What data leaves your system when you use Jev (TypeSafe AI)? Retention, training and ZDR by route
Every Jev request carries your state text and questions to TypeSafe, either directly or through a gateway. This page quotes what each route's own text says about training, retention and zero data retention (ZDR), with the gateway layer and the TypeSafe provider layer kept apart. It ends with a route picker by type of data, a pre-launch checklist and what the integrations the pool audited send.
On the six routes read, no primary text allows training on your prompts without consent. TypeSafe's contract grants it a licence "in perpetuity" to use Customer Data to derive telemetry and to monitor for fraud and abuse; three gateways nonetheless label TypeSafe zero-retention.
If you need zero retention, it has to hold at both layers: the gateway, and TypeSafe as the provider. TypeSafe's docs offer ZDR directly only "for enterprise customers". The MCA licence is a right to process, not a statement that data is kept: MCA 10.3 says TypeSafe has "no obligation to store or retain Customer Data". This does not mean Jev never stores your data. Resellers are excluded because their terms are unknown.
A reading of the text, not legal advice.
Two layers your data passes through
Where a Jev request goes, and whose terms apply at each step
- Your applicationSends
stateand questions. What goes in is up to you and your integration (see payloads). - Gateway layer (if any)OpenRouter, Vercel, Cloudflare or Opper. Its own logging, retention and ZDR terms apply. Going direct to TypeSafe skips this layer.
-
TypeSafe as providerTypeSafe's MCA, DPA and Privacy Policy apply. U.S. hosting.DigitalOcean (Vercel only)Vercel lists it as a second Jev provider and marks it
has_zdr: false.
Route by term: training, retention and ZDR
Quotes are copied, not interpreted, and each is at most 25 words. Gateway terms and TypeSafe terms sit in separate columns. Where the route is a gateway, the provider column shows what the gateway says about TypeSafe (or another provider). Abbreviations: PP = TypeSafe Privacy Policy (19 Nov 2025); MCA = Master Customer Agreement (23 Sep 2026); DPA = Data Processing Addendum (24 Apr 2026). All three dates were rechecked on 7 Oct 2026, 05:19 UTC and are unchanged. Route pages read 05:26–05:31 UTC.
- Text supports the safer reading
- Condition or gap to check
- Available if you turn it on
- Not ZDR, or unknown
- No layer or not stated
| Route | Term | Gateway layer: what the gateway says about itself | Provider layer: TypeSafe (or the provider the gateway names) |
|---|---|---|---|
| TypeSafe direct, standard account Documented | Training | No gateway | No training without consent PP: "We (1) will not train or fine tune any artificial intelligence or machine learning models on Input". MCA 4.1: no training on Customer Data "without Customer's prior consent". But MCA 4.3: "TypeSafe may Process Telemetry without restriction, including to improve the Services". Telemetry includes "technical logs, hashes, summary statistics and classifications, metrics, and learnings". |
| Retention | No gateway | No period stated MCA 4.1(c) grants TypeSafe a licence "in perpetuity" to use Customer Data "(i) to derive and generate Telemetry, (ii) to monitor for fraud and abuse of the Services". MCA 10.3: "no obligation to store or retain Customer Data and may delete Customer Data at any time". DPA Annex §8: "retained for as long as necessary taking into account the purpose of the Processing". | |
| ZDR | No gateway | Enterprise only Docs: "We also offer zero data retention (ZDR) for enterprise customers." The default for a standard account is not stated. | |
| TypeSafe enterprise Documented | Training | No gateway | As for a standard account, plus any signed terms (not public). |
| Retention | No gateway | Not public Vercel's ZDR page quotes a clause it attributes to TypeSafe: "TypeSafe shall not retain (a) prompts that are Customer Data for any longer than is necessary to generate Output". This clause is not in TypeSafe's public Terms, MCA, DPA or Privacy Policy (searched 1 Oct). | |
| ZDR | No gateway | Offered Offered "for enterprise customers"; eligibility, price and terms are not published. Contact changed: the docs legal page now sends ZDR requests to TypeSafe's sales mailbox; its 22 Sep 2026 archive copy named the privacy mailbox. The offer wording is unchanged. The change happened between 22 Sep and 6 Oct (exact date unknown); found by diff on 7 Oct 2026, 05:20 UTC. | |
| OpenRouter Documented | Training | No training Privacy Policy (31 Aug 2026): "OpenRouter does not use your Inputs or Outputs for model training." | No training TypeSafe endpoint data policy on OpenRouter: training: false, trainingOpenRouter: false, canPublish: false. |
| Retention | Not kept by default "your prompts are not retained unless you specifically opt in to prompt logging." | Not keptretainsPrompts: false. | |
| ZDR | ZDR by default "OpenRouter itself has a ZDR policy". Provider ZDR can be enforced "globally, per model group, per guardrail, or per request". | On the ZDR list The endpoint typesafe/jev-1.13-20260917 is in OpenRouter's ZDR endpoint list (922 endpoints). OpenRouter says it "in some cases creates special agreements with providers"; whether one exists with TypeSafe is not stated. | |
| Vercel AI Gateway two providers: TypeSafe AI and DigitalOcean Documented | Training | On the no-training list The disallow-prompt-training page (10 Sep 2026) lists "TypeSafe AI ✓". | No training (both providers) Endpoints API (7 Oct 2026, 05:19 UTC; unchanged since 6 Oct): TypeSafe AI and DigitalOcean both has_no_training: true. |
| Retention | Not kept "Vercel AI Gateway has a ZDR policy and does not retain prompts, outputs, or sensitive data." | Not stated per provider Nothing beyond the ZDR marks below. | |
| ZDR | Enforceable On Pro and Enterprise: per request with zeroDataRetention: true (no added cost), or team-wide at $0.10 per 1,000 requests. | TypeSafe AI ✓ DigitalOcean: not ZDR Vercel's ZDR docs mark "TypeSafe AI ✓", with the quoted clause that is not in TypeSafe's public text. Endpoints API on 7 Oct 2026, 05:19 UTC (unchanged since 6 Oct): typesafe-ai has_zdr: true, digitalocean has_zdr: false (on 1 and 2 Oct it returned only DigitalOcean). The models API's zdr is now "some" (was "none" on 5 Oct) and no_training "all": model-level values across both providers. | |
| Cloudflare Workers AI Documented | Training | No training Data usage page (21 Apr 2026): Cloudflare does not use your Customer Content "to (1) train any AI models made available on Workers AI". | Third-party terms Jev is labelled "Third-party": models "may be subject to ... license terms that apply between you and the model provider." |
| Retention | AI Gateway logs on by default Content is stored only "if you specifically use a storage service". If you add AI Gateway: "Logs are enabled by default for each gateway" (24 Sep 2026). | Not stated | |
| ZDR | Not stated | ZDR "Yes" Model page: "Zero data retention Yes". | |
| Opper Documented | Training | No training by default "No training by default". | No training "No training on customer data." (route card, "Verified by Opper on 2026-09-18"). |
| Retention | None on the Gateway plan "Prompts and outputs stored by Opper: None. Usage metadata only." Control Plane tracing is optional: "1 to 30 days". | Not stated | |
| ZDR | ZDR rule available "store no prompts or outputs at Opper and allow only providers that neither train on nor log your content". | Not established "Zero data retention posture is not established for this route." Region "United States"; "Transfer mechanism unknown". | |
| Lookalike resellers Reported | All three | Unknown Eye Security (25 Sep): your prompts pass through the resellers' own servers. Details on official vs reseller sites. | Unknown |
Netlify is not in this table because its terms were not read term by term. Its AI Gateway docs say "The AI Gateway does not store your prompts or model outputs" (Netlify docs, checked 4 Oct 2026, 05:31 UTC; Documented); TypeSafe's own handling still applies. Sources for each cell are listed at the end of the page.
On Vercel, your request may not reach TypeSafe
Vercel lists two providers for Jev (checked 7 Oct 2026, 05:19 UTC; unchanged since 6 Oct): TypeSafe AI (zero data retention) and DigitalOcean (no zero data retention). Vercel picks a provider by uptime and latency unless you set the provider order. So has_zdr: true on one provider does not tell you where a given request goes: by default Vercel "dynamically chooses the default providers … based on a combination of recent uptime and latency" (provider options, read 6 Oct 2026, 05:24 UTC). So without ZDR enforcement, a Vercel request may be served by DigitalOcean, which Vercel marks as not ZDR. If you need ZDR on Vercel, set zeroDataRetention: true (Pro or Enterprise); Vercel's provider options (order, only) also let you restrict providers (not tested). Whether DigitalOcean forwards requests to TypeSafe or serves the model itself is not stated. On 1 and 2 Oct the endpoints API returned only DigitalOcean. Which Jev version typesafe-ai/jev serves is not stated either (model IDs by route). Documented
Correction: the route matrix previously showed Vercel's zdr "none" as the Vercel data term. That value is a model-level aggregate across both providers, not a statement about TypeSafe.
Which route fits your data?
Open the most sensitive type of data you plan to send; opening one closes the others. Each answer rests on the table above and on the TypeSafe terms below.
Public textAny official route
No route's text permits training on your prompts without consent. Avoid lookalike resellers anyway: their terms are unknown and your prompts pass through their servers.
Personal data (GDPR)The DPA, or ZDR at both layers
- Direct: sign TypeSafe's DPA (EU Standard Contractual Clauses; the Services are hosted in the U.S.), ask sales for ZDR and get a retention period in writing. None is published.
- Gateway: enforce ZDR at both the gateway and the provider layer. OpenRouter lists the TypeSafe endpoint as ZDR; on Vercel set
zeroDataRetention: true. - Opper keeps no prompts on its Gateway plan, but its TypeSafe route is U.S.-based with an "unknown" transfer mechanism.
Health or financial dataNo route documents it
No route found documents HIPAA or a BAA. TypeSafe's public Terms, AUP, MCA, DPA, Privacy Policy and docs contain no HIPAA, BAA or PHI term. Treat this as unsupported until TypeSafe states otherwise in writing.
Secrets in an agent's contextSend less
Prefer integrations that redact or send nothing: the official plugin (no Jev call), jev-claude (regex redaction) or oh-my-claudecode (200-character excerpts, off by default). Avoid guards that send the last 30 messages in full, such as LangChain's AutoModeMiddleware. See payloads.
Data that must stay in the EUNot available at the TypeSafe layer
TypeSafe's Privacy Policy says "The Services are hosted in the United States". Gateway in-region routing (OpenRouter EU, Opper EU) does not change where TypeSafe processes the request. No EU region or residency commitment was found in TypeSafe's text.
No TypeSafe EU region or data-residency option was found in TypeSafe's docs or trust center (checked 5 Oct 2026, 05:14–05:18 UTC; all six subprocessors are listed in the USA). Opper is hosted in the EU, but its Jev route is TypeSafe in the United States ("TypeSafe AI — United States" on its route card). Documented Boundary: TypeSafe docs full text (llms-full.txt, llms.txt), the typesafe.ai homepage and the trust center subprocessors page. Context: a Hacker News user wrote on 30 Sep 2026 "there is only US hosting and I specifically need EU hosting" (HN 49907998). Reported An EU cloud region on Bedrock or Foundry is not a route either: Jev is not listed in the Amazon Bedrock model cards at 5 Oct 2026, 05:18 UTC, nor in the Azure AI Foundry model catalog at 5 Oct 2026, 05:19 UTC (Is Jev on Amazon Bedrock or Azure AI Foundry?).
Before you send personal data: 8 checks
| Check | What to do | Why |
|---|---|---|
| Decide which layer must not keep data, then read both the gateway and the provider rows for your route. | Route table | |
On Vercel, set zeroDataRetention: true (Pro or Enterprise) if you need ZDR. | Otherwise a request can go to DigitalOcean, marked has_zdr: false | |
| If you route through Cloudflare AI Gateway, turn off logging or payload collection. | "Logs are enabled by default for each gateway" | |
| Leave prompt logging off (it is opt-in) and enforce ZDR on the request or the account. | So a provider policy change cannot reach you | |
| Sign the DPA, ask sales for ZDR and get a retention period in writing. | No retention period is published | |
Snapshot trust.typesafe.ai/subprocessors when you sign, and diarise the 15-day objection window. | DPA 3.2: "reasonable advance notice", objection "within 15 days" | |
| Drop names, emails and IDs the decision does not need, and check what your integration sends. | Some guards send the full conversation (payloads) | |
| Do not use a lookalike reseller for any non-public data. | Their terms are unknown; prompts pass through their servers |
Human review, subprocessors and deletion
Documented TypeSafe's PP, MCA, DPA, Terms and docs; gateway pages where read. "Not stated" means not found in those documents.
| Term | TypeSafe (provider) | Gateways |
|---|---|---|
| Human review or staff access | Not stated. The nearest text is MCA 4.1(c)(ii), a licence to process data "to monitor for fraud and abuse of the Services". DPA Annex, sensitive-data safeguards: "N/A". | Not stated in the gateway pages read |
| Subprocessors, location and transfers | DPA 3.1 authorises subprocessors "as described in https://trust.typesafe.ai/subprocessors". The list was first read on 4 Oct 2026: 6 subprocessors, all in the USA (see below). PP: "The Services are hosted in the United States". DPA 6.1: transfers under the "EU SCCs" or the UK Addendum. DPA 5.2: breach notice "within 72 hours". | Opper: TypeSafe route region "United States", transfer mechanism "unknown". OpenRouter: in-region EU and US routing on Business and Enterprise plans; whether Jev is available in-region was not checked |
| Deletion and opt-out | PP: "When you request that we do so, we take measures to delete your personal data". DPA 4.1: TypeSafe forwards data-subject requests to the customer. No opt-out from Telemetry is stated. Training needs the customer's prior consent, so no opt-out is needed for it. | OpenRouter: prompt logging is opt-in. Opper: tracing off by default on the Gateway plan. Cloudflare AI Gateway: logging on by default, can be turned off |
TypeSafe's subprocessors: six listed, two added on 2 Oct 2026
The DPA points to trust.typesafe.ai/subprocessors for the list. The trust center only shows text when its scripts run, so earlier checks (1 Oct) could not read it. On 4 Oct 2026 (05:30 UTC) the pool rendered it with a local headless browser, read-only, with no account and no form submitted. Documented
| Subprocessor | What the trust center says it does | Location |
|---|---|---|
| Amazon Web Services | "Customer information for live requests is stored and processed on databases, caches and compute nodes within AWS" | USA |
| Modal | "Customer AI prompts are processed, but not stored, on compute nodes managed by Modal" | USA |
| Nebius added 2 Oct 2026 | "Customer AI prompts are processed, but not stored, on compute nodes managed by Nebius" | USA |
| CoreWeave added 2 Oct 2026 | "Customer AI prompts are processed, but not stored, on compute nodes managed by CoreWeave" | USA |
| Slack | Listed; purpose not recorded in the pool's notes | USA |
| Google Workspace | Listed; purpose not recorded in the pool's notes | USA |
- The change: the trust center's only update reads "Nebius and CoreWeave, Published October 2, 2026, Added subprocessors". The DPA (3.2) promises "reasonable advance notice" and an objection window of 15 days; whether customers were notified before 2 Oct was not checked.
- "Processed, but not stored" is TypeSafe's own wording about prompts on Modal, Nebius and CoreWeave compute nodes. AWS is described as storing and processing customer information for live requests. Neither statement sets a retention period.
- SOC 2: the trust center lists a resource named "SOC 2 Type II - 2026" behind "Request access". The report itself was not seen, so the pool states only that the trust center lists it.
- This does not change any route label above (OpenRouter's ZDR list, Vercel's
has_zdrper provider, Cloudflare's "Zero data retention Yes"), which were checked separately.
Compliance terms searched in TypeSafe's text
Searched: typesafe.ai home, Terms, AUP, MCA, DPA, PP, docs legal.md, the models page and llms.txt, 1 Oct 2026. These are negative results within those documents, not proof that no commitment exists elsewhere.
- Listed, not seenSOC 2The trust center lists "SOC 2 Type II - 2026" behind "Request access" (4 Oct 2026); the report was not seen
- Not foundHIPAA or BAANo HIPAA, BAA or PHI term in any public document
- Not foundGDPR as a commitmentThe DPA names the Irish supervisory authority for EEA data subjects and uses EU SCCs
- Not foundEU region or residencyThe PP says the Services are hosted in the U.S.; none found in the docs or trust center on 5 Oct 2026 (boundary)
- Not foundISO 27001Opper states ISO/IEC 27001:2022 for itself, not for TypeSafe
What audited integrations send to Jev
Carried from earlier audits with their original check dates; not re-audited this run. Failure behaviour and source links stay on Claude Code and MCP guardrails and products. Documented
| Integration | What it sends to Jev | Audit and check date |
|---|---|---|
Official typesafe@typesafe-ai plugin v0.5.7 | Nothing: instructions only, it never calls Jev | Commit 65a39f3, 29 Sep 2026 |
danna-zhou/jev-mcp hooks | The full shell command, only for commands on its "high-stakes" list | Commit 436469a, 29 Sep 2026 |
brunopivetta88/jev-claude 0.1.0 | User goal, full tool input with regex secret redaction, last 8 action summaries, working directory | Commit 7d7e876, 29 Sep 2026 |
jkudish/jev-mcp v0.11.0 | Only what the agent passes to a tool. v0.12.0 and v0.13.0 were compared with the audited version on 2 Oct 2026: the same content is sent; in 0.13.0 jev_verify puts claim text in state and asks one extra question per claim (version check) | 29 Sep 2026; checked at 0.13.0 on 2 Oct |
LangChain AutoModeMiddleware (langchain-typesafe 0.0.1a3) | The tool call with full arguments, the tool description and the last 30 messages in full | 29 Sep 2026 |
oh-my-claudecode v5.5.0 | Nothing unless OMC_JEV lists points; then per-point text cut to 200 characters | Commit 9fd35ec, 29 Sep 2026 |
| WordPress Jev Comment Triage (soderlind) | The default payload includes the comment author's identity | Products ledger, 28 Sep 2026 |
Third-party privacy claims vs the text
| Claim (who, date) | What the primary text says | Verdict |
|---|---|---|
| "Jev is not trained on customer requests or responses" (jevaiguide.com FAQ, checked 25 Sep) Reported | The models page and the PP say the same. MCA 4.1 adds "without Customer's prior consent", and MCA 4.3 lets TypeSafe use Telemetry "to improve the Services" | Matches but does not address the consent and Telemetry clauses |
| OpenRouter ZDR for Jev: "Not stated on the Jev page" (jevaiguide.com, 25 Sep) Reported | On 1 Oct, and again on 2 Oct, the TypeSafe endpoint is in OpenRouter's ZDR endpoint list, and its data policy reads retainsPrompts: false | Contradicted as of 1 Oct It may have changed after 25 Sep; the pool has no earlier reading of the list |
| "Retention is 'as long as necessary' — no number" (jev101.org, "verified 2026-09-28") Reported | DPA Annex §8 and the PP | Matches |
| "Jev is not HIPAA-compliant and does not sign BAAs"; customers must not submit PHI (vendortrustindex.com, "Last verified 2026-09-30") Reported | No HIPAA, BAA or PHI term in TypeSafe's public documents | Not addressed by public text. Its "SOC 2 Type II current" is Unverified: TypeSafe's trust center lists a SOC 2 Type II resource (4 Oct 2026), but the report was not seen |
What was not verified
- TypeSafe's SOC 2 report: listed on the trust center behind "Request access", not seen. SOC 2 status at the gateway layer.
- What Slack and Google Workspace process for TypeSafe, and whether customers were notified before Nebius and CoreWeave were added.
- Whether DigitalOcean on Vercel forwards requests to TypeSafe or serves Jev itself, why Vercel's endpoints API returned only DigitalOcean on 1 and 2 Oct, and which provider served any given request (no request was sent).
- Whether OpenRouter's ZDR listing of the TypeSafe endpoint rests on a special agreement, and whether the clause Vercel quotes comes from a contract that standard accounts also get.
- Human review or staff access at any layer; a TypeSafe retention period; a Telemetry opt-out.
- Netlify AI Gateway's data terms, beyond one docs sentence (4 Oct): whether TypeSafe retains prompts sent through Netlify, Netlify's region and any ZDR label.
- No account was opened and no request was sent on any route. This is a reading of public text only.
Sources and check times (1 Oct 2026, UTC)
- TypeSafe: Privacy Policy, MCA, DPA, Terms and AUP: quoted from the pool's captures of 30 Sep; "Last updated" dates rechecked 05:16. Docs legal page and models page (05:16). Trust portal (05:26, unreadable on 1 Oct).
- 4 Oct 2026: TypeSafe trust center subprocessors and updates, rendered with a local headless browser at 05:30:18–05:30:35 UTC (R7-S80); Netlify AI Gateway docs (05:31:22 UTC, R7-S82).
- 5 Oct 2026: route data labels (OpenRouter ZDR list, Vercel endpoints, Cloudflare model page, Opper route card) and TypeSafe legal "Last updated" dates rechecked 05:13:31–05:15:03 UTC, unchanged (R8-S29, R8-S33, R8-S40–R8-S44, R8-S48, R8-S49); trust center subprocessors rendered again at 05:14:25 UTC, unchanged (R8-S45); TypeSafe docs full text searched for "data residency", "region", "eu" and "europe" at 05:17:54 UTC (R8-S110); HN item 49907998 (05:21:28 UTC, R8-S121).
- 6 Oct 2026: route data labels (OpenRouter ZDR list, Vercel models and endpoints APIs, Cloudflare model page, Opper route card) and TypeSafe legal "Last updated" dates rechecked 05:15:34–05:15:35 UTC (R9-S28, R9-S29, R9-S33, R9-S40–R9-S44, R9-S48, R9-S49); only Vercel changed (second provider, TypeSafe AI,
has_zdr: true). Vercel provider options 05:24:28 UTC (R9-S112); Vercel Jev model page 05:24:29 UTC (R9-S113). Trust center subprocessors rendered again at 05:17:16 UTC, unchanged (R9-S45). - 7 Oct 2026: route data labels (OpenRouter ZDR list, Vercel models and endpoints APIs, Cloudflare model page, Opper route card) and TypeSafe legal "Last updated" dates rechecked 05:19:15 UTC, unchanged (R10-S45, R10-S28, R10-S46, R10-S29, R10-S33, R10-S37). Docs legal page compared with the Internet Archive copy of 22 Sep 2026, 15:56 UTC at 05:20:20 UTC: two changes only, the ZDR contact mailbox (privacy mailbox to sales mailbox) and a footer line (R10-S38). Trust center subprocessors rendered at 05:20:29 UTC, unchanged: 6 entries (R10-S39).
- OpenRouter: Jev 1.13 page and data policy, ZDR docs, privacy and logging, Privacy Policy (05:26); ZDR endpoint list (05:27).
- Vercel: Jev model page and ZDR docs (05:26); disallow-prompt-training page (05:28); endpoints API (05:30); models API (05:16).
- Cloudflare: Workers AI data usage, Jev model page, AI Gateway logging (05:26).
- Opper: TypeSafe route card (05:26); security docs, ZDR and retention rules (05:29).
- Third parties: Eye Security (05:16); jevaiguide.com, jev101.org, vendortrustindex.com (05:26).