PRIVACY AND DATA FLOW

Know what leaves
your machine.

Jev Social runs locally, but it is not an offline application. This page separates browser traffic, onboarding credentials, Jev decisions, report synthesis, child-process telemetry, and files saved on your machine.

Local UI · direct provider calls · child telemetry off by default · manual local retention

Follow each payload.

“Local” describes where Jev Social runs. It does not collapse every browser, model, and storage boundary into one.

  1. 01

    Browser and social site

    The selected social site loads in your Chrome session through the installed socai CLI. Jev Social does not read or copy the browser cookie store directly.

  2. 02

    Onboarding credentials

    Default onboarding can send the OpenRouter key to https://openrouter.ai/api/v1/auth/key for validation. A key entered interactively is saved in config.json; an existing OPENROUTER_API_KEY is used without writing a second copy.

  3. 03

    Jev decisions

    OpenRouter receives the goal, typed choices, observed URLs, action summaries, and up to 400 characters of visible text per captured item by default.

  4. 04

    Report synthesis

    A separate OpenRouter call receives a bounded evidence summary by default. Set OPENROUTER_REPORT_MODEL=off to use the deterministic report path.

Choose the path.
Keep the distinction.

Decision routing, report generation, and browser execution are independent choices.

DEFAULT DECISIONS

OpenRouter Jev

Decision requests go directly from Jev Social to OpenRouter. They do not pass through a Jev Social analytics service.

Payload
Bounded choices
Browser tools
None
LOCAL DECISIONS

Loopback System One

An explicit Kev or Simple Jev endpoint can receive the same decision payload on exact loopback HTTP. The OpenRouter key is not attached.

Host
Loopback only
Route
/v1/systemone
Open the local provider guide ↗
REPORT PATH

Separate and optional

Report synthesis has no browser or shell tools. Disable it independently when evidence must stay on the deterministic reporting path.

Disable
MODEL=off
Input
Sanitized evidence

Provider-side storage and retention are governed by OpenRouter and the selected model provider. A local decision server has its own model, log, and retention behavior; Jev Social does not manage that server.

Telemetry starts off.

Jev Social starts socai with SOCAI_TELEMETRY=0 when that setting is absent. Only the exact value 1 opts the spawned process in.

  • OPENROUTER_API_KEY, TYPESAFE_API_KEY, and SOCAI_API_KEY are excluded from the child environment.
  • Session-token variables are excluded too.
  • An independently running desktop process has its own process-level setting; configure that process separately.

For the audited socai v0.6.1 release, opting in sends structured events to socai.io/v1/events, which forwards client-supplied scalar fields to Axiom. Events can include a stable install ID, process and request IDs, device context, status, timing, search query text, and target arguments; available authenticated cloud context can include the full phone number, point balance, Pro expiry, and subscription status. That public contract does not specify a server-side deletion or retention period. Other socai versions can differ.

privacy-controls.env
# deterministic report
OPENROUTER_REPORT_MODEL=off

# default for spawned socai commands
SOCAI_TELEMETRY=0

# optional local decisions
JEV_SOCIAL_SYSTEM_ONE_URL=http://127.0.0.1:8009/v1/systemone

Local does not mean disposable.

Research output can contain personal or sensitive social content even when API keys and cookies are absent.

  1. 01

    State root

    The default Jev Social root is ~/.jev-social. JEV_SOCIAL_HOME can select another location.

  2. 02

    File modes

    Config and run JSON files use mode 0600; their directories are created with mode 0700.

  3. 03

    Separate artifacts

    socai keeps its own run directory. An expiring loopback media URL does not delete the underlying media file.

  4. 04

    Manual cleanup

    No automatic retention or cleanup schedule applies. Stop the app, inspect the files, and remove only specific runs you no longer need.

Read-only by construction.

Supported operations gather evidence; they do not change the social account or fabricate success.

ACCOUNT STATE

No engagement actions

Jev Social does not post, like, follow, message, purchase, or change settings.

MEDIA

Explicit intent only

TikTok media download appears only when the research goal explicitly requests it. The selected action records that authorization.

FAILURE

Partial stays partial

Login gates, empty searches, low-confidence decisions, access limits, and interruptions remain visible stop conditions.

One release. Public boundaries.

Review the security policy, use a separate browser profile for sensitive targets, and start with a small evidence set.

TERMINAL
npx github:socai-io/jev-social#v0.1.13 onboard
npx github:socai-io/jev-social#v0.1.13

Four boundaries to remember.

Is Jev Social offline?
No. It runs locally, while Chrome and the chosen social platform still use the network. OpenRouter is also the default decision and report provider.
Does it copy Chrome cookies?
No. Login state stays in the Chrome or socai profile selected by the installed CLI; Jev Social does not read the cookie store directly.
Can report synthesis stay deterministic?
Yes. Set OPENROUTER_REPORT_MODEL=off to prevent the separate synthesis call.
When are runs deleted?
They are not deleted automatically. Inspect and remove only the specific Jev Social and socai run artifacts you no longer need.