I think I saw a similar comment on here last month. It was a user saying that Gemma claimed to send his chats to Google. Which is clearly a hallucination.
I’m not a professional or expert on anything security and/or AI related but this is my take:
- In general there will not be data sent anywhere if you use the big/trustworthy open-source backends.
- Unless there are bigger security issues the model files shouldn’t contain such code.
- Data could be sent using MCP/tool calling but you can see each tool call as it is happening so it can’t be hidden.
If you really don’t trust something you can always try to use a network sniffer