FAQ
Questions
Last updated 18 September 2026
Short answers. The longer versions sit on About, Privacy and Terms.
How do I open the workspace?
Connect the Ethereum wallet you already have and sign one message. There is no email, password or transaction.
Is there a bill?
Not for the included models — they are free within 50,000 input and output tokens a month, shown on the Models page. Tokens are counted across everything sent to and received from the model: the conversation so far, a JAR's instructions and Knowledge, fetched pages, and each call in a browsing task. The allowance resets one month after you opened the account (UTC, on that same day of the month) and does not roll over.
Purchased credits are a separate balance: you top up in USDC from the wallet, one credit is one cent, and credits do not expire. The flagship models always run on credits. When the allowance is used up you can wait for the reset, buy extra included tokens from Settings → Credits (they stay on this account and only run included models), or, if it is offered, choose to continue on credits after confirming in that chat. Nothing is charged automatically, and prices differ by model and by input versus output. A monthly limit on paid spending can be set in Settings → Credits.
On rare days when the free capacity of the service is used up, included models pause for free use and say so. Storage and indexing limits for JARs are separate from the chat allowance. Settings shows the balance and what you used this month.
Where does a message go?
The browser talks only to Diogenes. The API sends the conversation to DigitalOcean Serverless Inference — an endpoint we control — and streams the reply back. We do not send what you write to a public AI provider by default.
Does the model run on my device?
No. Inference runs on that endpoint, not in the browser.
Are my chats encrypted?
Your chats are encrypted when stored. Diogenes unlocks them when you open a conversation or ask the AI to respond.
What is confidential inference?
Some models use confidential inference through NEAR AI. This protects model processing inside a hardware-isolated environment. Diogenes still processes your messages before sending them to the model. This is separate from encryption of stored chats and is not end-to-end encryption.
Diogenes checks cryptographic evidence for that service — the hardware, its signing key, the approved software and the connection — and, for each reply, a signature over exactly what was sent and received. Verification details sit on the reply and in Settings → Models. A verified reply is one that came from the checked service; it is not a claim that the answer is correct.
What can I attach?
Images, if the model can see them. PDF, text and source files on every model — the API reads the text and sends that, not the PDF bytes to a third party.
What is a JAR?
A shared space for you and your collaborators: one set of instructions, one folder of shared Knowledge (PDF, text and Markdown), and private chats that use both. The owner invites by wallet address; the invited wallet signs in and accepts. Nobody joins from a link.
Sharing is deliberate. Chats do not contribute to Knowledge on their own; members publish documents or use Save to JAR on an answer in a JAR chat. Shared Knowledge is readable by every member and is included in each model request for a chat in the JAR. It has a size limit: content that exceeds it cannot be published — nothing is silently truncated.
Your chats in a JAR are yours alone; other members, including the owner, cannot open them. Members see each other's wallet addresses, nothing else. Leaving or removal ends your access to shared Knowledge; what you published remains. If the owner deletes the JAR, shared Knowledge is removed for everyone, members keep their own chat transcripts, and citations to shared documents stop opening.
A JAR chat can also auto-save: switch it on from the chat menu and every completed answer in that chat is published to Knowledge as its own Markdown document. It is off unless you turn it on, applies only to answers written after that, and you are told before enabling that answers may carry information from your messages and attachments. Saved answers are model output, not verified facts. Turning it off stops new publications; what was published stays until someone deletes it. When Knowledge is full, auto-save pauses and says so.
Can it read a link?
Paste up to three public pages in a message and ask. A full https address or just the site name is enough. Diogenes fetches those pages itself — public addresses only, no logins, no cookies, respecting each site's robots rules — and gives the model their text as clearly marked, untrusted material. Any offered model can do this. The answer cites pages as [W1], [W2]… and says when a page could not be read or needs JavaScript or a login. Pages are not searched for, not crawled, and not saved to any JAR; only your answer can be, by Save to JAR (in a JAR chat) or auto-save. Fetched text stays with your chat and is deleted with it.
Can it use a dashboard?
Ask for it in words — “go to … and analyze its structure”, “open its pricing page”, “check the dashboard”. Diogenes decides from your message whether to read a page or to browse; a link quoted in passing, in a code block or with “do not browse” is only read, or left alone. There is no switch to set. When browsing is offered on your account, Diogenes opens the public page in an isolated, read-only browser with the model you selected, can change clearly identified view filters, and answers with citations. The model reads the page as text and structure only — no screenshot is ever sent to it. It cannot connect a wallet, pay, post, upload, export, create keys or change account settings. Only the final answer may be saved to a JAR; page excerpts and action logs are not.
Can it read a page behind a login?
Only if you sign in yourself. When a page asks for an account, the reply ends and the chat offers Sign in. That opens a live view of the same isolated browser, for you alone: you type your credentials, pass a second factor or a provider popup, and close the view when the page is open. Diogenes waits meanwhile. What you type is not recorded, password fields are blanked in anything a model could see, and no screenshot goes to a model — the picture is painted for you and discarded.
Nothing continues on its own. Continue analysis shows a confirmation first; only then does the assistant read the site as you, still read-only. Answers from a signed-in page are marked Signed-in source, later replies in that chat Builds on a signed-in source, and their citations say Requires login. Those replies are never auto-saved to a JAR; saving one yourself asks you to review the text first.
The signed-in browser is short-lived: Stop or Disconnect ends it at once, and it ends by itself after ten minutes without activity or 45 minutes in total. Its cookies are destroyed with it; Diogenes keeps no login for the next time. Sign out on the site itself if you want that side closed too. The browser runs on our server and says so to the sites it visits; Diogenes does not disguise it. Sign in with Google therefore does not work there — Google refuses automated browsers outright (“this browser or app may not be secure”) — and some other providers or bot checks may refuse too. A site's own login, by e-mail and code or by password, is the path that works.
Can it read the chain?
Paste an address, a transaction hash or an ENS name, or ask for a token's supply, a wallet's balance, a block or a price. When on-chain reading is offered, a model that can call tools reads live data from Ethereum and the other networks we run an RPC for, and cites each fact with a link to the block explorer — [C1], [C2]. Everything is read-only: nothing is signed, sent or approved, and Diogenes never asks for a key. Your own wallet address is used only when you say “my wallet” or “my balance”. Prices come from DefiLlama. Addresses you ask about go to our RPC provider and, for prices, to DefiLlama; they are public data, not your private chat.
Can it make a picture?
Ask in words — “draw a lantern in the dark”, “make a logo for …”. When image generation is offered, a model that can call tools writes a short description and DigitalOcean's Stable Diffusion paints it; the picture appears under the reply and opens full-size in a new tab. Before anything is drawn you see the price — the drawing model by name, the credits per image and the dollar figure — and press Generate; Cancel leaves the message in the composer. Pictures are paid from credits, never from the included allowance, and a failed generation is refunded. Asking about an image you attached, or mentioning “a picture” in passing, does not draw one.
Can I use it from code?
Yes. Settings → API gives you personal keys for an OpenAI-compatible endpoint, so scripts, notebooks and agent frameworks such as LangChain or CrewAI can talk to the same models you use here. A key acts as you: it spends your included tokens and credits, obeys your spending limit, and every exchange is stored as a chat in your workspace. Browsing and the sign-in view are not offered through the API, and a key never publishes to a JAR on its own. Revoke a key at any time; scripts using it stop at once.
What if nothing comes back?
A calm sentence in the composer beats a blank field. Status says whether the API and the model are up.
How do I leave?
Export or delete from Settings. Disconnect ends this browser. Other sessions can be revoked from there too.