The model is hosted inside of a special hardware instance with code that verifiably doesn't log. Thus, one can know that it isn't being spied upon, even by the AI provider.
Most is explained in our blog post:
https://ppq.ai/blog/introducing-tee-models
