Shadow Link AI is a private, uncensored AI service with something the privacy-first chat apps don’t have: hands. It doesn’t just talk about the job — it runs the commands, reads the output, fixes its own mistakes, reaches the machines you point it at, and comes back with the result — words, code, or the picture the job called for.
Sign in and start. No filter deciding which questions you’re allowed to ask, no company mining your conversations, and a vault that encrypts your history with a passphrase we do not hold and cannot recover. And when a job needs more horsepower than one model has, one toggle lets Shadow quietly consult a frontier model and fold the answer in — or summon a whole council of them.
You’re asked to accept a content filter that decides which questions are permitted, a company that can read everything you type, and an assistant that can only ever produce text. Shadow Link AI removes the filter, removes the ability to read your data, and replaces the text box with something that can act.
Built on Shadow v4.5, our open, uncensored model. No refusals, no lectures, no topics quietly walled off. It works for you, not for a policy team.
Real tools: run commands, read and write files, execute code, connect out to the machines you point it at. Give it a task, get an outcome — not a suggestion.
Your history is encrypted with a passphrase only you know. What sits on the server is ciphertext — unreadable to us, to staff, and to anyone who seizes it.
This is not a roadmap. Each item below is running in production and in daily use.
It plans, runs real commands, reads what came back, corrects itself, and reports what actually happened — the difference between an assistant that drafts instructions and one that finishes the task.
It can fetch, call APIs, clone a repository and talk to the servers you give it. Every task gets its own clean workspace, and the network path it uses is governed and rate-limited rather than wide open.
Feed it whole codebases, long documents or a sprawling multi-day thread and it keeps the plot. When a thread grows toward the window, older context is compacted automatically — long work stays coherent instead of falling apart halfway through.
Drop in documents, code, logs, spreadsheets, PDFs or images. They land in the task’s own workspace where the AI can open them, run them and take them apart — not just skim a preview of them. It can look at pictures too: screenshots, scans and photos are read, described, and their text transcribed.
Ask for a picture in any house-model conversation and it generates into the chat’s Files drawer — anime or photoreal, no mode to switch. Titles are set in real fonts and rendered into the scene with the spelling checked, and flat text edits are free forever. A section of its own →
Queue your next message while the current one is still running and it starts the moment a lane frees. Press stop and it stops — immediately, cleanly, with the partial work still on screen.
Long jobs survive dropped connections, flaky networks and closed laptops. Come back later and the work is there — finished, not abandoned.
On genuinely hard problems, Shadow can open a discreet consult with a frontier model — Claude, GPT, GLM, DeepSeek — on your own API key. It writes the question itself, folds the answer in, and keeps working as one conversation. It gets a section of its own →
A distraction-free terminal aesthetic that works the same on a desktop and a phone. Conversations in a tree, notes alongside them, syntax highlighting, keyboard shortcuts, answers that stream live and reconnect on their own.
Seats, plans and per-person limits, plus 30 days of real usage per person and optional automatic limits that step in before one runaway task spoils the day for everybody else.
The market split in two. The big assistants are powerful but filtered and surveilled. The privacy-first chat apps fixed the surveillance and stayed a text box — no tools, no ability to act, and often a history stranded in one browser. Shadow Link AI is the overlap.
| Mainstream AI assistants | Privacy-first chat apps | Shadow Link AI | |
|---|---|---|---|
| Answers without a policy filter | ✕ Refuses by design | ✓ | ✓ |
| Real tools — can do the work, not just describe it | ~ Limited, sandboxed | ✕ Text only | ✓ Full agent tooling |
| Operator cannot read your conversations | ✕ Stored and reviewable | ~ Varies; often browser-only | ✓ Zero-knowledge vault |
| Attach files the AI can actually open and run | ~ Preview and summarise | ✕ | ✓ Into the workspace |
| History follows you across devices | ✓ | ~ Often trapped locally | ✓ Encrypted, synced |
| Consult a frontier model on demand | ✕ Walled garden | ✕ | ✓ Consult Mode — any provider, your key |
| Generate images without a content filter | ~ Filtered and logged | ✕ Rarely offered | ✓ Built in — titles rendered in, spelled right |
| Context window | ~ Varies by tier | ~ Typically modest | 256K tokens |
House-model conversations now generate images natively. There is no mode to switch, no separate app, no different client: the model recognizes when the job needs a visual and fills the request itself, right in the thread where you were already working. The result lands in the chat’s Files drawer beside your code and documents — newest first, downloadable one or all — and the conversation simply carries on. Uncensored, encrypted like everything else, and bounded by honest published numbers instead of mystery.
The same philosophy that governs the chat, now for pictures: no banned-prompt list, no classifier deciding which images you are allowed to make. Adults making art for adults is your business, not ours. The ordinary limits of the law still apply — drawn by the Terms of Service, not by a keyword.
Two purpose-picked engines: anime for illustration, and photo for everything else — realistic people, posters, product shots, painting — written in plain natural language, no tag dialect to learn. It edits too: point it at any picture in the chat and say what to change — make it night, swap the background, add a hat — and the composition stays. Eight sizes from square to wide banner to phone story, up to two images per request.
Photo-style images letter themselves: quote the words and they are painted into the scene — a shop sign, a poster headline, a neon tube. On anime it sets them in a real font — 53 typefaces across poster, brand, script, serif, tech, horror, retro, gothic and western — then renders the letters into the scene as a material: neon tubes, chalk on a wall, molten gold, carved wood. Either way a vision model reads the result back and checks the spelling; a miss gets one retry, then the crisp flat version on anime or a plain note of what it read on photo — never a silent typo. Prefer clean type? A flat title with a contrast band is still there, up to 64 characters, and changing the words that way costs nothing and takes no time — no GPU involved.
On a vaulted account, generated images are sealed under your own vault key whenever no reply is being written in that chat — file names included — and sit on our disks as ciphertext, unreadable while your vault is locked. They are opened in the chat’s walled-off workspace only while a reply is in progress, and sealed again the moment it finishes. Generation is logged by prompt hash — never by raw prompt — and nothing you generate is used for training.
working · 2 images · filed to the drawer
[image] 832×1216 + 1216×832 · anime · in the Files drawer
you: title it “NIGHT SHIFT” — pink neon tubes, Monoton
[image] title rendered into the scene · spelling verified
you: flat version too — Bebas, #39FF9E, on the lockup
[image] re-composited · instant · zero GPU spent
Every model, sooner or later, meets a problem at the edge of what it can reason through alone. Most services leave you stuck right there. Shadow Link doesn’t: flip one toggle per conversation and your Shadow quietly opens a consult with a super-frontier model — on your own API key — gets the help it needs for the task at hand, and carries on as one seamless answer.
Your Shadow composes the consult itself: a focused, professional question carrying only the context it chooses — never your raw conversation tipped over the wall. Work that would stall in a hail of template refusals anywhere else gets a clean, direct technical answer here.
Claude, GPT, GLM, DeepSeek — plug in the API keys you already have and Shadow consults them on demand, at your provider, on your rates. Keys are sealed inside your vault and never touch the sandbox your AI runs in.
It doesn’t stop at a second opinion. Run the whole agent as one frontier model — full tools, full workspace — and let it consult a third. Or summon a council: every provider you’ve keyed answers the same question blind, in parallel, and Shadow states where it lands. The platform section below has it →
A consult is a real egress: one question plus chosen context, to the provider you picked. So each one is written into the conversation where you can read it, and any chat that ever used one is marked permanently — even after the toggle goes back off.
planning · 4 steps · consult ON
[consult] claude — “framing pattern for length-prefixed binary over TLS?”
[consult] answered · 11 lines · folded into step 2
done — workspace/client.js, two edge cases the consult caught
An agent that runs commands and spends money needs discipline built in, not bolted on. The pattern holds across everything below: toggle-gated per chat, budgeted per turn, carded in the transcript, and it fails in the safe direction. You get the leverage; the machine keeps the receipts.
Summon a council and every provider you’ve keyed — in-house Shadow included — answers the same question blind, in parallel, one card each. No model sees another’s answer. Your agent reads them all, weighs them, and states where it lands and why. Second opinions are cheap; groupthink is what’s expensive.
Opt in per chat and an external model vets destructive shell commands before they run. Four reviews a turn, verdicts cached, and two consecutive denials lock the turn — fail-closed. If the reviewer is unreachable, the command proceeds with a loud unvetted card, so visibility never depends on the reviewer being up. The concerns are shown verbatim.
Spawn a subagent on our own GPU pod and the bulk reading burns the child’s context, not yours — the parent grows only by the capped result. Each child gets its own scratch directory, inherits the egress gate and the review hook, and comes back as one collapsed line. Two per turn, two concurrent, 240 seconds each.
Move a job to another chat in your account and the conversation compiles the complete brief itself — goal, state, paths, constraints. On the far side it waits as a card with one button; nothing runs until someone presses it, and both transcripts keep the record. Your account, your continuity.
working · review ON · 4 reviews / turn
[review] rm -rf /staging/current — DENY — “current is a live symlink into prod; the tree you want is /staging/v3”
[review] rm -rf /staging/v3/build — PASS · circuit 1/2
rebuilt — /staging/v3/build, the live tree untouched
Most “we don’t log” promises are policy — a company choosing not to look, which it can reverse and a court can override. Ours is architecture: what sits on our servers is mathematically unreadable to us.
Shadow Link AI is a hosted service — you sign in and use it; the model, the tools and the capacity are ours to run. Seats are how it is sold: one for yourself, or a pool for a team.
Context doubled on every plan, same price — Shadow v4.5 runs a true 256K context window.
No, and not as a promise — as arithmetic. Your history is encrypted under a key derived from a passphrase that never leaves your control. We hold ciphertext. A subpoena gets the same ciphertext.
That history is gone. There is no reset link and no support ticket that recovers it. That is the cost of the guarantee being real, and we would rather say so on the pricing page than in an apology email.
There is no policy filter sitting between you and the model, and no topic list. What remains are the ordinary limits of any hosted service — you are still responsible for what you do with it, and abuse of the platform’s own resources is bounded.
Its own per-task workspace, the files you attach, and the outside network. It cannot touch the host, other accounts, or anything on your own machines unless you deliberately give it the way in.
One toggle per conversation. When it’s on, your Shadow may — at its own judgment — send a focused question to a frontier provider you configured, on your API key, and fold the answer back into its work. What leaves is the question and the context Shadow chose, not your whole transcript. Every consult is visible in the conversation, any chat that ever used one stays marked, and with the toggle off, nothing leaves at all.
Optionally, a second opinion. Review-before-destructive is a per-chat toggle: when it’s on, an external model vets destructive shell commands before they run and its concerns are shown verbatim. Two consecutive denials lock the turn outright. If the reviewer can’t be reached, the command proceeds — but the transcript gets a loud unvetted card, so you are never quietly trusting a service that was down.
Yes, with the same shape as the chat: no banned-prompt list and no classifier between you and the canvas, and the ordinary limits of the law still applying. The platform’s own resources are protected the honest way — published numbers, not mystery: twelve images per seat per hour, four per minute, with flat text edits unlimited and free. The GPU pod stays warm around the clock, so an image takes about thirty seconds and one with an in-scene title about a minute — the first of the day included.
You keep working. Past the line, the seat drops to a single lane at a reduced request rate until the daily reset at 00:00 UTC — requests wait their turn rather than fail. Only at three times the allowance, which is automation running around the clock rather than a person, does a seat pause until the reset. Nothing is deleted, nothing is billed as overage, and you can watch the number all day rather than discovering it at the end of the month.
Any month, both directions — write to [email protected] and it is done on your account. Team seats are added or removed the same way. Capacity changes take effect immediately, not at the next billing cycle.
To chat, no. To get the most out of the tools, it helps — this is a product for people who want the AI to finish the job, and finishing the job usually means touching real systems.
No. We could not if we wanted to.