Signals · opinion
The privacy setting
“The reason to start this business, motivated by owning our data.”
Privacy is not a feature we added to the product. It is the reason the product exists, and everything below is downstream of that one sentence.
Privacy is the mode that enforces it, and any client in the application can run it. With it on, no video, no image, and no text leaves your environment, except to the APIs you deliberately chose. Not the ones we picked for you. The ones you named.
What we built is not a safe corner of an otherwise leaky product. It is control over the decision itself. Every route out is one you set, and there is no route we quietly benefit from: tunbru does not train models on your work and does not sell what passes through the system. That takes greed out of the equation and leaves plain responsibility in its place — yours over your own material, ours for the environment it lives in.
Who the request belongs to
There is a second thing worth understanding, because it applies before you ever touch the setting. When data does leave, it does not leave as you. You are logged into our system and the call is made on your behalf, so what arrives at the provider is attached to the company, not strongly to the person who asked. Many requests, one party standing in front of them.
That is the default worth having: the best options the market can give, at arm's length from the market. Turn privacy on and the arm's length becomes a wall — nothing is sent at all, the work is processed on in-house servers, and what any provider retains stops being a question that concerns you.
Why it exists
Read the third-party terms. Most providers publish a retention schedule, and most business tiers say your content is not used for training. Both can be true, and your data still travels. An invoice, a private photo, a home video, a signed contract — it sits on someone else's servers for a defined window, is processed by systems you cannot inspect, and leaves metadata behind that outlives the file.
That is not a scandal. It is the arrangement, and it is the same one that has governed an ordinary web search for twenty years — the large players have always had that access. The problem is smaller and more human: the decision gets made unconsciously, at the moment of upload, by someone who never opened the page that describes it.
Self-hosting replaces blind trust in a company far out of reach with a relationship you can hold — with us. That is also why we invest in open source: rules you can read beat promises you have to take on faith.
A bet on independence
This began as an individual interest — deciding what to share and what to keep — and that decision is what spawned a business. Worth being plain about the motive: it was not made out of fear. It was made out of responsibility.
Independence is simply the practical form of it. Every provider we can reach is someone else's business decision — terms get rewritten, tiers retired, regions cut off, access priced out of reach. And sooner or later some right, a jurisdiction's or a platform's, will clash with the principle of privacy, and the principle will be the one asked to give way.
We do not plan to argue that clash. The architecture already answers it. The system plugs into any LLM provider — a decision we made early and on purpose — so if one is removed, the workload moves, including to free open-source models running privately on hardware inside the boundary. The same switch runs the other way: as intelligence on the open-source side keeps improving, we are already standing where it lands.
That is what owning your data looks like in practice — not a promise that the outside world stays still, but the ability to stay alive when it doesn't.
Three reasons we built tunbru
-
first
Optionality
We do not depend on public LLMs, and we use them fully — the frontier is unquestionably better at video and image. The architecture accepts any provider, so routing out stays a choice per job, never a dependency.
-
second
Ownership
You own your data, at a cost we state plainly: local models are slower, and in places weaker. Better you make that trade deliberately than never be shown the dial.
-
third
Approachable ally
Privacy is the mode; this is the attitude around it. Our interest is not scale but longevity and satisfaction — so where the big companies answer with automation, we bootstrap the beginning by hand: a live demo, the first week sat beside your team, then whatever it takes to get maximum profit from the platform.
Why we exist at all
The confusion is fair, and it comes up: the big players absorb everything, and on raw capability they do better work than us. So what is left?
What is left is the part capability does not cover. They are obliged to serve everybody — supermarkets for the entire world, where the shelves are loud, the choice is enormous, and none of it was arranged for one particular customer. We carry no such obligation. What gets built here is shaped around one business, and it stays: the adaptations, the workflows, the fitted pieces remain in your environment instead of being reset by somebody else's next release.
The rest is the part we will not trade away. Your interest is the one this system safeguards — there is no second business model underneath ours that needs your data, and no incentive waiting to appear once the scale arrives. And the mode that hooks the whole thing up to free, private, open-source models is not a promotional phase. It will never go away. Whatever the frontier does next, that door stays open, and it stays open from your side.
The rest of the argument is older than us, and we have written it before: run it yourself, or pay someone for the same access without the upkeep. The privacy setting answers the part that choice usually leaves out — you should be able to take the second option without surrendering the first one's guarantee. Your data stays yours, whatever happens upstream.
“We use one big player to store our servers, inside virtual private servers — and the sentence above still stands.”
The metal is rented; the environment is not. What runs inside that boundary — the models, the routing, the files, the workflows — stays inside it. Paying one large provider for machines is a different arrangement from handing them the work, and it is the only place in the stack where their name appears.
Run your environment on your terms
Join the waitlistSinais · opinião
A definição de privacidade
“A razão para começar este negócio, motivada por sermos donos dos nossos dados.”
A privacidade não é uma funcionalidade que acrescentámos ao produto. É a razão pela qual o produto existe, e tudo o que se segue decorre dessa única frase.
Privacidade é o modo que a impõe, e qualquer cliente na aplicação pode ativá-lo. Com ele ligado, nenhum vídeo, nenhuma imagem e nenhum texto sai do seu ambiente, exceto para as APIs que escolheu deliberadamente. Não as que escolhemos por si. As que nomeou.
O que construímos não é um canto seguro de um produto que, de resto, deixa fugir dados. É controlo sobre a própria decisão. Cada rota de saída é definida por si, e não existe nenhuma rota da qual beneficiemos discretamente: a tunbru não treina modelos com o seu trabalho e não vende o que passa pelo sistema. Isso tira a ganância da equação e deixa no lugar dela responsabilidade simples — a sua sobre o seu próprio material, a nossa pelo ambiente onde ele vive.
A quem pertence o pedido
Há uma segunda coisa que vale a pena compreender, porque se aplica antes de sequer tocar na definição. Quando os dados saem, não saem como você. Está autenticado no nosso sistema e a chamada é feita em seu nome, por isso o que chega ao fornecedor está associado à empresa, não fortemente à pessoa que perguntou. Muitos pedidos, uma só parte à frente deles.
Esse é o padrão que vale a pena ter: as melhores opções que o mercado pode dar, à distância de um braço do mercado. Ligue a privacidade e essa distância torna-se uma parede — nada é enviado, o trabalho é processado em servidores internos, e o que qualquer fornecedor retém deixa de ser uma questão que lhe diga respeito.
Porque existe
Leia os termos de terceiros. A maioria dos fornecedores publica um calendário de retenção, e a maioria dos escalões empresariais diz que o seu conteúdo não é usado para treino. Ambas as coisas podem ser verdade, e os seus dados viajam na mesma. Uma fatura, uma fotografia privada, um vídeo de família, um contrato assinado — fica nos servidores de outra pessoa durante uma janela definida, é processado por sistemas que não pode inspecionar, e deixa para trás metadados que sobrevivem ao ficheiro.
Isso não é um escândalo. É o acordo, e é o mesmo que rege uma pesquisa comum na web há vinte anos — os grandes intervenientes sempre tiveram esse acesso. O problema é mais pequeno e mais humano: a decisão é tomada inconscientemente, no momento do upload, por alguém que nunca abriu a página que a descreve.
Auto-alojar substitui a confiança cega numa empresa fora de alcance por uma relação que pode segurar — connosco. É também por isso que investimos em open source: regras que pode ler valem mais do que promessas que tem de aceitar de fé.
Uma aposta na independência
Isto começou como um interesse individual — decidir o que partilhar e o que guardar — e essa decisão foi o que gerou um negócio. Vale a pena ser claro sobre o motivo: não foi tomada por medo. Foi tomada por responsabilidade.
A independência é simplesmente a sua forma prática. Cada fornecedor a que podemos chegar é a decisão de negócio de outra pessoa — os termos são reescritos, os escalões descontinuados, as regiões cortadas, o acesso posto a um preço inalcançável. E mais tarde ou mais cedo algum direito, de uma jurisdição ou de uma plataforma, vai chocar com o princípio da privacidade, e será ao princípio que pedirão para ceder.
Não planeamos discutir esse choque. A arquitetura já lhe responde. O sistema liga-se a qualquer fornecedor de LLM — uma decisão que tomámos cedo e de propósito — por isso, se um for removido, o trabalho muda de lugar, incluindo para modelos open source gratuitos a correr em privado em hardware dentro da fronteira. O mesmo interruptor funciona no sentido inverso: à medida que a inteligência do lado open source continua a melhorar, já estamos no sítio onde ela aterra.
É isto que ser dono dos seus dados significa na prática — não uma promessa de que o mundo lá fora fica quieto, mas a capacidade de continuar vivo quando não fica.
Três razões pelas quais construímos a tunbru
-
primeira
Opcionalidade
Não dependemos de LLMs públicos, e usamo-los plenamente — a fronteira é inquestionavelmente melhor em vídeo e imagem. A arquitetura aceita qualquer fornecedor, por isso encaminhar para fora continua a ser uma escolha por tarefa, nunca uma dependência.
-
segunda
Propriedade
Os dados são seus, a um custo que declaramos com clareza: os modelos locais são mais lentos e, nalgumas áreas, mais fracos. Antes fazer essa troca deliberadamente do que nunca lhe mostrarem o botão.
-
terceira
Aliado acessível
A privacidade é o modo; isto é a atitude à volta dele. O nosso interesse não é a escala mas a longevidade e a satisfação — por isso, onde as grandes empresas respondem com automação, nós arrancamos o início à mão: uma demonstração ao vivo, a primeira semana sentados ao lado da sua equipa, e depois o que for preciso para tirar o máximo proveito da plataforma.
Porque é que existimos, afinal
A confusão é justa, e surge: os grandes intervenientes absorvem tudo, e em capacidade pura fazem melhor trabalho do que nós. Então, o que sobra?
Sobra a parte que a capacidade não cobre. Eles são obrigados a servir toda a gente — supermercados para o mundo inteiro, onde as prateleiras são barulhentas, a escolha é enorme e nada foi arranjado para um cliente em particular. Nós não carregamos essa obrigação. O que aqui se constrói é moldado à volta de uma empresa, e fica: as adaptações, os fluxos de trabalho, as peças à medida permanecem no seu ambiente em vez de serem repostos a zero pelo próximo lançamento de outra pessoa.
O resto é a parte que não trocaremos por nada. O seu interesse é o que este sistema protege — não há um segundo modelo de negócio por baixo do nosso que precise dos seus dados, nem um incentivo à espera de aparecer quando a escala chegar. E o modo que liga tudo isto a modelos open source gratuitos e privados não é uma fase promocional. Nunca vai desaparecer. Faça a fronteira o que fizer a seguir, essa porta fica aberta, e fica aberta do seu lado.
O resto do argumento é mais velho do que nós, e já o escrevemos antes: corra-o você mesmo, ou pague a alguém pelo mesmo acesso sem a manutenção. A definição de privacidade responde à parte que essa escolha costuma deixar de fora — deve poder tomar a segunda opção sem abdicar da garantia da primeira. Os seus dados continuam seus, aconteça o que acontecer a montante.
“Usamos um grande interveniente para armazenar os nossos servidores, dentro de servidores privados virtuais — e a frase acima mantém-se.”
O metal é alugado; o ambiente não é. O que corre dentro dessa fronteira — os modelos, o encaminhamento, os ficheiros, os fluxos de trabalho — fica dentro dela. Pagar a um grande fornecedor por máquinas é um acordo diferente de lhe entregar o trabalho, e é o único lugar da stack onde o nome dele aparece.