The parent instance, and therefore Maple’s own operators, cannot reach into the enclave to read what is being processed.

Two mechanisms turn that from a statement into something checkable. Enclave images are measured at boot, producing a PCR0 hash that uniquely identifies the exact code running inside. A remote attestation document, signed by AWS Nitro hardware, then proves the enclave’s identity and integrity to a party outside it. Because both the client and the enclave-side server code are public, the chain closes: anyone can build the source from GitHub and compare the resulting hash against the live attestation, which is the only way an attestation claim is worth anything — an attestation that proves unreadable code is running proves very little.

One caveat belongs here rather than in a footnote. At the time of checking, the interactive attestation demonstration on Maple’s proof page was labelled DRAFT beside its attestation.cbor file. The underlying technology is not in draft — AWS Nitro Enclaves are widely deployed and the attestation flow is documented by AWS itself, which Maple links to directly — but the specific on-page widget that lets a visitor verify a running fingerprint for themselves was not finished. For a product that stakes its position on independent verifiability, the demonstration is part of the claim, and it was not complete.

Maple is explicit about what a user still has to trust, which is a short and specific list: that AWS Nitro hardware performs as documented and independently audited, that the open-source enclave code does what it says, and that the attestation proof confirms the running code matches the published source. The company frames its own approach against two others. Standard AI services process prompts in plaintext on the provider’s servers. Privacy proxies place an intermediary in front of a model vendor, but the vendor still sees plaintext, and as Maple puts it, zero-data-retention there is a policy promise rather than a guarantee. The architectural comparison it draws for its own model is Apple’s Private Cloud Compute, which uses custom silicon with a Secure Enclave where Maple uses AWS Nitro Enclaves with attestation-verified code — different hardware, the same shape of guarantee, with data processing isolated in hardware and the software environment verified cryptographically.

The models matter to this architecture more than the marketing line suggests. The banner text promises models by OpenAI, Google, Kimi and Z.ai, which is true only of those companies’ open-weight releases — GPT-OSS 120B rather than a GPT flagship, Gemma 4 31B rather than Gemini. In practice the roster is GLM-5.3 and GLM-5.2, Kimi K3 and K2.6, DeepSeek V4.1 Flash, GPT-OSS 120B, Gemma 4 31B and Llama 3.3 70B. That is a limitation on raw capability and a considerable gain on privacy, because it means Maple runs the weights itself inside the enclave instead of relaying prompts to someone else’s API. The company states the consequence plainly: user data never touches OpenAI, Anthropic, DeepSeek or Google as companies. There is no external provider to extract a no-training commitment from, because there is no external provider in the request path.

Data outside the enclave is stored as encrypted blobs, one per user, with decryption keys living only inside the TEE and on user devices. Cross-device access works through a key derived from the account credentials: history is encrypted with that key before upload, and when a user signs in elsewhere the key is re-derived locally and used to decrypt on the new device. The Maple Proxy product extends the same enclave path to third-party tools such as OpenCode, Hermes and OpenClaw, so using an outside client does not mean leaving the isolated processing environment.

One field is left unstated because Maple does not state it: there is no separate claim about how the user’s IP address is handled at the network layer, distinct from the encryption of message content. Encryption before transmission is not the same guarantee as an operator that cannot see where a request came from, and Maple makes only the first claim.

Trust & Transparency

The source code is public in full under the MIT license, in a single repository holding both the client and the enclave-side backend. That second half is the part that carries weight — a published client with a closed server would leave the reproducible-build claim unverifiable, since the thing being attested runs on the server side. Development is visibly active rather than a one-time code drop: more than 3,800 commits, 83 releases with the latest at v3.4.1, and twenty contributors at the time of writing.

Retention is specified rather than gestured at. By default, conversational data processed without memory features enabled is not retained once the session ends. Enabling memory changes that deliberately: conversations and learned preferences are kept in a per-user encrypted vault for as long as the feature stays on, and users can view, export, selectively delete or wipe that memory, or switch the feature off. Deleting the account deletes the encrypted conversational data, subject to legal retention obligations. Account metadata — name, email, billing details — is held while the account is active and for a reasonable period afterwards for compliance. Data pulled in from connected services such as Gmail, Google Drive, Apple Health or Notion, when a user authorises the connection, is processed inside the same encrypted environment and not passed to third parties except where the law requires it.

There is one collection disclosure that does not sit under any of that encryption. The Privacy Notice states that Maple automatically collects IP addresses, browser and device characteristics, operating system details and referring URLs, described as needed for the security and operation of the service and for internal analytics and reporting. The notice describes no control for it and does not characterise it further. This is ordinary web analytics collection, and it is separate from message content, but a user who assumes the encryption story covers everything the company holds would be assuming too much.

The company is young and the record is correspondingly short. Maple Privacy Labs was founded by Mark Suman, the CEO, a former Apple engineer focused on AI and privacy who was previously Director of Mobile at Instructure Canvas, and Anthony Ronning, the CTO, an infrastructure engineer with a background in defense, security, networking and bitcoin who built the TEE architecture the product runs on. Both are named publicly with traceable histories, which is more than parts of this category offer. The company reports 5x user growth over six months and better than 90% month-over-month retention among paying customers; those are its own figures, not audited ones. It lists participation in Google Cloud for Startups and an “Inception Program,” named that way on its own site without identifying the sponsoring company.

No security breach or incident affecting Maple has surfaced. There is also no independent third-party security audit, which is true of every product in this category rather than a Maple-specific gap — but it means the reproducible-build-plus-attestation chain is doing all the verification work, and that chain only helps users who actually run the comparison.

Jurisdiction is the United States, with the operating entity based in Austin, Texas. That carries none of the specific legal protections some privacy products build their positioning on, and the US participates in the intelligence-sharing arrangement usually called the Fourteen Eyes. The mitigation here is structural rather than legal: a company that holds only per-user encrypted blobs, with the decryption keys inside a TEE and on user devices, has less to produce under compulsion than one holding readable logs.

Features

The core product, Maple Research, is the chat and research workspace, and it is the only part generally available. Maple Agent, which adds long-term memory, is in private beta behind a waitlist. Maple Teams covers organisations, and Maple Proxy exposes an OpenAI-compatible endpoint that routes third-party tools through the same encrypted enclaves.

Free accounts get end-to-end encryption, basic AI features and web search. Web search on a free tier is not a given in this category, and its presence here matters more than usual because the open-weight models on offer are smaller than proprietary flagships and benefit from outside context. What free accounts do not get is image or document upload, or API access.

Pro unlocks the full model roster and lets users switch between GLM, Kimi, DeepSeek and GPT-OSS within the product, along with image and document upload, voice recording and API access. Upload carries a real restriction: it works in the native applications only, not in the web interface. Anyone whose habit is to work in a browser tab will find the feature they paid for missing from the surface they use. Max adds 20x the usage allowance, priority support and early access to new features and models, without adding capability of its own. Team gives each seat the Pro feature set with double the per-user usage, a shared credit pool and unified billing.

Usability

Coverage is broad for a product this young: native applications for Windows, macOS 11.0 and later, Linux, Android and iOS, plus a browser version that needs no install. The Linux build carries a specific and worth-knowing constraint — Ubuntu 24.04 or newer only, not Linux generally, which rules out a good deal of the distribution landscape and most machines on an older LTS.

The onboarding is quick by the company’s own account, with download, signup and a first encrypted chat inside a minute. An account is required; there is no anonymous entry point, which follows from the key-derivation design rather than being an arbitrary gate — the account credentials are what the encryption key is derived from.

That design pays off in the place where encrypted chat products usually hurt. History is not stranded on one device: because the key is re-derived from credentials at each sign-in, conversations decrypt locally on any device the user logs into, while the server only ever holds ciphertext. Sync without server-side readability is the harder version of this problem and Maple solved it rather than sidestepping it by keeping history local.

The friction sits elsewhere. The free tier is thin enough that evaluating the product properly means paying, since two of the things most likely to be tested — document upload and API access — are behind the paywall. Web upload being unavailable at any tier is the more awkward limitation, because it applies to paying users too.

Price & Value

Pro is $20 a month, Max is $100 a month, and Team is $30 per user per month. There is no annual discount, no introductory rate and no promotional pricing at any tier — a single monthly rate, which at least makes the steady-state cost obvious with no renewal surprise, the failure mode that catches people out across much of this market.

At $20, Pro matches the going rate for mainstream AI assistants that offer nothing comparable in isolation guarantees, so the privacy architecture is effectively included rather than charged for. Against that, the models are open-weight rather than frontier, so the comparison is not like for like on capability either. Whether that trade is worth $20 depends entirely on whether the enclave guarantee is something a given user actually needs.

Max at $100 is harder to justify on the published description. It buys 20x usage, priority support and early access, but no capability Pro lacks — it is a volume plan, and only a heavy user hitting the Pro ceiling regularly will get value from a fivefold price increase. Team at $30 per seat is priced sensibly for what it adds over Pro: double the per-user usage, pooled credits and one invoice.

The free tier is best read as a demonstration rather than a usable plan. Encryption, basic chat and web search are enough to see how the product behaves, but without upload or API access it cannot carry real work.

Pros and Cons

  • Messages are encrypted on the device before transmission and decrypted only inside a hardware-isolated AWS Nitro Enclave, so Maple's own operators cannot read them
  • Enclave images are measured at boot into a PCR0 hash, and a remote attestation document signed by AWS Nitro hardware proves which code is running
  • Both the client and the enclave-side server code are public under the MIT license, so the attestation can be checked against a build from source
  • Open-weight models are deployed on Maple's own infrastructure inside the enclave, so prompts are never forwarded to an outside model vendor
  • Session-only retention by default, with persistence only when the user turns on memory, and full view, export and delete controls over that memory
  • Data outside the enclave is stored as per-user encrypted blobs with decryption keys held inside the TEE and on user devices
  • Encrypted history syncs across devices by re-deriving the account key locally, rather than forcing history to stay on one machine
  • Active public development with more than 3,800 commits, 83 releases and twenty contributors
  • Web search is available on the free tier, which matters given that the models on offer are open-weight rather than frontier
  • Native clients for Windows, macOS, Linux, Android and iOS plus a browser version
  • Both founders are publicly named with verifiable backgrounds, including a CTO who built the enclave architecture
  • Flat monthly pricing with no introductory rate that later jumps
  • The interactive attestation demonstration on the proof page was labelled DRAFT at the time of checking, so the verification a visitor can perform themselves was unfinished
  • No independent third-party security audit has been published
  • No separate claim about how the user's IP address is handled at the network layer, distinct from message encryption
  • The Privacy Notice discloses automatic collection of IP address, device and browser details and referring URLs, with no described control over it
  • The marketing line about running models by OpenAI and Google refers to their open-weight releases, not their flagship proprietary models
  • Image and document upload work only in the native applications, never in the web interface, including for paying users
  • The Linux build supports Ubuntu 24.04 and newer only, not Linux in general
  • The free tier has no file upload and no API access, so evaluating the product seriously requires paying
  • No annual discount at any tier
  • Max at $100 a month adds usage headroom and support priority but no capability beyond Pro
  • An account is required; there is no anonymous way to use the product
  • The company launched in January 2025, giving it a short operating record
  • Based in the United States, a jurisdiction with no particular legal protections for this kind of service
  • Maple Agent, the long-term-memory product, is still waitlisted in private beta

Our Rating

Maple suits someone who wants the confidentiality guarantee to rest on hardware and public source rather than on a policy page, and who is willing to accept open-weight models in exchange. The combination of client-side encryption, enclave-only decryption, published server code and reproducible builds is a genuinely stronger structure than a retention promise, and the cross-device sync design shows the architecture was worked through rather than bolted on. It suits someone less well if they need frontier-model capability, if they work primarily in a browser and expect to upload files there, if they run Linux on anything other than a recent Ubuntu, or if they want an independent audit before trusting a young company. The draft state of the on-page attestation demo is the sharpest gap, because it sits precisely where the product asks to be judged.

  • Privacy Architecture9.0/10

    Client-side encryption before anything leaves the device, decryption only inside hardware-isolated AWS Nitro Enclaves with boot-time code measurement and remote attestation, reproducible builds against public source, and open-weight models run on Maple's own infrastructure so no outside model vendor receives the traffic — held back from the top by the absence of any separate IP-handling claim and by the attestation demonstration still being labelled draft at the time of checking

  • Trust & Transparency7.5/10

    Both client and enclave-side server code are public under the MIT license with active development, retention behaviour is stated precisely and tied to a user-controlled feature, and the two founders are named with verifiable backgrounds — set against a company founded in 2025 with no independent third-party security audit and a US base that carries no special legal protection

  • Features7.0/10

    Six open-weight model families with free switching between them, web search available even on the free tier, plus file upload, voice recording and an OpenAI-compatible proxy API on paid plans — but uploads work only in the native apps and not on the web, and the agent product with long-term memory is still waitlisted

  • Usability7.0/10

    Five native clients plus the web app, encrypted history that re-derives its key and syncs across devices rather than trapping conversations on one machine, and a fast first-run flow — against a free tier with no uploads or API and a Linux build restricted to Ubuntu 24.04 and newer

  • Price & Value6.0/10

    Pro at $20/month is in line with mainstream assistants that offer no comparable isolation guarantee, but there is no annual discount at any tier, the $100 Max plan buys usage headroom rather than capability, and the free tier withholds both file upload and API access

Overall7.6/10

Privacy Architecture 30% · Trust & Transparency 20% · Features 20% · Usability 20% · Price & Value 10%

See our rating methodology →

Ready to try Maple?

Visit Maple →

Last updated: September 30, 2026By Juan Martinez