Docs

Privacy checks

Before a machine is offered on the marketplace, the CLI inspects the local model runtimes for settings that keep prompts or responses, and reports a privacy tier. This page lists what it looks at and, just as important, what it cannot prove.

Self-attested, not a guarantee

The checks run on the provider's own machine and the result is reported by the CLI. This is not remote attestation. We call machines privacy-first, checked by the CLI, never guaranteed.

Tiers

  • private: every shared runtime was checked and no prompt or response logging or history was detected.
  • unverified: at least one runtime could not be checked, for example a remote host, a process the CLI cannot read or an unknown runtime. Offered only if the provider allows it, and buyers can exclude it.
  • logging: retention of prompts was detected. These machines are never offered on the marketplace.

Routing prefers private over unverified by default. Buyers can switch to requiring private machines only. Run tokmine privacy to see the result for your machine with hints on how to fix findings.

What it checks, per runtime

The CLI reads process arguments, the environment of the process where readable, well-known config keys and default log locations. It does not read the contents of your conversations.

RuntimeExamples of what counts as logging
OllamaDebug mode that writes prompts to the log.
LM StudioSaved conversation history.
vLLMRequest logging flags such as --enable-log-requests.
llama.cpp / llama-serverFlags such as --verbose-prompt or --log-file.
LocalAI, Jan, KoboldCppKnown logging and history options for each.
Anything elseGeneric checks only, so usually reported as unverified.

The exact checks evolve with each CLI release; tokmine privacy always shows what your installed version looks for.

What it cannot prove

  • That a provider's operating system, GPU driver, proxy, network tap or screen recorder is not capturing data.
  • That the runtime or model binary is unmodified, or that a patched runtime is not logging in ways the CLI does not know about.
  • That a provider modified the CLI, or reported results truthfully. The report comes from the provider's machine.
  • That nothing changes after the check. It repeats about every six hours and when the runtime changes, not on every request.
  • That output is correct or safe. Treat marketplace output like any third-party API.

What Tokmine does

  • Tokmine does not store request or response bodies, and the CLI never writes them to disk or logs, in any mode.
  • Providers are anonymous to buyers and the other way around.
  • Machines that report logging are removed from the marketplace until a later check passes.

If you need hard guarantees about where data goes, use your own machines instead of the marketplace. See marketplace docs and security.