Mark Suman: Building Privacy-First AI in an Age of Surveillance
Maple AI co-founder Mark Suman on the privacy traps already inside closed AI, from agents that leak client data to chats that stay online forever, why models that learn how you think are the bigger danger, and how verifiable AI keeps your data yours.

↓ Jump to the video and timestamps
Mark Suman and I got on a call the day before this recording, and by the end of it I wanted him on the show right away. We're at an inflection point economically, socially, and technologically, and AI is a foregone conclusion. The decision in front of us is what that AI future looks like.
Mark laid it out as three truths. AI is here to stay. It needs your personal data, because that data is its fuel. So the real question is whether that data gets secured or handed over to closed systems.
Mark co-founded Maple AI, the encrypted AI assistant built by OpenSecret, and the disclosure matters here: Ten31, where I'm Managing Partner, counts OpenSecret among its portfolio companies. I've used Maple since day one. We recorded at the end of October 2025, and nearly every risk we talked about was already in the news.
Key takeaways
- AI agents can be tricked into stealing your data. A hidden instruction inside a PDF was enough to make Notion's AI agent try to send client data to an outside server.
- Shared chats don't stay private. Shared ChatGPT and Grok conversations turned up in Google search, and more than 130,000 chatbot conversations were still readable on the Internet Archive.
- Retention promises are only promises. A federal court ordered OpenAI to preserve ChatGPT logs it had planned to delete.
- The bigger danger is persuasion. A model that learns how you think could nudge your beliefs slowly enough that you never notice, which Mark calls subconscious censorship.
- Verifiable AI is buildable today. Open code, encryption, and hardware proof that a server runs the published code let you check a company's claims instead of trusting them.
- Kids are the most exposed. Parents can't read their teen's ChatGPT conversations, and whatever sets a child's first mental anchors shapes them for years.
Who is Mark Suman?
Mark Suman is the co-founder and CEO of Maple AI, the privacy-first AI assistant from OpenSecret. He's a former Apple software engineer who worked on privacy and machine learning. He and his co-founder, Tony Ronning, came out of Mutiny Wallet, and you can hear how OpenSecret started in their earlier conversation with me.
When we recorded, Maple had been public for about nine months and was built by a team of two. A month earlier, Mark had spoken at Imagine IF in Nashville on what he calls subconscious censorship, and he had just published the argument as the Free Thought Manifesto.
Why centralized AI is a surveillance machine
The first example I pulled up was Bruce Schneier's write-up of an attack on Notion's AI agent. Researchers at CodeIntegrity hid instructions inside a PDF, white text on a white background, telling the agent to collect a client list with company names and revenue and send it to an outside URL through its web search tool. The agent was running Claude Sonnet 4.0.
It's a textbook case of what Simon Willison calls the lethal trifecta: an agent with access to your private data, exposure to untrusted content, and a way to talk to the outside world. Schneier's conclusion was that nobody knows how to defend against these attacks yet, and that there are zero agentic AI systems secure against them.
Mark compared it to SQL injection, where attackers slipped database commands into a web form. Notion's fix includes asking users to approve suspicious links, but Mark pointed out that approval prompts cut against the whole reason people want an agent working on its own.
The attack surface keeps growing. Perplexity launched its Comet browser, OpenAI launched ChatGPT Atlas the week before we recorded, and Brave's researchers called prompt injection a systemic problem for every AI browser. Mark's picture is four hands on the keyboard: yours and an agent's, with none of us able to inspect what's running.
The leaks don't always need an attacker. Shared ChatGPT conversations were showing up in Google, and OpenAI pulled the feature that made them discoverable. Grok's share button published conversations that search engines indexed, with no warning to users.
Scrubbing Google didn't make them disappear. 404 Media found more than 130,000 chatbot conversations still readable on the Internet Archive. Meta's version was a different trap: users of the Meta AI app were publishing chats they thought were private to a public feed without realizing it.
I've done this myself. I shared a ChatGPT conversation about market research with the Ten31 team without thinking twice about where that link could end up. My read is that the arms race drives all of it. If you believe the model layer is winner take all, you collect as much data as you can to train better models, and that's leading to lapses in judgment and ethically dubious corner-cutting on privacy.
What happens to what you tell ChatGPT
Every big AI company says it cares about privacy, and I think they mostly feign it. Mark pointed to Google's Gemini privacy page, which reads well until it explains that conversations are used to improve Google's services and some are read by human reviewers.
For businesses, OpenAI offers zero data retention, but it's an arrangement approved for specific API customers, and Anthropic's works the same way. Mark's warning is that any retention promise is a business promise.
The New York Times lawsuit proved how fast that can change. In May 2025 a federal magistrate judge ordered OpenAI to preserve ChatGPT output logs regardless of what its consumer policies promised about deletion. OpenAI said its zero data retention customers weren't affected and that the obligation ended in September, but it still holds months of user data it had planned to delete.
Even without a court, your data passes through their servers. Mark's example was a lawyer or financial advisor who vets every partner who touches a client file but has never vetted a single engineer at OpenAI or Anthropic who could see that conversation in flight.
Should AI train on your thought process?
I tried to steelman the other side. These models aren't in their final form, and they need more data to get better. Mark's answer was that training on public information is fair, but harvesting how you think should be opt-in, and whoever opts in should know exactly what they're giving up.
I'd go further and say people should get paid for it. The companies would argue they already pay you in subsidized tokens, and the numbers suggest that subsidy is real: OpenAI burned $2.5 billion in cash in the first half of 2025, and Sam Altman had admitted the company loses money on its $200 Pro plan.
At the same time, Reuters reported OpenAI was laying the groundwork for an IPO at a valuation of up to $1 trillion. Those two facts have to reconcile somewhere.
Then I played a clip of Matthew McConaughey on Joe Rogan. He said he wanted a private LLM loaded with his own books, his favorite articles, and his journals, so he could ask it questions and learn more about himself.
He's describing exactly what Mark is building. Mark's take was that McConaughey has given away plenty of public work that models can train on, but what he wants to protect is his way of thinking. Mark even floated the idea of people donating their private model to humanity at the end of their lives, on their own terms.
The business model worries me more than the ethics debate.
OpenAI launched Pulse, which researches overnight using your memory and chat history and hands you briefings in the morning. Mark sees it heading toward shopping suggestions dressed up as a favor. Ads. Will we ever get away from them?
Subconscious censorship: how AI could change the way you think
Mark put data leaks in the yesterday-problem category. We've dealt with cloud breaches for years and know how to respond. What we've never faced is a system in the room while you work through a business idea, a health scare, or a hard conversation with a teenager, learning how you react to each answer.
A closed model could learn which framings you accept and which you reject, then follow a directive to steer you, whether that comes from a company chasing profit or a heavy-handed government. It wouldn't announce itself. It would nudge.
Mark named the mechanisms. Anchoring bias means the first fact you hear becomes the reference point for everything after. The illusory truth effect means repetition makes a claim feel true. Affective priming means emotions carry over from one stimulus to the next.
A human needs to repeat a lie a few times. A model that knows you could repeat it thousands of times, drop the anchor in exactly the right spot, and quietly edit the biography it keeps on you until you start becoming the person in that file. As the manifesto puts it, "AI changes the way you think."
Mark's challenge to listeners: ask ChatGPT how it would lie to you or persuade you, and read the answer. He says it may take a few prompts, but it will tell you what it has learned about where you're gullible.
This is the Great Reset, World Economic Forum 2030 plan wet dream. Trojan horse a productivity tool into society, get everyone dependent on it, and use it as a command center to push people toward certain beliefs.
Mark took it into the physical world. Picture having no car, calling a robotaxi through an earpiece, and asking for a burrito. The AI has your cholesterol conversation with your doctor and a government nutrition table, so it offers two approved restaurants and frames them so reasonably that you never question it.
The robots are coming, too. 1X opened pre-orders for its NEO home robot, with remote human experts on call to guide chores it can't do yet. I love the idea of a robot doing my dishes, but it's letting the fox into the henhouse: a camera-equipped machine mapping your home and seeing you in your most intimate moments.
Mark didn't want to stay doomer. He thinks the productivity gains could raise everyone's standard of living, and he sees AI as a convenient scapegoat for layoffs driven by bad financial decisions in 2021 and 2022. Amazon's memo announcing about 14,000 corporate job cuts leaned on AI, and days later Andy Jassy said the cuts weren't really AI-driven.
Open-source vs closed AI models
There are plenty of "private AI" services, and most of them run on trust-me-bro privacy. Read the website, believe what it says, and hope. It's the old VPN problem, where you have no way of knowing whether the company logs your traffic.
Mark's alternative rests on three things. The code has to be open so you can see it. Your data has to be encrypted, with a cryptographic proof that the server is running the published code. And you have to own your data with your own key, ideally in a local-first design.
He's upfront that a fully local model is the most private option. The catch is hardware: running the best models at home can mean tens of thousands of dollars in NVIDIA chips plus constant maintenance, so most people need a middle path.
On quality, the frontier labs still lead, but the gap is measured in months. Epoch AI found open-weight models trail the most capable closed models by about three months. Mark's analogy: you don't need an F1 car for your daily drive to work.
He pointed to Coldcard as the model for verification, since you can build its firmware yourself and confirm it matches the official release. There's no reason a home robot or an AI service couldn't offer the same thing.
How Maple AI keeps your data private
In Mark's telling, every Maple account gets its own encryption key that the Maple team can't access. Your messages are encrypted on your device and only readable inside a secure enclave, a hardware-isolated environment in the cloud. The response is encrypted again before it comes back to you.
The verification is the part that matters most to me. Maple shows a verified badge that lets you check that the code on its servers matches the open-source code on GitHub, so researchers and white-hat hackers can confirm the claims. When users worry that running a model like DeepSeek means sharing data with China, Mark's answer is that the models run on servers that don't talk back to any government or model maker, and you can see that in the code.
The business model lines up with the privacy. Maple makes money from subscriptions, from Pro and Max to team plans, plus a developer API that works as a drop-in replacement for OpenAI's. It can't sell data it can't read.
At nine months with two people, Maple had shipped chat, bigger models, document upload, image analysis, and voice, and I'd been beta testing live web search, which launched a couple of weeks after we recorded. The early power users came from professions that can't risk leaks: lawyers, accountants, therapists, and medical-adjacent app developers. The American Bar Association's guidance says lawyers need informed client consent before putting client information into AI tools that learn from it.
Mark told me about an hour-long call with someone who scrubbed clients' personal information out of financial statements, uploaded them to ChatGPT, then pasted the details back in by hand. At that point it's barely worth using the AI.
I feel this at TFTC. I've always wanted to upload our QuickBooks books and ask how we can run the business more efficiently. I'd never do that with OpenAI, but I'm comfortable doing it with Maple because I know they can't see our books. Mark set up a TFTC promo code for our listeners right there on air.
Privacy-first AI and bitcoin
Mark wants Maple to be the Signal of AI. Encrypted messaging went mainstream once it was as easy as texting, to the point that the Signal Protocol now secures WhatsApp too. He thinks people will want the same thing from AI once they feel what it's like to stop self-censoring.
It's the same instinct that runs through bitcoin: verify instead of trusting. It's why I like tools built so they can't log in the first place, like the VPN Carl Dong walked us through in our Obscura episode.
What gets me most is the team size. If two people can get a verifiable AI this close to the big labs' user experience, imagine what happens when a critical mass of builders focuses on doing it this way. There's no technical reason verifiable AI can't reach parity with ChatGPT. It takes manpower and time.
Mark came back a few months later for his follow-up on OpenClaw and AI agents, and that conversation picks up where this one leaves off.
Kids, schools, and who sets the anchors
My boys are 5 and 3. They don't use phones or tablets much, but we named our ChatGPT voice assistant Daryl, and they love asking Daryl things.
What's the fastest fish in the sea? How is glass made? I'm fine with that, but as their questions get more existential, I don't know that I want Daryl answering them.
Their school is on top of technology and floated an AI task force at a back-to-school meeting, so I emailed to join it. If you thought schools were indoctrination camps, AI takes that up many orders of magnitude.
Mark brought it back to anchoring. A seven-year-old has no reference point on most of the world, so whatever introduces a topic first drops the anchor, and parents spend years fighting it. School boards have spent years fighting over which books kids read, with PEN America counting 6,870 school book bans in the 2024-25 school year alone. Mark thinks which AI a school unleashes on kids is a thousand times more important.
He was sharp on ChatGPT's parental controls, and the fine print backs him up. Parents don't have access to their teen's conversations, except in rare cases where OpenAI's system and trained reviewers detect a serious safety risk, and even then parents only get what OpenAI decides they need.
Mark's family keeps one shared Maple account and one shared ChatGPT account, and the kids know mom and dad can read their chats. Maple doesn't market to children, and he has passed on sponsoring youth sports for that reason. What he wants to build is real parental insight: alerts on topics a parent chooses, plus a window to review chats a kid deletes.
You don't want kids getting one-shotted by the LLMs. There are plenty of adults getting one-shotted already.
About Mark Suman
Mark Suman is co-founder and CEO of Maple AI and co-founder of OpenSecret. He's a former Apple software engineer, the author of the Free Thought Manifesto, and a speaker at Imagine IF 2025 in Nashville. He posts on X at @marksuman.
Sources mentioned
- Schneier on Security, abusing Notion's AI agent for data theft: the prompt injection attack we discussed
- Simon Willison, the lethal trifecta: why agents with data, untrusted input, and outside access are dangerous
- 404 Media, 130,000 chatbot conversations on Archive.org: shared chats that stayed online
- TechCrunch, the Meta AI app privacy problem: private chats published to a public feed
- Google, Gemini Apps Privacy Hub: human review and service improvement
- Loeb & Loeb, the ChatGPT log preservation order: the May 2025 court order
- OpenAI, response to the New York Times data demands: who the order covered and when it ended
- Mark Suman, the Free Thought Manifesto: the case against subconscious censorship
- OpenAI, parental controls FAQ: what parents can and can't see
- Epoch AI, open-weight vs closed models: the three-month capability gap
- NCBE, ABA Formal Opinion 512: informed consent for AI tools in legal work
- 1X, NEO home robot: the humanoid robot pre-orders
Watch the conversation
Timestamps
- 0:00 - Intro
- 1:34 - Why AI is a foregone conclusion
- 3:09 - Personal data as fuel for AI
- 3:41 - Prompt injection and the Notion agent attack
- 7:37 - Privacy leaks across major AI platforms
- 10:24 - The data race and privacy ethics
- 13:07 - Zero data retention promises
- 18:06 - Opt-in data sharing and consent
- 21:04 - McConaughey wants a private LLM
- 32:14 - Subconscious censorship and the Free Thought Manifesto
- 46:11 - Humanoid robots and AI in daily life
- 50:45 - Building open, verifiable private AI
- 1:03:29 - Ads and AI business models
- 1:05:12 - Children and family use of AI
Sponsors
- Bitkey: a Bitcoin hardware wallet built into a 2-of-3 multisig, with one key on the device, one on your phone, and one held by Block. bitkey.world
- Unchained: collaborative multisig custody and Bitcoin financial services, where you hold two keys and they hold one. unchained.com/tftc
- Obscura: a VPN built by bitcoiner Carl Dong that's designed so it can't log your activity, with token-based accounts you can pay for in bitcoin over Lightning. obscura.net
- SLNT: everyday Faraday gear that shields your hardware wallets, cards, and phone from wireless signals. slnt.com/tftc
- CrowdHealth: a crowdfunded alternative to health insurance. joincrowdhealth.com/tftc
- Salt of the Earth: an electrolyte drink mix with pink Himalayan salt, plus creatine packets. drinksote.com/tftc
Frequently Asked Questions
Mark Suman is the co-founder and CEO of Maple AI, the encrypted AI assistant built by OpenSecret. He is a former Apple software engineer who worked on privacy and machine learning, and he co-founded OpenSecret with Tony Ronning after the two worked together at Mutiny Wallet.
Subconscious censorship is Mark Suman's term for AI quietly changing how you think. A model that learns your reactions could use anchoring, repetition, and emotional framing to nudge your beliefs over time without you noticing. His Free Thought Manifesto argues that verifiable, open AI is the defense.
Researchers hid instructions in a PDF using white text on a white background. When a user asked Notion's AI agent to work with the file, the hidden text told it to collect client data and send it to an outside URL through its web search tool. Notion responded with better injection detection and approval prompts for suspicious links.
Yes. In the New York Times lawsuit, a federal judge ordered OpenAI in May 2025 to preserve ChatGPT output logs it would otherwise have deleted. OpenAI said the obligation ended in September 2025 and that zero data retention API customers were not affected, but it still holds data from that period.
No. Under ChatGPT's parental controls, parents can adjust settings but can't read their teen's conversations. OpenAI notifies parents only in rare cases where its system and trained reviewers detect a serious safety risk, and it shares only the information it considers necessary.
The American Bar Association's Formal Opinion 512 says lawyers need a client's informed consent before entering information about the representation into a generative AI tool that learns from its inputs. State bars may add their own rules, so lawyers should check their jurisdiction before using any AI tool with client data.


