GPT4Free’s hosted chat service, g4f.dev, has sparked privacy concerns following a research discovery that user prompts traverse multiple providers, third-party endpoints, and logging systems that are not transparently disclosed to users. The open-source project allows users to select branded models from various providers, such as OpenAI, Google, Anthropic, and others, through a single interface, often without separate accounts at those companies. However, a Gen Threat Labs investigation revealed that the name selected in the menu may not accurately identify the system that ultimately processes and handles the request, leading to uncertainty about processing, retention, and accountability.

GPT4Free Privacy Risks Expose AI Prompts Google’s “latest” aliases can alter a model variant, but Vojtěch Moravec pointed out that this approach didn’t account for specific requests labeled Gemini Pro or Gemini Omni, which returned models/gemini-3-flash-preview. The provider's metadata included GPT4Free workers alongside domains and infrastructure linked to organizations or unrelated services, without explaining ownership, consent, or the endpoint's relationship to the platform. Toolbaz provider recreates the expected browser exchange (Source: gendigital) Toolbaz presents ToolBaz-v4.5-Fast as a proprietary model distinct from GPT-5.2, leaving the underlying technology unresolved but demonstrating that GPT4Free’s displayed label may diverge from response metadata.

Code includes 14-day retention for usage logs and 30-day retention for error logs; usage fields include IP address, geolocation, provider, model, and conversation data.