Last updated: January 2026
Peta keeps secrets server-side and routes risky agent actions through human approvals. This policy explains what we collect, how we use it, and how we protect it.
Peta Core, Console, and Desk run on servers you deploy. Your MCP configurations, agent policies, approval flows, and runtime usage stay in your environment and are not transmitted to Peta without your explicit permission.
Secrets (passwords, credentials, API keys) are encrypted in your Vault-backed storage; Peta cannot decrypt or access them. The only data we retain centrally are the account and payment details you provide when purchasing a commercial license.
External credentials stay encrypted in Vault and are injected server-side at runtime. Agents and users receive short-lived tokens instead of raw API keys. Access, approvals, and decryptions are logged for audit.
We segregate environments and tenants, follow least-privilege, and never sell your data.
We retain only the account and billing records you share for licensing, plus any support communications you choose to send. Your MCP audit logs stay in your environment; we do not collect them. You may request deletion of account data; some billing records may be retained where required for security or legal purposes.
Questions about this policy? Email privacy@peta.io.