privacy policy
what pepita collects, why we collect it, who we share it with, and how you can control it.
this policy explains what personal data we collect when you use pepita, what we do with it, and the choices you have. pepita is designed with the idea that your site content belongs to you, and we try to collect as little personal data as we can while still running a useful service.
1. who we are
the pepita service ("pepita", "we", "us") is operated by Barely Notable OÜ, a private limited company registered in estonia (registry code 17542871), registered address Tornimäe tn 5, Kesklinna linnaosa, 10145 Tallinn, Estonia. for privacy questions, contact us at privacy@pepita.dev.
we are the data controller for the personal data described below. we may use third parties as data processors to help run the service; they are listed in section 6.
2. what we collect
account data (via google sign-in)
when you sign in with google, we receive: your name, email address, profile picture url, and a stable google account identifier. we store these in our database to identify your account. we don't receive or store your google password.
content you create
the text, images, and other files you create or upload to your pepita sites. this is stored in the github repository pepita creates for each of your sites and in our infrastructure to serve the site at its public url.
site metadata
slugs, custom domains you attach, deployment timestamps, and publishing history.
analytics for your published site
every pepita site has analytics, and it cannot be switched off. pepita collects privacy-friendly, cookieless visitor statistics for your site — page views, referrers, approximate country, device and browser type — using our self-hosted analytics, on your behalf. no cookies are set on your visitors, and no cross-site tracking is performed. you read the numbers in your site's editor.
for this visitor data you are the data controller and pepita acts as your processor. because analytics cannot be turned off, that role isn't optional either: you are responsible for telling your own visitors about it where your local law requires — for example, a privacy notice on your site.
we keep this visitor data for as long as we run the service, and it is not automatically deleted when you delete a site or your account. if you want it removed, email privacy@pepita.dev and we will delete it.
information about other people
you may give us another person's information in two ways: by inviting a teammate to a site, or by including someone's personal data in the content you publish — for example a name, photo, quote, or contact details in a team page, testimonial, or contact section. in both cases you are responsible for making sure you have the right to use and share that information and, where required, for telling that person how it will be used.
for personal data you put into your published site content, you are the data controller and pepita simply hosts it on your behalf. for information you give us to run a feature (such as a team invite), we use it only to operate that feature.
technical data
- a session cookie that keeps you signed in
- ip address and basic request data (browser/user-agent, approximate region), processed by cloudflare to deliver the service and prevent abuse
- logs of errors and api requests, retained short-term for debugging
billing data
if you subscribe to a custom domain or top up ai credits, polar.sh (our merchant of record) collects and stores your name, email, billing address, and payment details. pepita does not see or store card numbers; we only see what polar tells us about each successful order — site id, product, amount, and a redacted payer reference. we keep records of orders and balances in our own database to run your account.
ai chat — built-in credits (default)
when you use the ai assistant on built-in credits, your prompts and the file context the assistant reads pass through pepita's servers on the way to anthropic (the model provider). we keep the conversation per-site so you (and your teammates on that site) can reopen it later, and we keep a per-call usage record (model name, token counts, cost) to bill the prepaid balance. we don't read your prompts beyond what's necessary to route and account for the call. anthropic's own privacy policy applies to the call leg they handle.
ai chat — bring your own key
if you paste your own anthropic api key in settings → ai, your prompts still flow through pepita's servers (so the assistant can keep running when you close your browser tab and so teammates see the same conversation), but we use your key to call anthropic — anthropic bills your card directly and we don't deduct anything. your key is stored encrypted at rest using aes-gcm with a key that lives only on our worker secrets; it is decrypted only at the moment of each anthropic call and never written to logs.
real-time collaboration
when you and a teammate are on the same site at the same time, our servers relay each person's cursor position, name, colour, and editor changes to the other. presence data is transient (lives in memory only while you're connected). edit history that's part of the live document state may be persisted briefly so a returning collaborator sees the same content; once everyone disconnects and the room is idle, that state collapses to the saved file contents. the ai conversation for a site is shared with all current and future collaborators on that site.
support communications
if you email us or use the in-app support chat (our own, self-hosted on cloudflare — no third-party chat provider), we keep the content of that correspondence — and, for the chat, basic session data such as the pages you visited and your approximate location — to respond to your request and keep a short history of our conversation.
3. how we use it
we use the data we collect to:
- run the service — sign you in, show you your sites, publish your site to the web
- keep the service secure — detect abuse, debug problems, protect against fraud
- communicate with you about your account, service updates, and billing (if any)
- improve the product — in aggregate, without identifying individual users
- comply with legal obligations — tax records, lawful requests, safety
we do not sell your personal data. we do not share your personal data with third parties for their own marketing purposes.
we don't train ai on your data. your prompts and site content are sent to the model provider only to generate the response you asked for. we do not use your content to train pepita's systems, and our ai provider (anthropic) does not use data submitted through its api to train its models.
4. legal basis (gdpr)
if the european general data protection regulation (gdpr) or uk gdpr applies to you, the legal bases we rely on are:
- contract — to provide the service you signed up for
- legitimate interest — to secure the service, prevent abuse, and improve the product
- legal obligation — to meet tax, accounting, and lawful-request requirements
- consent — for anything we explicitly ask permission to do (you can withdraw consent at any time)
5. where it's stored
- user accounts, site metadata, ai usage and billing records — cloudflare d1, a serverless database hosted on cloudflare's network. primary region: eastern europe.
- site content and assets — cloudflare r2 object storage (both your in-progress drafts and your published site files) and the github repositories pepita creates for your sites (in a pepita-operated github organisation).
- real-time collaboration state and ai conversations — a per-site cloudflare durable object holds the live editing document, presence list, and the ai chat. ai conversations persist across server restarts; presence is in-memory only while you're connected.
- byok api keys — encrypted (aes-gcm) in cloudflare d1; the encryption key lives only on our worker secrets and is never logged.
- working tree cache — your browser's local indexeddb mirrors the latest server state for fast preview. this copy lives on your device only.
- session and cache — cloudflare kv.
6. who we share it with
the third parties we rely on to run pepita (our processors) are:
- cloudflare — workers, d1, r2, kv, durable objects, dns, ssl. primary infrastructure, and the host of our self-hosted support chat.
- github (microsoft) — stores each user's site code in a private repository inside our pepita-operated github organisation.
- google — oauth sign-in only. google receives the authentication request; they do not receive your site content.
- anthropic — powers the built-in ai assistant. when you use the assistant on built-in credits, your prompts and the file context it reads are sent to anthropic so they can produce a response. with bring-your-own-key, the call goes through anthropic under your own account.
- polar.sh — handles billing as merchant of record. polar processes the card payment, collects vat / sales tax globally, and pays out the net amount to us. polar receives your name, email, billing address, and payment details — pepita does not see card numbers.
we do not share your personal data with advertising networks, data brokers, or anyone who does not directly help us run the service.
we may disclose data if we are legally required to (for example, a valid court order), or if necessary to protect the rights, property, or safety of pepita, our users, or the public. where permitted by law, we will notify you of such requests.
7. international transfers
some of our processors are based in the united states or have global infrastructure. when personal data is transferred outside the european economic area or the uk, we rely on appropriate safeguards, typically the european commission's standard contractual clauses and, where applicable, supplementary measures recommended by european data protection authorities.
8. data retention
- account and site data — kept while your account is active
- after account deletion — we remove your account, sites, and assets within 30 days, except where we're required to keep limited records (for example, billing records for tax purposes)
- visitor analytics for your published sites — not covered by the 30 days above: it is kept until you ask us to delete it (see section 2)
- logs — rotated and purged within 90 days
- backups — overwritten on a rolling cycle; any residual data is purged within 90 days
you can request deletion at any time (see section 9).
9. your rights
depending on where you live, you have some or all of the following rights:
- access — a copy of the personal data we hold about you
- rectification — correct inaccurate data
- erasure — delete your account and associated data
- portability — a machine-readable copy of the content you created
- restriction — ask us to stop using certain data while we resolve a dispute
- objection — object to processing based on legitimate interests
- withdraw consent — for anything processed on the basis of your consent
- complain — to your local data protection authority. in the eu, see edpb.europa.eu.
to exercise any of these rights, email privacy@pepita.dev. we will respond within 30 days. there is no fee unless your request is manifestly unfounded or excessive.
these rights are available to all users, wherever you live. if your local law grants you additional or equivalent privacy rights — for example, brazil's lgpd, canada's pipeda (and quebec's law 25), switzerland's fadp, or other us state privacy laws — we honour them; just contact privacy@pepita.dev.
10. california (ccpa / cpra)
if you are a california resident, the california consumer privacy act (ccpa), as amended by the cpra, gives you the rights described in section 9 plus:
- the right to know what personal information we collect and how we use it
- the right to delete personal information we have collected
- the right to correct inaccurate personal information
- the right to opt out of the "sale" or "sharing" of personal information
- the right to limit use of sensitive personal information
- the right to not be discriminated against for exercising these rights
we do not sell or share personal information within the meaning of the ccpa. we do not use sensitive personal information for purposes that require the right to limit.
11. cookies
pepita itself sets a small number of strictly-necessary cookies:
pepita_session— keeps you signed in. http-only, secure, same-site. expires when you sign out or after a period of inactivity.pepita_oauth_state— csrf protection during sign-in. short-lived, cleared after you're signed in.
our support chat is self-hosted and cookieless — it uses your browser's local storage (not cookies) to keep your chat session going and recognise you as a returning visitor. apart from the strictly-necessary cookies above, we do not set advertising or cross-site tracking cookies.
do not track. because we don't track you across other websites, there is nothing for a "do not track" browser signal to switch off. we treat every user the same way, whether or not such a signal is sent.
12. security
we apply reasonable technical and organisational measures to protect your data: encrypted connections (https everywhere), at-rest encryption for tokens, scoped access for third-party credentials, and minimum-privilege infrastructure roles. no service can guarantee perfect security, but we take it seriously. if we become aware of a personal data breach, we will notify affected users and relevant regulators within the timeframes required by applicable law.
13. children
pepita is intended for adults. you must be at least 18, or the age of majority in your jurisdiction, whichever is higher, to use pepita — consistent with our terms of service. pepita is not directed at children, and we do not knowingly collect personal data from anyone under that age. if you believe someone under that age has given us personal data, contact privacy@pepita.dev and we will delete it.
14. changes to this policy
we may update this policy from time to time. when we do, we will update the "last updated" date at the top. if the changes are material, we will try to notify you by email or via a notice in the app before the changes take effect.
15. pepita connector (mcp)
pepita publishes an official connector — a model context protocol (mcp) server — that lets an ai assistant such as claude work on your pepita sites on your behalf. connecting it is optional and entirely under your control.
what it can access
once you connect and authorize it, the assistant can do the same content actions you can do in the editor: list your sites, read and edit files, save a draft, and publish. it cannot change billing, custom domains, team members, or delete a site — those stay in the editor.
what data flows, and to whom
when the assistant uses the connector, the relevant data — your list of sites and the file contents it reads or writes — is sent to the ai client you connected (for example, anthropic's claude) so it can carry out your request. that part is governed by that client's own privacy policy (e.g. anthropic's privacy policy). pepita only relays these calls to your own sites; we do not use connector activity for any purpose beyond serving your request and basic security / rate limiting.
how it's authorized
- local connector — reuses the access token created by
pepita login, stored only on your own machine (~/.pepita/config.json). - hosted connector — you authorize it through pepita's normal sign-in (oauth); a scoped token is issued to the ai client, and no password is shared.
revoking access
you can revoke a connector (or any cli device) at any time in settings → connected devices. revoking immediately stops the assistant from acting on your sites.
16. contact
email us at privacy@pepita.dev for any questions about this policy or about how pepita handles your personal data.