Files
docs/models.md
T

2.2 KiB

Models

The co-op serves models from multiple providers. This is the single list — both the chat and the API draw from it, so it's the one place to look (and the one place to update).

Naming

Models are named provider/model-name, so you can choose not just which model but where it runs. The provider part tells you the value it stands for:

Provider Value What it means
Tinfoil private Models run inside hardware enclaves (TEEs), and requests/responses are encrypted end-to-end (EHBP), so neither we nor the provider can read your prompts or responses. Verifiable via remote attestation.
GreenPT green Models served on 100% renewable energy in the EU. Cleaner energy, but standard (non-enclave) hosting — privacy here is a policy commitment, not architectural.
PublicAI public (coming soon — publicly developed models.)

Current models

Model Provider Value Notes
deepseek-v4-1-flash Tinfoil private Default; best for agentic tasks (1M context, tool calling).
gpt-oss-120b Tinfoil private Lightweight fallback.
glm-5-3-flash Tinfoil private Fast, efficient MoE model.
greenpt/green-r GreenPT green Reasoning, renewable energy.
greenpt/green-l GreenPT green Lightweight, renewable energy.

Note: the three Tinfoil models currently use their bare names (no tinfoil/ prefix). They'll be renamed to tinfoil/deepseek-v4-1-flash and so on in an upcoming change — we'll email members before that happens. GreenPT models already use the greenpt/ prefix.

Limitations on privacy

Only Tinfoil offers architectural privacy. The other providers are chosen for their value (renewable energy, public models) but do not run in enclaves — prompts and responses pass through them in the ordinary way. Your chat history is also stored on our server so you can revisit it, and that stored history is not encrypted in a way that prevents us from technically reading it — we commit not to. The full distinction — what's architecturally private versus what's a policy commitment — is in the Privacy Policy.