Last updated: August 2026
The data controller responsible for data processing on this website is:
If you have questions about data protection, please contact us at [email protected].
We collect the minimum data necessary to provide and improve our service:
Your name and email address, provided during registration (including via Google OAuth). Legal basis: Art. 6(1)(b) GDPR (performance of contract).
Payment information (credit card details, billing address) is collected and processed exclusively by Stripe, our payment processor. We only receive a confirmation of payment status, your Stripe customer ID, and subscription state. We do not store your full card number. Legal basis: Art. 6(1)(b) GDPR (performance of contract).
Login timestamps, IP addresses, and basic service interaction logs (e.g., environment provisioning status). This data is used to operate, secure, and improve the service. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in service security and improvement).
Each customer gets their own dedicated, isolated environment: its own runtime instance, its own database, and its own object storage, none of which is shared with another customer. Within that environment, the customer-facing user account is separated from the platform service account that runs Peter's bundled software.
We are the operator of your environment. We have administrative access to it over our private management channel so we can provision it, apply security updates, ship deploys of Peter's software, respond to incidents, and act on abuse reports. As a matter of policy we do not browse your business data, conversations, or files outside of those operational reasons, and we do not run any routine job that copies your environment's contents back to our infrastructure. Your conversation transcripts are additionally sealed with encryption inside your own environment, and unsealing them requires a key that exists only in our management system; every such access is recorded in an audit log. We do not claim to be technically incapable of accessing your environment, because we are not.
There are two arrangements, and which applies to you depends on your plan.
On our standard plans, Peter runs on SayPeter's own OpenAI account. You do not need an AI subscription of your own and we never ask you for one; your plan includes a monthly usage allowance instead. Your prompts and Peter's responses are sent by us to OpenAI under our commercial API agreement, under which that content is not used to train OpenAI's models. Because we are the ones sending it, OpenAI acts as our sub-processor for this data and is listed as such in our Data Processing Agreement.
On a bring-your-own-account plan, Peter instead runs on the ChatGPT/Codex or Claude account you connect. Your prompts and Peter's responses go to that provider under your own account, governed by that provider's terms and privacy policy for it; usage counts against your own quota and a paid plan with that provider is required. Our software makes these calls on your instruction, but the account, its plan, and its data-handling settings are yours, not ours.
In both cases we log operational metadata such as the model used, timestamps, and token counts, for billing, service health and abuse prevention. We do not retain prompt or response content beyond the brief window needed for in-flight processing.
We use Stripe, Inc. to process payments. Stripe processes your payment data under their own privacy policy. See: stripe.com/privacy
We use Cloudflare to run the compute where Peter executes, to store your environment's files, and for secure ingress. Both the compute and the object storage are pinned to the EU jurisdiction. See: cloudflare.com/privacypolicy
Your environment's database is a managed PostgreSQL database hosted in an EU region. See: neon.com/privacy-policy
Our management server and platform infrastructure are hosted in the European Union (Germany).
We use Tailscale for secure private network management between our platform and customer environments, which processes connection metadata. See: tailscale.com/privacy-policy
On our standard plans, we send your prompts and Peter's responses to OpenAI, L.L.C. under our own commercial API agreement so that Peter can answer. OpenAI is a SayPeter sub-processor for this data. See: openai.com/policies/privacy-policy
If you are on a bring-your-own-account plan, Peter runs on the ChatGPT/Codex or Claude account you connect. Your prompts and Peter's responses are transmitted to that provider under your own account, which the provider processes as your provider under the terms and privacy policy applicable to that account. In that arrangement the provider is not a SayPeter sub-processor for this data; it is a service you connect, like the other accounts you link to Peter. See: openai.com/policies/privacy-policy and anthropic.com/legal/privacy
If you accept marketing cookies, we deploy the Meta Pixel and the Meta Conversions API to measure the performance of our advertising on Facebook and Instagram. The Pixel sets the _fbp and _fbc cookies in your browser; the Conversions API sends a parallel server-to-server event with the same hashed identifiers we already process for your account (email, phone, name, country) so duplicate browser/server events are deduplicated by Meta. We act as joint controllers with Meta for this measurement. You can revoke consent at any time using ; revoking will stop the Pixel firing and prevent future Conversions API events that rely on browser identifiers. See: facebook.com/privacy/policy
Cookies fall into three categories. The first is set automatically; the other two are off until you opt in via the consent banner.
cookie_consent). These are exempt from consent under ePrivacy Article 5(3)._fbp, _fbc) so we can measure how our ads on Facebook and Instagram perform. Off by default; only set after you accept marketing cookies. We don't run ads on this site. Retained for up to 90 days.You can change your mind at any time via .
You have the following rights regarding your personal data:
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
If you believe that our processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory authority.
Your data is primarily processed within the European Union. Where data is transferred to third countries, we ensure adequate safeguards:
We may update this privacy policy from time to time. We will notify you of material changes by email or by posting a notice on our website.
For data protection inquiries and to exercise your rights:
Email: [email protected]