Security & data · Summary for buyers

Security & data: where production requests go.

The buyer-facing summary of how Pareta handles the requests your application sends through the model ID auto: where they are processed, who else processes them, how long they are kept, and what Pareta does not do with them. Every fact on this page is taken from the Privacy Policy (last updated 2026-08-01) and the Terms of Service (version 2026-08-17), which govern; nothing here extends them.

What governs
Summary only — the full Privacy Policy and Terms of Service govern.
Pareta has tried to write the Privacy Policy the way the system actually works, without vagueness. If anything here is unclear, ask support@pareta.ai.
Read the Privacy Policy →

1. Where requests go

Pareta matches each request to the specialist that holds the workload’s quality bar, or to a frontier model when none does. That means your inputs are processed by:

Models Pareta hostsPareta-hosted specialists run on Pareta’s own GPU infrastructure — Google Cloud and Modal, primarily in the United States. A request is served by a Pareta specialist when a deployed specialist holds the workload’s quality bar; that is the default path for the marketed workloads.
Third-party frontier model providersCurrently OpenAI, Anthropic, and Google, when routing selects one of their models to serve, verify, or grade a request. These providers process your data as Pareta’s subprocessors under their API terms, which prohibit them from training on it.

A third-party AI provider may process a request in three ways: real-time verification, when a specialist result is checked before the response is served; frontier serving, when routing selects a frontier model to produce the response; and ongoing quality monitoring, when samples of completed traffic are re-run and scored after serving to measure and maintain answer quality.

Real-time verification

The quality gate applied to a specialist's result before the response is served. It runs at request time and may use a third-party model as a grader.

Automatic frontier escalation

A frontier model (OpenAI, Anthropic, or Google) produces the response when needed to meet the workload's quality bar — when the specialist path does not clear verification, or when no Pareta specialist holds the bar for that workload.

Ongoing quality monitoring

After serving, samples of completed traffic are re-run and graded on a rolling basis, including by third-party models acting as graders, to check that answers hold the quality bar. Human review is limited to cases the monitor flags as quality exceptions; staff access to stored request content is recorded in your organization's audit log.

Verification is not a frontier call on every request: output parsing and schema checks run on every specialist response; model-graded checks run on tasks whose measured quality calls for them. A frontier-served response is returned as served. Verification is a quality gate, not a guarantee that an AI output can never be wrong — AI model outputs are probabilistic and can be wrong; you are responsible for evaluating outputs before relying on them, and for human review where outputs affect health, legal, financial, or safety decisions.

2. Retention

What Pareta keeps, why, and for how long.

DataWhy it is keptKept for
Prompts and responsesService operation — debugging failures and investigating abuse — and quality monitoring. Applies to API traffic and playground use, and includes any documents or images in the request.Up to 30 days, then deleted automatically.
Benchmark datasets and evaluation resultsSo you can re-run and compare over time. Deleting a dataset deletes its items, uploaded files, and run results.Until you delete them.
Usage and billing metadataBilling integrity, audit, and service analytics. Timestamps, token counts, latency, status, cost, and the routing decisions taken — without prompt or response content.Indefinitely.
Organization audit logLogins, key creation, admin actions, and any staff access to stored request content.Kept.
Account dataTo operate your account. Email address, name, a hash of your password, and the Terms of Service version you accepted and when.For as long as your account exists.
No opt-out todayThere is currently no opt-out from the retention that supports quality monitoring. If your use case requires zero retention, contact support@pareta.ai before sending production traffic.
Deletion and your rightsDeleting a benchmark dataset removes it and its results. Closing your account removes account data, and stored request content ages out within the 30-day window; billing and audit metadata are retained as required for financial records. Depending on where you live, you may have additional statutory rights (for example under GDPR or CCPA); Pareta honors requests to the extent the law requires.

3. No training on your data

Pareta does not use your inputs or outputs to train models, and does not sell them.

Pareta-hosted modelsPareta does not train models on your inputs or outputs.
Frontier providersOpenAI, Anthropic, and Google process your data as Pareta’s subprocessors under their API terms, which prohibit them from training on it.
No sale, no advertisersPareta does not sell your data, and does not share it with advertisers.
No tracking cookiesThe only cookie the product sets is the session cookie that keeps you signed in. The marketing site collects anonymous usage statistics — page views and button clicks, with the referring site’s domain — sent only to Pareta’s own servers; no cookies, no advertising identifiers, no third-party analytics, and your IP address is not stored with them.

4. Data location

Pareta operates primarily from the United States (us-central1). If you use the Service from elsewhere, your data is transferred to and processed in the US.

Pareta-hosted models run on Google Cloud and Modal, primarily in the United States. A regional-processing option is not offered today — see §8.

5. Subprocessors

The subprocessor table from the Privacy Policy, §3, reproduced in full. The first five process request content — as infrastructure, inference, or routed and sampled requests; the remaining five do not.

ProviderPurposeSees request content?
Google CloudHosting, storage, databasesYes (infrastructure)
ModalGPU model servingYes (inference)
OpenAIFrontier serving + quality gradingYes (routed/sampled requests)
AnthropicQuality grading; frontier servingYes (routed/sampled requests)
Google AI (Gemini)Quality grading; evaluation runsYes (routed/sampled requests)
StripePaymentsNo (billing data only)
ResendTransactional emailNo (email address only)
CloudflareBot protection on signupNo
Pydantic LogfireOperational telemetryNo (metadata only — no prompt content)
SlackSupport channels (opted-in orgs)No (what you post there)

Source: Privacy Policy §3. The policy’s table governs; this page is updated when it changes.

6. Encryption and keys

What the Privacy Policy and Terms state about transport, credentials, and API keys.

In transitTraffic is encrypted in transit (TLS).
PasswordsStored hashed. Pareta never stores the password itself.
API keysStored as hashes and shown to you exactly once. Keep your password and API keys confidential; you are responsible for all activity under your account and keys.
CompromiseTell Pareta promptly at support@pareta.ai if you believe an account or key is compromised. Key creation is recorded in your organization’s audit log.

7. Audit logging

Access to stored request content by Pareta staff is restricted and recorded in your organization’s audit log.

What the log recordsLogins, key creation, admin actions, and any staff access to stored request content. The log is kept.
Human reviewIn quality monitoring, human review is limited to cases the automated monitor flags as quality exceptions, and that access to stored request content is logged in your organization’s audit log.

8. Zero retention and regional processing

Not offered today. There is no opt-out from the 30-day retention, and no option to process data outside the United States.

If your use case requires zero retention or regional processing, contact support@pareta.ai before sending production traffic.

9. Security contact

No system is perfectly secure. Report suspected vulnerabilities to support@pareta.ai. Use the same address if you believe an account or API key is compromised.

Pareta Inc. · support@pareta.ai · Full documents: Privacy Policy (last updated 2026-08-01) · Terms of Service (version 2026-08-17).

Benchmark the production workload you already run

Evaluate Pareta on representative examples before sending production traffic — an evaluation set is 5–50 items, and the datasets you upload stay until you delete them. Use the OpenAI client already in your application and set the model ID to auto.

$30 in credit · no card required · OpenAI-compatible