Data handling
How Peeve retains, removes, and stores data. This complements the Privacy policy and Data processing agreement and mirrors the retention window and infrastructure described there.
Data retention
Peeve retains customer workspace data (the interface route map, semantic fingerprints, session traces, and analytics) only for as long as needed to provide the service, governed by the retention window each customer configures, up to a maximum of 90 days for session-level records. Account and billing records are kept for the life of the account and for any period required by tax or legal obligation. Aggregate, de-identified metrics used to operate and improve the product may be kept longer, as they are not linked to an individual. Peeve does not train models on customer or end-user data, and never retains passwords, session tokens, or the contents of masked fields.
Data archival & removal
Customers can remove data at any time through the Service: deleting a workspace purges its route map, fingerprints, and session traces on the configured schedule (up to the 90-day maximum), and any stored screenshots are deleted with them. On termination or expiry of the agreement, Peeve deletes or returns all personal data at the customer's choice, unless retention is required by law. Peeve keeps no long-term archive beyond operational backups; residual copies in those encrypted backups are purged on the standard backup rotation rather than persisting indefinitely.
Data storage
Customer data is stored with Peeve's infrastructure sub-processors, Supabase (primary database, authentication, and file/object storage; US / EU) and Vercel (application hosting and global edge network; US), and is encrypted both in transit and at rest. Access is least-privilege and role-based, limited to production systems that need it. Credentials are isolated from the model, which requests capabilities by name and never sees a token, and fields the customer masks, along with passwords and session tokens, are never collected in the first place. Regional storage follows each sub-processor's listed location.
Data deletion requests
Customers can delete their own data at any time from within the Service: removing a workspace purges its route map, fingerprints, and session traces on the configured schedule (up to 90 days), with backup copies purged on the standard rotation. For anything that can't be self-served, or for a data subject exercising their rights, email legal@peeve.ai: we verify the requester, action verified requests without undue delay (and within 30 days where GDPR or CCPA applies), and confirm completion. When an end user contacts Peeve directly about data a customer controls, Peeve does not act unilaterally. It promptly notifies the customer (the Controller) and carries out the deletion on the customer's instructions, consistent with the Data processing agreement.
Contact
Questions about data handling or deletion go to legal@peeve.ai.