GPT4Free Privacy Risks Expose AI Prompts to Third-Party Servers and Hidden Logs
Brief
GPT4Free’s hosted chat service, g4f.dev, is facing privacy questions after researchers found that user prompts can move through multiple providers, third-party endpoints, and logging systems that are not clearly disclosed to visitors.
The open-source project lets users select branded models associated with OpenAI, Google, Anthropic, and others from a single interface, often without separate accounts at those companies.
However, a Gen Threat Labs investigation found that the name selected in the menu may not reliably identify the system that ultimately handled a request, creating uncertainty over processing, retention, and accountability.
Tests involving options labeled as Gemini showed requests passing through an OpenAI-compatible endpoint at g4f. space before reaching Google infrastructure. In some cases, the returned model identifier did not match one chosen in GPT4Free.
