# PearPie Privacy Policy ## What changed in this version - New **Reports you submit** entry (Sections 5 and 6). The apps now let you report an AI response you find harmful, offensive, or misleading, without leaving the app. When you choose to do so, the response you flagged is sent to us and stored so we can review it. Nothing else from that conversation is included, and the response is shown to you in full before it is sent — reporting is always your decision, never automatic. ## 1. Who we are PearPie B.V. ("**PearPie**", "**we**", "**us**") is a private limited company incorporated in the Netherlands. - **Registered office:** Douvenrader Allee 1c, 6411 RZ Heerlen, the Netherlands - **Chamber of Commerce (KvK):** 42083183 - **VAT (BTW):** NL869629773B01 - **General contact:** info@pearpie.ai - **Privacy contact:** privacy@pearpie.ai PearPie is a privacy-focused way to use AI. The Service consists of the PearPie application and the **PearPie Network**: our EU-based gateway that sits between you and third-party AI model providers. We receive your request, minimise it, route it to an EU/EEA-located model, and return the result, exposing as little of your data as technically possible to anyone, including ourselves. This Privacy Policy explains what personal data we process, why, how long we keep it, with whom we share it, and your rights. It applies to our website, apps, APIs, and related services. ## 2. The two ways PearPie handles your data It matters where your data lives, so we distinguish clearly between the two: **a. Local use — data that stays with you.** Some features process and store your content on your own device(s), run AI models locally, or synchronise content and share processing directly between your trusted devices (including delegated inference, where one of your devices runs AI processing on behalf of another), without any of it passing through PearPie's servers. For that content, **PearPie holds nothing**: we cannot see it, access it, hand it over, or recover it if it is lost. This Policy's sections on processing, retention, and sharing simply do not apply to it, because it never reaches us. **b. Use via the PearPie Network — requests we route for you.** When you use a premium AI model, your request passes through the PearPie Network to a model provider. We process it **transiently**: it is held only as long as needed to produce and return the response, and is then discarded. We do not store the content of your prompts, inputs, files, or outputs, except in the limited cases described in Section 6. ## 3. Our approach 1. **Data minimisation by design.** We process the least personal data necessary to deliver a result. 2. **No storage of your requests by default.** Request content is processed transiently and discarded. It is retained only when a specific request must be acted on (see Section 6). 3. **Processing in Europe.** Personal data processed through the Service stays within the EEA. The one exception is billing data held by our payment provider (see Sections 7 and 8). 4. **You hold the keys.** Where the Service uses keys or encryption only you control, only you can access that data. We cannot see it and cannot recover it if you lose your keys (see Section 9). 5. **The Service knows no identity.** PearPie does not operate user accounts. Within the Service you are identified only by your **public key**; the Service holds no name, email address, or payment details. Payment is handled by our payment provider, which keeps its own payment records under its own privacy policy (see Section 7). 6. **Never used for training, never permanently stored.** We do not train AI models on your content, and we only work with model providers that contractually do not train on your content and do not permanently store it (see Section 7). If a provider would or might use your content for training, we do not offer that model. ## 4. The data controller **PearPie B.V. is the controller** for: your public key and acceptance signature, credit-balance data, and security and operational data. For **the content of your requests and the outputs**, PearPie acts as an intermediary that transmits your content to model providers strictly on your instruction. In respect of the **name, email, and payment data you provide to take payment**, our payment provider acts as a **separate, independent controller** under its own privacy policy. The PearPie Service does not hold that data; within the Service we use only a payment reference and confirmation. Where necessary to process a refund, resolve a payment dispute, prevent fraud, or meet a legal obligation, we can consult the records held by the payment provider (see Section 7). Being transparent about the consequence: when you purchase credits, your public key can be linked to your real-world identity through the payment relationship. If you never purchase, you remain fully pseudonymous. ## 5. What personal data we process, and why **What we do not collect.** We operate no accounts and collect no email address, phone number, username, or password; no contact lists or address books; no biometric data; and nothing for advertising, profiling, or behavioural targeting. We never sell, rent, or monetise your personal data. What we do process: | Data | What it is | Purpose | Legal basis (Art. 6 GDPR) | |---|---|---|---| | Key and acceptance data | Your public key and the signature accepting our Terms and this Policy. The public key is the only identifier we use; we do not link it to your real-world identity. | Authenticating you; evidencing your acceptance | Contract (6(1)(b)) | | Credit and billing reference | Credit balance, subscription status, and a payment reference from our payment provider | Delivering paid features; reconciling payments | Contract (6(1)(b)) | | Request content (transient) | Prompts, inputs, files, outputs; processed transiently, not stored by default | Producing your response | Contract (6(1)(b)) | | Reports you submit | Only if you report an AI response: the response text you flagged, the reason you selected, the model that produced it, and any note you add. Sent only when you choose to report, and shown to you before sending. | Reviewing reported output; improving the safety of the models we offer; meeting the reporting obligations app stores place on us | Legitimate interests (6(1)(f)); legal obligation (6(1)(c)) where applicable | | Technical and security data | Timestamps, request metadata (model, token counts, status codes), rate-limit counters, and security logs. Kept minimal; not linked to request content. | Operating, securing, and billing the Service; preventing abuse and fraud | Legitimate interests (6(1)(f)); legal obligation (6(1)(c)) where applicable | | Communications | Messages you send us and our replies | Support, disputes, legal notices | Contract (6(1)(b)) for support; otherwise legitimate interests (6(1)(f)) | We do not store IP addresses or device/browser information; connection data is processed transiently to serve your request and is then discarded. The Service holds nothing beyond the items above. Your name, email, and card details exist only in the **payment provider's** records, under its own privacy policy; we do not copy them into the Service, but we can consult those records where necessary for refunds, payment disputes, fraud prevention, or legal obligations (see Section 7). We do not seek special categories of personal data (Article 9 GDPR). You control what you send; please avoid submitting such data unless necessary. Where we rely on legitimate interests, we have balanced them against your rights. You may object (see Section 11). ## 6. How long we keep data - **Request content:** not stored. It is processed in memory to produce your response and then discarded. **Exception:** if a specific request must be acted on (it is flagged for abuse review, is the subject of a dispute, or must be kept to comply with a legal obligation or to establish, exercise, or defend legal claims), we retain that specific request and the minimum related data, which may include a violation recorded against your public key, for as long as needed to handle the matter, and no longer. Non-flagged requests are never stored. A response you choose to report is a separate case, covered by the next bullet. - **Reports you submit:** kept for as long as needed to review the report and to address what it identifies, plus a reasonable period to detect recurrence, and no longer. - **Public key and acceptance signature:** for as long as the key is active with us, plus a reasonable period to evidence the agreement. - **Security and technical logs:** a limited, rolling period proportionate to security needs, then deleted or anonymised, unless part of an active investigation. - **Communications:** as long as needed to handle your matter, plus a reasonable period. - **Payment and transaction data:** held by our payment provider under its own policy, not by us. When a retention period ends, we delete the data or irreversibly anonymise it. ## 7. Who we share data with We share personal data only as needed to run the Service, under a data processing agreement with every processor acting on our behalf. **a. AI model providers.** Your request content is transmitted to the model provider that fulfils it. Every provider we offer processes within the EEA and is contractually barred from training on your content. Providers do not retain your content beyond what is needed to deliver the response, except that a provider may briefly retain a specific request where required for automated abuse or security monitoring, after which it is deleted. Our current providers are: **Amazon Web Services** (Bedrock, EU regions: Claude and DeepSeek models), **Scaleway** (France: Qwen models), and **Mistral AI** (EU). **b. Infrastructure and hosting.** Cloud hosting, storage, and security providers, all located in the EEA. A current list is available on request via privacy@pearpie.ai. **c. Payment provider.** Stripe collects and holds your name, email, and payment details directly from you, as a separate controller under [its own privacy policy](https://stripe.com/en-nl/privacy). Within the Service we use only a payment reference and confirmation; we do not store your billing data in our own systems, but we can access the provider's records where necessary to process refunds, resolve payment disputes, prevent fraud, or meet legal obligations. The provider may process billing data outside the EEA (for example in the United States) under its own GDPR transfer safeguards, such as Standard Contractual Clauses. **d. Professional advisers and authorities.** Accountants, auditors, and lawyers under confidentiality; and authorities or courts where we are legally required to disclose, or where necessary for legal claims. We do not sell your personal data and do not share it for advertising. ## 8. Where we process data Personal data processed through the Service is processed **within the EEA**. Our infrastructure and model providers are selected so that personal data does not leave the EEA in the ordinary course of providing the Service. If a transfer outside the EEA is ever unavoidable, we will only carry it out with an appropriate safeguard under Chapter V GDPR (an adequacy decision or Standard Contractual Clauses, with supplementary measures where needed) and update our sub-processor list. Billing data held by our payment provider may be processed outside the EEA under the provider's own transfer safeguards, as described in Section 7. This concerns billing data only, never your requests or their content. ## 9. Security We apply appropriate technical and organisational measures: encryption in transit, access controls, minimisation, and logging. Two things are important to understand: 1. **You are responsible for your own access.** We cannot secure devices, networks, or key stores under your control. Keep your private key, credentials, and devices safe; if they are compromised, the protection the Service offers can be defeated. 2. **We cannot recover what only you can unlock.** Where data is protected by keys or credentials only you hold, we have no way to access, reset, or restore it. Because we do not retain your request content, there is no backup on our side. Keep your own backups. No method of transmission or storage is completely secure; we work to protect personal data but cannot guarantee absolute security. If we agree a separate written agreement covering data handling, retention, backup, or hosting (see Section 14), that agreement governs the data it covers. ## 10. AI transparency - **You are interacting with AI.** Responses are generated by AI models running locally or routed through the PearPie Network. AI output can be inaccurate, incomplete, or unsuitable; use your own judgement and do not treat it as professional advice. - **No training on your content, ever** (see Section 3). - **No automated decisions with legal effect.** PearPie does not use your personal data to make decisions producing legal or similarly significant effects about you within the meaning of Article 22 GDPR. - We will update our disclosures as the EU AI Act's transparency obligations take effect. ## 11. Your rights Under the GDPR you have the right to access, rectify, and erase your personal data; to restrict or object to processing; to data portability; to withdraw consent at any time where processing is based on consent; and not to be subject to solely automated decisions with legal effect. To exercise a right, contact privacy@pearpie.ai. We respond within one month (extendable for complex requests, with notice). Because we do not operate accounts, we verify requests by asking you to demonstrate control of the public key in question, for example by signing a challenge. **Data we do not hold.** We cannot provide, correct, or delete data we do not have. The Service does not retain your request content by default and holds no name, email, or payment details; those records exist only with our payment provider, which is the controller of that data. ## 12. Complaints Please contact us first at privacy@pearpie.ai. We would like the chance to resolve your concern. You also have the right to complain to a supervisory authority. In the Netherlands this is the **Autoriteit Persoonsgegevens** ([autoriteitpersoonsgegevens.nl](https://www.autoriteitpersoonsgegevens.nl)), or the authority in your EU country of residence or work. ## 13. Cookies Our website does not use cookies, so no cookie banner is shown. Payment is completed on Stripe's own pages, which operate under Stripe's own cookie policy. If we ever introduce cookies, we will describe them here and set non-essential cookies only with your consent. ## 14. Business and custom use This Policy is written for individual use of the standard app and API. If you use the Service for your business, or we provide services beyond the standard offering (for example backup/storage or a hosted node), separate written terms apply. Contact info@pearpie.ai. ## 15. Children The Service is not directed to children. You must be at least 16 years old (or older where your country requires it) to use the Service. We do not knowingly process personal data of children below that age. ## 16. Changes to this Policy We may update this Policy, for example to reflect changes in the Service, our providers, or the law. For material changes we will update the version number, notify you by appropriate means, and may ask you to re-confirm acceptance with your public key. The current version is always available at [https://www.pearpie.ai/legal/privacy/](https://www.pearpie.ai/legal/privacy/). Every version is permanently retrievable from the version history there, together with the SHA-256 hash of its canonical text, so the version you accepted remains independently verifiable. ## 17. Contact **PearPie B.V.** · Douvenrader Allee 1c, 6411 RZ Heerlen, the Netherlands · privacy@pearpie.ai · KvK 42083183 *This Privacy Policy is governed by Dutch law and the GDPR. Where any provision conflicts with mandatory EU or Dutch data-protection law, that mandatory law prevails.*