diff --git a/README.md b/README.md index fc16083..719a787 100644 --- a/README.md +++ b/README.md @@ -65,7 +65,14 @@ Because Tinfoil requires EHBP-encrypted request bodies (it rejects plaintext wit Members govern the project through [Loomio](https://www.loomio.com) and the Open Collective. See the [Charter](charter.md) for the cooperative's values, membership terms, and governance structure, and [Open Questions](open-questions.md) for the decisions currently open for member discussion. -During the pilot phase, Nathan Schneider serves as Managing Director and has sole final discretion on decisions. +During the pilot phase, Nathan Schneider serves as Managing Director and has sole final discretion on decisions. + +## Legal + +- [Terms of Service](terms-of-service.md) — the agreement between the cooperative and its members about the service. +- [Privacy Policy](privacy-policy.md) — how we handle your data, including what we can and can't see. + +By creating your account, you agree to these terms. --- diff --git a/privacy-policy.md b/privacy-policy.md new file mode 100644 index 0000000..30cba09 --- /dev/null +++ b/privacy-policy.md @@ -0,0 +1,83 @@ +# Privacy Policy + +**Last updated:** September 10, 2026 + +## In plain language + +- We collect only what we need: your email, name, and basic usage data. +- **Your AI conversations are encrypted** — even we can't read them at the inference step. +- We **do** store your chat history on our server (so you can revisit it). We promise not to read it, but this is a promise, not a technical guarantee. +- We never train on your data, and we never sell it. +- You can export or delete your data at any time. + +The full policy is below. Questions? info@inference.coop. + +--- + +## 1. Our privacy philosophy + +The Inference Cooperative is a member-governed cooperative. We are **not** an ad-supported or data-extractive business — we have no incentive to read or sell your data. Privacy is a structural value, built into how we operate. + +## 2. What we collect + +- **Account data:** your email and name (from Open Collective). +- **Membership data:** your contribution status and role. +- **Usage data:** token counts, model used, and timestamps (for metering your monthly budget). +- **Content:** your prompts and the AI's responses (stored in your chat history). +- **Billing data:** handled by Open Collective — we do not see full payment details. + +## 3. What we *can't* see (architectural privacy) + +Inference runs inside **encrypted enclaves** (TEEs). Your model inputs and outputs are encrypted end-to-end, so **even our own infrastructure cannot read them at the inference step.** This is verifiable through remote attestation — it's a property of the system, not a promise. + +## 4. What we *can* see (an honest caveat) + +Your **chat history is stored on our server** so you can revisit past conversations. Unlike the inference step, stored chat history is **not** encrypted in a way that prevents us from technically reading it. + +We commit not to read it. But this is a **policy commitment**, not an architectural guarantee. We're transparent about this distinction because it matters. + +## 5. Search + +Web search runs through our self-hosted search instance. Search queries are forwarded to the underlying search engines (e.g. DuckDuckGo), which may see them. This is inherent to how web search works. + +## 6. What we do NOT do + +- We do **not** train models on your data. +- We do **not** sell, rent, or share your data. +- We do **not** use your data for advertising or profiling. + +## 7. Third parties + +- **Tinfoil** — provides encrypted inference (cannot read your content). +- **Open Collective** — handles billing and membership (their own privacy policy applies). +- **Cloudron** — our self-hosted platform; no third-party cloud provider. +- **Search engines** — receive your search queries (see §5). + +## 8. Retention and deletion + +- Chat history is retained until you delete it. +- On leaving, your account is deactivated (data preserved for reactivation). +- You may request full deletion at any time: info@inference.coop. + +## 9. Security + +- Self-hosted on Cloudron (sandboxed apps, SSL, backups). +- Per-member API keys; access gated on live membership. +- No external dependencies for core infrastructure. + +## 10. Your rights + +- **Access, correct, export, and delete** your data. +- As a member, you also have **governance** rights over this policy itself (through Loomio). + +## 11. Children + +The service is for people **18 and older**. We do not knowingly collect data from children. + +## 12. Changes + +We may update this policy as the cooperative evolves. Material changes are announced to members and, where appropriate, decided through Loomio. + +## 13. Contact + +**info@inference.coop** diff --git a/terms-of-service.md b/terms-of-service.md new file mode 100644 index 0000000..fff0f78 --- /dev/null +++ b/terms-of-service.md @@ -0,0 +1,93 @@ +# Terms of Service + +**Last updated:** September 10, 2026 + +## In plain language + +- You are a **member**, not a customer. You own and govern this cooperative. +- We provide **private AI chat** through open models, protected by encryption. +- You keep ownership of what you write and what the AI produces. +- We don't train on your data, and we don't sell it. +- AI can be wrong. Use your judgment. +- If you misuse the service, we may remove you (per our Charter). +- Our liability is limited to what you've paid in dues. + +The full terms are below. If anything is unclear, write to info@inference.coop. + +--- + +## 1. Who we are + +The **Inference Cooperative** ("we", "us") is a member-governed cooperative providing private AI inference. We are fiscally sponsored by **Metagov**, a nonprofit that provides our financial and legal services. + +When you join, you become a **member** — an owner with a voice in how the cooperative is run — not a customer of a vendor. + +## 2. Membership + +- Membership is through **Open Collective**, where you pay dues on a sliding scale. +- You must be **18 or older** to join. +- Membership is governed by our [Charter](charter.md), including our Code of Conduct. +- We may suspend or remove membership for Code of Conduct violations or non-payment, as described in the Charter. + +## 3. The service + +We provide: + +- **Private AI chat** through open-source models, served through encrypted (TEE-protected) infrastructure. +- **Web search** and **file uploads** within the chat interface. +- **Governance** — a seat in decisions about models, pricing, and direction. + +The service is provided **"as is"** and may change as the cooperative evolves. We do not guarantee uptime or specific performance at this stage. + +## 4. Acceptable use + +You agree not to: + +- Use the service for anything illegal. +- Harass, abuse, or harm others. +- Attempt to circumvent usage limits or the privacy architecture. +- Share your account credentials or resell access. +- Use the service to generate content that violates our [Code of Conduct](charter.md). + +## 5. Usage limits + +- Membership includes a **monthly credit budget** (currently $15 of usage). +- When your budget is exhausted, requests pause until the next cycle. +- The pricing and budget model is itself a governance decision — members can change it through Loomio. + +## 6. Your content + +- You **own** your prompts and the AI's outputs. +- We do **not** train models on your data. +- We do **not** sell or share your content. +- See our [Privacy Policy](privacy-policy.md) for how your data is handled. + +## 7. Privacy + +Your privacy is a core value, not an afterthought. Inference runs in encrypted enclaves so that even our own infrastructure cannot read your model inputs and outputs at the inference step. Details are in the [Privacy Policy](privacy-policy.md). + +## 8. Termination + +- You may leave at any time by cancelling on Open Collective. +- On leaving, your account is deactivated (data preserved for reactivation). You may request full deletion. +- We may remove members per the Charter (Code of Conduct, non-payment). + +## 9. Governance + +- Decisions are made through **Loomio** and governed by the [Charter](charter.md). +- During the pilot phase, the General Manager holds final discretion; this transitions to full member governance as the cooperative grows. + +## 10. Disclaimers and liability + +- **AI outputs may be inaccurate or inappropriate.** We provide no warranty of correctness. Use your judgment. +- To the maximum extent permitted by law, our liability is limited to the amount of dues you have paid. +- As a cooperative, members are not personally liable for the cooperative's obligations. + +## 11. Changes to these terms + +- We may update these terms as the cooperative evolves. +- Material changes are announced to members and, where appropriate, decided through Loomio. + +## 12. Contact + +**info@inference.coop**