Privacy Policy
Last updated: August 31, 2026
1. Introduction
Mixpeek Inc. ("Mixpeek," "we," "us," or "our") operates a multimodal data processing and retrieval platform (the "Service"). This policy explains what we collect, who we send it to, where it is processed, and what you can ask us to do with it.
Two very different sets of data are described below and it is worth keeping them apart. Platform data is the content you upload and what we derive from it. Website data is what we collect when someone browses mixpeek.com. The advertising and visitor-identification tools in section 7 run on the website only. They do not run inside the Service and they never touch customer content.
2. Information We Collect
2.1 Information you provide
- Account information: name, email address, and organization details
- Content you upload: text, images, video, audio, and documents
- API keys and credentials you create or store
- Billing details, handled by our payment processor (see section 4)
- Support requests, feedback, and communication preferences
2.2 Collected automatically
- Usage and API request logs, including timestamps and endpoints called
- Error reports and diagnostic traces
- Device, browser, and IP address information
- Cookies and similar technologies on the website (see section 7)
2.3 Data we derive from your content
- Embeddings, extracted features, labels, and metadata
- Search and retrieval queries, and the results returned for them
- Interaction signals such as which result was selected and at what position
- Performance and usage metrics
3. How We Use Information
- Operating, maintaining, and securing the Service
- Processing your content through the pipelines you configure
- Ranking and improving retrieval quality within your own namespace
- Billing, account management, and support
- Detecting abuse, fraud, and security incidents
- Meeting legal and regulatory obligations
4. Subprocessors
Running the Service means sending some data to other companies. These are the ones that can process customer data on our behalf.
| Subprocessor | Purpose | Data reached |
|---|---|---|
| Google Cloud Platform | Compute, object storage, hosting | Uploaded content, derived features, logs |
| Amazon Web Services | Object storage | Uploaded content and derived artifacts |
| Google (Gemini API) | Embedding and extraction models | Content submitted to those extractors |
| OpenAI, Anthropic | Language-model features where you enable them | Prompts and the content included in them |
| MongoDB | Document and configuration metadata | Metadata, not raw media |
| ClickHouse | Usage and performance analytics | Event and usage records |
| Stripe | Payment processing | Billing details. We do not store full card numbers. |
| Sentry | Error monitoring | Diagnostic traces, which can include request context |
Which model providers are reachable depends on the extractors and features your namespace uses. If you need a deployment where content never leaves infrastructure you control, self-hosting is the supported route.
5. Where Data Is Processed
Our production infrastructure runs in the United States, in Google Cloud regions us-east1 and us-central1 and in AWS us-east-1. We do not currently operate a European or Asia-Pacific region, so data you send to the hosted Service is processed in the United States regardless of where you are.
If you are in the European Economic Area, the United Kingdom, or Switzerland, that is an international transfer. We rely on Standard Contractual Clauses for it. Customers with a data residency requirement we cannot meet in the hosted Service should talk to us about self-hosting.
6. AI Models and Training
We do not train foundation models on your content, and we do not contribute your content to any third party's model training.
We do use data inside your own namespace to improve results for that namespace. Retrieval quality features learn from interaction signals such as which result was selected and at what rank. Those signals stay scoped to the namespace that produced them and are not pooled across customers.
Where a feature calls a third-party model provider, your content is sent to that provider to produce the result and is governed by their terms in addition to this policy. Section 4 lists which providers those are.
7. Website Analytics and Advertising
These tools run on mixpeek.com. They do not run inside the Service and they do not have access to customer content.
- PostHog for product and page analytics
- Google Analytics and Google Tag Manager for traffic measurement
- Meta Pixel for advertising measurement
- RB2B, which attempts to identify individual business visitors to the website and match them to a professional profile
- Sentry for front-end error reporting
RB2B is worth calling out plainly rather than leaving inside a general reference to cookies. It exists to turn anonymous website traffic into identified people, and we use it for business development. If you would rather we did not, email [email protected] and we will suppress your record.
PostHog also records browsing sessions on the website so we can see how pages are used. Form inputs are masked and elements marked private are excluded, so the recording does not capture what you type.
Your choices. Where prior consent is legally required, which includes the European Economic Area, the United Kingdom, and Switzerland, none of these load until you accept them in the banner. Declining leaves them unloaded. Everywhere else they load by default, and you can opt out at any time by emailing [email protected].
We honor the Global Privacy Control browser signal everywhere, not only where it is legally required. If your browser sends it, none of the tools above load, and accepting the banner cannot override it.
8. Sharing and Disclosure
We share information with:
- The subprocessors listed in section 4, for the purposes stated there
- Law enforcement or regulators where we are legally required to
- An acquirer, in a merger or sale of assets, subject to this policy
- Other parties only where you direct it
We do not sell customer content. We do share website visitor identifiers with the advertising and identification tools in section 7, which some privacy laws treat as a sale or a share. The opt-out in that section covers it.
9. Your Rights
Depending on where you live, you may have the right to access, correct, delete, export, or restrict processing of your personal information, to object to processing, and to withdraw consent. You can also ask us not to discriminate against you for exercising any of these.
Account owners do not have to wait on us for the two that matter most. The API carries them directly, and each is processed within 30 days:
POST /v1/organizations/dsar/exportreturns a full export of your organization's dataPOST /v1/organizations/dsar/deleteerases it, under GDPR Article 17 and CCPA section 1798.105. This one cannot be undoneGET /v1/organizations/dsar/statusshows where an open request has got to
For anything else, or if you do not have an account with us, email [email protected]. We will verify the request and respond within the period the law requires, which is 30 days under GDPR and 45 days under the CCPA. If we cannot fulfil a request we will tell you why.
Where we act as a processor for content you upload, requests from your own end users should come to you, and we will support you in answering them.
10. Retention
We keep your content for as long as your account is active or as long as you need it to provide the Service. You can delete content and namespaces yourself at any time through the API or the Studio.
When you close your account, or when you call the deletion endpoint above, we remove your content and personal information within 30 days, except where we must keep records for legal, tax, or accounting reasons. That deletion covers stored objects, derived features and vectors, organization records such as users, API keys and webhooks, and usage analytics. Backups and logs age out on their own schedules afterwards.
11. Security
Data is encrypted in transit and at rest. Access to production systems is restricted and logged. Our current certification status, including what we hold and what we do not, is published at mixpeek.com/trust.
If we become aware of a breach affecting your personal information, we will notify you and any required regulator without undue delay.
12. Children's Privacy
The Service is not intended for anyone under 13, and we do not knowingly collect personal information from them. If you believe a child has given us personal information, contact us and we will delete it.
13. Changes to This Policy
When this policy changes we update the date at the top of this page and, for changes that materially affect your rights, we notify account holders by email. The date reflects the last time the text below it changed.
14. Contact
Privacy questions and rights requests: [email protected]
Mixpeek Inc., 915 Broadway, Suite 1200, New York, New York 10010