Data processing by route
Last checked: 2026-09-22. This page summarises the public terms of each company that receives form data on each Formsieve route. We read them on that date; the providers can change their terms unilaterally, so follow the links for the current versions. This is information, not legal advice. As the site owner you are the controller of your visitors' data and decide whether a route suits your obligations.
What Formsieve sends is the same on every route: the ordinary text and choice fields of the submission (phone numbers redacted by default), the domain of the sender's e-mail address, your site and form description and a few numeric signals. Never IP addresses, user agents, full e-mail addresses, passwords, payment fields, uploads or fields that look like health, ID or bank data. Details: How it works.
Who receives the data
| Route | Chain of recipients |
|---|---|
| TypeSafe (direct) | Your site → TypeSafe AI, Inc. (USA) → TypeSafe's sub-processors (USA) |
| Vercel AI Gateway | Your site → Vercel Inc. (USA) → TypeSafe AI, Inc. (USA) → TypeSafe's sub-processors |
| OpenRouter | Your site → OpenRouter, Inc. (USA) → TypeSafe AI, Inc. (USA) → TypeSafe's sub-processors |
| Custom base URL | Your site → the endpoint you configured → (normally) TypeSafe AI, Inc. |
On a gateway route there are two recipients: neither Vercel nor OpenRouter lists TypeSafe as its own sub-processor; both treat the model provider as a third party under its own terms. Formsieve's consent screen and privacy-policy text therefore name both. No route offers processing in the EU for Jev as of 2026-09-22: every route ends at TypeSafe in the United States.
TypeSafe (direct)
- Company: TypeSafe AI, Inc., San Francisco, California, USA.
- Role: processor ("service provider") under its Data Processing Agreement, with the EU Standard Contractual Clauses (modules 2 and 3) and the UK Addendum; 15 days to object to a new sub-processor.
- Hosting: United States. Sub-processors listed at trust.typesafe.ai: Amazon Web Services (live request data is "stored and processed on databases, caches and compute nodes within AWS"), Modal, Nebius and CoreWeave (prompts "processed, but not stored"), and Slack and Google Workspace for support communications. All in the USA.
- Retention: "as long as necessary" for the purpose, with no fixed period; the agreement also says TypeSafe "may delete Customer Data at any time". Zero data retention is offered to enterprise customers only.
- Training: TypeSafe's privacy policy states that it will not train or fine-tune models on your prompts or other input.
- Links: Terms (Master Customer Agreement) https://typesafe.ai/legal/mca · Privacy policy https://typesafe.ai/legal/privacy-policy · DPA https://typesafe.ai/legal/data-processing · Sub-processors https://trust.typesafe.ai/subprocessors
Vercel AI Gateway
- Company: Vercel Inc., USA, then TypeSafe AI, Inc.
- Role: Vercel acts as your processor only for teams on a paid Pro or Enterprise plan; its DPA does not cover the Hobby plan, which is for personal, non-commercial use. Vercel's terms allow it to use Hobby and trial-Pro content for model training. TypeSafe is a "Non-Vercel Service" whose own terms apply.
- Hosting: Vercel's primary processing is in the United States, and a request can be processed in any Vercel region. Jev has no regional option on Vercel. TypeSafe: USA.
- Retention: Vercel states that AI Gateway does not retain prompts or responses (they are deleted after the request) and keeps metadata, with routing details for 30 days. Vercel lists TypeSafe as a zero-data-retention provider under a negotiated clause that is not part of TypeSafe's public terms.
- Training: Vercel states it does not train on your prompts (paid plans; Hobby as above). Vercel's catalogue marks Jev as no-training.
- Your obligations under Vercel's AI Product Terms: do not put sensitive personal information (health data, financial account numbers, government identifiers) into requests (Formsieve excludes such fields automatically), and tell end users in advance that your application uses AI (Formsieve's AI notice line is on by default for this route).
- Links: AI Product Terms https://vercel.com/legal/ai-product-terms · Privacy policy https://vercel.com/legal/privacy-policy · DPA https://vercel.com/legal/dpa · then TypeSafe's links above.
OpenRouter
- Company: OpenRouter, Inc., New York, USA, then TypeSafe AI, Inc. as the model provider.
- Role: processor under OpenRouter's DPA, which is part of its terms (EU Standard Contractual Clauses module 2, UK Addendum, Swiss terms).
- Hosting: Google Cloud Platform in US regions. Jev is not available through OpenRouter's EU routing.
- Retention: OpenRouter's DPA says it deletes inputs and outputs promptly after generating the output unless you opt into logging in your OpenRouter account. OpenRouter lists TypeSafe's Jev endpoint as not retaining prompts and includes it among its zero-data-retention endpoints.
- Training: OpenRouter states it does not use your inputs or outputs for training (unless you opt into its discount programme); TypeSafe's endpoint is marked as not training.
- What Formsieve does: with "Require zero data retention" on (the default), every request asks OpenRouter to route only to zero-data-retention endpoints and to deny data collection. If no such endpoint is available the check is skipped and the submission follows your fail mode (delivered by default); the Dashboard's last API error shows
no_eligible_endpoint, and a notice on Formsieve's screens says so until the model answers again. - Your obligations: OpenRouter's terms ask you to bind your own customers to each model's terms; for Jev OpenRouter points to https://typesafe.ai/legal/terms.
- Links: Terms https://openrouter.ai/terms · Privacy policy https://openrouter.ai/privacy · DPA https://openrouter.ai/data-processing-agreement · then TypeSafe's links above.
Custom base URL
The endpoint you configure receives the data first. Formsieve cannot know its terms: you confirm in the wizard that you have your own agreement with its operator. A LiteLLM pass-through that you host with your own TypeSafe key adds no third party beyond TypeSafe.
AI/ML API (reachable only through Custom): operated by Boiler Labs FZ-LLC (United Arab Emirates, Estonian law), which describes itself as the data controller. As of 2026-09-22 we found no data processing agreement and no statement on retaining or training on API inputs, and its processing location is not stated. Formsieve warns about this when you point it at api.aimlapi.com.
What we do not claim
Formsieve gives you tools for data minimisation, consent, disclosure, export, erasure and retention. It does not make a site "GDPR compliant" by itself, it does not keep data in the EU, and zero data retention is not available on every route (TypeSafe offers it to enterprise customers only).
Open questions
As of 2026-09-22, TypeSafe has not published a retention period for self-serve accounts, has not said whether the no-retention clause it gave Vercel applies to all customers, and does not state whether it is certified under the EU-U.S. Data Privacy Framework. These questions are being put to [email protected]; this page will be updated with the answers.