PeerLM logoPeerLM

Data handling

What we store, what we send, and what we never do

PeerLM does not train on your content. OpenRouter inference is restricted to zero-data-retention endpoints. We still store the comparison receipt in your workspace — that is the product. This page is the short version; Privacy and Terms are the binding one.

We do not train

PeerLM does not use your prompts, production traffic, model outputs, or scores to train, fine-tune, or evaluate any model of our own. We do not sell that content, and we do not share it with other customers.

The receipt stays with you

A Monitor is an audit trail. We store the sampled prompts, candidate outputs, judge results, and verdict in your workspace so you can inspect and export them. That retention is the product, not a side effect.

OpenRouter ZDR for inference

Hosted generations and judging go through OpenRouter with zero data retention enabled. First-party OpenAI, Anthropic, and Google APIs are not used; those models run on Azure, Bedrock, and Vertex endpoints OpenRouter classifies as ZDR.

What PeerLM stores

Production traffic you connect, prompts you paste, candidate and judge outputs, scores, and the living verdict. We also store account identity, billing status from Stripe, and product-usage events (runs started, features used — not prompt bodies).

Ingest runs a best-effort redaction pass for common secrets and identifiers (emails, phone numbers, SSNs, card numbers, API keys, and similar patterns). It is not a guarantee that every secret is stripped. Do not send us logs you would not send a processor.

Why PeerLM is not zero data retention

Observed control compares challengers with the exact captured production response. Prompt CI and every Run report need the prompt, both outputs, and the panel's votes. Deleting that after the call returns would delete the evidence the product exists to produce. OpenRouter ZDR covers the inference hop, not the receipt we keep for you.

Enterprise can turn on truncated storage: we keep structure and aggregates, and cut stored prompt text to 200 characters and responses to 100. That is PeerLM-side truncation. It also makes observed control ineligible — there is nothing left to replay.

Downstream providers

OpenRouter is the default router. Zero data retention is enabled on the PeerLM OpenRouter account, so hosted generations and judging only route to endpoints with a ZDR policy. OpenRouter itself does not store prompt and completion content unless logging is opted in; we do not enable that logging, or OpenRouter's optional "use of inputs/outputs" product-improvement setting. OpenRouter's ZDR documentation describes the routing: first-party OpenAI, Anthropic, and Google APIs are excluded; Azure, Bedrock, and Vertex remain.

Groq is used for some models. Groq does not train on API inputs or outputs; it may keep reliability logs for a short window unless ZDR is enabled on the Groq account.

How long reports last

Each plan guarantees the report stays available for at least the window below while the account is open. Deleting a Monitor or Run soft-deletes it for 30 days, then removes it. Closing the account starts a 30-day deletion of account data, except where law requires a longer hold.

PlanReport availability
Free7 days
Pro90 days
Team180 days
Enterprise365 days

Sharing and cache

A share link is public to anyone who has it. Review prompt and response visibility before you create one. Cached generations are keyed to your workspace's prompt records and are not reused across customers.

Published pages on peerlm.com/compare are PeerLM-run evaluations, not traffic from customer Monitors.

Questions about a pilot or a processor list: privacy@peerlm.com