3.8 KiB
Models
The co-op serves models from multiple providers. This is the single list — both the chat and the API draw from it, so it's the one place to look (and the one place to update).
Providers
Models are named provider/model-name, so you can choose not just which model
but where it runs. Providers differ along two independent axes: privacy
(how protected your prompts and responses are) and green energy (how the
compute is powered). These are gradations, not binary switches — and no
provider today is best on both.
| Provider | Value | Privacy | Green energy | What that means |
|---|---|---|---|---|
| Tinfoil | private | Strongest — architectural | Not a green claim | Runs in hardware enclaves (TEEs) with end-to-end encryption (EHBP), verifiable via remote attestation. Neither we nor Tinfoil can read your prompts or responses at inference time. Energy mix is not disclosed. |
| GreenPT | green | Policy-based | Strongest — 100% renewable | Standard (non-enclave) hosting in the EU; privacy rests on GreenPT's commitments and EU data rules, not on cryptography. Compute runs on 100% renewable energy. |
| PublicAI | public | (to be confirmed) | (to be confirmed) | Coming soon — publicly developed models. Details pending. |
Reading the gradations:
- Privacy: architectural (Tinfoil) beats policy-based (GreenPT). An enclave protects you even if the provider is compromised; a policy protects you only as far as the provider keeps its word. Both are better than a provider with neither.
- Green energy: 100% renewable (GreenPT) beats undisclosed (Tinfoil). GreenPT reports its energy mix; Tinfoil does not, so we can't claim greenness for it — it may or may not be renewable.
Trade-offs are real: the most private option (Tinfoil) isn't the greenest, and the greenest option (GreenPT) isn't the most private. The point of the co-op is that you choose which axis matters more for a given task.
Current models
Pricing is per 1 million tokens, input / output (what the co-op pays the provider — your own cost is your monthly allowance, not per-token billing).
| Model | Provider | Privacy | Green energy | Pricing (in / out) | Notes |
|---|---|---|---|---|---|
tinfoil/deepseek-v4-1-flash |
Tinfoil | architectural | undisclosed | $0.65 / $1.45 | Default; best for agentic tasks (1M context, tool calling). |
tinfoil/gpt-oss-120b |
Tinfoil | architectural | undisclosed | $0.15 / $0.60 | Lightweight fallback. |
tinfoil/glm-5-3-flash |
Tinfoil | architectural | undisclosed | $0.40 / $1.25 | Fast, efficient MoE model. |
greenpt/green-r |
GreenPT | policy | 100% renewable | $0.35 / $0.95 | Reasoning, renewable energy. |
greenpt/green-l |
GreenPT | policy | 100% renewable | $0.25 / $0.80 | Lightweight, renewable energy. |
greenpt/glm-5.3-flash |
GreenPT | policy | 100% renewable | $0.11 / $0.44 | Fast GLM model, renewable energy. |
Some models also have a discounted cached-input rate (when a prompt is reused
and doesn't need to be re-read) — see the code/litellm config for the exact
numbers. Pricing here mirrors the model_info in the LiteLLM config
(code/litellm/config.yaml), which is the authoritative source — the two are
kept in sync.
Limitations on privacy
Only Tinfoil offers architectural privacy. The other providers are chosen for their value (renewable energy, public models) but do not run in enclaves — prompts and responses pass through them in the ordinary way. Your chat history is also stored on our server so you can revisit it, and that stored history is not encrypted in a way that prevents us from technically reading it — we commit not to. The full distinction — what's architecturally private versus what's a policy commitment — is in the Privacy Policy.