Blog / Questions / FIG. 129
Can Jev Handle PII?
Can Jev handle PII? It can process it, but the better question is how little you send. The minimization pattern, a PII-finding build, and what to ask.
Technically yes: Jev, TypeSafe AI's decision model, will judge whatever text you send it, personal data included. Whether you should send it is a question for your vendor review and your architecture, and the architecture half usually shrinks the PII problem more than any policy does.
What Jev's data terms are (retention, training use, residency, certifications) is TypeSafe AI's to state at docs.typesafe.ai. Nothing on this page substitutes for that, and none of it is legal advice.
The minimization pattern in one paragraph
A decision model needs only enough context to rule, and it returns a closed answer rather than free text, so there's no output channel echoing your data back. That makes minimization cheap: send the fields the question needs, not the whole record; redact or tokenize names where the verdict doesn't depend on identity; extract locally and ship only derived text. The full treatment, including logging and audit posture, lives on the security and privacy page, which owns this topic.
Builds that treat PII carefully
The receipts here aren't cost numbers; they're patterns worth copying.
- Using Jev to find the PII. One build tags personal details, such as names, inside Postgres support messages so redaction can target meaningful spans instead of blanking a whole column (build). The verdict layer becomes part of the privacy control.
- Redacting before anything persists. A local decision cache redacts and canonicalizes inputs before hashing them, so repeated verdicts don't leave raw text lying around in cache keys (build).
- Keeping raw data on the device. A macOS automation build identifies controls with local CoreML and Apple Vision OCR, and only then asks Jev to choose an action (build). Pixels stay local.
A caution on the first pattern: a PII detector that misses a span is a leak, so treat its verdicts as one layer, pair it with deterministic rules for structured identifiers (emails, phone numbers), and calibrate on your own data. Irreversible steps, like publishing or sharing a record, shouldn't hinge on a single verdict.
Frequently asked questions
Is it safe to send personal data to Jev?
That depends on TypeSafe AI's published data terms and your own obligations; check docs.typesafe.ai and run a vendor review. Architecturally, send the minimum fields a verdict needs.
Can Jev detect PII in text?
Builders use it that way, for example to tag names in support messages before redaction. Pair it with rule-based detection for structured identifiers and calibrate before relying on it.
Should verdict logs contain the original text?
Preferably not: log references or redacted excerpts, and apply retention rules to verdict logs as you would to the source data, per the security page.
Is Jev HIPAA compliant?
Compliance is a vendor and contract question, not a model feature; the HIPAA page covers what to ask.
Numbers throughout are as reported by the build authors, not verified by shipwithjev. Code-shaped examples are pseudocode; the official docs live at docs.typesafe.ai.