This policy describes what Pareta Inc. ("Pareta",
"we") collects when you use the Pareta platform, why, how long we keep it,
and who else processes it. We have tried to write it the way the system
actually works, without vagueness. If anything here is unclear, ask us at
support@pareta.ai.
At a glance
Retention
Prompts and responses — including any documents or images in them —
are stored for up to 30 days, then deleted automatically. Benchmark
datasets and evaluation results stay until you delete them. Usage and
billing metadata (no prompt or response content) is kept for billing
integrity and audit.
Model training
We do not train models on your inputs or outputs. Frontier
providers process them under API terms that prohibit training.
Data location
Operated primarily from the United States (us-central1). If you
use the Service from elsewhere, your data is transferred to and
processed in the US.
Subprocessors
Google Cloud (hosting, storage, databases) and Modal (GPU serving)
for the models we host. OpenAI, Anthropic, and Google for frontier
serving, verification, and quality grading. Stripe, Resend, Cloudflare,
Pydantic Logfire, and Slack do not see request content. Each
provider's role is listed in §3 below.
Analytics
The marketing site (pareta.ai) uses a first-party anonymous beacon:
page views and button clicks with the referring domain, sent only to
our own servers. No cookies, no advertising identifiers, no third-party
analytics, and your IP address is not stored with the events. The
product sets one sign-in session cookie and no tracking cookies.
Zero retention
Not offered today, and there is no opt-out from the 30-day
retention. If your use case requires it, contact
support@pareta.ai before sending
production traffic.
Three processes that can involve your request content
Real-time verification
The quality gate applied to a specialist's result before the
response is served. It runs at request time and may use a
third-party model as a grader.
Automatic frontier escalation
A frontier model (OpenAI, Anthropic, or Google) produces the
response when needed to meet the workload's quality bar — when the
specialist path does not clear verification, or when no Pareta
specialist holds the bar for that workload.
Ongoing quality monitoring
After serving, samples of completed traffic are re-run and
graded on a rolling basis, including by third-party models acting as
graders, to check that answers hold the quality bar. Human review is
limited to cases the monitor flags as quality exceptions; staff access
to stored request content is recorded in your organization's audit
log.
Summary only — the full policy below governs.
1. What we collect and why
Account data
Email address, name, and a hash of your password (we never store the
password itself), plus a record of which Terms of Service version you
accepted and when. Used to operate your account. Kept for as long as your
account exists.
API inputs and outputs
The requests you send — full prompts, including any documents
or images in them — and the responses returned are stored for up to 30
days, then deleted automatically. This applies to API traffic and
playground use. We keep them for two reasons:
Service operation — debugging failures and
investigating abuse.
Quality monitoring — the core of Pareta is a
routing system that must prove its answers hold the published quality
bar. To do that, samples of production traffic are automatically re-run
and scored on a rolling basis, including by third-party AI models acting
as automated graders (currently OpenAI, Anthropic, and Google models).
Human review is limited to cases the automated monitor flags as quality
exceptions, and staff access to stored request content is logged in your
organization's audit log.
There is currently no opt-out from this retention. If your use case
requires zero retention, contact us before sending production traffic.
Benchmark and evaluation data
Datasets you upload for benchmarking (including documents) and the
results of evaluation runs are stored until you delete
them — they exist so you can re-run and compare over time.
Deleting a dataset deletes its items, uploaded files, and run results.
Usage and billing metadata
Per-request metadata — timestamps, token counts, latency, status, cost,
and the routing decisions taken — without prompt or response content. Kept
indefinitely for billing integrity, audit, and service analytics. Your
organization's audit log (logins, key creation, admin actions, and any
staff access to stored request content) is likewise kept.
Support
If you contact support, we keep the correspondence.
Marketing site
Our public pages (pareta.ai) collect anonymous usage statistics — page
views and button clicks, with the referring site's domain. No cookies, no
advertising identifiers, and no third-party analytics: events go only to
our own servers, and your IP address is not stored with them.
2. Where your requests are processed
Pareta routes each request to the model that serves it best. That means
your inputs are processed by:
Models we host on our own GPU infrastructure
(Google Cloud and Modal, primarily in the United States); and
Third-party frontier model providers (currently
OpenAI, Anthropic, and Google) when routing selects one of their models
to serve, verify, or grade a request. These providers process your data
as our subprocessors under their API terms, which prohibit them from
training on it.
3. Subprocessors
Provider
Purpose
Sees request content?
Google Cloud
Hosting, storage, databases
Yes (infrastructure)
Modal
GPU model serving
Yes (inference)
OpenAI
Frontier serving + quality grading
Yes (routed/sampled requests)
Anthropic
Quality grading; frontier serving
Yes (routed/sampled requests)
Google AI (Gemini)
Quality grading; evaluation runs
Yes (routed/sampled requests)
Stripe
Payments
No (billing data only)
Resend
Transactional email
No (email address only)
Cloudflare
Bot protection on signup
No
Pydantic Logfire
Operational telemetry
No (metadata only — no prompt content)
Slack
Support channels (opted-in orgs)
No (what you post there)
4. What we don't do
We do not train models on your inputs or outputs.
We do not sell your data, and we do not share it with
advertisers.
We do not use tracking cookies. The only cookie the product sets is
the session cookie that keeps you signed in.
5. Security
Traffic is encrypted in transit (TLS). Passwords are stored hashed; API
keys are stored as hashes and shown to you exactly once. Access to stored
request content by Pareta staff is restricted and recorded in your
organization's audit log. No system is perfectly secure; report suspected
vulnerabilities to support@pareta.ai.
6. Your rights and choices
Access / export — your usage data is visible in the
product; write to us for anything not surfaced there.
Deletion — deleting a benchmark dataset removes it
and its results; closing your account removes account data, and stored
request content ages out within the 30-day window. Billing and audit
metadata are retained as required for financial records.
Correction — update your name and email in the
product, or ask us.
Depending on where you live, you may have additional statutory rights
(for example under GDPR or CCPA); we honor requests to the extent the law
requires. Contact support@pareta.ai.
7. Data location
Pareta operates primarily from the United States (us-central1). If you
use the Service from elsewhere, your data is transferred to and processed
in the US.
8. Children
The Service is not directed to children and may not be used by anyone
under 18.
9. Changes
We will update this policy as the system evolves and note the date
above. For material changes we will notify you before they take
effect.