jevmemjevmem

What leaves my machine?

From a project you have turned on, jevmem sends message text to TypeSafe to be scored, with common secrets scrubbed first: your message, the previous two turns and your memory lines, and, for the guard, the command or the file being changed. From a project you have not turned on it sends nothing; it has no telemetry; and it sends nothing to OpenAI or Anthropic unless you set writer in jevmem.config.json.

Last updated: · jevmem 0.6.4 · Install · Source on GitHub

Memory lines that a teammate or a pull request adds are checked before Claude sees them: on a 44-line test set (2026-09-25), that check blocked 20 of 22 planted lines, with 0 false blocks on 22 legitimate rules (results). The scrubber matches patterns, so a secret written in a form it does not know can get through, and names, phone numbers and addresses are not removed.

The rest of this page is the repository's PRIVACY.md, as it stands. To set jevmem up: install.

Last updated: 2026-10-04

This page describes jevmem 0.6.4, the release on npm.

jevmem reads your prompts and parts of your Claude Code conversations (and, for the guard, the shell commands and file edits Claude is about to make). It stores some of that text on your machine and sends it to the services listed below. Prompts can contain personal data, so this page says what goes where. SECURITY.md has the full detail.

Who #

jevmem is an open-source tool (MIT licence) by Avinash Jetwani. It runs on your machine. I run no server, and jevmem sends nothing to me. There is no telemetry: no analytics, no usage reports, no call home.

What leaves your machine, and where #

Only from a project you have enabled (jevmem enable or jevmem init, which create jevmem.config.json), and only when a TypeSafe API key is set. From any other project jevmem sends nothing (tested).

Before anything is sent, secrets are replaced with [REDACTED] by pattern matching: API keys and tokens in the shapes of OpenAI, Anthropic, GitHub, GitLab, Slack, AWS, Google, Stripe, npm and Hugging Face keys, JWTs and bearer tokens; the value after a name that ends in PASSWORD, PASSWD, PWD, SECRET, TOKEN or KEY, such as DB_PASSWORD=, PGPASSWORD=, apiKey: or "authToken":; passwords in connection strings; private keys; email addresses; and 16-digit, card-shaped numbers. The exact rules are in SECURITY.md. Names such as PGPASSWORD, with no underscore before the word, and the "name": "value" form are caught since 0.5.8: 0.5.7 and earlier sent PGPASSWORD=… and "password": "…" as written, so if your chats in an enabled project had such lines, rotate those credentials (advisory GHSA-2r3p-5hmg-46p5, CHANGELOG). Because it only matches patterns, a secret written in a form it doesn't know can still get through, and people's names, phone numbers and postal addresses are not removed at all, so don't put anything in a prompt that you don't want sent.

To TypeSafe AI, at https://api.typesafe.ai/v1/systemone, or the URL in TYPESAFE_BASE_URL if you set one. TypeSafe's Jev model decides what to save and what to recall.

To OpenAI (https://api.openai.com) or Anthropic (https://api.anthropic.com), or the URL in OPENAI_BASE_URL or ANTHROPIC_BASE_URL, only when the project's jevmem.config.json sets "writer": "openai" or "anthropic" and that provider's key is set. Then, for each turn Jev decides to save, the text of that turn, to condense it into one line. A key in your environment is not enough on its own (tested). By default jevmem writes the line itself and sends nothing to either.

These are the only network calls in jevmem's code (a test checks the source for others).

Third parties #

The data goes to these services under your own API key. What they do with it is governed by their own terms and privacy policies, not by jevmem:

jevmem can ask for zero data retention on each TypeSafe request ("jev": { "zeroDataRetention": true } in jevmem.config.json). Whether it applies is TypeSafe's policy, which jevmem does not check.

What's stored, and where #

All of it on your machine:

How to delete it #

In each project:

  1. jevmem disable stops jevmem there. It moves jevmem.config.json into .jevmem/.
  2. jevmem daemon stop, then delete .jevmem/: the logs, queue, decisions and cached answers.
  3. Remove the lines you don't want from JEVMEM.md, or delete the file. Lines you already committed stay in your git history.
  4. If you set the project up with jevmem init, jevmem init --remove-hooks removes its hooks.

Then, once:

Data already sent to TypeSafe, OpenAI or Anthropic is covered by their policies above.

Contact #

Questions and requests: GitHub issues. Security problems: private vulnerability reporting, as SECURITY.md describes.

The limits, in short #

Every limit, with the numbers: the FAQ.