The controller responsible for this website within the meaning of Art. 4 No. 7 GDPR is the private operator of the GPT4Free project (a privately hosted developer located in Germany). Because this is a non-commercial private project, no postal address is published here in accordance with § 5 (3) TMG / Art. 30 (2) GDPR considerations for small-scale processing. You can reach the controller at any time via the community page: g4f.dev/community.
| Data | Purpose | Legal basis (GDPR) | Retention |
|---|---|---|---|
| Server log files (IP address, time, requested URL, user agent) | Technical provision of the website, abuse and attack prevention | Art. 6 (1) lit. f GDPR (legitimate interest in secure operation) | Automatic deletion after max. 14 days |
| Local storage entries in your browser (settings, conversations, preferences) | Saving your settings and chat history on your own device | Art. 6 (1) lit. f GDPR / § 25 (2) TDDDG (technically necessary, in your sole control) | Until you delete them in your browser or in the chat settings |
| Prompts and uploaded files that you send in /chat/ | Forwarding to the selected or automatically chosen AI provider to generate a response | Art. 6 (1) lit. a GDPR (consent — requested before first use) | Not permanently stored by us; short-term excerpts for abuse prevention max. 14 days (see below); forwarding see section 4 |
| Optional member session (only if you actively log in) | Authentication for quota features | Art. 6 (1) lit. b GDPR | Until logout / session expiry |
| Account data of optional member accounts (e.g. login identifier, quota status, ban status) | Authentication, provision of quota features, enforcement of bans and abuse prevention | Art. 6 (1) lit. b / lit. f GDPR | At least 90 days after last use or deletion, so that bans and quota abuse remain traceable |
| Usage logs (IP address, time, request patterns) | Detecting multiple accounts, quota abuse and attacks | Art. 6 (1) lit. f GDPR | Automatic deletion after max. 14 days |
| Excerpts of prompts and responses | Abuse prevention and investigation of violations of the Terms of Service | Art. 6 (1) lit. f GDPR | Automatic deletion after max. 14 days |
g4f.dev is an aggregator and proxy: when you send a chat message, the prompt is forwarded to one of over 100 third-party AI endpoints (the "providers"). Which provider is used is shown to you in the chat interface for every single answer ("Provider: … with …"). If you select Provider: Auto, the system picks a working provider automatically and displays the actually used one afterwards.
For these external providers, their own privacy policies apply. We have no influence on whether and how they log, store or train with your prompts. Assume that every prompt can be stored by the receiving provider. A current, community-maintained list of the endpoints in use can be found in the open-source repository (g4f/Provider).
The website is operated on infrastructure of Cloudflare, Inc., 101 Townsend St, San Francisco, CA (Cloudflare Pages/Workers) including a CDN edge presence in the EU. When you access the site, Cloudflare technically processes connection data (IP address, TLS metadata) as our processor and as a controller for DDoS protection. Cloudflare's privacy policy applies: cloudflare.com/privacypolicy.
We do not set any tracking or marketing cookies. The chat interface uses your browser's local storage exclusively to save your own settings (e.g. dark mode, selected provider, conversation history) locally on your device. This storage is technically necessary for the function you requested (§ 25 (2) TDDDG) and can be cleared at any time via the settings or your browser ("Clear site data").
When ads from Google AdSense are displayed on the homepage or in the documentation, Google may set cookies and process data as a controller in its own right; see section 7.
On the homepage and in the documentation, we may display ads served by Google AdSense (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA, USA). The chat itself remains free of advertising.
When ads are displayed, Google sets cookies or uses similar technologies and — as a controller in its own right — processes data such as your IP address as well as information about your device and browser, potentially also for personalized advertising. The legal basis is our legitimate interest in financing the free operation of this project (Art. 6 (1) lit. f GDPR); where required, consent is obtained via Google's consent dialog. Further information and opt-out options: policies.google.com/privacy and policies.google.com/technologies/ads.
Under the GDPR you have the right to information (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). Since we operate without mandatory accounts and without central storage of your conversations, in most cases you yourself hold all of your data locally — deleting it in your browser is the fastest form of "erasure". For stored account data, usage logs or prompt excerpts, contact us via g4f.dev/community. You also have the right to lodge a complaint with a supervisory authority, in Germany e.g. with the LDI NRW or the authority responsible for your place of residence.
All connections are TLS-encrypted (HTTPS). We operate minimal infrastructure: static files plus a stateless proxy layer. There is no central database containing your conversations; the only exception are the short-term prompt excerpts described in section 2 (max. 14 days, abuse prevention).
We may adapt this policy to legal or technical developments. The version linked in the footer of g4f.dev is always the current one.
Verantwortlicher im Sinne von Art. 4 Nr. 7 DSGVO für diese Website ist der private Betreiber des GPT4Free-Projekts (ein privat gehosteter Entwickler mit Sitz in Deutschland). Da es sich um ein nicht-kommerzielles Privatprojekt handelt, wird hier gemäß § 5 Abs. 3 TMG keine Postanschrift veröffentlicht. Der Verantwortliche ist jederzeit über die Community-Seite erreichbar: g4f.dev/community.
| Daten | Zweck | Rechtsgrundlage (DSGVO) | Speicherdauer |
|---|---|---|---|
| Server-Logfiles (IP-Adresse, Zeitpunkt, abgerufene URL, User-Agent) | Technische Bereitstellung der Website, Missbrauchs- und Angriffsabwehr | Art. 6 Abs. 1 lit. f DSGVO (berechtigtes Interesse am sicheren Betrieb) | Automatische Löschung nach spätestens 14 Tagen |
| Local-Storage-Einträge in Ihrem Browser (Einstellungen, Unterhaltungen) | Speicherung Ihrer Einstellungen und des Chatverlaufs auf Ihrem eigenen Gerät | Art. 6 Abs. 1 lit. f DSGVO / § 25 Abs. 2 TDDDG (technisch notwendig, allein in Ihrer Kontrolle) | Bis Sie diese im Browser oder in den Chat-Einstellungen löschen |
| Prompts und hochgeladene Dateien, die Sie in /chat/ senden | Weiterleitung an den gewählten bzw. automatisch gewählten KI-Anbieter zur Antwortgenerierung | Art. 6 Abs. 1 lit. a DSGVO (Einwilligung — wird vor der ersten Nutzung abgefragt) | Keine dauerhafte Speicherung durch uns; kurzfristige Auszüge zur Missbrauchsprävention max. 14 Tage (siehe unten); Weiterleitung siehe Abschnitt 4 |
| Optionale Mitglieds-Sitzung (nur bei aktivem Login) | Authentifizierung für Kontingent-Funktionen | Art. 6 Abs. 1 lit. b DSGVO | Bis zum Logout / Sitzungsablauf |
| Kontodaten optionaler Mitgliedskonten (z. B. Login-Kennung, Kontingent-Status, Sperr-Status) | Authentifizierung, Bereitstellung von Kontingent-Funktionen, Durchsetzung von Sperren und Missbrauchsprävention | Art. 6 Abs. 1 lit. b / lit. f DSGVO | Mindestens 90 Tage nach letzter Nutzung oder Löschung, damit Sperren und Kontingent-Missbrauch nachvollziehbar bleiben |
| Nutzungsprotokolle (IP-Adresse, Zeitpunkt, Anfragemuster) | Erkennung von Mehrfachkonten, Kontingent-Missbrauch und Angriffen | Art. 6 Abs. 1 lit. f DSGVO | Automatische Löschung nach spätestens 14 Tagen |
| Auszüge aus Prompts und Antworten | Missbrauchsprävention und Aufklärung von Verstößen gegen die Nutzungsbedingungen | Art. 6 Abs. 1 lit. f DSGVO | Automatische Löschung nach spätestens 14 Tagen |
g4f.dev ist ein Aggregator und Proxy: Wenn Sie eine Chat-Nachricht senden, wird Ihr Prompt an einen von über 100 externen KI-Endpunkten (die „Provider“) weitergeleitet. Welcher Anbieter verwendet wird, zeigt Ihnen die Chat-Oberfläche für jede einzelne Antwort an („Provider: … with …“). Bei der Auswahl Provider: Auto wählt das System automatisch einen funktionierenden Anbieter aus und zeigt den tatsächlich genutzten danach an.
Für diese externen Anbieter gelten deren eigene Datenschutzhinweise. Wir haben keinen Einfluss darauf, ob und wie diese Ihre Prompts protokollieren, speichern oder zum Training verwenden. Gehen Sie davon aus, dass jeder Prompt vom empfangenden Anbieter gespeichert werden kann. Eine aktuelle, von der Community gepflegte Liste der genutzten Endpunkte finden Sie im Open-Source-Repository (g4f/Provider).
Die Website wird auf Infrastruktur der Cloudflare, Inc., 101 Townsend St, San Francisco, CA (Cloudflare Pages/Workers) betrieben, inklusive CDN-Kantenpräsenz in der EU. Beim Aufruf der Seite verarbeitet Cloudflare technisch bedingt Verbindungsdaten (IP-Adresse, TLS-Metadaten) als unser Auftragsverarbeiter und als Verantwortlicher für DDoS-Schutz. Es gilt die Datenschutzerklärung von Cloudflare: cloudflare.com/privacypolicy.
Wir setzen keine Tracking- oder Marketing-Cookies. Die Chat-Oberfläche nutzt den Local Storage Ihres Browsers ausschließlich, um Ihre eigenen Einstellungen (z. B. Dunkelmodus, gewählter Provider, Unterhaltungsverlauf) lokal auf Ihrem Gerät zu speichern. Diese Speicherung ist für die von Ihnen angeforderte Funktion technisch notwendig (§ 25 Abs. 2 TDDDG) und kann jederzeit über die Einstellungen oder Ihren Browser („Websitedaten löschen“) entfernt werden.
Wenn Werbung über Google AdSense auf der Startseite oder in der Dokumentation eingeblendet wird, kann Google als eigenständiger Verantwortlicher Cookies setzen und Daten verarbeiten; siehe Abschnitt 7.
Auf der Startseite und in der Dokumentation können wir Werbung über Google AdSense einblenden (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland, sowie Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA, USA). Der Chat selbst bleibt werbefrei.
Bei der Einblendung von Werbung setzt Google Cookies oder nutzt ähnliche Technologien und verarbeitet — als eigenständiger Verantwortlicher — Daten wie Ihre IP-Adresse sowie Informationen zu Ihrem Gerät und Browser, ggf. auch für personalisierte Werbung. Rechtsgrundlage ist unser berechtigtes Interesse an der Finanzierung des kostenlosen Betriebs dieses Projekts (Art. 6 Abs. 1 lit. f DSGVO); soweit erforderlich, wird die Einwilligung über den Consent-Dialog von Google eingeholt. Weitere Informationen und Widerspruchsmöglichkeiten: policies.google.com/privacy und policies.google.com/technologies/ads.
Sie haben nach der DSGVO das Recht auf Auskunft (Art. 15), Berichtigung (Art. 16), Löschung (Art. 17), Einschränkung der Verarbeitung (Art. 18), Datenübertragbarkeit (Art. 20) und Widerspruch (Art. 21). Da wir ohne Pflichtkonten und ohne zentrale Speicherung Ihrer Unterhaltungen betreiben, liegen Ihre Daten in den meisten Fällen bei Ihnen selbst lokal — das Löschen im Browser ist die schnellste Form der „Löschung“. Für gespeicherte Kontodaten, Nutzungsprotokolle oder Prompt-Auszüge erreichen Sie uns über g4f.dev/community. Zudem haben Sie das Recht, sich bei einer Aufsichtsbehörde zu beschweren, in Deutschland z. B. bei der LDI NRW oder der für Ihren Wohnort zuständigen Stelle.
Alle Verbindungen sind TLS-verschlüsselt (HTTPS). Wir betreiben minimale Infrastruktur: statische Dateien plus einer zustandslosen Proxy-Schicht. Es gibt keine zentrale Datenbank mit Ihren Unterhaltungen; einzige Ausnahme sind die in Abschnitt 2 beschriebenen kurzfristigen Prompt-Auszüge (max. 14 Tage, Missbrauchsprävention).
Wir können diese Datenschutzerklärung an rechtliche oder technische Entwicklungen anpassen. Die im Fußbereich von g4f.dev verlinkte Fassung ist stets die aktuelle.