← Signals

Signals · opinion

The privacy setting

Privacy & data ownership · ~2 min read

“The reason to start this business, motivated by owning our data.”
tunbru — founding line

Privacy is not a feature we added to the product. It is the reason the product exists, and everything below is downstream of that one sentence.

Privacy is the mode that enforces it, and any client in the application can run it. With it on, no video, no image, and no text leaves your environment, except to the APIs you deliberately chose. Not the ones we picked for you. The ones you named.

What we built is not a safe corner of an otherwise leaky product. It is control over the decision itself. Every route out is one you set, and there is no route we quietly benefit from: tunbru does not train models on your work and does not sell what passes through the system. That takes greed out of the equation and leaves plain responsibility in its place — yours over your own material, ours for the environment it lives in.

Who the request belongs to

There is a second thing worth understanding, because it applies before you ever touch the setting. When data does leave, it does not leave as you. You are logged into our system and the call is made on your behalf, so what arrives at the provider is attached to the company, not strongly to the person who asked. Many requests, one party standing in front of them.

That is the default worth having: the best options the market can give, at arm's length from the market. Turn privacy on and the arm's length becomes a wall — nothing is sent at all, the work is processed on in-house servers, and what any provider retains stops being a question that concerns you.

Why it exists

Read the third-party terms. Most providers publish a retention schedule, and most business tiers say your content is not used for training. Both can be true, and your data still travels. An invoice, a private photo, a home video, a signed contract — it sits on someone else's servers for a defined window, is processed by systems you cannot inspect, and leaves metadata behind that outlives the file.

That is not a scandal. It is the arrangement, and it is the same one that has governed an ordinary web search for twenty years — the large players have always had that access. The problem is smaller and more human: the decision gets made unconsciously, at the moment of upload, by someone who never opened the page that describes it.

Self-hosting replaces blind trust in a company far out of reach with a relationship you can hold — with us. That is also why we invest in open source: rules you can read beat promises you have to take on faith.

A bet on independence

This began as an individual interest — deciding what to share and what to keep — and that decision is what spawned a business. Worth being plain about the motive: it was not made out of fear. It was made out of responsibility.

Independence is simply the practical form of it. Every provider we can reach is someone else's business decision — terms get rewritten, tiers retired, regions cut off, access priced out of reach. And sooner or later some right, a jurisdiction's or a platform's, will clash with the principle of privacy, and the principle will be the one asked to give way.

We do not plan to argue that clash. The architecture already answers it. The system plugs into any LLM provider — a decision we made early and on purpose — so if one is removed, the workload moves, including to free open-source models running privately on hardware inside the boundary. The same switch runs the other way: as intelligence on the open-source side keeps improving, we are already standing where it lands.

That is what owning your data looks like in practice — not a promise that the outside world stays still, but the ability to stay alive when it doesn't.

Three reasons we built tunbru

Why we exist at all

The confusion is fair, and it comes up: the big players absorb everything, and on raw capability they do better work than us. So what is left?

What is left is the part capability does not cover. They are obliged to serve everybody — supermarkets for the entire world, where the shelves are loud, the choice is enormous, and none of it was arranged for one particular customer. We carry no such obligation. What gets built here is shaped around one business, and it stays: the adaptations, the workflows, the fitted pieces remain in your environment instead of being reset by somebody else's next release.

The rest is the part we will not trade away. Your interest is the one this system safeguards — there is no second business model underneath ours that needs your data, and no incentive waiting to appear once the scale arrives. And the mode that hooks the whole thing up to free, private, open-source models is not a promotional phase. It will never go away. Whatever the frontier does next, that door stays open, and it stays open from your side.

The rest of the argument is older than us, and we have written it before: run it yourself, or pay someone for the same access without the upkeep. The privacy setting answers the part that choice usually leaves out — you should be able to take the second option without surrendering the first one's guarantee. Your data stays yours, whatever happens upstream.

Addendum
“We use one big player to store our servers, inside virtual private servers — and the sentence above still stands.”

The metal is rented; the environment is not. What runs inside that boundary — the models, the routing, the files, the workflows — stays inside it. Paying one large provider for machines is a different arrangement from handing them the work, and it is the only place in the stack where their name appears.

Run your environment on your terms

Join the waitlist