PeerLM logoPeerLM

Privacy Policy

Last updated: September 21, 2026

A shorter, customer-facing summary lives on How we handle your data. If that page and this policy differ, this policy controls.

1. Who we are

PeerLM Inc. ("PeerLM," "we," "us," or "our") operates the PeerLM service at peerlm.com and app.peerlm.com (together, the "Service"). This policy describes how we collect, use, disclose, and retain information when you visit the marketing site or use the product.

2. Information we collect

Account information

Name, email address, and authentication credentials. If you sign in with Google, we receive your name, email, and profile picture from Google.

Customer content

Content you submit or connect so we can run the Service: production traffic (prompts, system prompts, captured responses, model identifiers, token and cost metadata), evaluation configurations, generated candidate outputs, judge outputs and scores, verdicts, and exports. This is stored in your workspace because the product is an inspectable comparison receipt.

Usage information

Product events such as pages viewed, features used, runs started or completed, and error diagnostics. We use PostHog for product analytics, Sentry for error tracking, and Axiom for structured logs. We configure these tools so prompt bodies, production traffic, and model outputs are not sent to them as event properties. Error reports may still include request metadata (URLs, status codes, user or workspace identifiers).

Payment information

Stripe processes payments. We do not store full card numbers. We store subscription status, plan, and billing period as Stripe returns them to us.

Marketing-site information

On peerlm.com we collect the information you submit on forms (for example a trial request) and product-analytics events (page views, search, CTA clicks) via PostHog. We also use essential cookies for that analytics session.

3. How we use information

  • Provide, maintain, secure, and support the Service
  • Run evaluations, Monitors, Prompt CI, and generate reports
  • Send transaction mail (run completions, billing receipts)
  • Prevent abuse and investigate security incidents
  • Understand product usage from events and aggregated metrics — not from your prompt or traffic content

4. No training on customer content

PeerLM does not use Customer Content to train, fine-tune, or evaluate any model that we own or operate. We do not sell Customer Content. We do not share it with other customers or use it to build a public benchmark of your traffic.

Published comparisons on peerlm.com/compare are evaluations PeerLM runs on its own prompts, not traffic from customer Monitors.

5. Model providers and subprocessors

Generating and judging requires sending the relevant prompts and outputs to large-language-model providers. Those calls are how the Service works. We share data only as described here.

  • OpenRouter — default router for candidate generation and judging. Zero data retention is enabled on the PeerLM OpenRouter account, so those calls only route to endpoints with a ZDR policy. First-party OpenAI, Anthropic, and Google APIs are not used; those models run on Azure, Bedrock, and Vertex. OpenRouter does not store prompt and completion content unless logging is opted in; we do not enable that logging, or OpenRouter's optional "use of inputs/outputs" product-improvement setting. See OpenRouter's ZDR documentation.
  • Groq — used for some models. Groq does not train on API inputs or outputs. It may keep reliability or abuse logs for a limited period unless zero data retention is enabled on the Groq account.
  • Bring Your Own Key (Enterprise) — generations and judges run with credentials you supply. That traffic is also subject to the agreement between you and that provider.
  • AWS — application infrastructure. Customer Content is stored in us-east-1.
  • Stripe — payment processing.
  • Sentry and Axiom — errors and operational logs, without prompt or traffic bodies as described above.
  • PostHog — product analytics on the app and the marketing site.
  • Resend — transactional email.
  • Cloudflare — hosts the marketing site.
  • Google — sign-in, if you choose that method.

OpenRouter ZDR covers the inference hop. PeerLM still stores the comparison receipt in your workspace. A readable summary is on the data handling page.

6. Redaction, truncation, cache, and sharing

On ingest we apply best-effort redaction for common identifiers and secrets (including emails, phone numbers, SSNs, card numbers, and API-key patterns). This is not a guarantee that every secret is removed. You remain responsible for what you send us.

Enterprise workspaces may enable truncated storage, which keeps aggregates and short prefixes (200 characters of prompt, 100 of response) instead of full bodies. Truncation is applied after classification, on PeerLM's storage — not as a processor zero-retention flag. Observed control cannot run on truncated traffic. Provider calls in that mode still use PeerLM-managed keys unless BYOK is configured.

Response caching reuses a generation for an identical model and prompt record inside your workspace. Cache keys include your prompt record identifiers; cached content is not reused across customers.

Shareable report links are reachable by anyone who has the URL. Paid plans can include prompts and responses in a share when you turn that visibility on. Treat a share link as public and revoke it from the Run when you want access to end.

7. Retention

While your account is open we keep Customer Content so the Service can show history, receipts, and living verdicts. Each plan guarantees that reports remain available for at least:

  • Free: 7 days
  • Pro: 90 days
  • Team: 180 days
  • Enterprise: 365 days

Deleting a Monitor or Run soft-deletes it and removes it permanently after 30 days. After you close an account we delete account data within 30 days, except where we must keep a record to meet law, resolve disputes, or enforce our terms. Backups roll off on their normal cycle.

8. Security

We encrypt data in transit (TLS 1.2+) and encrypt sensitive data at rest (AES-256). API keys we store for Enterprise BYOK are encrypted with AES-256-GCM under a dedicated key; only the last four characters are ever shown. Application hosts sit in a VPC with security-group isolation. We log security-relevant actions. No method of transmission or storage is perfectly secure.

9. Your rights

Depending on your jurisdiction, you may have the right to access, correct, delete, or export personal data, to object to certain processing, and to withdraw consent where processing is based on consent. You can export evaluation data as CSV or JSON from the Service where that export exists. To exercise other rights, email privacy@peerlm.com.

10. Cookies and analytics

We use essential cookies for authentication and session management on the app, and PostHog cookies on the marketing site and app for product analytics. We do not use advertising cookies or sell personal information. You can block non-essential cookies in your browser; some analytics will then be unavailable.

11. International transfers

We process information in the United States (including AWS us-east-1). Model providers may process inference in other regions under their own terms. If you access the Service from outside the United States, you understand that information is transferred to and processed in the United States.

12. Children

The Service is not intended for anyone under 18. We do not knowingly collect personal information from children.

13. Changes

We may update this policy. We will change the date above and, for material changes, notify account owners by email. Continued use after the effective date is acceptance of the updated policy.

14. Contact

Privacy questions: privacy@peerlm.com.