Draft — pending legal review. Last updated 2026-08-09.
The short version
OpenPeach is a personal assistant you are not charged for. You bring your own Large Language Model — a cloud API key or a model on your own machine. We are the control plane that stores your data (notes, to-dos, calendar, documents, memories) and orchestrates your model. We don’t sell your data. We may use your conversations to train our own models, but only if you turn that on — it is a separate, unticked box at signup, not part of accepting the Terms, and a switch in Settings (“Help train OpenPeach’s models”) either way. You can switch it off again at any time and delete everything you’ve contributed. We keep contributed turns for 5 years while it’s on and 30 days after you switch it off. We never train on your files — your uploaded documents and their contents, your Bio Vault, your health data and your document scans are never training data, either way.
What we store
- Your account: email, a bcrypt password hash, timezone, settings.
- Your content: chats, to-dos, calendar events, notes, Bio Vault people/documents (document scans stored encrypted-at-rest in our database), meetings, commitments, watchers, and memories — all scoped to your account.
- Provider keys: if you add a cloud provider, its API key is stored encrypted (AES-256-GCM) and used only server-side to call that provider. We never display it back.
- Usage mirror: token counts per turn, so you can see what your provider will bill you. We do not bill you.
Your model, your data path
When Peach answers, your message and the relevant context are sent to the model you configured — your cloud provider, or a model on your own machine via the peachd node (in which case your content never leaves your hardware for inference). We don’t add our own model in the middle.
Training OpenPeach’s own models — optional, and off until you turn it on
We use your conversations to train our own Large Language Models — but only when you turn this on. It is a separate box on the signup form, it starts unticked, and accepting the Terms neither turns it on nor depends on it: you can create an account and use everything with it off. You can turn it on or off whenever you like in Settings → “Help train OpenPeach’s models”. Turning it off stops capture immediately and costs you nothing: OpenPeach is free and behaves identically either way. This is your consent under Art. 6(1)(a) GDPR, and withdrawing it is as easy as giving it.
This is exactly what it covers:
- What is eligible. The conversation: your Peach Chat conversations, your Ask Muse conversations, and your Vibe Peach coding turns. A coding turn includes the instruction you gave, the reply, the agent’s reasoning, and the tool calls it made in the project you pointed it at — including the code it read and wrote there. Alongside each turn we store which model produced it and the outcome (whether it committed, what the review said).
- We never train on your files. The documents and files you upload to Files — and the file contents that Files search reads out of them — are never training data, and neither are your Bio Vault, your health records or your document scans. Any Peach Chat you mark incognito is excluded too. What is eligible is the conversation about a file: if Peach quotes, cites or summarises one of your documents in a reply, that reply is part of the conversation. In short: we never train on your files; we may train on the conversation about them.
- How long we keep it. Contributed turns are kept for 5 years while training is on. If you switch it off, what was already captured is kept for 30 days and then deleted — sooner if you erase it yourself.
- When personal details are removed. Captured turns are stored as you wrote them. A deterministic, pattern-based scrubber runs later — before anything is used for training, at the point a turn is curated into a training example: it replaces email addresses, phone numbers, IP addresses, payment-card numbers and API keys/secrets with typed placeholders. It does not detect or remove names or postal addresses, so please don’t treat contribution as anonymisation — treat it as sharing the conversation with us under the commitments below.
- We never sell it, and never use it for anything but training our own models. No ads, no third parties.
- You can withdraw and erase, separately. The switch stops future capture and stops any further training example being built from what you already sent. Erasure is a separate button: “Delete my training contributions” in Settings removes both the raw turns and any curated examples at once, so every dataset snapshot built afterwards excludes them. Deleting your account removes everything.
Where data-protection law applies (e.g. the EU/UK GDPR), our lawful basis for this processing is your consent, given when you accept the Terms and disclosed in the signup form itself. You may withdraw it at any time from Settings, without affecting your access to OpenPeach or the lawfulness of processing before withdrawal, and all other statutory rights — access, portability, erasure — continue to apply.
Your rights
You can export everything we hold for you as JSON, and delete your account (which removes all of your data) — both from Settings, at any time.
What we don’t do
We don’t sell your data, we don’t read your content to advertise, and we don’t connect to third-party messaging channels on your behalf. We don’t access your email.
Questions: [email protected] · See also the Terms.