# Chutes.ai security/privacy questions

**URL:** https://discuss.privacyguides.net/t/chutes-ai-security-privacy-questions/35540
**Category:** Questions
**Created:** 2026-02-16T10:29:38Z
**Posts:** 42

## Post 1 by @wildcat253 — 2026-02-16T10:29:38Z

What do you guys think about chutes.ai and especially their TEE models?

On first glance all of it looks solid but I’m not sure if I’m missing something. If I understand it correctly their TEE models could be great for privacy?

Let’s say for example that I’m using the model GLM-5 TEE from Chutes. From what I understand they use NVIDIAs official remote attestation to check if the hardware/GPU of the miner is secure, what it claims to be, not tampered with and using the TEE as intended.

Is that implementation is done correctly? And am I understanding it correctly that TEE blocks reading the prompt from the GPU memory, dumping the VRAM content, log the requests and blocks modifying the model and code?

I got the feeling that I’m missing something crucial otherwise I don’t know why nobody else on here is talking about it since 3$/month for 300 requests daily for very good security/privacy sounds great.

---

## Post 2 by @Onscreen5341 — 2026-02-16T10:35:37Z

> [@wildcat253](#):
>
> chutes.ai

I just went to the site and on first look it looks like something I would run away.  
Their website is full of buzzwords without any meaning.

For example:  
“Breakthrough **Serverless** Compute for AI, At Scale.” What the actual fuck … the word “serverless” is like saying a car without a car. It doesn’t make sense and feels more like the PR is just putting words on it, to sound cool and fancy.

The service might be good, however I would be already scared away from such buzzwording.

---

## Post 3 by @wildcat253 — 2026-02-16T10:36:41Z

I think by serverless they mean that they use decentralised computing for running AI and don’t host it themselves.

---

## Post 4 by @Onscreen5341 — 2026-02-16T10:38:53Z

Might be, but then serverless is just wrong. The right word would be decentralized.  
And the one of the few reasons to obfuscate the meaning of words in such way is to sound fancy, new and go with the hype.  
Not to provide an actual benefit for the user. Which is something that I don’t like and which is a red flag from me.

---

## Post 5 by @wildcat253 — 2026-02-16T10:44:57Z

Fair. I’m personally more concerned with the technicalities and to be honest often even don’t really read the startpage completely and just go to the technical documentation so I completely missed that until you pointed that out.

I stumbled across them on Reddit once again and thought I might check them out. I’ve seen their name before in OpenCode, OpenRouter and various different platforms so they seem to be somewhat established.

---

## Post 6 by @kissu — 2026-02-16T13:27:01Z

Just some hype and BS _product_, nothing to see.  
You can do it yourself without a third party involved.

Avoid.

---

## Post 7 by @wildcat253 — 2026-02-16T14:10:31Z

What about it is BS in your opinion and what other product would you recommend?

Are the security claims not correct or what about them is BS?

---

## Post 8 by @privacy.slouchy — 2026-02-16T15:12:33Z

From their [privacy policy](https://chutes.ai/privacy):

> We collect information you provide directly to us, such as when you create an account, use our services, or contact us for support.
> 
> - **Account Information** : When you create an account, we collect your name, email address, and other contact information.
> - **Usage Data** : We collect information about how you use our services, including API requests, model usage, and platform interactions. We do not collect the content of your requests.
> - **Technical Information** : We automatically collect certain technical information, including IP addresses, browser type, device information, and log data.
> - **Payment Information** : We collect payment information when you subscribe to our services, though this is processed securely by our payment providers.

> We do not sell, trade, or otherwise transfer your personal information to outside parties except as described in this policy.
> 
> - **Service Providers** : We may share your information with third-party service providers who assist us in operating our platform.
> - **Legal Requirements** : We may disclose your information if required by law or if we believe such action is necessary to comply with legal obligations.
> - **Business Transfers** : In connection with any merger, sale of company assets, or acquisition of all or a portion of our business.

They admittedly collect a bunch of PII. Any big tech data aggregation company could gain access to that information if they bought them out tomorrow

Not what you want to see

---

## Post 9 by @wildcat253 — 2026-02-16T15:49:37Z

I created an account with them for testing and never had to provide anything else besides a made up username. Not even an e-mail address or something similar which is imo not bad.

You can also pay using TAO (which you can buy with XMR) or by using a code which you can buy on another website making it even harder for them to track you.

So in reality if you log in using the Tor browser, pay using TAO and only use the service via OpenCode using a proxy they basically have nothing on you?

The only things they should know is when you send queries and some other metadata like size etc. This matters of course but realistically speaking how bad is it in comparison to other AI providers?

I guess that is basically my main question: How good are they in comparison to other AI providers and if there are better ones which and why?

Please don’t answer “just run LLMs locally bro”. Models that a consumer can run locally are currently way behind and for me personally not good enough.

---

## Post 10 by @Linus_Sex_Tips — 2026-02-16T16:00:54Z

In terms of inference providers that offer models running in TEEs, Chutes is the cheapest and has the largest model catalogue by far. The only other option I can think of off the top of my head for you to compare to is Tinfoil.sh (since it seems like you want API access).

There are others discussed on this forum like Maple (which just uses Tinfoil as their upstream provider anyway), Lumo and Confer (neither of which provide an API), and then spammers like Phala that use bot accounts on Reddit to promote themselves.

Personally would have no problem using Chutes, and from what I’ve seen from them on X, they have reasonable takes regarding privacy. It seems like you also read their privacy policy and came to the same conclusion, so I’d just stick with it.

---

## Post 11 by @wildcat253 — 2026-02-16T16:27:06Z

Thanks person with the questionable username! I’ll check out tinfoil.sh :slight_smile:

Do you think the technical implementation of Chutes is solid from what you know? I haven’t seen any problems with it but it sounds a bit too good especially for the price.

I think Confer and Lumo might be a great tools in the future but feel a bit unfinished rn.

---

## Post 12 by @Linus_Sex_Tips — 2026-02-16T16:43:14Z

To be frank I haven’t looked into this enough to give you a good answer. I’d also like to note there are _very_ few people who would be able to give you accurate information on this. Especially on this forum where it seems to be the case that most are vehemently anti-AI for one reason or another.

In my opinion, your best bet would be to read about the topic on your own and work through Chutes’/Tinfoil’s documentation, sending them questions if you have any.

---

## Post 13 by @anon61753997 — 2026-02-16T16:48:20Z

I don’t know where @Linus_Sex_Tips gets information from, but [Lumo doesn’t use confidential computing](https://proton.me/support/lumo-privacy).

Confer is the most barebones. I don’t have anything positive to say about it.

Maple provides mobile apps with a ChatGPT-like experience.

Tinfoil uses the pay-as-you-go pricing model.

Chutes has the most LLM models to choose from.

> [@wildcat253](#):
>
> Do you think the technical implementation of Chutes is solid from what you know? I haven’t seen any problems with it but it sounds a bit too good especially for the price.

None uses any metadata reduction techniques. Consider using Tor/VPNs.

---

## Post 14 by @Colter — 2026-02-16T17:33:18Z

Do I get thus correctly that you need a subscription to run a AI model on your own hardware or are you talking a out AI hosting?

---

## Post 15 by @Linus_Sex_Tips — 2026-02-16T17:40:29Z

Third-party hosting. For models that are way too large to run on almost any consumer hardware most people have

---

## Post 16 by @Colter — 2026-02-16T17:42:45Z

If it run on a different machine then you can’t guarantee that they don’t access it.

The only thing you can do then, is to use it anonymously

---

## Post 17 by @Colter — 2026-02-16T17:45:05Z

The only exception are very specific action that could be performed on arbitrary data without knowing what’s inside.

Then the server could process encrypted data.

---

## Post 18 by @wildcat253 — 2026-02-16T17:56:31Z

That is basically what TEE is trying to solve.

[Wikipedia article](https://en.wikipedia.org/wiki/Trusted_execution_environment) about TEE:

> A **trusted execution environment** ( **TEE** ) is a secure area of a [main processor](https://en.wikipedia.org/wiki/Central_processing_unit). It helps the code and data loaded inside it be protected with respect to [confidentiality and integrity](https://en.wikipedia.org/wiki/Information_security#Confidentiality). Data confidentiality prevents unauthorized entities from outside the TEE from reading data, while code integrity prevents code in the TEE from being replaced or modified by unauthorized entities, which may also be the computer owner itself as in certain [DRM](https://en.wikipedia.org/wiki/Digital_rights_management) schemes described in [Intel SGX](https://en.wikipedia.org/wiki/Software_Guard_Extensions).

TEE is not everything that is needed for that but a big piece. I think Chutes explains it fairly well: [Confidential Compute for AI Inference: How Chutes Delivers Verifiable Privacy with Trusted Execution Environments | Chutes Blog](https://chutes.ai/news/confidential-compute-for-ai-inference-how-chutes-delivers-verifiable-privacy-with-trusted-execution-environments)

The question however is if they really implement it the way they say.

---

## Post 19 by @Colter — 2026-02-16T18:43:42Z

> [@wildcat253](#):
>
> The question however is if they really implement it the way they say.

Yes, and how should that be verified?

---

## Post 20 by @wildcat253 — 2026-02-16T19:03:13Z

My initial question was basically if anyone knows if it’s done correctly. Yes, I could’ve said THROUGH audits from reputable 3rd parties for example.

You could also verify it through

> real-time, public access to TD Quotes, NVIDIA attestations, and full IMA software manifests so third parties can independently validate the environment and running code.

as Chutes says in their blog post. I thought because there are so many smart people here that I might’ve missed an audit, some architectural design flaws, or some other information.

Sometimes people on here (at least in the past) had very nice insights, inputs or once or twice even insider knowledge. That is why people ask questions in here in the first place.

---

## Post 21 by @kissu — 2026-02-16T19:45:39Z

> [@wildcat253](#):
>
> What about it is BS

Why would you need a product or 3rd party in between you and something you can do yourself?  
The amount of companies created in the past 2 years that are literally ChatGPT in/out thanks to wrapper is quite long.  
This is just one more of them with no specific added value and it can go down anytime.

And yeah, also the general vibe + buzzwords + style on Twitter, it’s part of an overall identity trend that startups try to replicate, the Vercel style pretty much.

> [@wildcat253](#):
>
> what other product would you recommend

Why do you need a product for an open source LLM like Qwen or DeepSeek?  
Do you need to pay for a product to check the weather? Nah you can search it online yourself or through the window, same here, unnecessary middleman.

---

## Post 22 by @wildcat253 — 2026-02-16T19:58:12Z

What do you mean with this:

> Why do you need a product for an open source LLM like Qwen or DeepSeek?

I literally can’t host things like GLM-5 or DeepSeek V3.2 model myself. No normal consumer can because of the amounts of memory and processing power that is needed. Which means I have to rely on some provider. Which lead to me searching for providers that have good privacy policies and security practices.

Or do you mean I just simply shouldn’t use AI? That would be totally another discussion and not the one I asked for here.

Or do you mean I should just use Qwen or DeepSeek from the developers themselves and basically give my data to companies heavily associated with the government of the PRC?

So I once again ask: Do you (or anyone else for that matter) have a better recommendation for someone who needs an AI provider with SOTA models?

---

## Post 23 by @kissu — 2026-02-16T20:39:30Z

> [@wildcat253](#):
>
> I literally can’t host things like GLM-5 or DeepSeek V3.2 model myself

If you don’t have the size/computer/RAM/NPUs for it, use some cloud functions or VPS.  
It will be cheaper because less people in the middle.

I know that not all models are hella huge anyway. And bigger doesn’t always mean better too.

> [@wildcat253](#):
>
> Which lead to me searching for providers

Nobody does that if we’re honest.  
Moreover, if you want the best, just pay for some ChatGPT.

Paying for an in-between _product_ is having the worst of both worlds.

> [@wildcat253](#):
>
> Or do you mean I should just use Qwen or DeepSeek from the developers themselves

No. Do it by yourself as much as possible, at home or on a rented VPS/cloud function.

---

## Post 24 by @wildcat253 — 2026-02-16T20:53:06Z

> If you don’t have the size/computer/RAM/NPUs for it, use some cloud functions or VPS.

Can you link a VPS that is affordable and has a better design when it comes to privacy protection than Chutes.ai? Even if I rent a VPS from a provider I still need to know they don’t have the ability to snoop otherwise we’re comparing apples to bananas imo.

> [@kissu](#):
>
> ![](https://forum-cdn.privacyguides.net/user_avatar/discuss.privacyguides.net/wildcat253/48/11848_2.png) wildcat253:
> 
> > Which lead to me searching for providers
> 
> Nobody does that if we’re honest.

Well I am. We all should as AI is becoming more important than ever and privacy there is important.

> Moreover, if you want the best, just pay for some ChatGPT.

First: ChatGPT being the best is heavily debated, depends on the use case etc.  
Second: Did you even read the privacy policy of ChatGPT? I feel like every week I read something about ChatGPT being bad when it comes to privacy. It’s probably one of the worst companies when it comes to privacy and ethics.

I feel when it comes to AI people interested in privacy either turn a blind eye and pretend like ChatGPT is not 100x worse than Google when it comes to the data we feed it or they just pretend it doesn’t exist, hate it or both which of course doesn’t change the fact that AI is becoming increasingly more important in todays world.

---

## Post 25 by @anon61753997 — 2026-02-16T21:25:03Z

> [@wildcat253](#):
>
> My initial question was basically if anyone knows if it’s done correctly.

No. In their blog post, Chutes said that verifiability is “the end goal”. In other words, it’s not verifiable at the moment.

> [@Colter](#):
>
> If it run on a different machine then you can’t guarantee that they don’t access it.

[Confidential computing](https://en.wikipedia.org/w/index.php?title=Confidential_computing) has its upsides and downsides. You need two _hardware_ features for it to work:

- Remote attestation: For example, I give you a software binary, which you can hash and compare it with the hash that the hardware produces from the software that it is running.
- TEE: If being used correctly by software, it can deprive the hardware owners of access to some data. The most popular use case is for “premium content protection”. :upside_down_face:

Connect the two dots and you can roughly understand how confidential computing works.

> [@wildcat253](#):
>
> Do you (or anyone else for that matter) have a better recommendation for someone who needs an AI provider with SOTA models?

Out of the four (Chutes, Maple, Tinfoil, and Confer), Tinfoil is the best at transparency by virtue of being open source. I’m pretty sure that none are being audited by third-parties. You can read how their remote attestation works [here](https://tinfoil.sh/blog/2025-01-13-how-tinfoil-builds-trust). [Their blog](https://tinfoil.sh/blog) is also great if you want to learn more about confidential generative AI. But again, it has less LLM models than Chutes, which is unverifiable right now (but may in the future).

---

## Post 26 by @kissu — 2026-02-16T21:26:45Z

> [@wildcat253](#):
>
> Can you link a VPS that is affordable and has a better design

There are a few names on the forum in previous VPS recommendation but in EU, Hetzner is a decent choice. It really is a subjective topic with no clear winner.  
You’ll never know if they do snoop or not anyway but that’s the drawback of not having your own beefy hardware for those kind of things as discussed in this previous threads. :sweat_smile:

> [@wildcat253](#):
>
> we’re comparing apples to bananas imo

Having a sustainable cloud provider (like Hetzner) vs a random no-name 2 year old startup is definitely not a :banana: vs :red_apple: comparison.  
Especially given the fact that the startup will anyway be using a Cloud provider for their own infra. Hence it’s more of a (:banana: + :red_apple:) vs (:red_apple:) kind of comparison.

> [@wildcat253](#):
>
> Well I am

Sorry, quoted poorly above. I meant to reply to the entire sentence aka

> providers that have good privacy policies and security practices

VPS providers are doing their best given security and privacy given regulations etc.

What I was referring to when I said

> Nobody does that if we’re honest.

is that the AI landscape is a wild west and nobody cares about your privacy: it is actually quite the opposite.  
Everybody wants you to use their walled-garden toolkit and spend as much money while giving away all your access/data otherwise _oh man, we can’t have good AI if you no give your data oi!_ kind of situation.

Even then, probabilistic nature makes it still quite unreliable for basic tasks.

* * *

Not everybody needs a beefy model for their needs but if you do have enough of those needs, then going open model + VPS (if not self-host) is still the most sustainable and privacy-respectful approach by far.

Burning an entire forest to know what’s the temperature outside is achieved the best by the biggest Tech companies. The more _“accurate”_ you need that info from somebody else, the more you will need to give your privacy away.

AI and privacy are going into very opposite directions and the parity in terms of _“quality”_ will never be equal.  
_old school_ ways might still be just fine enough for some use cases, don’t give up too easily :+1:t2:

* * *

> [@wildcat253](#):
>
> ChatGPT being the best is heavily debated

What I meant by “ChatGPT” here can be replaced by literally any other one.  
Don’t be fooled, Microsoft, Google, Anthropic or anyone else really, do not care and are equally just awful.  
You could spend your entire day following the latest propaganda and micro changes, realistically they all the want the same from you and are pouring trillions into their latest kinks of grandeur. :grinning_face_with_smiling_eyes:

Imagine investing 4 time your yearly turnover into some hardware and then, being like

> you know what? nah I don’t want a return on investment really, I’ll just cure cancer and help those people for the free because I don’t need to have money, just peace of mind knowing that I am a good human being really :innocent:

> [@wildcat253](#):
>
> It’s probably one of the worst companies when it comes to privacy and ethics.

I really don’t care about the ~~weekly~~ hourly drama around those companies if we’re honest.  
They are all lying and equally bad because this is just the AI rat race based on FOMO, buzzword, BS _“thoughtleaders”_. :+1:t2:

> [@wildcat253](#):
>
> the fact that AI is becoming increasingly more important in todays world.

Are those your thoughts?  
Or you starting to think it now that those companies shoved enough ideas into your mind with lots of marketing and potential _groundbreaking social improvements_?

* * *

Kinda related video that I just posted.

> [@Jeff Geerling - AI is destroying open source, and it's not even good yet](https://discuss.privacyguides.net/t/jeff-geerling-ai-is-destroying-open-source-and-its-not-even-good-yet/35557):
>
> A bit of pragmatism, sadness and things going south with the current AI landscape. face_exhaling

---

## Post 27 by @kissu — 2026-02-16T21:36:26Z

> [@anon61753997](#):
>
> No. In their blog post, Chutes said that verifiability is “the end goal”. In other words, it’s not verifiable at the moment.

Unless it’s verifiable 100%, expect all of those AI bros/companies to probably just lie.  
Sorry to break down the bad news here. :sweat_smile:

Caught live? Oh, ~~apologize~~ burn the evidence :fire:, rebrand under a new name and milk some people elsewhere with some over-the-weekend _“product”_.

> [@anon61753997](#):
>
> [Confidential computing](https://en.wikipedia.org/w/index.php?title=Confidential_computing) has its upsides and downsides

I moreover don’t see anybody realistically investing any money into this as fast as the other privacy-invasive companies are doing on their side. :sweat_smile:  
Or just making it sustainable/decently priced to their customers.

> [@anon61753997](#):
>
> I’m pretty sure that none are being audited by third-parties

Would be curious to see how easy it is even to audit those claims, knowing that they could setup their servers in a way before the audit and revert to snoopy approaches after the audit.  
Or that the audit teams even know how to audit those ones thoroughly.

Maybe I just don’t know enough about that topic, fair assumption too.

---

## Post 28 by @anon61753997 — 2026-02-16T22:26:10Z

> [@kissu](#):
>
> I moreover don’t see anybody realistically investing any money into this as fast as the other privacy-invasive companies are doing on their side. :sweat_smile:

You said this because you think confidential computing only exists because of LLMs, aren’t you? The EU recognized it in its [“state of the art” guideline](https://www.teletrust.de/fileadmin/user_upload/2021-09_TeleTrusT_Guideline_State_of_the_art_in_IT_security_EN.pdf) published in 2021:

> Privileged access by administrators to data during processing is traditionally only secured with organizational or reactive measures against misuse of the privilege. With the help of confidential data processing (Confidential Computing), this data is tamper-proof and preventively protected against unauthorized access. This is particularly important for applications in the field of cloud computing. Confidential data processing corresponds to the protection requirement when cloud services are used for **critical infrastructures** or for **sensitive data processing processes** , e.g. in medicine, industry or in regulated areas (e.g. regTech).

Meanwhile, the first one to use confidential computing for LLMs is Apple with its Private Cloud Compute, which released in mid-2024.

Granted, there are some unique problems when applying confidential computing to LLMs.

> [@kissu](#):
>
> Or just making it sustainable/decently priced to their customers.

This is true, though. Those hardware requirements have a price tag.

> [@kissu](#):
>
> Would be curious to see how easy it is even to audit those claims, knowing that they could setup their servers in a way before the audit and revert to snoopy approaches after the audit.  
> Or that the audit teams even know how to audit those ones thoroughly.

The most straightforward way is open-source software and (additionally) reproducible builds. Even Apple publish some parts of the Private Cloud Compute.

---

## Post 29 by @wildcat253 — 2026-02-16T22:30:25Z

I appreciate your thorough reply but I really think you’re contradicting yourself in several places here. Prepare for a long reply.

> Having a sustainable cloud provider (like Hetzner) vs a random no-name 2 year old startup is definitely not a :banana: vs :red_apple: comparison.

The age of a company doesn’t automatically make it more or less trustworthy. By that logic we should never trust any new privacy tool or service and just stick with the old giants forever. Mullvad was “new” once. Proton was “new” once. Pretty much project Privacy Guides recommends was a “random no-name startup” at some point. Age doesn’t equal trustworthiness, what matters is what they actually do. Dismissing something solely because it’s young is not a privacy argument, it’s an appeal to tradition. I thought that was something we are actively challenging here :cry:

> You’ll never know if they do snoop or not anyway

So your argument is essentially “trust nobody, verify nothing, just give up and use a VPS”? Because you literally just admitted you can’t verify what Hetzner does with your traffic either. So how is that really different from trusting a provider that has actually published their security architecture and privacy policies? At least some of these AI startups are publishing security docs and opening up to scrutiny. Hetzner isn’t exactly letting you audit their hypervisors either. Not that this matters as Hetzner isn’t an option anyways but more on that later.

> the AI landscape is a wild west and nobody cares about your privacy

“Nobody” is doing a LOT of heavy lifting in that sentence. TEE implementations, confidential compute, E2EE approaches like Confer’s passkey-based encryption, zero-data-retention API policies. Afaik these are real, technical, verifiable privacy mechanisms that exist right now. Maybe I was also just drugged and am hallucinating. They’re not perfect, sure. But you know what? Nothing is. But saying “nobody cares” just because the big players are bad actors is like saying “nobody makes a secure phone OS” because Samsung and Xiaomi are awful. GrapheneOS exists. And in the AI space, privacy-focused approaches exist too. You just have to actually evaluate them instead of blanket-dismissing everything.

> Don’t be fooled, Microsoft, Google, Anthropic or anyone else really, do not care and are equally just awful. They are all lying and equally bad

This kind of blanket nihilism is actually counterproductive to the privacy community imo. If everybody is “equally bad” then nothing matters and there’s no point evaluating anything. This is exactly the attitude that benefits the **worst** actors the most. There ARE material differences between companies. Lumping together a provider that uses TEE + accepts crypto + publishes no-log policies with OpenAI (which is literally court-ordered to retain all chat logs indefinitely) is not useful analysis. It’s doomerism dressed up as skepticism.

> Not everybody needs a befy model for their needs but if you do have enough of those needs, then going open model + VPS (if not self-host) is still the most sustainable and privacy-respectful approach by far.

I actually agree with this in principle. But the keyword is _“if you do have enough of those needs.”_ Not everyone does, and not everyone has the technical skill or budget to spin up a VPS with GPU passthrough. For those who need something more capable than what a small VPS can run, dismissing every cloud option as “equally bad” doesn’t help them make informed decisions. It just leaves them with zero actionable advice.

And about the “just use a VPS” suggestion. Let’s do the actual math on that. GLM-5, lets just call it the current open-weights SOTA, is a 744B parameter model that needs ~1.5TB of VRAM at full precision, or ~241GB even at aggressive 2-bit quantization. Hetzner’s best GPU server (GEX131) has 96GB VRAM and costs €889/month. Afaik you can’t split LLM inference across separate physical servers, so you’d need a specialized GPU cloud with an 8x H100/H200 node. We’re tlking $15,000-25,000/month, not exactly the “affordable VPS” you’re casually recommending. And if that is affordable for you then I seriously want your salary. You _could_ run it on CPU with RAM offloading on a high-RAM dedicated box, but at 1-2 tokens/second it’s essentially unusable. And sure, you can run a 7B or 13B model on the €184/month GEX44, but then we’re back to what you yourself called “quite unreliable for basic tasks” because small open models are exactly that. So the realistic choice for most people who actually need capable AI for work is: spend thousands on hardware for a self-hosted setup that still can’t match frontier models, or use a cloud AI service with the best privacy practices you can find. Dismissing the second option as “equally bad” doesn’t help anyone make that decision.

> Are those your thoughts? Or you starting to think it now that those companies shoved enough ideas into your mind with lots of marketing?

Come on mate. That’s just condescending. We don’t need any of that here. Yes, those are my thoughts. I use AI for work daily. Not because marketing brainwashed me, but because my workflow genuinely benefits from it and in some cases it’s pretty much required to reach goals. You can dislike the AI industry (I do too in maaaaany ways) without pretending that everyone who finds it practically useful has been manipulated.

And, I say this respectfully, you’re telling me all these companies are “equally awful” and that I’ve been brainwashed by marketing… while you [stream on YouTube, speak at Google tech conferences, and run your whole streaming setup off a Mac Studio](https://discuss.privacyguides.net/t/how-to-livestream-without-doxxing-yourself/34380)? You’re actively participating in Google’s and Apple’s ecosystems — two of the companies you just called “equally just awful”. You’re even [considering running Cursor](https://discuss.privacyguides.net/t/how-to-livestream-without-doxxing-yourself/34380) (an AI-powered code editor) on your streaming rig (which kinda tells me you use it on another computer) while telling me that thinking AI is useful means I’ve had ideas “shoved into my mind” by marketing.

And then there’s the contrast with how you treat startups. You dismiss Chutes as a “random no-name 2 year old startup” that can’t be trusted, but then you shared [shared urban-privacy.com](https://discuss.privacyguides.net/t/urban-privacy/33925) which is a company selling anti-facial-recognition clothing with zero testing data, zero peer-reviewed validation, and crazy high prices that other people rightfully called out. And your response was “let’s be patient and not kill them already” and “let’s assume that their intentions are honest.” So new startups deserve the benefit of the doubt and patience… unless they’re in the AI space?

> Burning an entire forest to know what’s the temperature outside

Great metaphor honestly. But the solution isn’t to pretend forests don’t exist or that nobody should ever check the temperature. The solution is to find the most efficient and privacy-respecting way to do it. Which is literally what I tried with this thread before it turned into a lecture about how nothing matters because everyone is bad.

The “everything is equally terrible so don’t bother evaluating” approach helps nobody. It’s the privacy equivalent of “don’t vote, all politicians are the same.” Real threat modeling involves nuance not nihilism.

---

## Post 30 by @hydrogenperoxide — 2026-02-16T22:30:32Z

If you use OpenRouter and enable “Use ZDR Endpoints only” and disable “Enable paid endpoints that may train on inputs" in privacy settings, Chutes will be blocked for the following reasons:

 ![brave_t26xvG4Fa0](https://forum-uploads.privacyguidesusercontent.com/original/3X/7/0/70f30ded0fff236795b26d5331237ef0ebf43647.png)

Therefore, based off of that alone, I wouldn’t recommend using Chutes.

---

## Post 31 by @wildcat253 — 2026-02-16T22:31:59Z

Now thats a good find! It might be good to follow that lead and find out why exactly and if that’s still up to date.

---

## Post 32 by @deimos — 2026-02-17T05:56:22Z

Roughly two years ago, a client asked if I could build them a fully encrypted server to run airgapped LLMs. I ended up building them a solution based on dual socket AMD EPYC 7702P 64-Core Processors. With AMD’s memory encryption, SEV-SNP, hardware-encrypted SSDs with an encrypted filesystem on top tied to the TPM and hardware token, and 512GB of ECC RAM. It’s not as fast as GPUs, but it still gets in the 100-200 tokens/sec on most modern LLMs. It met their requirements of encrypted at rest, encrypted in ram, and encrypted processing.

An example test is “what’s the airpseed of an unladen swallow?” with results along the lines of:

eval count: 585 token(s)  
eval duration: 6.140339888s  
eval rate: 95.27 tokens/s

This is full TEE/encrypted LLM processing. The Nvidia GPUs (at the time) with TEE-like capabilities were not fully encrypted and attestation was really only stating something was loaded into the TEE part of the GPU. Also, these GPUs were about as expensive as the entire system itself.

Once the models are loaded into ram, it’s really pretty responsive. In the end, we build a second system that used off-the-shelf AMD GPUs because they figured they could trust the PCI-e bus between the CPU/RAM and the GPU if the chassis was secured and one can’t snoop on the PCI bus if you can’t install any hardware to do it. This was vastly faster, with 4 GPUS per system plus the EPYC cpus, the whole thing is quite usable for models loaded into encrypted ECC RAM and then the VRAM loading is nearly instant.

All this is a long way to say, I’m seriously considering starting a site that runs something similar, but doesn’t require traditional accounts. I want it to be on my bare metal hardware, with something like a BIP-32 key for the account. Once payment clears, then you’re good to go. I want it to work with any device, with minimal javascript and zero webgl/wasm required. It should work with Tor/Mullvad browser in complete strict security mode.

Moxie has made some progress with passkey-based system running in TEEs provided by other cloud providers.

The more providers like tinfoil, running on real hardware, the better. As OpenAI’s ad-model and all these people reselling it show; your data is still the new oil.

---

## Post 33 by @wildcat253 — 2026-02-17T09:33:01Z

Impressive to hear about your experience building an air-gapped LLM server using AMD processors. Achieving about 100/tps while having encryption at all stages is no small feat!

If you ever decide to build something similar for the public post it here please! I’m pretty sure a lot of people on here would find it very interesting.

---

## Post 34 by @Linus_Sex_Tips — 2026-02-17T11:26:48Z

[https://xcancel.com/jon\_durbin/status/1951685136732581918](https://xcancel.com/jon_durbin/status/1951685136732581918)

---

## Post 35 by @Linus_Sex_Tips — 2026-02-17T11:30:49Z

Good comment, I don’t have the patience to write all this out and normally just ignore these people.

Annoying how every discussion about LLMs results in someone lecturing about why we can’t use them.

---

## Post 36 by @anon19752758 — 2026-02-17T12:28:47Z

So if I’m understanding this correctly this should be fixed now since they use TEE? I think I might send them and OpenRouter an e-mail and ask them about this.

Edit: I’m still a bit unsure of what is going on here and who to trust so I’ll likely just watch from the side until all the smoke has cleared.

---

## Post 37 by @Linus_Sex_Tips — 2026-02-17T12:40:44Z

They still offer models not running in TEEs. But your best bet would be to ask them yes

---

## Post 38 by @anon19752758 — 2026-02-17T12:45:53Z

I will report back once I hear from them. In the meantime I might get some popcorn and watch this thread or other AI related threads as they seem to make people very emotional.

---

## Post 39 by @anon19752758 — 2026-02-17T22:48:34Z

I ended up messaging both OpenRouter and Chutes and both have answered pretty fast.

Chutes answer has been this:

> We have never collected or trained on user data. We’re working on getting this flag removed, but OpenRouter has been difficult. Our last response was their verification team was “on vacation.” This flag should be removed soon, as we will likely have TEE-only models on OpenRouter.
> 
> If you’re concerned about privacy, use TEE models only. Miners could, hypothetically, retain logs on non-TEE models, but it would be difficult. This was the reason for the flag in the first place, as we were honest about this.

OpenRouters answer has been this:

> Our data retention and training classifications are based on direct discussions with each provider, not solely on their public-facing privacy policies. We require explicit, unambiguous confirmation before assigning a favorable classification. Public documentation using phrasing like “no persistent storage” or “we do not collect the content of your requests” may not meet our threshold if the language leaves room for interpretation.
> 
> We have evaluated Chutes’ policies, but the language we’ve reviewed so far hasn’t been explicit enough to confirm zero data retention to our standards. We’re always willing to re-evaluate if additional documentation or clarification becomes available from the provider.
> 
> You’ve got it right. The “unknown” classification is a conservative default we apply when a provider hasn’t provided sufficiently explicit confirmation. We err on the side of caution to ensure transparency. It doesn’t necessarily mean there’s a genuine concern about how Chutes handles data, just that we haven’t received the level of explicit confirmation we require.
> 
> If you have any direct contact with the Chutes team, feel free to encourage them to reach out to us with explicit documentation addressing data retention and training policies. We’d be happy to reassess their classification based on that.

Make of that what you will but here are my thoughts:  
From what I’m reading here it could be a genuine misunderstanding that should be resolved soon. I would advise people including OP to stop using it for now or at least only use it for non-personal stuff. I’m not saying that it is 100% safe when it has been verified by OpenRouter but at least people from a 3rd party have looked at it and deemed it safe. The verification team of OpenRouter probably knows more about this than most of the keyboard-warriors in this thread including me.

If you end up using it only use the TEE models.

---

## Post 40 by @Encounter5729 — 2026-02-18T12:43:28Z

Additional info on what [open router allows in ZDR](https://openrouter.ai/announcements/is-implicit-caching-prompt-retention) and the list of [ZDR providers](https://openrouter.ai/docs/guides/features/zdr)

---

## Post 41 by @kissu — 2026-02-18T17:12:26Z

> [@anon61753997](#):
>
> You said this because you think confidential computing only exists because of LLMs, aren’t you? The EU recognized it in its [“state of the art” guideline](https://www.teletrust.de/fileadmin/user_upload/2021-09_TeleTrusT_Guideline_State_of_the_art_in_IT_security_EN.pdf) published in 2021:

Hey, never heard of that one but it’s definitely a cool initiative! :heart:  
I’m not against secure and private tools, quite the opposite, the more control/transparency the better. :+1:t2:

* * *

> [@wildcat253](#):
>
> The age of a company doesn’t automatically make it more or less trustworthy

I never said that the age was the only aspect, meanwhile if we take some examples of companies that are young-ish like:

- Ente, been interviewed and has some public visibility while being very clear about their product and communication
- Immich, same: they do have quite a few videos on Futo and are active + transparent with their community accross mainstream channels
- [Servury](https://discuss.privacyguides.net/t/servury-cloud-server-provider/34128), literally joined the server and asked how to improve his website/app
- plenty of other product founders are here[[1]](#footnote-140279-1), transparent, take feedback + criticism, iterate and improve on community’s input

So it’s not specifically about how long you’ve been alive but it’s also about what you did in that timeframe.  
It’s one thing to ship claims, another to be transparent.

Meanwhile, when I do visit chutes.ai, I am greeted with this amazing stack of tracking in every direction.

 ![CleanShot 2026-02-18 at 16.40.27@2x](https://forum-uploads.privacyguidesusercontent.com/original/3X/5/2/52d172213aabde76697dd82bc069a58d44475fd2.png)

Don’t tell me it’s because they are a startup and don’t have the bandwidth because they do have a fulltime Frontend developer at their company.

I understand if some people can’t do better than that, yet the basic-bitch shadcn/ui starter pack hosted on Vercel, yeah all but inspires anything but scammy hype startup fueled by VC money.  
Looking more into their online presence, I wasn’t even able to properly understand if they’re `bittensor` or some other company. Sounds like a rushed thing overall with no clear ownership and only a few videos here and there on YouTube with no real person to even talk to.

I guess you can Discord or Twitter DM them. :woman_shrugging:t2:

> [@wildcat253](#):
>
> At least some of these AI startups are publishing security docs and opening up to scrutiny

So far, the best I saw is a tweet saying

> trust me bro, we really do not train on any personal data fr fr

Let’s assume it’s correct, so then…how about their sustainability?  
I do understand how Hetzner is making money. Meanwhile, when that kind of startup runs out of VC money, what happens?  
Not sure you can survive a team of 11 people on kofi donations.  
Hm, I guess there are other ways those kind of companies could make money then. Like…selling data?

If not, the VC board will come some time soon anyway to juice them out of their funds.  
Otherwise, not sure how is their stack and if they do own their own hardware + how are stable/independent are they, but what happens if some companies or components crank up their prices?  
Will they be able to eat the blow?

I mean, if raising the prices to your customers is the way to go, then no problem.  
Not a stable solution in anyway but it would at least be respectful yet very brittle.  
It’s not what I saw from similar companies in the industry (especially AI) so far.

Hence yes, I do trust a random company to have less incentive and things to prove because they do have a stable running business with a reputation to hold.  
Some random guys on Twitter that created their thing 15 months ago, sorry to say: have a bit more things to prove still.  
But hey, it’s my own skepticism and feel free to just trust them blindly, not my problem after all[[2]](#footnote-140279-2). :+1:t2:

> [@wildcat253](#):
>
> And in the AI space, privacy-focused approaches exist too. You just have to actually evaluate them instead of blanket-dismissing everything.

In terms of ratio, we’re far from a majority overall.  
I never heard of chutes.ai before that day. Doesn’t mean that marketing matters for street-cred or that it’s a proof of anything sure, but eh they also do not shine by being a silver bullet that’s unique in their own genre.

Maybe I’m wrong and fine with that tbh, but I guess I am mostly just fed up with those kind of startups popping left and right with only bold claims + abstract futuristic starter pack visuals to hype hype.  
It’s just like those 20 new database startups every year pretty much, tiresome and not very _useful_. :grinning_face_with_smiling_eyes:

> [@wildcat253](#):
>
> This kind of blanket nihilism is actually counterproductive to the privacy community imo

Just the sad reality of your local bro not being able to deliver the same amount of tokens/s as Altman.  
Am I happy about it? No.  
Do I like that some people are trying to move the needle? Yes.  
Is it enough and worth the jump? Not sure it is meaningful enough just yet.

I think nobody is blind enough to see that AI is pushing rich people to juice the least privileged with unequal weapons. Not sure what is the way to fight against but embracing some AI middleman startup is maybe not the way yet. And hey, it’s fine if we do not have a cool alternative to that problem just yet, in time we probably will. :+1:t2:

* * *

> [@wildcat253](#):
>
> a 744B parameter model that needs ~1.5TB of VRAM at full precision, or ~241GB even at aggressive 2-bit quantization

Okay, on this one. :joy:

So, I do see things with those levels:

1. you use AI in a casual way, eh the basic answers from Brave, DuckDuck or else are just enough to get you what you’re looking for
2. you need a bit more and don’t care about privacy, you can sell your soul to the myriad of companies just selling you dreams
3. you’re privacy conscious and do care about running something local while being tech-savvy
4. you need more and feel like exporting the compute to some VPS/cloud function or alike for more raw power, yet nothing like 1.5TB of RAM
  - even better, you eat the bullet and just build something bulky as described above by @deimos, something that is realistically prosumer accessible

5. you have the needs for \>1TB of RAM, at this point you’re probably more concerned by security rather than privacy
  - or you do have government funds to build such a thing on-prem
  - or you’re just raising money from VC by building hype/FOMO/FUD or whatever tool :crab:

6. you can use an actual deterministic software tool to get a problem solved with _old school_ tech, no AI fanciness
7. you realize that rather than pouring (M/B/T)-illions :money_with_wings: into some nonsense, you could have maybe just hired a professional freelance or team to solve/create/build the actual thing rather than brute-forcing it with the wrong approach whatsoever

So…given all of this. On which level are we talking here?  
I’m not sure how/why you would use [GLM-5](https://z.ai/blog/glm-5) in a personal context[[3]](#footnote-140279-3) because again:

- if it’s for work, your thing being code, automation or whatever probably doesn’t need to be private
- if it’s for personal use, I mean idk what are your “needs” with that kind of stuff, but hey feel free to enlighten me on what I’m missing out on here :grinning_face_with_smiling_eyes:
- business? you should have the money for that kind of hardware/infra because you did some market study and know you can succeed

The last point is definitely something that you can pay 15k€/month, just one business expense like any other that you will turnover by selling something to offset that cost. :+1:t2:  
For other needs, self-hosted or paying for Anthropic/whatever will do just fine.

> So the realistic choice for most people who actually need capable AI for work is: spend thousands on hardware for a self-hosted setup that still can’t match frontier models

AI is unfair.  
Might not be needed.  
If it’s a **need** , pay for it or accept it not being 100% private.  
Not all kind of work is compatible, no magic solution either, what do you want me to say here? :man_shrugging:t2:

For some reason, people 3 years ago were still able to do their job just fine.  
What have changed? Curious to know in which field AI is gamebreaker if not used.

Even nowadays, some people still “ **NEED** ” to have a Bugatti to show up at a client’s meeting to sell them a house.  
Others just do fine without any and drive their old rusty Ford.  
Not sure how they manage those poor people without a fancy car, guess they just found ways without. :face_savoring_food:

* * *

> [@wildcat253](#):
>
> Come on mate. That’s just condescending. We don’t need any of that here

Didn’t meant it in that way. :light_blue_heart:  
I’ve just been a victim myself of FOMO/FUD from Twitter where I felt like I was missing out and needed something. Taking a detox cleared up my mind and I don’t really care nor am sad about any of this “gold rush”.

I mostly realized that if you’re exposed for long enough to some stuff, you then kinda start thinking like it is an actual need. While nah, it’s just daily brain-washing that gets into your brain. Hence why I was feeling like asking to take a step back and rethink if you couldn’t achieve your job without spending thousands on a VPS. :mending_heart:

Like I’m no Bezzos either but eh, the whole thing is just Web3/NFT nonsense back again to me, quite an obvious one. I’m not into get-rich-quick scheme either, just learned how to distance myself from all of that. :grin:

> [@wildcat253](#):
>
> I use AI for work daily. Not because marketing brainwashed me, but because my workflow genuinely benefits from it and in some cases it’s pretty much required to reach goals

Same here, I’m a Developer during work hours so I basically am forced to use it for productivity reasons as of lately. :grinning_face_with_smiling_eyes:  
I don’t really care about privacy in the context of working on a company’s codebase tho.  
Like realistically what’s my threat model or ownership on a company owned laptop? :joy:

> [@wildcat253](#):
>
> So new startups deserve the benefit of the doubt and patience… unless they’re in the AI space?

It was quite new to me and I found it funny.  
Never told anybody to buy anything or alike.  
I didn’t buy anything myself because I don’t need that but could maybe be useful/fun for others?  
Meanwhile yes, having a scarf or fancy hacker hoodie is less of a problem: I consider that wearing organic cotton as a lesser evil than uploading data to some startup.

Is it BS? Maybe, I don’t really care that much.  
I will still be able to wear and use it offline while feeling like a sexy boomer. :joy:

> [@wildcat253](#):
>
> with this thread before it turned into a lecture about how nothing matters because everyone is bad

Was never my intention.  
I mostly explained why I felt like the Venn diagram of privacy + cheap-enough + ownership is a weird need to have. But hey, maybe I’m just stranger to how AI impacted some jobs.

* * *

> **Regarding myself personally**
>
> I won’t comment or explain my own choices to a new account, not worth my time.  
> 95% of my thoughts are already online publicly and you can investigate further if you wish to have some answers to your criticism regarding my own choices, answers to them are out there already. :slightly_smiling_face:  
> No need to link my own posts tho :laughing:, I’m very well aware of what I’m saying and cautious of what I’m typing on my computer, yet not hiding lots.
> 
> Wouldn’t share it on a public crawl-able forum otherwise.

* * *

1. from what I saw, almost everybody has an amazing product that solves some concrete problems [↩︎](#footnote-ref-140279-1)

2. you asked for opinions after all, feel free to disagree :grinning_face_with_smiling_eyes: [↩︎](#footnote-ref-140279-2)

3. assuming you do not do anything shady [↩︎](#footnote-ref-140279-3)

---

## Post 42 by @wildcat253 — 2026-02-18T20:05:32Z

I’ll try to be structured about it because there’s a lot to unpack here and I want to be fair and objective. I’m sorry if you think I’m not always achieving that :heart:. I like to believe you want to actually help me and I am thankful for that :heart: even though I have to remark some of your comments feel a bit immature.

> So it’s not specifically about how long you’ve been alive but it’s also about what you did in that timeframe.

Fair point and I agree. But you’re kind of making my argument for me here? Chutes has a working product on [OpenRouter with 19 models available](https://openrouter.ai/provider/chutes), processing hundreds of billions of tokens monthly (855.1 billion tokens in the last 30 days) . This makes them bigger than competitors you probably know like Mistral, Grok, DeepSeek, Azure, Cerebras etc. They have a [public GitHub org](https://github.com/chutesai), named team members with defined roles, published architecture docs, and they’ve been shipping consistently since 2024. That’s not “bold claims + abstract futuristic starter pack visuals.” That’s a working product at scale with measurable output. You can disagree with their approach but pretending they haven’t _done anything_ in their timeframe is just not accurate.

> Meanwhile, when I do visit chutes.ai, I am greeted with this amazing stack of tracking in every direction.

I mean yeah, fair criticism on the tracking. I’d love to see them clean that up and it’s a very valid thing to point out on a privacy forum. But judging a backend AI inference platform’s privacy posture by their marketing website’s tracker count is like judging the security of BitWardens Password Manager by checking if their website includes trackers (Spoiler: It does). The product is the API and infrastructure, not the landing page. Their frontend dev should fix it, sure, but it doesn’t tell you anything about how they handle your inference data.

> trust me bro, we really do not train on any personal data fr fr

Look, I get the skepticism on “trust me bro” claims. But you’re selectively ignoring the actual technical mechanisms I’ve been talking about this entire thread. I’m starting to wonder if you just don’t understand them. TEE/confidential compute isn’t a tweet. It’s a hardware-enforced isolation boundary that even the provider can’t peek into (if implemented correctly of course). Chutes themselves literally list “TEE/Secure Compute” as a product category. You can evaluate the _implementation_, sure, but dismissing the entire concept as “trust me bro” is intellectually lazy when the whole point of TEE is that you _don’t_ have to trust the operator.

> Let’s assume it’s correct, so then…how about their sustainability?

This is actually the first solid point you’ve made imo. Sustainability and business model matter for any provider you depend on. But Chutes isn’t running on kofi donations. Once again I don’t know where you got that from… Sometimes it seems like you’re making arguments without even thinking just for the sake of it. They operate as Bittensor’s top subnet (Subnet 64), with multiple revenue streams: subscription tiers (Base, Plus, Pro, Enterprise), pay-as-you-go per-token billing via TAO or fiat, invoiced enterprise clients, and private compute instances. Revenue is auto-staked back into the network to reward the GPU miners who provide the compute. It’s a decentralized compute marketplace, not a VC-funded “move fast and figure out monetization later” play. You’d know this if you spent 5 minutes looking into how they actually work instead of assuming they’re a scam because their website uses shadcn. And yes, the site looks like a mass produced shadcn template. You know what that tells you? That the people building it are probably backend and infra engineers, not designers. Anyone who’s worked in IT knows the meme: when a frontend dev goes fullstack nothing works, when a backend dev goes fullstack the website looks like shit or very basic. Chutes is clearly the latter. The infrastructure works, the API works, the models work. The marketing site looking generic is the most backend-engineer thing imaginable. But I get it, if you judge tools by how pretty their landing page is rather than what’s running under the hood, I can see how you’d end up skeptical. Not everything that shines is gold though, and not everything that looks plain is worthless.

> I’m not sure how/why you would use GLM-5 in a personal context

You built this entire argument around my GLM-5 example as if I said everyone needs to run it locally??? Whats going on? I was making a _cost analysis point_ to show that the “just use a VPS” advice you **keep casually tossing around** falls apart once you need anything beyond a toy model. You yourself acknowledge “AI is unfair” and “if it’s a need, pay for it.” Great, so then we agree that for capable models, people need cloud providers, and evaluating _which_ cloud provider has better privacy practices is exactly the kind of conversation a privacy forum should be having. Which is literally what I started this thread to do before you derailed it into “everything is equally bad so why bother.”

And honestly, I’m getting tired of having to argue _for_ a company I’m not even entirely sold on myself. I’m still skeptical about Chutes. I came here to have that conversation, to poke holes, to evaluate them critically. But when the counter-argument is just “everything is a scam, nobody cares, don’t even bother looking” then I end up defending them by default just to push back against the doomerism. That’s not a productive dynamic. I was taught growing up that if you don’t have anything constructive to add, it’s better to just not say anything. I came here looking for actual technical feedback on AI privacy, threat models, provider comparisons, implementation analysis, and instead got paragraphs of philosophical doomerism about how the whole field is a VC scam. That’s a lot of time spent writing to essentially say and do nothing useful (by both of us).

> For some reason, people 3 years ago were still able to do their job just fine. What have changed?

According to the [U.S. Bureau of Labor Statistics](https://www.bls.gov/opub/ted/2025/ai-impacts-in-bls-employment-projections.htm), software developer employment is projected to grow 17.9% through 2033, with AI cited as both a driver of demand and a key productivity tool. The [World Economic Forum](https://www.weforum.org/stories/2026/01/software-developers-ai-work/) (small side note: fucking hell what is this timeline where I’m citing WEF) reports 65% of developers expect their role to be redefined in 2026 toward architecture and AI-enabled decision-making. The Stanford AI Index 2025 [documents consistent 10-25% performance gains](https://www.knowledgeworker.com/en/blog/ai-in-the-workplace-in-2025) across knowledge tasks like writing, research, and programming. These aren’t marketing claims, they’re labor economics data. Three years ago people did their jobs fine without these tools. Doesn’t mean they’re not genuinely useful now.

> Even nowadays, some people still “NEED” to have a Bugatti to show up at a client’s meeting

The Bugatti analogy doesn’t land mate. A Bugatti and a Ford both get you to the meeting. A 7B quantized model running on a €184/month Hetzner GPU and a SOTA model are not comparable outputs. One regularly hallucintes on basic tasks and the other can do complex multi-step reasoning, code generation, and analysis that actually matches the quality bar my work requires. This isn’t vanity, it’s a capability gap. You as a developer should understand this better than most (and I’m pretty sure probably do but yeah)

> I mostly realized that if you’re exposed for long enough to some stuff, you then kinda start thinking like it is an actual need.

And I mostly realized that the same logic applies to privacy nihilism. If you’re exposed for long enough to “everything is a scam, nobody cares about your privacy, all companies are equally awful,” you start thinking evaluating anything is pointless. That’s not healthy skepticism, that’s [learned helplessness](https://en.wikipedia.org/wiki/Learned_helplessness). And it’s exactly the mindset that benefits the companies that actually _are_ terrible, because if nobody evaluates the differences, the worst actors face no competitive pressure to improve.

> I won’t comment or explain my own choices to a new account, not worth my time. 95% of my thoughts are already online publicly and you can investigate further if you wish

So let me get this straight. You spend multiple posts scrutinizing Chutes’ website trackers, their team size, their business model, their shadcn starter pack, their Vercel hosting, their VC funding, and their Twitter presence. But when someone applies the same level of scrutiny to _your_ publicly available posts, suddenly it’s “not worth my time” and “no need to link my own posts”? Then again you literally tell me to “investigate further if you wish” and that your “answers are out there already.” What I found is a pattern of double standards that I think is worth addressing, because it directly undermines the arguments you’re making in this thread.

You don’t get to put someone else’s entire operation under a microscope and then wave away your own contradictions with “I’m very well aware of what I’m saying.” Being aware of your contradictions doesn’t make them less contradictory (but realizing your mistakes is a good first step). If a company you don’t like would do that you’d probably jump at the chance of critizing them.

Your choices _are_ publicly visible so I’ll just note once again what anyone can see: you [run a Mac Studio, stream on YouTube, speak at Google tech conferences](https://discuss.privacyguides.net/t/how-to-livestream-without-doxxing-yourself/34380), use Brave (which has Leo AI built in, you might have disabled that though), and you’re [considering Cursor](https://discuss.privacyguides.net/t/how-to-livestream-without-doxxing-yourself/34380), an AI-powered code editor that sends your code to cloud LLMs for inference, and your previous screenshot is made by CleanShot which is afaik only available for macOS. All while telling me that everyone who finds AI useful has been brainwashed by marketing, and that Google/Apple/Microsoft are all “equally awful.” You don’t owe me an explanation, but the contradiction speaks for itself.

And the startup double standard is still there, and it’s actually worse than I originally thought after looking more into it. You dismiss Chutes as a “random no-name startup” that can’t be trusted. I have to say it once again but when you [shared urban-privacy.com](https://discuss.privacyguides.net/t/urban-privacy/33925) on this forum, a company selling anti-facial-recognition clothing with zero peer-reviewed testing data and no published validation against modern FR systems, your response to criticism was “let’s be patient and not kill them already” and “let’s assume their intentions are honest.” This is a company that [literally markets their OFLAIN bag to people worried about being tracked at protests](https://urban-privacy.com/collections/abschirmende-handytaschen-fur-dein-digital-detox/products/oflain-v2-the-anti-tracking-smartphone-bag), telling them basically “Worried of being trackable – even at protests? Put an end to it!” for €115. They’re selling unproven counter-surveillance products to potentially vulnerable people: protesters, activists, journalists, people in countries where facial recognition is used to [identify and arrest dissidents](https://restofworld.org/2024/facial-recognition-government-protest-surveillance/). If that anti-FR clothing doesn’t actually work (and nobody has proven it does), someone at a protest trusting it could face very real consequences. You probably heard what’s happening to protesters in countries like Iran. The stakes for protesters are arguably _higher_ than a cloud AI inference provider, because the failure mode is physical danger, not data exposure. And yet that startup gets “let’s be patient” and “assume honest intentions” while Chutes, which has a working, measurable product processing hundreds of billions of tokens, gets “random no-name scam.” How does that double standard work exactly?

Oh and since you brought up the chutes.ai tracker screenshot: [urban-privacy.com runs on Shopify](https://urban-privacy.com/), which [comes bundled with its own analytics tracking, third-party cookies, and Google integrations by default](https://www.shopify.com/legal/cookies) :slight_smile:

> Was never my intention.

I believe that. But the end result is the same: multiple long posts that amount to “everything is bad, AI is a scam, you’re brainwashed if you disagree, and nobody has a solution so just accept it.” That’s not actionable. That’s not useful for someone coming to a privacy forum trying to make informed choices.

If you genuinely think everything is equally hopeless, I respect that perspective, but I’m not sure what value it adds to a thread specifically asking “how do I use AI more privately.” That’s like going into a thread about what encrypted email prodiver to use and writing an essay about how email itself is fundamentally broken. Nobody asked for that.

Nuance over nihilism. That’s all I’m asking for :frowning:
