Skip to content
Trust

Privacy notice

Pilot phase · last updated 20 July 2026

Who runs Bayeto

Bayeto is operated by Pierre Neuman as an individual — no legal entity exists yet, so this names a person rather than a company. For anything on this page: Contact.

What we collect

Account: your email address and sign-in credentials, handled by our authentication provider (Clerk). We never see or store your password.

Telemetry you upload: usage exports are parsed against a fixed 12-field whitelist (timestamp, model, token and cache-token counts, cost, application label, provider, region, latency, status). In the web app, parsing happens IN YOUR BROWSER: the upload preview names every accepted and ignored column, and only the normalized whitelisted rows are transmitted — prompts, user identifiers, emails, session ids and unknown columns never leave your machine (the server re-validates every transmitted field). Telemetry pushed via the API is filtered server-side with the same whitelist: the raw payload is processed in server memory and unfiltered content is never written to disk or database. The schema contains no personal data by design.

Nothing else: no analytics trackers, no advertising cookies. The only cookies are the session cookies authentication requires.

Where it lives

Telemetry and derived analysis are stored and processed in the EU (Amsterdam/Frankfurt). The 2 exceptions are dns, tls and edge delivery (Cloudflare), authentication and sso (Clerk), which may process account metadata outside the EU — named above, nothing silent.

No language-model provider receives your telemetry, or any figure derived from it: the engine is deterministic and nothing is sent to a model to produce a recommendation.

Your control

You can delete any uploaded workspace yourself (Settings → Delete workspace); deletion immediately and permanently removes its telemetry rows, declared context, API keys, share links, implementation marks and audit trail. Some operational records — delivery journals, staged spans awaiting pricing, signed receipts, application-identity records, implementation-event logs, telemetry connection settings, benefit-stream records, upload attestations, pre-change baseline records, recommendation-delivery records, ingest-batch provenance, and derived caches — are not yet covered by the self-serve purge; the security page carries the same list until extending the purge ships. For full account deletion, email us; it is performed manually and completed within 30 days.

What we never do

We don't sell data, share it with third parties beyond our subprocessors — Railway (Application hosting), Neon (Postgres database), Cloudflare (DNS, TLS and edge delivery), Clerk (Authentication and SSO), the same generated list the security page carries in full — or use your telemetry to train models. Recommendations are computed by a deterministic engine; your data is used to produce your recommendations, nothing else.

© 2026 Bayeto