Sovatela app icon

Sovatela

A desktop app for AI chat, with the model hosted in Europe. It runs GLM-5.2 — developed by Z.ai, hosted in Paris by Scaleway — and your keys are stored only on your device, sent to your provider to authenticate you and to nobody else. There is no account here and no server of ours in the path; this site and the downloads are served by GitHub.

Chat and image understanding run on Scaleway in Paris. Optional search, image generation and terminal tools have different data paths; web search can contact public websites anywhere. See the security page.

PDF extraction can be incomplete. On macOS and Windows, pages with no readable digital text are read from their pictures by the system's own text recogniser, and marked as recognised; it can misread or leave out words. A PDF partly read warning names pages and graphics that were not read, but it does not catch every omission, so check the original before relying on an answer. Linux has no text recogniser: scanned pages there are named as unread.

  1. Download the app. macOS, Windows or Linux 1
  2. Get a Scaleway account. Free at scaleway.com 2
  3. Generate an API key. Copy it, paste it into the app 3

Free and open source — but you'll need a paid Scaleway key. Sovatela has no AI of its own: it uses your own Scaleway account, and Scaleway bills you directly for what you use — typically a few cents a day for ordinary chat. Sovatela never handles payment and takes no cut, and the app shows a running cost estimate on your device.

macOS .dmg · universal — Apple Silicon & Intel Download Windows .exe installer · 64-bit — experimental: unsigned, Windows will warn Download Linux .AppImage · 64-bit — experimental: unsigned Download

Windows and Linux are experimental builds. They are not code-signed, and they have never been installed, upgraded and removed on a clean machine — nobody has walked that path start to finish, so treat them as being for people comfortable with an unsigned installer. macOS is the tested platform: on Apple silicon and in a macOS virtual machine. Intel Macs and a clean-machine install have not been tested.

macOS builds are signed and notarized by the developer, so they open normally. Windows and Linux builds are unsigned by choice and experimental; signing them is not planned. On Windows, SmartScreen will say the publisher is unknown, and opening it takes More info → Run anyway. That warning is accurate: it means nobody has paid a certificate authority to vouch for this installer, and on this app nobody is going to.

Checking the SHA-256 below tells you the file arrived intact. On its own it proves the download matches what was published, not who published it — so the list is signed, and the signature is what says the publisher vouches for it. Every installer also carries a build attestation binding it to the commit that produced it. All three commands are under Verify your download below. On macOS, notarization is the check that needs none of them: it is verified against Apple, not against us.

Also available: Windows .msi (for managed deployment) · Debian/Ubuntu .deb · Fedora/RHEL .rpm

Be told about new versions

Sovatela has no automatic updater — nothing installs itself. You can press Check for updates, or turn on Check for a new version when Sovatela starts, which is off until you enable it; either one reads a static file and tells you a release exists. Two ways to hear about one — including a security release — without opening the app at all:

There is no mailing list and no signup, deliberately. Both routes are things you subscribe to at your end: the feed is a static file your reader fetches, and the GitHub option is held by GitHub. No address is collected here, so there is none to lose.

Verify your download (SHA-256)

After downloading, check the file's hash matches below. On macOS/Linux: shasum -a 256 <file> · On Windows: certutil -hashfile <file> SHA256. The canonical list is also at SHA256SUMS.txt.

macOS (universal)dc32f28be08b4b71cff6d818d22acd6b594c6af147c740fb62f5195a66ee557b
Windows (.exe)70e4437013f2887c28c284f43d89012f495cbfe268c494a2a41d992aee75eb25
Windows (.msi)a65e4548509c257edc426e1ef0bbc06fbc948ae87d25166efd424a4800451a4f
Linux (.AppImage)2f8d7c2fb6acf3cb48661f123b44493fe90e6dd23ae94222345cd960f8805867
Linux (.deb)043caf77d068f3251f592699f2252e4371e8b0c27cf9870ac10337055e4c37dc
Linux (.rpm)1dd97c3baf333ffe0aaa2f9d11ec617fde07aa09717323e28a6959d0e0a8d4bd

Two further checks, strongest last. The list itself is signed — fetch SHA256SUMS.txt.minisig and verify against the public key below, so replacing the installers would take the signing key rather than write access to the release:

minisign -Vm SHA256SUMS.txt -P RWScASFw3nNXud4ei+79moVeRYRyxX3v5wcB92PI7jSSGOyGduhuuI5V

And every installer carries a build attestation binding it to the public commit and workflow that produced it — the claim a checksum cannot make: gh attestation verify <file> --repo jacobla1/sovatela.