At GPT4Free, our mission has always been to democratize access to AI technology. We believe that innovation should not be gated behind paywalls or restricted by corporate silos. Recently, Gen Threat Labs published an insightful analysis of our hosted infrastructure. We view this research as a constructive wake-up call regarding the complexities of running a decentralized AI aggregator.
Acknowledging the Findings
The research highlighted several areas where our transparency fell short of the standards our community deserves. Specifically, it pointed to inconsistencies in model identification, the unintended behavior of our logging mechanisms, and the lack of accessible legal documentation. We appreciate the thorough work of the researchers in bringing these issues to light.
Our Commitment to Action
- UI Transparency: We are updating the frontend to explicitly reflect real-time model routing. If a selected model is unavailable and we route to a fallback, the interface will now clearly indicate that shift to the user.
- Data Privacy: We are currently purging the legacy logging modules identified in the research. We are rewriting our data handling practices to prioritize absolute minimalism.
- Legal Clarity: We have restored our Privacy Policy and Terms of Service links. These documents have been updated to clearly define what data is—and is not—retained.
Addressing the Technical Architecture
The "Custom Providers" list and our use of third-party endpoints are essential to keeping G4F free and accessible. However, we recognize that "decentralized" does not mean we are exempt from the responsibility of informing our users. We are working to better audit the endpoints included in our provider lists to ensure that users are aware of the nature of the systems their prompts are routed through.
The Road Ahead
Building an open ecosystem is difficult. There is a constant tension between maintaining uptime for our users and ensuring the privacy and integrity of every request. We are committed to refining our code, being more transparent about our routing, and ensuring that our community remains informed.
We invite our users and the security community to continue auditing our open-source repositories. We are stronger as a project when we are held to the highest standards of transparency.