Repository navigation
feat(models): add provider legal metadata - #2438
Conversation
Adds headquarters (ISO country code) and data policy fields (apiTraining, consumerTraining, promptLogging, retentionPeriod) to all provider definitions. Shows this info on provider detail and list pages so users can evaluate data practices without clicking through to external privacy/terms links. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
WalkthroughAdds a ProviderDataPolicy type and optional ChangesProvider Data & Privacy Metadata
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~25 minutes Possibly related PRs
Suggested reviewers
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 0
🧹 Nitpick comments (1)
packages/models/src/providers.ts (1)
24-29: 💤 Low valueConsider simplifying
retentionPeriodnullability.The
retentionPeriodfield is both optional (?:) and nullable (| null), which creates semantic ambiguity:
undefined= field not setnull= field set but value unknownstring= actual valueLooking at the populated data, all providers explicitly set
retentionPeriodto either a string ornull—none leave itundefined. Since the distinction betweenundefinedandnullisn't being used in practice, consider either:
- Making it required:
retentionPeriod: string | null(forces explicit null for unknown)- Using only undefined:
retentionPeriod?: string(omit field when unknown)The current implementation works correctly, but clearer semantics would improve maintainability.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@packages/models/src/providers.ts` around lines 24 - 29, The ProviderDataPolicy interface currently declares retentionPeriod as optional and nullable which is ambiguous; change the declaration in ProviderDataPolicy to be required but nullable (retentionPeriod: string | null) and update any places constructing ProviderDataPolicy objects to always include retentionPeriod (explicit string or null) so existing provider data that sets null continues to type-check.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@packages/models/src/providers.ts`:
- Around line 24-29: The ProviderDataPolicy interface currently declares
retentionPeriod as optional and nullable which is ambiguous; change the
declaration in ProviderDataPolicy to be required but nullable (retentionPeriod:
string | null) and update any places constructing ProviderDataPolicy objects to
always include retentionPeriod (explicit string or null) so existing provider
data that sets null continues to type-check.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository UI
Review profile: CHILL
Plan: Pro
Run ID: 7c98677c-097d-435c-b2ca-0ef3b4c800bd
📒 Files selected for processing (3)
apps/ui/src/components/providers/hero.tsxapps/ui/src/components/providers/providers-grid.tsxpackages/models/src/providers.ts
Updates data policies to match OpenRouter's standardized values: - All providers: apiTraining = false (no provider trains on API data) - Zero retention: DeepSeek, Groq, Together, DeepInfra, Perplexity, AWS Bedrock, Azure, Google Vertex - 30 day retention: Anthropic, xAI, Mistral, Xiaomi - 55 day retention: Google AI Studio - OpenAI: retained for unknown period Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Source: https://openrouter.ai/docs/guides/privacy/provider-logging Key corrections: - DeepSeek: May train, retained for unknown period - Moonshot AI: Zero retention, does not train - Z.ai: Zero retention, does not train - Alibaba: Retained for unknown period, does not train - MiniMax: Retained for unknown period, does not train - ByteDance (Seed): Zero retention, does not train Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Nebius Token Factory reports zero retention per OpenRouter docs. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
EmberCloud (US/Delaware): does not train on API data, short-lived operational logs for security/abuse prevention. Source: https://www.embercloud.ai/privacy Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
There was a problem hiding this comment.
🧹 Nitpick comments (1)
packages/models/src/providers.ts (1)
28-28: 💤 Low valueConsider documenting the expected retentionPeriod format.
The
retentionPeriodfield uses string values like "0 days", "30 days", "55 days" across different providers. Consider adding a JSDoc comment to document the expected format, or use a union type to constrain valid values.📝 Example documentation addition
export interface ProviderDataPolicy { apiTraining: boolean | null; consumerTraining: boolean | null; promptLogging: boolean | null; + /** Retention period in human-readable format (e.g., "0 days", "30 days", "55 days"), or null if unknown */ retentionPeriod?: string | null; soc2?: boolean | null; iso27001?: boolean | null; gdpr?: boolean | null; }🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@packages/models/src/providers.ts` at line 28, The retentionPeriod field currently accepts freeform strings which causes inconsistency; update the declaration for retentionPeriod (the property named retentionPeriod in the provider interface/type) by adding a JSDoc comment that documents the expected format (e.g., "<number> days" and special case "0 days"), and optionally replace string | null with a constrained union type listing allowed values (e.g., "0 days" | "30 days" | "55 days" | null) or a branded type to enforce format; ensure the JSDoc sits immediately above the retentionPeriod property and references the exact allowed values/format so consumers and IDEs get clear guidance.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Nitpick comments:
In `@packages/models/src/providers.ts`:
- Line 28: The retentionPeriod field currently accepts freeform strings which
causes inconsistency; update the declaration for retentionPeriod (the property
named retentionPeriod in the provider interface/type) by adding a JSDoc comment
that documents the expected format (e.g., "<number> days" and special case "0
days"), and optionally replace string | null with a constrained union type
listing allowed values (e.g., "0 days" | "30 days" | "55 days" | null) or a
branded type to enforce format; ensure the JSDoc sits immediately above the
retentionPeriod property and references the exact allowed values/format so
consumers and IDEs get clear guidance.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Repository UI
Review profile: CHILL
Plan: Pro
Run ID: d058cc56-8a84-423f-b4d5-d8624a8b86e7
📒 Files selected for processing (1)
packages/models/src/providers.ts
| </Button> | ||
| </div> | ||
|
|
||
| {(provider.dataPolicy || provider.headquarters) && ( |
There was a problem hiding this comment.
this is bad as it might now then show some other fields that exist below
Summary
headquarters(ISO 3166-1 alpha-2 country code) anddataPolicyfields to all provider definitionsdataPolicytracks:apiTraining,consumerTraining,promptLogging,retentionPeriodTest plan
pnpm --filter @llmgateway/models buildpassespnpm --filter gateway buildpassespnpm --filter api buildpasses/providers+/providers/[id]pages render🤖 Generated with Claude Code
Summary by CodeRabbit