Built-in Wellness Project AI advisor requests are routed through Vercel AI Gateway before reaching the selected model provider, currently Anthropic, OpenAI, Google, or xAI, with other providers potentially used where applicable. We send the message you submitted and the subset of profile, health, fitness, or attached content needed to answer the request.
For Wellness Project-powered AI features, our provider arrangements prohibit providers from using the data we submit to train, fine-tune, evaluate, or otherwise improve their generalized models. We minimize the payload for the requested feature and do not send identifying account metadata beyond what is appropriate for the feature or required by the provider’s API. Vercel states that AI Gateway does not train on gateway traffic and deletes prompts and outputs at the gateway after inference. It also provides centralized Zero Data Retention and no-prompt-training controls for provider routing.
Vercel is built for enterprise security, not just model routing.
Vercel’s security program includes SOC 2 Type 2 and ISO 27001, regular third-party penetration testing and vulnerability scanning, least-privilege access controls, dedicated security governance, and ongoing security assessments.
Vercel’s Data Processing Addendum describes the organizational and technical safeguards behind that program.
Built-in advisor vs. a connected external assistant
A connected external assistant, such as a user-authorized MCP connection to an outside AI service, is different. When you choose that connection, the outside provider processes the conversation and requested Wellness Project context under your relationship with that provider and its own data practices, not under Wellness Project’s built-in AI provider contracts. When sharing sensitive health data, we strongly recommend disabling model training and prompt retention with that provider, or using its strongest available zero-retention controls.