Skip to content

feat(models): add provider legal metadata - #2438

Merged
steebchen merged 16 commits into
theopenco:mainfrom
analogpvt:feat/provider-legal-metadata
May 31, 2026
Merged

steebchen merged 16 commits into
theopenco:mainfrom
analogpvt:feat/provider-legal-metadata

Conversation

@analogpvt

@analogpvt analogpvt commented May 28, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Adds headquarters (ISO 3166-1 alpha-2 country code) and dataPolicy fields to all provider definitions
  • dataPolicy tracks: apiTraining, consumerTraining, promptLogging, retentionPeriod
  • Provider detail page shows a "Data & Privacy" card with color-coded badges (green = no training, red = trains on data)
  • Provider list page shows country code and "No training" shield badge for privacy-respecting providers
  • Existing terms/privacy links remain as supplementary references

Test plan

  • pnpm --filter @llmgateway/models build passes
  • pnpm --filter gateway build passes
  • pnpm --filter api build passes
  • UI builds and /providers + /providers/[id] pages render
  • Visual check of provider detail page with data policy card
  • Visual check of provider list page with badges

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features
    • Added a "Data & Privacy" card on provider pages showing headquarters, training/logging badges (API training, consumer training, prompt logging), and retention period with "Unknown" when unspecified — badges use clear success/failure styling.
    • Enhanced provider cards with headquarters display, models/count metadata, and a visible "No training" shield indicator when applicable.

Review Change Stack

Adds headquarters (ISO country code) and data policy fields
(apiTraining, consumerTraining, promptLogging, retentionPeriod)
to all provider definitions. Shows this info on provider detail
and list pages so users can evaluate data practices without
clicking through to external privacy/terms links.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented May 28, 2026 •

Copy link
Copy Markdown
Contributor

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

Walkthrough

Adds a ProviderDataPolicy type and optional headquarters/dataPolicy fields to providers, populates provider entries with those values, and surfaces the metadata in the UI via a new "Data & Privacy" hero card and badge indicators in the provider grid.

Changes

Provider Data & Privacy Metadata

Layer / File(s) Summary
Data model: ProviderDataPolicy interface and ProviderDefinition extensions
packages/models/src/providers.ts
Defines exported ProviderDataPolicy with boolean
Provider data population: headquarters and dataPolicy for providers
packages/models/src/providers.ts
Populates built-in providers with headquarters (country codes) and dataPolicy objects containing training/logging flags, optional retention periods, and optional compliance flags; some providers set both fields to null.
Hero page: Data & Privacy card with DataPolicyBadge component
apps/ui/src/components/providers/hero.tsx
Adds lucide icon imports, creates DataPolicyBadge component to render null→"Unknown", true→red, false→green badges, inserts a conditional "Data & Privacy" card showing HQ and policy rows, and adjusts terms/privacy spacing.
Provider grid: Card header with headquarters and training indicators
apps/ui/src/components/providers/providers-grid.tsx
Adds MapPin and ShieldCheck icon imports; enriches provider card header to display headquarters with a location icon and a conditional "No training" shield badge when dataPolicy.apiTraining is explicitly false.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Possibly related PRs

Suggested reviewers

  • smakosh
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately describes the main change: adding legal metadata (headquarters and dataPolicy fields) to provider definitions.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 0

🧹 Nitpick comments (1)
packages/models/src/providers.ts (1)

24-29: 💤 Low value

Consider simplifying retentionPeriod nullability.

The retentionPeriod field is both optional (?:) and nullable (| null), which creates semantic ambiguity:

  • undefined = field not set
  • null = field set but value unknown
  • string = actual value

Looking at the populated data, all providers explicitly set retentionPeriod to either a string or null—none leave it undefined. Since the distinction between undefined and null isn't being used in practice, consider either:

  1. Making it required: retentionPeriod: string | null (forces explicit null for unknown)
  2. Using only undefined: retentionPeriod?: string (omit field when unknown)

The current implementation works correctly, but clearer semantics would improve maintainability.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/models/src/providers.ts` around lines 24 - 29, The
ProviderDataPolicy interface currently declares retentionPeriod as optional and
nullable which is ambiguous; change the declaration in ProviderDataPolicy to be
required but nullable (retentionPeriod: string | null) and update any places
constructing ProviderDataPolicy objects to always include retentionPeriod
(explicit string or null) so existing provider data that sets null continues to
type-check.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Nitpick comments:
In `@packages/models/src/providers.ts`:
- Around line 24-29: The ProviderDataPolicy interface currently declares
retentionPeriod as optional and nullable which is ambiguous; change the
declaration in ProviderDataPolicy to be required but nullable (retentionPeriod:
string | null) and update any places constructing ProviderDataPolicy objects to
always include retentionPeriod (explicit string or null) so existing provider
data that sets null continues to type-check.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: 7c98677c-097d-435c-b2ca-0ef3b4c800bd

📥 Commits

Reviewing files that changed from the base of the PR and between 5e6f075 and 570ce64.

📒 Files selected for processing (3)
  • apps/ui/src/components/providers/hero.tsx
  • apps/ui/src/components/providers/providers-grid.tsx
  • packages/models/src/providers.ts

analogpvt and others added 9 commits May 29, 2026 14:11
Updates data policies to match OpenRouter's standardized values:
- All providers: apiTraining = false (no provider trains on API data)
- Zero retention: DeepSeek, Groq, Together, DeepInfra, Perplexity,
  AWS Bedrock, Azure, Google Vertex
- 30 day retention: Anthropic, xAI, Mistral, Xiaomi
- 55 day retention: Google AI Studio
- OpenAI: retained for unknown period

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Source: https://openrouter.ai/docs/guides/privacy/provider-logging

Key corrections:
- DeepSeek: May train, retained for unknown period
- Moonshot AI: Zero retention, does not train
- Z.ai: Zero retention, does not train
- Alibaba: Retained for unknown period, does not train
- MiniMax: Retained for unknown period, does not train
- ByteDance (Seed): Zero retention, does not train

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Nebius Token Factory reports zero retention per OpenRouter docs.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
EmberCloud (US/Delaware): does not train on API data,
short-lived operational logs for security/abuse prevention.
Source: https://www.embercloud.ai/privacy

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
packages/models/src/providers.ts (1)

28-28: 💤 Low value

Consider documenting the expected retentionPeriod format.

The retentionPeriod field uses string values like "0 days", "30 days", "55 days" across different providers. Consider adding a JSDoc comment to document the expected format, or use a union type to constrain valid values.

📝 Example documentation addition
 export interface ProviderDataPolicy {
 	apiTraining: boolean | null;
 	consumerTraining: boolean | null;
 	promptLogging: boolean | null;
+	/** Retention period in human-readable format (e.g., "0 days", "30 days", "55 days"), or null if unknown */
 	retentionPeriod?: string | null;
 	soc2?: boolean | null;
 	iso27001?: boolean | null;
 	gdpr?: boolean | null;
 }
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@packages/models/src/providers.ts` at line 28, The retentionPeriod field
currently accepts freeform strings which causes inconsistency; update the
declaration for retentionPeriod (the property named retentionPeriod in the
provider interface/type) by adding a JSDoc comment that documents the expected
format (e.g., "<number> days" and special case "0 days"), and optionally replace
string | null with a constrained union type listing allowed values (e.g., "0
days" | "30 days" | "55 days" | null) or a branded type to enforce format;
ensure the JSDoc sits immediately above the retentionPeriod property and
references the exact allowed values/format so consumers and IDEs get clear
guidance.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Nitpick comments:
In `@packages/models/src/providers.ts`:
- Line 28: The retentionPeriod field currently accepts freeform strings which
causes inconsistency; update the declaration for retentionPeriod (the property
named retentionPeriod in the provider interface/type) by adding a JSDoc comment
that documents the expected format (e.g., "<number> days" and special case "0
days"), and optionally replace string | null with a constrained union type
listing allowed values (e.g., "0 days" | "30 days" | "55 days" | null) or a
branded type to enforce format; ensure the JSDoc sits immediately above the
retentionPeriod property and references the exact allowed values/format so
consumers and IDEs get clear guidance.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro

Run ID: d058cc56-8a84-423f-b4d5-d8624a8b86e7

📥 Commits

Reviewing files that changed from the base of the PR and between 71ce59c and 351d380.

📒 Files selected for processing (1)
  • packages/models/src/providers.ts

</Button>
</div>

{(provider.dataPolicy || provider.headquarters) && (

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this is bad as it might now then show some other fields that exist below

@steebchen
steebchen merged commit f4d765a into theopenco:main May 31, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants