1. Where your text goes
Your client sends text to the Overwing API, which runs on Vercel. Overwing sends it to TypeSafe, whose Jev model answers the rules, and returns the verdict to you. If the text is stored, it is stored in our Supabase database. Stripe never receives it, and it goes nowhere else.
- TypeSafe — Evaluates submitted text with the Jev model (United States).
- Supabase — Database and authentication hosting (United States).
- Vercel — Application hosting and edge network (United States).
- Stripe — Payments, invoicing, and card storage (United States).
Overwing does not use submitted text to train models. TypeSafe’s published privacy policy (effective November 19, 2025) says it does not train or fine-tune models on input and does not disclose input to third parties other than its service providers. TypeSafe does not publish a fixed retention period for input, so do not send text you are not permitted to share with a model provider; redact it first.
2. What is stored
- With an API key. The input text, the context, the verdict and scores, and your metadata, so you can retrieve and audit evaluations. They are kept until you delete them, unless you change that below.
- Without a key, or paid per request over x402. The text and the context are never stored. The verdict is kept for counting.
- API keys. Only a SHA-256 hash and a 12-character prefix. The full key is shown once and cannot be recovered.
- The hosted MCP endpoint is stateless: it keeps no session and nothing a caller sends beyond what the API call itself stores.
3. Controls you have
- Do not store one request. Send
"store": falsewith an evaluation. The check runs; the text and the context are not kept. The response headerX-Input-Storedconfirms it. - Do not store any request.
PATCH /api/v1/orgwith{"store_inputs": false}, or the dashboard settings page. - Retention window.
{"retention_days": 30}on the same endpoint deletes evaluations older than that, once a day. - Delete. One evaluation, all evaluations before a date, or the whole organization, from the API or the dashboard. Deletion is immediate and not recoverable by us.
- Scoped keys. A key with scope
evaluatecan run checks and read rule sets. It cannot read stored evaluations, change rule sets, manage keys, webhooks or billing, or delete anything. Give that key to an agent and keep thefullkey out of its reach. Tower agent keys are scoped per operation. - Rotation and audit. Keys are minted and revoked from the API or the dashboard, and
GET /api/v1/audit-loglists key, webhook, rule-set, data-setting and billing events, including rejected keys.
4. How it is protected
- In transit: TLS on every connection, with HSTS, including the connection between the application and the database.
- At rest: the database and its backups are encrypted with AES-256 by our database host.
- Tenant isolation: every query is scoped to the organization behind the key, and row-level security denies direct access to every table.
- Webhooks are signed with HMAC-SHA256 and are only delivered to public https addresses.
- Per-minute and per-day limits apply to every key and to callers without one.
- Card numbers never reach our servers; Stripe holds them.
- Access to production data is limited to the operator.
5. The MCP server and SDKs
The overwing-mcp package and the JavaScript and Python SDKs are open source under the MIT license. The MCP server runs on your machine, reads no files, runs no commands, and makes network requests only to the Overwing API. It has two runtime dependencies. Read the source before you run it: github.com/frod27/overwing-mcp.
6. What we have not done
Overwing is a young service run by one operator. It has not had an independent security audit and holds no certification such as SOC 2 or ISO 27001. Our hosting, database and payment providers hold their own. If you need to evaluate regulated data, turn storage off, redact before sending, or contact us first.
7. Reporting a problem
Email support@overwing.ai with what you found and how to reproduce it. Good-faith reports are welcome and we aim to acknowledge them within three business days. Test against your own account, and do not run load tests or access other customers’ data. If we learn of a breach that affects you, we will tell the account owner by email without undue delay.
See also the privacy policy and security.txt.