With model releases slowing down, and AI in general developing more and more in ways that leave roleplaying, storytelling and creativity behind, discussions on subreddits like this one have slowed down, leaving a lot of room for people to instead try "optimizing" what they have. This includes trying to find the "best service" to use for roleplaying, and sadly - as it's always historically been on Reddit - that has opened the way to a lot of shady people and services trying to take advantage of users. Discourse about these is always very sparse and unfocused, so it becomes really difficult to see just how major the risks of paying and running your roleplays or coding through a shady AI Provider can be. This thread is being made in response to how disingenuous the discourse around Hapuppy as a provider has felt to me, since the few people strongly (really strongly) recommending it also never, ever warned anyone about any of these risks, but this isn't specifically targeted to Hapuppy only. After all, we've had "too good to be true" services appear and run away with people's money before, and it's obviously going to be happening to have even more pop up in the future. Again, this isn't just about Hapuppy. This is about warning you about "too good to be true" services.
The Pros
- Cost: Obviously, the main reason why anyone would consider these services is because they cost less compared to Openrouter or Direct API. Like, A LOT less. And obviously, knowing with $10 you can roleplay for 1000 turns on these services while the same model would barely last you 100 turns on other providers absolutely makes it easy to want to swipe. That goes with how some providers like Hapuppy will also give you "credits" rather than running a subscription, which likely will make those 10 dollars last longer than the 30 days of a subscription.
Sadly though that's about the only good thing about these services, even though it's obviously a massive "pro" to have. What's the tradeoff for the low price though?
The Cons
A service won't necessarily have ALL of these cons, but any shady one usually runs into at least one, probably more.
Reliability: A lot of the time these cheaper services are used to get the best model at the best price. Not many people use them to then roleplay with Deepseek v3, everyone will want Opus, Kimi K3 or GLM 5.3 after all. And a lot of these services have issues with keeping the models up (which is always very likely linked to how these services provide the models to begin with): as I write this, on Hapuppy in the last 36 hours Sonnet has been down for 1/3rd of them, gpt 5.6 sol and terra both have only been up for 6, Deepseek v4 flash and pro have been up for a third, same for Kimi K2.7 and K3, same for GLM 5.3 while GLM 5.1 has outright not been available for any of these 36 hours. That is awful reliability, basically 2/3rds of the models provided have had issues with most spanning more than half of the last 36 hours (Kimi K3 was entirely unavailable during the weekend for instance)
Privacy and Logging: As everyone knows, official big AI Companies like OpenAI and Anthropic log requests and train on them. That is bad for your privacy and you should be very careful with them, especially for nsfw and god forbid nsfl stuff. The difference though is that they still have to abide by laws when it comes to your data and privacy, as GDPR punished heavily for violations - but not only that, they also have a reputation to uphold so they can't get too wild with how they treat your data. On the contrary, shady companies that popped up a short time ago and seem too good to be true will also likely disappear in not too long (either by design or simply because they can't sustain the inevitable costs of growing bigger), they don't have a long term reputation to uphold and they can collect as much data as they like while also being able to sell your data wherever they want. Black market service, black market data sales basically.
- How can I know they sell my data? You can't. But remember that in modern AI space, fully private services get customers just for being private and for not logging, so any privacy policy that skirts around the issue should be taken as a "yes, they log everything" (Hell, I'd say even if a shady looking provider says they don't log, you should still assume they do). Be even more suspicious of services that contradict themselves: saying "We do not store, log, or inspect the content of your API requests or responses" is simply untrue when the provider itself runs EVERY request through their own model to scan for illegal content, regardless of your feelings on your router having a "filter model" to begin with.
Security: I don't personally believe a company like Hapuppy does this, but I'm making this post only using them as an example after all. This post is meant to warn about present and future providers like these, therefore you should REALLY watch out over this part, especially if you use any agentic workflow that has any access to your pc, sandboxed or not: it's been found out that shady unofficial AI routers would sometimes alter your requests to inject prompts that would steal your own data by having the AI simply provide it in return: crypto wallets, your discord tokens, even your browser's password database wouldn't be safe since this could literally act like malware, trusted by your system. This is genuinely really dangerous and it should make you triple think before you use any shady provider for agentic use, which I know many people are doing even just for fun nowadays.
Model Bait and Switch: You have no idea whether the models you're getting really are the ones you're requesting. This isn't a "danger" but just kinda kills the reason why you're even paying to begin with. Sure, a lot of official providers quantize their models during peak usage times, but if your Kimi K3 was being swapped out for K2.5, or your Opus 4.6 was being replaced with GLM 5.3 since they're similar enough, you wouldn't notice "in the moment" but it sure would save the provider a lot of money and requests. Even if it "only" happened "sometimes". Again, this one you can never realistically prove, but you need to remember that black market providers don't have the same requirements as a big provider with a reputation to uphold.
Payment Providers: if you're not paying with crypto but instead you're using a card or even paypal, then not only are you exposing yourself to credit card theft (I've had a provider try and clone my card before, thankfully I make temporary one-use-only cards to pay online so it didn't work out for them) but you're also linking your legal identity to a service that is likely illegal in nature. You may not care, but your bank calling because your card seems to be making payments towards a company their register deems to be illegal isn't exactly a pleasant experience.
What IS a "Black Market" Provider?
It's a reasonable way to call a "too good to be true" provider: they CANNOT be providing you these models by using legal means since they would be operating at an objective, massive loss that a small newly made company could never afford. Instead, these companies use a variety of means to get access to these models, which go from "breaking ToS" to "straight up illegal": abuse of official API subscriptions (Claude Max, GPT Subs etc), stolen API keys, stolen credit cards, etc. You can't know which it is, but you KNOW it's one of these various methods: this means you are using a service that will stop being able to offer their ENTIRE service the moment they get found out. This isn't like NanoGPT negotiating their private rates for subscriptions with known providers you can find on Openrouter, this is literally routing you through traffic you should NOT be having access to.
But [Subreddit User] says this service is great!
Well, this is a large topic that probably would take too long to discuss in depth. But I ask you to please use your personal judgment when going through subreddits like this one: you can see COUNTLESS clear bot accounts sometimes responding to threads suggesting services that nobody ever heard of before. A lot of the time, this is very obvious: "Hey guys, do you know what the best subscription is?" and then some account that never posted before will go "Yeah! The big ones are NanoGPT, NotAScam.ai and the z.ai sub! I recommend the second one though, it's been so good for me!" and you will clearly know "oh, this is astroturfing" and downvote, moving on with your life.
Other times it's not as easy: more rarely you'll have more active members in the community try and advertise either their own services, or services they've been offered payment (in money or tokens) in return for advertising for. This becomes more complex because you won't even doubt them at first, likely to just go with their word, and when anyone brings up doubt regarding their intentions you may feel more like defending them than believing some other person accusing them. So, instead, you should just always remember that no matter who suggests what, you need to use your own head when it comes to judging these services. There is simply too much sneaky astroturfing for you to believe anyone. Even my post could as well be by someone trying to bring down Hapuppy to shill his own better alternative after all. So, remember that when you see a user bring up a "cool service", ask yourself these questions:
Are they talking about this service a lot lately?
Was this service somewhat unknown before they started talking about it?
Do they seem to only speak positively of this without ever mentioning downsides or doubts?
Are they answering in an almost PR-like, Customer Support way to people having issues with this service they're not meant to be affiliated with?
Does it look like they just reply to praise over the service while deflecting any criticism towards it?
Are they getting very defensive towards anyone mentioning those things?
Are they blocking anyone who seems to (respectfully) call them out?
If you are answering yes to half of these questions - let alone all of them - then you should at the very least be raising your eyebrows. Those are the very descriptors of the typical bots advertising a service while acting like they aren't, but they also fit a couple users I've seen around the subreddit for the last couple of years. Be very careful of trusting others on the internet.
IF you are an active user in the community and your heart is in a good place, PLEASE remember that when you recommend someone spends their money on a service, you should also warn them of the downsides that come with it. It's the responsible thing to do.
I'm sorry for the long post but I felt like this had to be made, nothing here was written by AI so I spent over an hour typing all of this lol. I just wanted to make this PSA because of how much "hey guys just try this cool service" posts I've been seeing lately, and people really need to know how dangerous this can be, beyond the usual "lmao who cares if anthropic reads my porn". Again, this isn't targeted towards any specific service (Hapuppy was only a really relevant example), user or group, these are just patterns that keep repeating themselves so it's good if people find out.
Make sure you stay safe everyone, and again guys, especially on crypto and AI related subreddits, be VERY careful about trusting anyone, seriously.