Skip to content

What renters can and can't reach

Short version: renters can send AI requests to the models on your machine, and nothing else.

A renter gets an API key. Their requests go to GPUFlow first. GPUFlow answers the list of models itself and sends only one kind of request on to your computer:

RequestWhat it does
POST /v1/chat/completionschat with one of your models

That request goes through GPUFlow’s relay to the agent on your computer, and the agent passes it to your AI engine (Ollama).

The agent also has its own list, as a second lock. It accepts only /v1/models, /v1/chat/completions, /v1/completions and /v1/embeddings, and refuses everything else, no matter where the request came from.

  • Reach your network. Your computer only makes outgoing connections. Nothing on your router is opened, and renters never learn your IP address.
  • Get a shell or run their own programs on your machine.
  • See or change your files.
  • Download, delete or change your models.
  • See your machine’s stats. Only you see them.

The installer sets up the agent as a system service with strict limits. It runs as a temporary user with no password, can’t gain extra rights, sees the rest of the system as read-only, and can’t see home folders. Its settings live in /etc/gpuflow/agent.env and its data in /var/lib/private/gpuflow.

  • Prompts and answers pass through your machine. That’s how the AI runs. Respect your renters’ privacy: don’t record or read their prompts.
  • Keep the machine updated. Install your Linux updates and your GPU driver updates as usual. The agent restarts by itself afterwards.
  • Watch the temperature. Renters can keep your GPU busy for hours. The live stats on My Machines show its temperature, so make sure the case gets enough air.