Coding Assistants
v0
High riskVercel's generative UI and app builder that turns prompts into React/Next.js code and deploys it on the Vercel platform.
Is v0 safe for confidential data?
The live issue with v0 is Vercel's 2026 AI policy shift: under the policy effective March 31, 2026, prompts, interactions, and project data from paid Pro plans are opted in to Vercel's model training by default, with Hobby and trial users opted out by default and Enterprise customers contractually excluded. Opt-out is self-serve in Team Settings, but coverage of the change notes that data ingested before an opt-out cannot be un-learned — opting out protects future data only. Vercel states sensitive content such as environment variables and API keys is anonymized and redacted before use, but code structure and prompts from default-configured Pro teams flow into training. For a firm generating proprietary product UI on v0, this is a policy-default risk you have to actively switch off, and the deadline dynamics made timing matter.
Risk by plan
The same product often carries very different terms depending on the tier — consumer plans are where the exposure concentrates.
Opted out of model training by default under the 2026 policy, but consumer terms with no organizational agreement; verify current defaults at v0.app/policy, which Vercel can update.
Opted in to model training by default under the policy effective March 31, 2026 — an admin must disable it in Team Settings > Data Preferences. Sensitive values are redacted per Vercel, but prompts and code structure are included.
Vercel states Enterprise customer data is not used for model training or shared with third parties; terms are contractual.
Data handling
Training on inputs
Under the Vercel AI policy effective March 31, 2026: paid Pro plan users are opted in to model training by default; Hobby and trial users are opted out by default; Enterprise data is not used for training or shared. Opt-out is in Team Settings > Data Preferences.
Retention
Prompts, interactions, and project data are retained per Vercel's privacy policy; data already ingested for training before an opt-out is not removed from the training set, per coverage of the policy change.
Residency
Vercel's global cloud; no v0-specific residency controls published. Canadian organizations with PIPEDA or Quebec Law 25 obligations should treat processing as US/global and assess accordingly.
Compliance
- SOC 2Yes
- GDPR / DPAYes
- HIPAA BAANot verified
Certifications typically apply to specific tiers and contracts — confirm scope in writing before relying on them.
New to these frameworks? See our plain-language guides to SOC 2 and the other AI compliance standards.
Enterprise controls
- Team-level data preference controls
- SSO / SAML (Vercel Enterprise)
- Contractual training exclusion (Enterprise)
- Vercel DPA coverage
- Deployment and environment access controls
Frequently asked questions
Does Vercel v0 train on your code?
By default on paid Pro plans, yes — Vercel's AI policy effective March 31, 2026 opts Pro users' prompts, interactions, and project data into model training, while Hobby/trial users are opted out by default and Enterprise data is excluded entirely. Vercel says environment variables, API keys, and personal data are anonymized and redacted first, but the code and prompt content itself is in scope unless you switch it off.
How do we opt out of Vercel AI training?
A team admin disables it under Team Settings > Data Preferences, or you move to Enterprise where exclusion is contractual. Note the asymmetry reported around the March 31, 2026 deadline: opting out stops future use, but data already ingested into the training set is not un-learned — so opt out before meaningful proprietary work goes through v0, not after.
Designers and engineers are prototyping in v0 on personal accounts. Does the company opt-out cover them?
No — a team-level data preference only governs that team's workspace. Personal and Hobby accounts sit under consumer terms with their own defaults, outside your DPA and your settings. Bring v0 use under a company team where an admin controls Data Preferences, and keep an inventory of the AI builders people use before anyone thought to ask.
Policy changelog
- Initial entry published from Vercel's published AI policy and cited coverage.
Sources
- Vercel AI policy (v0)
- Vercel changelog: terms of service updates, March 2026
- Quave: Vercel is using your code to train AI
This profile summarizes the vendor's published policies as of the verification date. It is not legal advice.
v0 is probably already in your organization.
Sanitized AI shows you who is using it and redacts sensitive data from prompts before it leaves your control.
More AI tool profiles
AWS's AI coding assistant and agent for IDEs, the CLI, and the AWS console, with completions, chat, and code transformation tied into AWS accounts.
Browser-based AI app builder from StackBlitz that generates, runs, and deploys full-stack JavaScript applications from prompts, popular with founders and rapid prototypers.
AI-first code editor that sends repository context to hosted models for completions, chat, and multi-file agentic edits.
Autonomous AI software engineer that plans and executes multi-step development work with its own shell, browser, and repository access, sold to teams and enterprises.