Privacy Policy — Your Data and Controls

What JevStation collects, how your Jev evaluations reach the model provider, how long we keep them, and the controls you have over your data.

Last updated:

Overview

JevStation ("we", "us") is a hosted workspace for running evaluations with Jev, TypeSafe's System One model. You paste a state — a support ticket, a review, a specification, or a JSON record — define typed questions, and Jev returns structured answers with probability distributions and confidence values instead of prose.

This policy explains what personal information we collect when you use the Service, why we collect it, who it is shared with, and the choices you have. It covers the website, the playground, the docs, the shared apps catalog, and your account area.

Information we collect

Account information. Your name, email address, avatar image, and interface language. If you sign up with an email address and password, the password is hashed before it is stored — we never keep it in readable form. If you sign in with Google or GitHub, we receive the basic profile those providers share (account identifier, name, email address, avatar) and the tokens needed to keep you signed in.

Sign-up attribution. When you create an account we record the first utm_source value we saw for you, the IP address of the signup request, and your interface locale, so we can tell which channels bring people to the Service.

Session and security data. Session tokens and expiry times, plus the IP address and browser user-agent associated with a signed-in session. We also keep short-lived rate-limit records used to prevent abuse.

Evaluation content. The material you run through the playground: the state you submit (up to 8,000 characters), any context you attach (up to 2,000 characters), the questions you define (names, types, instructions, and the options or levels you supply), the answers Jev returns — including probability distributions and confidence values — and the model and provider used for the run. Evaluations are stored against your account with a title derived from their content so you can return to them.

Usage and metering records. Credit grants and consumption, your balance over time, the scene or feature a credit was spent on, expiration dates, and request timestamps.

Billing records. Orders, amounts, currency, the credit pack purchased, purchase and refund records, and the payment provider and transaction reference. Card and bank details are entered directly with the payment provider — we do not receive or store full payment card numbers.

Support content. The subject and messages of any support ticket you open, and any images you attach to it.

Submissions. If you use the public submit form, we collect the title, link, category, description, and contact email you provide.

API keys. The label you give a key, a short display prefix, a one-way hash of the key, an encrypted copy so you can copy it again from your account, and last-used timestamps.

Device and usage analytics. Only where the operator has enabled an analytics provider (see "Cookies and similar technologies"): pages viewed, referring URL, approximate location derived from IP address, and device and browser type.

How your evaluations reach the model provider

Jev is not a text generator. An evaluation is a single request and response, not a token stream. When you run one, the state, the context, and your questions are transmitted to the model provider configured for the Service — TypeSafe's Jev API, or a self-hosted or OpenAI-compatible gateway the operator has set up — so that it can return answers.

That provider processes the content under its own terms of service and privacy policy. We do not send your account credentials, payment details, or API keys to it, and provider credentials are held server-side and never reach your browser or your code.

We do not use your evaluation content to train models, and we do not sell it.

Evaluations are scoped to the signed-in user. One account can never read another account's evaluations.

How we use information

  • Provide, operate, maintain, and secure the Service.
  • Run evaluations and meter them against your credit balance.
  • Process payments, administer purchases and refunds, and send related confirmations and notices.
  • Send account emails such as address verification and password reset links.
  • Respond to your support tickets and other requests.
  • Review submitted apps and, where they are a fit, publish the listing in the shared catalog.
  • Detect, investigate, and prevent abuse, fraud, and attempts to bypass credits or rate limits.
  • Understand aggregate usage so we can improve the Service.

Cookies and similar technologies

We use a small number of cookies and browser storage entries:

  • Session cookie — keeps you signed in. Strictly necessary; without it you cannot use your account.
  • Locale cookie — remembers whether you chose English or Chinese, so later visits stay in the language you picked.
  • utm_source cookie — set only when a link you followed carries a utm_source parameter, and kept for 30 days, so the channel that first brought you here can be recorded if you sign up.
  • Local storage — remembers your light or dark theme preference.

Where the operator has configured them, optional third-party tools may also load: Google Analytics or Plausible for traffic measurement, Google AdSense for advertising, Crisp or Tawk.to for live chat, and Google One Tap for a one-click sign-in prompt. These providers may set their own cookies and receive your IP address, device and browser information, and the pages you visit. They are governed by their own privacy policies, not this one.

You can block or delete cookies and site data through your browser settings. Blocking the session cookie will prevent you from signing in; blocking the locale cookie resets your language choice.

When we share information

We do not sell your personal information. We share it only in these cases:

  • Service providers. The model provider that runs your evaluations; the payment processors that handle your purchases; the email provider that delivers account email; the object storage or CDN that serves uploaded images; and our hosting and database infrastructure. When one of the optional tools above is enabled, that provider is included too. These providers act on our instructions and are bound to use the data only to deliver their service to us.
  • Legal and safety. To comply with a law, regulation, or valid legal process; to enforce our Terms of Service; or to protect the rights, property, or safety of us, our users, or the public.
  • Business transfer. If the Service or its assets are transferred, merged, or sold, information may transfer as part of that transaction. This policy continues to apply to the data afterwards.

We do not share your evaluation content with advertisers, and we do not disclose it to other users.

International transfers

The Service runs on infrastructure chosen by the operator, and our service providers may process data in countries other than the one you live in. Where required, we rely on appropriate safeguards for those transfers, such as standard contractual clauses.

How long we keep information

  • Account information — while your account exists.
  • Evaluation content — until you delete it. Deleting an evaluation from the playground removes it and its messages from the active database. Copies may persist briefly in backups before they are overwritten.
  • Support tickets — for a reasonable period after the ticket is closed, so we can keep context for follow-ups.
  • Billing and metering records — for as long as accounting, tax, and dispute-resolution obligations require, which may be longer than the life of your account.
  • Cookies and local storage — as described above, or until you clear them.

Security

We protect your information with encryption in transit, access controls limited to the people who need them, and regular review of how the Service handles data. Passwords are hashed rather than stored, API keys are kept as one-way hashes and are never displayed in full after creation, and configurable secrets can be encrypted at rest with AES-256-GCM when the operator sets an encryption key.

No method of transmitting or storing data is completely secure. If you believe your account or a credential has been compromised, email support@jevstation.com or open a support ticket immediately so we can help.

Your rights and choices

You can manage most of your information directly:

  • Update your name and avatar in Settings → Profile.
  • Delete an individual evaluation from the playground.
  • Review your credit balance and history in Settings → Credits.
  • Review purchases and invoices in Settings → Payments.
  • Review your purchase history in Settings → Billing.
  • Create and revoke API keys in Settings → API Keys.
  • Open a support ticket in Settings → Support Tickets.

To request a copy of your personal information, or to have your account and associated personal data deleted, open a support ticket. We may ask you to verify that you control the account before we act. We will respond within the timeframe required by applicable law.

Depending on where you live, you may have additional rights — for example, under the GDPR in the EEA, the UK, or Switzerland, or under California privacy law. These can include the right to access, correct, delete, restrict, or object to processing, the right to data portability, the right to withdraw consent, and the right to complain to your local supervisory authority. We do not discriminate against anyone for exercising these rights. Where we process data to perform our contract with you or on the basis of your consent, that is the legal basis for the processing described here; we also process some data for our legitimate interest in operating and securing the Service.

We do not currently respond to browser "Do Not Track" signals, because there is no common industry standard for interpreting them.

Children

The Service is not intended for children. You must be at least 16 years old to create an account, and we do not knowingly collect personal information from anyone under that age. If you believe a child has created an account, email support@jevstation.com or open a support ticket and we will delete it.

Changes to this policy

We may update this policy as the Service changes. When we do, we update the date at the top of this page. For material changes we will also give notice through the Service — for example, a message in your account area — before the change takes effect.

Contact us

For any question about this policy, or to exercise a privacy right, email support@jevstation.com. If you have an account, you can also open a support ticket at Settings → Support Tickets — a ticket stays linked to your account and order history, which lets us verify a request against the right account and keep a record of our reply.