did you validate that those sites do not batch data input over time and send them out, much later than your direct user input interactions?
I think that is correct.
Also I agree with previous posters who pointed out that for the common JWT use-case: user authentication in an SPA or website, the JWT is running in users browsers and so should not contain any sensitive information to begin with.