Removed numerical ordering, added privacy/convenience question

This commit is contained in:
inference-admin committed 2026-09-09 23:36:52 +00:00
1 parent 483962a4fa
commit 6b7c33c152
1 file changed
+16 -16
+16 -16
View File
@@ -6,7 +6,7 @@ A living list of decisions the cooperative needs to make. Each question is frame
## Privacy & Infrastructure
### 1. Search: self-managed or Tinfoil's encrypted search?
### Search: self-managed or Tinfoil's encrypted search?
We currently run our own [SearXNG](https://searxng.github.io/searxng/) instance (`search.inference.coop`) to power web search in the chat. Tinfoil also offers a `websearch` model — a private, encrypted search that runs inside their enclave.
@@ -15,7 +15,7 @@ We currently run our own [SearXNG](https://searxng.github.io/searxng/) instance
**Question:** Do we prioritize self-hosting (control, no external deps) or encrypted search (stronger privacy, but a dependency on Tinfoil)?
### 2. Green energy vs. privacy — when we can't have both?
### Green energy vs. privacy — when we can't have both?
Our inference runs through Tinfoil (TEE-protected, verifiable privacy), but Tinfoil's energy mix is not disclosed. Self-hosting on renewable-powered hardware (e.g. Hetzner hydropower, Scaleway wind+hydro) would be greener but would lose the TEE privacy guarantee at our current scale.
@@ -24,23 +24,29 @@ Our inference runs through Tinfoil (TEE-protected, verifiable privacy), but Tinf
**Question:** When the two conflict, which value wins? Is there a threshold (e.g. member count, cost) at which we'd switch?
### 3. Should we adopt Tinfoil's other models (embeddings, private search, audio)?
### Should we adopt Tinfoil's other models (embeddings, private search, audio)?
Tinfoil's catalog includes `nomic-embed-text` (embeddings), `websearch` (private search), and audio models (Whisper, TTS). We currently use Open WebUI's bundled local embedding model for file uploads.
**Question:** Do we standardize on Tinfoil for all model needs (consistency, privacy), or keep the local embedding model (no per-token cost, no dependency)?
### 3b. Which models should we offer?
### Which models should we offer?
We currently expose three chat models: DeepSeek V4 Flash (default), GPT-OSS 120B, and GLM-5.3 Flash. Tinfoil's full catalog also includes GLM-5.3 (full), Kimi K3, Llama 3.3 70B, Gemma 4 31B, and others.
**Question:** Which models should members have access to? Should we offer a curated few (simpler, cheaper, easier to govern) or the full catalog (more choice, but more cost and governance overhead)? Who decides when to add or remove a model — the General Manager, or members via Loomio?
### Should personal data be collectively or individually managed?
Currently chat history is stored on co-op servers. We could potentially switch to storing it in browser cache, which would be more private but less convenient. How do we balance privacy and convenience?
### Should we prioritize running and owning our own infrastructure, or are we comfortable collectively buying tokens from others?
---
## Pricing & Fairness
### 4. How should pricing account for unequal usage?
### How should pricing account for unequal usage?
Members currently pay a flat $15/month for a $15/month credit budget. But usage is unequal — some members use far more tokens than others.
@@ -51,7 +57,7 @@ Members currently pay a flat $15/month for a $15/month credit budget. But usage
**Question:** What pricing model best balances fairness, simplicity, and the cooperative's solidarity values? How do we handle a member who consistently exceeds their budget?
### 5. What happens when a member's budget runs out mid-month?
### What happens when a member's budget runs out mid-month?
Currently LiteLLM enforces the $15 budget cap — requests stop when it's exhausted.
@@ -61,35 +67,29 @@ Currently LiteLLM enforces the $15 budget cap — requests stop when it's exhaus
## Governance & Membership
### 6. What does "member-governed" mean in practice before 50 members?
### What does "member-governed" mean in practice before 50 members?
The charter says the General Manager (Nathan) has full governance until 50 members, then transitions to member governance. But members can already deliberate on Loomio.
**Question:** Which decisions should be opened to member input *now* (even if non-binding), versus reserved for the General Manager during the pilot?
### 7. How do we handle institutional members?
### How do we handle institutional members?
AI Potluck's "government-as-contributor" framing suggests a path for institutions (universities, municipalities) to contribute compute or data without owning the whole.
**Question:** Should we create an institutional membership tier? What would institutions contribute, and what would they get?
### 8. What's our stance on the "coalition vs. cooperative" question?
We're a cooperative (member-owned, formal bylaws, accountable). AI Potluck is a coalition (no single owner, maximally resilient, but no one to hold accountable).
**Question:** Is the cooperative model the right long-term structure, or should we explore hybrid forms (e.g. a cooperative that federates with other co-ops)?
---
## Values & Product
### 9. Should we adopt "provenance transparency" as a product feature?
### Should we adopt "provenance transparency" as a product feature?
AI Potluck commits to "every response shows its provenance: the model, the organization, the compute, the country." We could surface which model served each response (already possible via LiteLLM).
**Question:** Is this worth building? What's the right level of transparency without cluttering the chat?
### 10. Should we articulate an "anti-engagement" stance?
### Should we articulate an "anti-engagement" stance?
AI Potluck explicitly rejects the extractive engagement model ("AI that wants you to turn it off," "doesn't sell you sycophancy"). A cooperative has no engagement-maximization incentive — a structural advantage.