# Privacy policy

_Updated 14 Aug 2026._

Canonical: https://peeve.ai/legal/privacy/

## What we collect

We collect the structure of your interface (element roles, accessible names, and positions) and a record of each session Peeve runs. We do not collect your users' passwords, session tokens, or the contents of fields you have masked.

Screenshots are optional and off by default. When enabled, masked selectors are removed before the image leaves the browser, not after it arrives.

> We do not train models on your data or your users' data. Not on an opt-out basis, not at all.

## How we use it

We use the data to operate the service: to find elements, resolve questions, detect drift, and produce your analytics. We use aggregate, de-identified metrics to improve the product.

## What we never do

We never sell your data, never use it to train models, and never hold your users' credentials. The model requests capabilities by name and never sees a token.

## Google API Services: Limited Use

Peeve's use of information received from Google APIs adheres to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.

When you connect a Google account, Peeve accesses your Gmail messages only to let your support assistant read and respond to your support email inside Peeve. We request the minimum scopes needed for this: gmail.readonly to read incoming support email, and gmail.send to send replies on your behalf.

Where Peeve processes your content through AI service providers to power these features, it does so under those providers' business or API terms, which prohibit training on your data. Where Peeve operates a self-hosted service within its own isolated infrastructure (for example, our self-hosted website-crawling service), that data is processed locally and is never shared with the underlying provider for training or any other secondary purpose.

You can disconnect your Google account at any time from Peeve's connector settings, which revokes Peeve's access.

> We do not use, transfer, or sell Google user data (whether raw, aggregated, anonymized, or derived) to create, train, or improve any generalized or foundational artificial-intelligence or machine-learning model. Google user data is used solely to provide and improve the user-facing features you have connected it to, and is not transferred to others except as necessary to provide those features, for security, or to comply with applicable law.

## Analytics & cookies

On this website we use Google Analytics and PostHog to understand how visitors use the site (pages viewed, clicks, scroll depth and time on page) and to record anonymized session replays with all form inputs masked, so we can find and fix rough edges. This site analytics is separate from the product data above and is used only to improve the site.

You can limit this through your browser's cookie and Do-Not-Track controls. We don't use it to identify you personally beyond what you choose to submit (for example, subscribing to the blog), and we never sell it.

## Sub-processors

We use a small set of sub-processors (including Supabase, Vercel, Anthropic, OpenAI, Stripe, Resend, Meta, Google Analytics and PostHog), each listed with its purpose and region on our Sub-processors page. We give notice before adding a new one.

## Your rights

You can access, correct, export or delete the data associated with your workspace. Where GDPR or similar law applies, you may exercise the rights it grants by contacting legal@peeve.ai.

## Deletion

Deleting a workspace removes its route map, fingerprints and session traces on the schedule set by your retention setting, up to a maximum of 90 days. Screenshots, where stored, are deleted with them.

## Contact

Privacy questions and data requests go to legal@peeve.ai.
