Pypeo

Privacy Policy

Last updated Aug 14, 2026

How Pypeo handles personal data. The Service at https://pypeo.com is operated by KVESTERA UAB, which is the data controller for the personal data described below. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and Lithuanian data protection law.

1. Who to contact

Reach us on privacy matters at [email protected]. If our response does not satisfy you, complain to Lithuania’s State Data Protection Inspectorate (VDAI, https://vdai.lrv.lt) or the supervisory authority of the EU country where you live or work.

2. What we collect and why

Account data — name, email, password hash, workspace name — so we can give you a login and a place to hold your tokens.

Billing data — the transaction reference, currency, amount, VAT identifier if you supply one, and the last four digits of the card. Kept to issue receipts and invoices, to reconcile against the ledger and to satisfy tax and accounting law. Full card numbers never reach our servers.

Pipeline and Run data — the definitions of your Pipelines, the Inputs you route through them, the Outputs models produce, the connector calls made, the tokens metered, and the timestamps on the ledger. Kept so the Service works, so the ledger stays trustworthy, and so we can investigate incidents.

Your API keys for model providers and connectors — supplied by you, held encrypted at rest, decrypted only inside the Run engine at the point a joint needs to make a call.

Technical data — IP address, browser and device information, log timestamps and cookie identifiers. Needed to serve the Service, secure it and improve reliability.

Support data — the tickets, messages and attachments you send us, and our replies. Kept so we can help.

3. Legal bases

Performance of the contract with you to run the Service, legitimate interests to keep the Service secure and to improve it, legal obligations to keep tax and accounting records and to answer lawful requests from authorities, and consent for optional cookies and any marketing you actively opt in to.

4. Who we share it with

We use vetted providers to run the Service — cloud hosting, email delivery, payment processing, error monitoring, product analytics. Each acts as our processor under a written agreement. Because Pypeo does not resell AI model calls, calls made from a Run travel from our infrastructure to the model provider whose key you supplied, and the model provider then acts as a separate controller under its own terms. The same goes for third-party service connectors your Pipeline touches (Slack, Telegram, webhooks, HTTP endpoints). We disclose personal data to comply with the law, to answer lawful requests, to protect the Service and its users, and in connection with a corporate transaction. We do not sell personal data.

5. Model training

Pypeo does not use your Input or Output to train models. Because model calls hit the third-party provider whose key you supplied, whether that provider processes the request for its own training purposes is governed by that provider’s policy on the key or account you supplied. Where the provider offers a no-training setting through the API, we honour it if set on the key.

6. Retention

Account data lives while the account is open and up to twelve months after closure for legitimate follow-up. Billing records are kept for the period required by Lithuanian and EU accounting and tax law (currently ten years). Pipeline definitions, Runs and ledger entries stay for the life of the account and are deleted on closure, except where retention is required by law or to defend a claim. Support tickets are kept for up to three years. Technical logs and security data are kept for up to twelve months. Your stored API keys are deleted when you remove them, or on account closure.

7. International transfers

If data moves outside the European Economic Area — for example because a connector or a support tool is hosted there, or because the model provider whose key you supplied processes the call outside the EEA — we cover our own transfers with recognised safeguards, typically the EU Standard Contractual Clauses paired with technical measures such as encryption in transit and at rest, or an adequacy decision where one applies.

8. Your rights

Access, rectification, erasure, restriction, portability, objection to processing based on legitimate interests, and withdrawal of consent for anything you consented to. Write to [email protected]. We answer within thirty days and may ask you to verify identity before we act.

9. Security

Encryption in transit and at rest, isolated tenancy per workspace, least-privilege access, monitoring, staff training and vendor reviews. Your stored API keys are AES-encrypted at rest and never returned to the client after they are saved. We do not promise perfect security — no online service can — but we treat protection of your data as a first-class concern.

10. Children

Pypeo is not intended for anyone under 18 and we do not knowingly collect data from children. Tell us if you believe a child has provided data through the Service and we will remove it.

11. Cookies

Cookies and similar technologies have their own document — see the Cookie Policy.

12. Changes

We may update this policy as the Service, our providers or the law change. Material updates will be flagged in advance.

Contact

KVESTERA UAB · Company code 308067032 · Laisvės pr. 60, LT-05120 Vilnius, Lithuania · +370 661 02858 · [email protected]