Back to home

Privacy Policy

Last updated: July 2026

1. Data Controller

The data controller responsible for data processing on this website is:

SayPeter

Operated by: Jordi [Full legal entity to be determined]

Email: [email protected]

If you have questions about data protection, please contact us at [email protected].

2. What Data We Collect

We collect the minimum data necessary to provide and improve our service:

Account data

Your name and email address, provided during registration (including via Google OAuth). Legal basis: Art. 6(1)(b) GDPR (performance of contract).

Payment data

Payment information (credit card details, billing address) is collected and processed exclusively by Stripe, our payment processor. We only receive a confirmation of payment status, your Stripe customer ID, and subscription state. We do not store your full card number. Legal basis: Art. 6(1)(b) GDPR (performance of contract).

Usage data

Login timestamps, IP addresses, and basic service interaction logs (e.g., VM provisioning status). This data is used to operate, secure, and improve the service. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in service security and improvement).

3. Architecture and Access

Each customer gets their own dedicated virtual machine, isolated from other customers at the hypervisor level. Within your VM, the customer-facing user account is separated from the platform service account that runs Peter's bundled software.

What we operate, and therefore can technically access

We are the operator of your VM. We have administrative access to it via our private Tailscale network so we can provision it, apply security updates, ship deploys of Peter's software, respond to incidents, and act on abuse reports. As a matter of policy we do not browse your business data, conversations, or files outside of those operational reasons, and we do not run any routine job that copies VM contents back to our infrastructure. We do not claim to be technically incapable of accessing your VM, because we are not.

How AI requests are handled

Peter runs on the OpenAI ChatGPT/Codex account you connect. Your prompts and Peter's responses are sent to OpenAI under that account and are governed by OpenAI's terms and privacy policy for it; usage counts against your account's own quota, and a paid ChatGPT plan is required. Our software makes these calls on your instruction, but the account, its plan, and its data-handling settings are yours, not ours. We do not use a shared or pooled model key, and there is no alternate AI provider behind the scenes. We log operational metadata such as the model used, timestamps, and observed quota headers for service health and abuse prevention. We do not retain prompt or response content beyond the brief window needed for in-flight processing.

What is isolated

  • Other customers' VMs are isolated from yours at the hypervisor level.
  • Platform secrets on your VM (the deploy environment file holding service credentials) are owned by the platform service account and are not readable by your customer-facing user.
  • Third-party tokens you connect (e.g., your own ChatGPT/Codex, Google, or Stripe account via OAuth) are stored encrypted at rest in our management database and pushed to your VM only as service-account-readable secrets, not readable by your customer-facing user. Your ChatGPT/Codex token is refreshed automatically as it nears expiry so the connection stays live. We use these credentials only to run Peter and to execute the actions you ask Peter to perform.

4. Third-Party Processors

Stripe (Payment Processing)

We use Stripe, Inc. to process payments. Stripe processes your payment data under their own privacy policy. See: stripe.com/privacy

Cloud Infrastructure Provider

Your dedicated VM and our platform infrastructure run on cloud servers located within the European Union.

Tailscale (Network Management)

We use Tailscale for secure network management between our platform and customer VMs. See: tailscale.com/privacy-policy

OpenAI (Your Connected AI Account)

Peter runs on the ChatGPT/Codex account you connect. Your prompts and Peter's responses are transmitted to OpenAI under your own account, which OpenAI processes as your provider under the terms and privacy policy applicable to that account. OpenAI is therefore not a SayPeter sub-processor for this data; it is a service you connect, like the other accounts you link to Peter. See: openai.com/policies/privacy-policy

Meta Platforms Ireland Limited (Advertising Measurement)

If you accept marketing cookies, we deploy the Meta Pixel and the Meta Conversions API to measure the performance of our advertising on Facebook and Instagram. The Pixel sets the _fbp and _fbc cookies in your browser; the Conversions API sends a parallel server-to-server event with the same hashed identifiers we already process for your account (email, phone, name, country) so duplicate browser/server events are deduplicated by Meta. We act as joint controllers with Meta for this measurement. You can revoke consent at any time using ; revoking will stop the Pixel firing and prevent future Conversions API events that rely on browser identifiers. See: facebook.com/privacy/policy

5. Cookies

Cookies fall into three categories. The first is set automatically; the other two are off until you opt in via the consent banner.

  • Strictly necessary: session cookie (sign-in), CSRF token, Stripe fraud cookies during checkout, and the consent record itself (cookie_consent). These are exempt from consent under ePrivacy Article 5(3).
  • Analytics: first-party measurement of how the site performs. Off by default. Currently unused; reserved for future deployment.
  • Marketing: the Meta Pixel (_fbp, _fbc) so we can measure how our ads on Facebook and Instagram perform. Off by default; only set after you accept marketing cookies. We don't run ads on this site. Retained for up to 90 days.

You can change your mind at any time via .

6. Data Retention

  • Account data - retained for as long as your account is active. Upon deletion, personal data is erased within 30 days.
  • VM data - upon cancellation, your dedicated VM is preserved for 30 days to allow data export. After 30 days, the VM is permanently destroyed.
  • Payment records - retained as required by applicable tax and commercial law.

7. Your Rights Under GDPR

You have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)
  • Right to withdraw consent

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

8. Right to Lodge a Complaint

If you believe that our processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory authority.

9. International Data Transfers

Your data is primarily processed within the European Union. Where data is transferred to third countries, we ensure adequate safeguards:

  • Stripe (USA) - EU-US Data Privacy Framework; EU Standard Contractual Clauses.
  • Tailscale (USA) - EU Standard Contractual Clauses.
  • OpenAI (USA) - via the ChatGPT/Codex account you connect. Your prompts and Peter's responses are transferred to OpenAI under your own account and OpenAI's terms for it; by connecting the account and instructing Peter, you direct this transfer.

10. Changes to This Privacy Policy

We may update this privacy policy from time to time. We will notify you of material changes by email or by posting a notice on our website.

11. Contact

For data protection inquiries and to exercise your rights:

Email: [email protected]