$ techbeacon▋
Threats

Research Reveals GPT4Free Routes User Prompts Through Third-Party Servers, Raising Privacy Concerns

Research Reveals GPT4Free Routes User Prompts Through Third-Party Servers, Raising Privacy Concerns

Independent investigators have uncovered that the GPT4Free service, which advertises direct access to OpenAI's language models via its web portal, actually forwards user inputs through a layered chain of external code providers before reaching the AI backend. The discovery suggests that personal prompts may be exposed to entities beyond the intended model host.

The analysis, initially reported by the security community GBHackers, traced the data flow from the public interface at g4f.dev to a series of intermediary scripts hosted on third‑party domains. These scripts act as proxies, relaying the text to the model and then returning the generated response. While the architecture enables the platform to offer a free interface, it also creates multiple points where the content can be intercepted, logged, or otherwise processed without the user’s explicit consent.

Privacy experts warn that such hidden routing can compromise sensitive information, especially when users employ the tool for drafting confidential documents, coding assistance, or personal queries. Because the intermediary services are not publicly disclosed, users have limited visibility into who might be storing or analyzing their prompts. Moreover, the research identified residual log files on some of the proxy servers, indicating that prompt data may be retained for undefined periods.

The findings arrive amid growing scrutiny of AI‑powered applications that operate under “free” models. Regulators in several jurisdictions are evaluating whether existing data‑protection frameworks, such as the EU’s GDPR, adequately cover the indirect data handling practices observed in services like GPT4Free. Companies offering AI access without clear disclosure of data pathways could face legal challenges if they fail to obtain informed consent or to provide mechanisms for data deletion.

In response, the maintainers of GPT4Free have issued a brief statement acknowledging the technical complexity of their setup and pledging to improve transparency. They assert that the third‑party components are employed solely to route traffic efficiently and that no personal data is sold or used for advertising. However, the research community recommends that users treat the platform as a public forum and avoid sharing proprietary or personally identifiable information until clearer safeguards are in place.

Going forward, security analysts suggest that independent audits and open‑source verification could help restore confidence in free AI interfaces. Meanwhile, users seeking guaranteed privacy may opt for direct subscriptions to official model providers or self‑hosted alternatives that eliminate reliance on undisclosed intermediaries.

Source: GBHackers
Rakesh Meena — Rakesh tracks CVEs, zero-days, and exploit disclosures as they break, translating advisories into plain-language impact analysis. Background in vulnerability research, follows NVD and vendor bulletins closely.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related