What leaves my machine?
From a project you have turned on, jevmem sends message text to TypeSafe to be scored, with common secrets scrubbed first: your message, the previous two turns and your memory lines, and, for the guard, the command or the file being changed. From a project you have not turned on it sends nothing; it has no telemetry; and it sends nothing to OpenAI or Anthropic unless you set writer in jevmem.config.json.
Memory lines that a teammate or a pull request adds are checked before Claude sees them: on a 44-line test set (2026-09-25), that check blocked 20 of 22 planted lines, with 0 false blocks on 22 legitimate rules (results). The scrubber matches patterns, so a secret written in a form it does not know can get through, and names, phone numbers and addresses are not removed.
The rest of this page is the repository's PRIVACY.md, as it stands. To set jevmem up: install.
Last updated: 2026-10-04
This page describes jevmem 0.6.4, the release on npm.
jevmem reads your prompts and parts of your Claude Code conversations (and, for the guard, the shell commands and file edits Claude is about to make). It stores some of that text on your machine and sends it to the services listed below. Prompts can contain personal data, so this page says what goes where. SECURITY.md has the full detail.
Who #
jevmem is an open-source tool (MIT licence) by Avinash Jetwani. It runs on your machine. I run no server, and jevmem sends nothing to me. There is no telemetry: no analytics, no usage reports, no call home.
What leaves your machine, and where #
Only from a project you have enabled (jevmem enable or jevmem init, which create jevmem.config.json), and only when a TypeSafe API key is set. From any other project jevmem sends nothing (tested).
Before anything is sent, secrets are replaced with [REDACTED] by pattern matching: API keys and tokens in the shapes of OpenAI, Anthropic, GitHub, GitLab, Slack, AWS, Google, Stripe, npm and Hugging Face keys, JWTs and bearer tokens; the value after a name that ends in PASSWORD, PASSWD, PWD, SECRET, TOKEN or KEY, such as DB_PASSWORD=, PGPASSWORD=, apiKey: or "authToken":; passwords in connection strings; private keys; email addresses; and 16-digit, card-shaped numbers. The exact rules are in SECURITY.md. Names such as PGPASSWORD, with no underscore before the word, and the "name": "value" form are caught since 0.5.8: 0.5.7 and earlier sent PGPASSWORD=… and "password": "…" as written, so if your chats in an enabled project had such lines, rotate those credentials (advisory GHSA-2r3p-5hmg-46p5, CHANGELOG). Because it only matches patterns, a secret written in a form it doesn't know can still get through, and people's names, phone numbers and postal addresses are not removed at all, so don't put anything in a prompt that you don't want sent.
To TypeSafe AI, at https://api.typesafe.ai/v1/systemone, or the URL in TYPESAFE_BASE_URL if you set one. TypeSafe's Jev model decides what to save and what to recall.
- After each turn (in Claude Code, or in Codex while
jevmem watchruns): your message, the previous two turns (shortened) and up to 200 of your memory lines. Claude's reply is included only when a broad keyword check reads your message as a question or a bug report, or when it has no text. Since 0.6.0, a turn that is saved gets one more request: the sentences of the text its line is written from (your message, or Claude's reply when the line comes from it), scrubbed, so that Jev can pick the one that states the memory and the one that gives its reason. A turn that is not saved sends nothing more. - On each prompt: the prompt and every live memory line, up to 250 (up to 0.5.10: up to 60 of them), and for a line that replaced earlier ones, the text of up to two of those superseded lines, so Jev can tell what the line is about. Superseded lines are never put into Claude's context.
- Before a Bash, Edit or Write call, from the guard (docs/guardrails.md; since 0.6.0): only for a call that shares a path, filename, command or enough words with one of the project's saved
[constraint]rules. It sends the command, or the file path plus a short scrubbed snippet of the change (at most 600 characters of the new text and 300 of the replaced text), and those rules. Forgit add,git stageandgit commit, the guard first runsgit statuson your machine to see which files the command would stage or commit; of those, it sends only the paths (at most 10) of the ones a rule about committing names, such as.env (untracked), and keeps none of the list. Nothing is sent for a call that shares nothing with a rule, when the answer is already cached, or whenguard.modeisoff. - When you or the agent use the MCP tools or
jevmemcommands: a line to add, your memory lines, statements fromCLAUDE.md,AGENTS.mdand Cursor rules (jevmem import), and forjevmem auditthe project's file names to depth 3 (not their contents),package.jsonfields and the first 3,000 characters of the README.
To OpenAI (https://api.openai.com) or Anthropic (https://api.anthropic.com), or the URL in OPENAI_BASE_URL or ANTHROPIC_BASE_URL, only when the project's jevmem.config.json sets "writer": "openai" or "anthropic" and that provider's key is set. Then, for each turn Jev decides to save, the text of that turn, to condense it into one line. A key in your environment is not enough on its own (tested). By default jevmem writes the line itself and sends nothing to either.
These are the only network calls in jevmem's code (a test checks the source for others).
Third parties #
The data goes to these services under your own API key. What they do with it is governed by their own terms and privacy policies, not by jevmem:
- TypeSafe AI: privacy policy, terms of use
- OpenAI: privacy policy, services agreement
- Anthropic: privacy policy, commercial terms
jevmem can ask for zero data retention on each TypeSafe request ("jev": { "zeroDataRetention": true } in jevmem.config.json). Whether it applies is TypeSafe's policy, which jevmem does not check.
What's stored, and where #
All of it on your machine:
JEVMEM.md, in the project: the memory lines. It is meant to be committed, so everyone with access to the repository can read it..jevmem/, in the project, local and gitignored: a copy of the memory lines, a log of each Jev call and of any line the poisoning check withheld, the save queue and recent decisions with the scrubbed turn text, yourrightandwronglabels, cached Jev answers, and hashes of the lines jevmem wrote. Since 0.6.0, the guard also keeps its index of your rules, its cached answers (kept by hashes of the rule and the call, not the call's text) and a log,.jevmem/guard-log.jsonl: one line per Bash, Edit or Write call it checked, with the time, the tool and how it was decided, and for a call it asked about, denied or warned about, the rule, Jev's score and a short scrubbed summary of the command or edit.jevmem guard logshows it, and nothing in it is sent anywhere; since 0.6.1 a call where a part of the check failed also carries the error, scrubbed. Also since 0.6.0, a turn that waits for its background subagents is kept in.jevmem/turns.json, with its scrubbed text, until it is decided, next to the ids of the turns already decided. WithJEVMEM_DEBUG=1, also the raw hook input.- The plugin's data folder (
~/.claude/plugins/data/…): the paths of the jevmem CLI and Node it found and, in an enabled project without the CLI, the ids of the sessions it has shown the "CLI not found" message. - The system temp folder: the
Stophook's input, until jevmem reads and deletes it. - Your TypeSafe API key: in
~/.jevmem/envor<project>/.jevmem/.envif you put it there, it is in that file. For a plugin installed from a marketplace you can instead enter it in the plugin's settings (/plugin configure jevmem; the plugin added from the Claude plugin directory,jevmem@synced, has no such setting): Claude Code keeps it in your system's secure credential store, and jevmem doesn't write it to a file or a log (tested). Since 0.5.10,jevmem keywrites it to~/.jevmem/envfor you: the folder and the file readable only by you, and the key never printed or logged (tested).
How to delete it #
In each project:
jevmem disablestops jevmem there. It movesjevmem.config.jsoninto.jevmem/.jevmem daemon stop, then delete.jevmem/: the logs, queue, decisions and cached answers.- Remove the lines you don't want from
JEVMEM.md, or delete the file. Lines you already committed stay in your git history. - If you set the project up with
jevmem init,jevmem init --remove-hooksremoves its hooks.
Then, once:
claude plugin uninstall jevmemremoves the plugin. When you uninstall it from the last place it's installed, Claude Code also deletes its data folder, unless you pass--keep-data.- A key you entered in the plugin's settings is held by Claude Code in the credential store, not by jevmem; remove it there. Delete
~/.jevmem/envif you created it. npm uninstall -g jevmemremoves the CLI.
Data already sent to TypeSafe, OpenAI or Anthropic is covered by their policies above.
Contact #
Questions and requests: GitHub issues. Security problems: private vulnerability reporting, as SECURITY.md describes.
The limits, in short #
- jevmem needs a TypeSafe API key (where to get one, and the install steps).
- Message text is sent to TypeSafe to be scored, with common secrets scrubbed first (what leaves your machine).
- It is automatic in Claude Code, automatic in Codex while
jevmem watchruns, and in Cursor only when the agent calls it (what each tool does). - Rules every task must follow still belong in
CLAUDE.md(jevmem next to CLAUDE.md). - The guard is a backstop, not a sandbox (what it misses).
Every limit, with the numbers: the FAQ.