Confidential work does not belong in a model you cannot check
On 29 July 2026, OpenAI offered researchers free access to its frontier models and to Codex, and wrote that participant data “is not used to train our models by default” [1]. Six weeks later it announced an internal resolution of the Navier–Stokes problem, and added that it could not rule out that de-identified usage data helped improve the model [2]. The weights are closed, so that promise cannot be checked.
What you are being asked to trust
A proof draft, a patent memo, a client’s facts, and a clinical note seem unrelated. They share one thing: they are valuable only while they stay confidential. A cloud vendor can say lookups are forbidden and training is off by default. That sentence cannot be exercised, and it cannot be audited.
The Navier–Stokes case is one illustration, not the product. Two mathematicians had been drafting in Codex [3]. OpenAI said no specific user data was accessed, and in the same post wrote that it could not rule out that usage data helped improve the model [2]. The weights, the training cut, and the agent prompts are not open. The only check is the vendor’s sentence.
The announcement set off a public row. Tristan Buckmaster published a statement questioning the timing, the unusual path the company then described, and whether Codex sessions had entered training [3]. Levent Alpöge quoted the “cannot rule out” sentence back at the company [5]. Terence Tao called the pair’s own Lean-checked work a remarkable achievement, and noted that external events forced them to publish their own work far earlier than planned [6].
Look across the AI mathematics results published so far, and the same limit shows up. These systems have not yet independently found a new method, a new idea, a new mathematical concept, or a new construction that solves a problem. They push programs mathematicians already opened. Navier–Stokes, in the public record, sits on the Córdoba–Martínez-Zoroa program [3][6]. The short-gap announcement a few days earlier is the same story in another field: Zhang, Maynard, and Polymath had already proved infinitely many prime gaps of size at most 246; the model narrowed the gap to 186 inside that sieve [4]. Searching a known method harder is not the same as inventing the method. It is also not a path you can audit when the model is closed.
What TeeChat offers
TeeChat is built so confidential work does not depend on that sentence.

The archive stays in a folder you choose. Ordinary chats are Markdown on your machine. Cancel the subscription and the history is still yours. It is not a transcript in a vendor account, waiting to improve a model you will never see.
If the work cannot leave the device, use a local open model. The prompt does not go to a lab that later announces it solved your problem. There is no usage corpus to de-identify.
If you need a stronger model, verify before you send. Confidential mode locks the message with the Open Privacy Envelope before it leaves the device. The routing server forwards. It should not unscramble the chat. The engine decrypts only inside a hardware-protected environment, then locks the reply on the way back.
You do not take that on faith. In Settings → Verify attestation you compare the live gateway and engine with published fingerprints — measurement, platform manifest, hashes — and only then release the prompt. The protocol and the Rust inference engine are open. Experts can read the blueprints. You check that the running system matches them.

The step-by-step check is in How to verify confidential chat on TeeChat.
What this is not
TeeChat does not claim to have solved the Navier–Stokes problem, and it does not ask you to treat a privacy policy as something that can be exercised. Open models on the local path, and a verifiable hosted path when you choose to leave the device, are the offer. Closed weights plus “we cannot rule out” are the alternative [1][2].
Start at chat.teechat.ai. Confidential chat does not work in the WeChat in-app browser. Open the link in a system browser such as Safari or Edge, or a mainstream browser such as Chrome, Firefox, or Brave.
References
[1] OpenAI, “Accelerating scientific discovery with ChatGPT for Academic Researchers,” 29 July 2026. https://openai.com/index/chatgpt-for-academic-researchers/
[2] OpenAI, “On the Navier–Stokes Millennium Prize Problem,” 8 September 2026. https://openai.com/index/navier-stokes-solution/
[3] Tristan Buckmaster, statement, 8 September 2026. https://cims.nyu.edu/~tristanb/statement.pdf
[4] OpenAI, “Improved short gaps between primes,” 30 August 2026. https://cdn.openai.com/pdf/51126fac-1b68-4128-9666-c908bcc16033/short_gaps.pdf
[5] Levent Alpöge, post on X, 8 September 2026. https://x.com/__alpoge__/status/2097206973418611054
[6] Terence Tao, Mathstodon, 8 September 2026. https://mathstodon.xyz/@tao/117233527638291447