Back to home

Privacy Policy

Last updated: August 2026

1. Data Controller

The data controller responsible for data processing on this website is:

SayPeter

Operated by: Jordi [Full legal entity to be determined]

Email: [email protected]

If you have questions about data protection, please contact us at [email protected].

2. What Data We Collect

We collect the minimum data necessary to provide and improve our service:

Account data

Your name and email address, provided during registration (including via Google OAuth). Legal basis: Art. 6(1)(b) GDPR (performance of contract).

Payment data

Payment information (credit card details, billing address) is collected and processed exclusively by Stripe, our payment processor. We only receive a confirmation of payment status, your Stripe customer ID, and subscription state. We do not store your full card number. Legal basis: Art. 6(1)(b) GDPR (performance of contract).

Usage data

Login timestamps, IP addresses, and basic service interaction logs (e.g., environment provisioning status). This data is used to operate, secure, and improve the service. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in service security and improvement).

3. Architecture and Access

Each customer gets their own dedicated, isolated environment: its own runtime instance, its own database, and its own object storage, none of which is shared with another customer. Within that environment, the customer-facing user account is separated from the platform service account that runs Peter's bundled software.

What we operate, and therefore can technically access

We are the operator of your environment. We have administrative access to it over our private management channel so we can provision it, apply security updates, ship deploys of Peter's software, respond to incidents, and act on abuse reports. As a matter of policy we do not browse your business data, conversations, or files outside of those operational reasons, and we do not run any routine job that copies your environment's contents back to our infrastructure. Your conversation transcripts are additionally sealed with encryption inside your own environment, and unsealing them requires a key that exists only in our management system; every such access is recorded in an audit log. We do not claim to be technically incapable of accessing your environment, because we are not.

How AI requests are handled

There are two arrangements, and which applies to you depends on your plan.

On our standard plans, Peter runs on SayPeter's own OpenAI account. You do not need an AI subscription of your own and we never ask you for one; your plan includes a monthly usage allowance instead. Your prompts and Peter's responses are sent by us to OpenAI under our commercial API agreement, under which that content is not used to train OpenAI's models. Because we are the ones sending it, OpenAI acts as our sub-processor for this data and is listed as such in our Data Processing Agreement.

On a bring-your-own-account plan, Peter instead runs on the ChatGPT/Codex or Claude account you connect. Your prompts and Peter's responses go to that provider under your own account, governed by that provider's terms and privacy policy for it; usage counts against your own quota and a paid plan with that provider is required. Our software makes these calls on your instruction, but the account, its plan, and its data-handling settings are yours, not ours.

In both cases we log operational metadata such as the model used, timestamps, and token counts, for billing, service health and abuse prevention. We do not retain prompt or response content beyond the brief window needed for in-flight processing.

What is isolated

  • Other customers' environments are isolated from yours. No runtime, database, or storage is shared between customers.
  • Platform secrets in your environment (the deploy environment file holding service credentials) are owned by the platform service account and are not readable by your customer-facing user.
  • Third-party tokens you connect (e.g., Google, Stripe, your email provider, or on a bring-your-own-account plan your own ChatGPT/Codex or Claude account) are stored encrypted at rest in our management database and pushed to your environment only as service-account-readable secrets, not readable by your customer-facing user. A connected ChatGPT/Codex token is refreshed automatically as it nears expiry so the connection stays live. We use these credentials only to run Peter and to execute the actions you ask Peter to perform. You can disconnect at any time from your dashboard, which deletes the stored credential from our systems and erases it from your assistant.
  • On our standard plans, the key used to reach OpenAI is never placed in your environment. Peter's model requests leave your environment to a service we run, which holds that credential and adds it there, so no AI provider credential of ours exists on the machine your Peter runs on.

4. Third-Party Processors

Stripe (Payment Processing)

We use Stripe, Inc. to process payments. Stripe processes your payment data under their own privacy policy. See: stripe.com/privacy

Cloudflare (Compute, Storage and Ingress)

We use Cloudflare to run the compute where Peter executes, to store your environment's files, and for secure ingress. Both the compute and the object storage are pinned to the EU jurisdiction. See: cloudflare.com/privacypolicy

Neon (Managed Database)

Your environment's database is a managed PostgreSQL database hosted in an EU region. See: neon.com/privacy-policy

Hetzner (Platform Infrastructure)

Our management server and platform infrastructure are hosted in the European Union (Germany).

Tailscale (Network Management)

We use Tailscale for secure private network management between our platform and customer environments, which processes connection metadata. See: tailscale.com/privacy-policy

OpenAI (AI Inference)

On our standard plans, we send your prompts and Peter's responses to OpenAI, L.L.C. under our own commercial API agreement so that Peter can answer. OpenAI is a SayPeter sub-processor for this data. See: openai.com/policies/privacy-policy

Your Own Connected AI Account (bring-your-own-account plans only)

If you are on a bring-your-own-account plan, Peter runs on the ChatGPT/Codex or Claude account you connect. Your prompts and Peter's responses are transmitted to that provider under your own account, which the provider processes as your provider under the terms and privacy policy applicable to that account. In that arrangement the provider is not a SayPeter sub-processor for this data; it is a service you connect, like the other accounts you link to Peter. See: openai.com/policies/privacy-policy and anthropic.com/legal/privacy

Meta Platforms Ireland Limited (Advertising Measurement)

If you accept marketing cookies, we deploy the Meta Pixel and the Meta Conversions API to measure the performance of our advertising on Facebook and Instagram. The Pixel sets the _fbp and _fbc cookies in your browser; the Conversions API sends a parallel server-to-server event with the same hashed identifiers we already process for your account (email, phone, name, country) so duplicate browser/server events are deduplicated by Meta. We act as joint controllers with Meta for this measurement. You can revoke consent at any time using ; revoking will stop the Pixel firing and prevent future Conversions API events that rely on browser identifiers. See: facebook.com/privacy/policy

5. Cookies

Cookies fall into three categories. The first is set automatically; the other two are off until you opt in via the consent banner.

  • Strictly necessary: session cookie (sign-in), CSRF token, Stripe fraud cookies during checkout, and the consent record itself (cookie_consent). These are exempt from consent under ePrivacy Article 5(3).
  • Analytics: first-party measurement of how the site performs. Off by default. Currently unused; reserved for future deployment.
  • Marketing: the Meta Pixel (_fbp, _fbc) so we can measure how our ads on Facebook and Instagram perform. Off by default; only set after you accept marketing cookies. We don't run ads on this site. Retained for up to 90 days.

You can change your mind at any time via .

6. Data Retention

  • Account data - retained for as long as your account is active. Upon deletion, personal data is erased within 30 days.
  • Environment data - upon cancellation, your dedicated environment is preserved for 30 days to allow data export. After 30 days, the environment and its data are permanently deleted.
  • Payment records - retained as required by applicable tax and commercial law.

7. Your Rights Under GDPR

You have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR)
  • Right to erasure (Art. 17 GDPR)
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR)
  • Right to object (Art. 21 GDPR)
  • Right to withdraw consent

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

8. Right to Lodge a Complaint

If you believe that our processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory authority.

9. International Data Transfers

Your data is primarily processed within the European Union. Where data is transferred to third countries, we ensure adequate safeguards:

  • Stripe (USA) - EU-US Data Privacy Framework; EU Standard Contractual Clauses.
  • Cloudflare (USA) - your environment's compute and object storage are pinned to the EU jurisdiction; EU Standard Contractual Clauses.
  • Neon (USA) - your environment's database is hosted in an EU region; EU Standard Contractual Clauses where applicable.
  • Tailscale (USA) - EU Standard Contractual Clauses.
  • OpenAI (USA) - on our standard plans, we transfer your prompts and Peter's responses to OpenAI as our sub-processor under our commercial API agreement, relying on EU Standard Contractual Clauses.
  • OpenAI or Anthropic (USA) - on a bring-your-own-account plan, via the ChatGPT/Codex or Claude account you connect. Your prompts and Peter's responses are transferred to that provider under your own account and its terms for it; by connecting the account and instructing Peter, you direct this transfer.

10. Changes to This Privacy Policy

We may update this privacy policy from time to time. We will notify you of material changes by email or by posting a notice on our website.

11. Contact

For data protection inquiries and to exercise your rights:

Email: [email protected]