This is very cool because it allows you to use any model. Obviously, it still lets the model and its operator see the entire context of the conversation.
I quite like Moxie's Confer[1] approach to just encrypt the whole thing in such a way that no one except the end-user sees the plaintext.
[1] https://confer.to/