Legal

Privacy

What we collect, why we collect it, where it lives, and what we will never do with a recording, a photo or a clip you send us.

Last updated 11 September 2026Being finalised with counsel. For anything binding, talk to us first.

Who we are

Perit is the brand of Zyno AI Inc, a training-data company. We collect and annotate speech, video, image and text for AI teams; we run benchmarks and environments for speech models; and we are building embodied-data collection — egocentric video, depth, teleoperation and handheld-gripper demonstrations — for robotics teams. The work happens on two platforms we operate: Foundry, where annotation and review are done, and the contributor workspace, where recording sessions run.

Four groups give us personal data: contributors who record, film or annotate; people who apply for roles on the bench; customers who commission or license data; and visitors to this site. Perit is the controller for data collected through the site and the two platforms. Where a customer commissions a collection to their own specification, or sends us their own material to annotate, we act as their processor for that dataset and the engagement terms apply alongside this policy.

What we collect

  • Contributors: name, email, payout details, the locale and accent you tell us, your device and room conditions, and the recordings, footage, images or text you submit, with the metadata attached to each session — device, duration, prompt, environment, QC status.
  • Annotators and reviewers on Foundry: the credential you applied with, your training and test results, your production history, quality scores and payment records.
  • Applicants: what you enter in the application form for a role, and the test credentials we issue for Foundry's training and testing modules.
  • Customers: work email, company, the content of a data request, a brief or a pilot scope, and the booking details when you schedule a call.
  • Visitors: basic request logs and privacy-preserving analytics. No advertising trackers, no cross-site profiling.

Voice recordings and consent

A voice recording is personal data and, in several jurisdictions, biometric data. We do not collect one without an explicit, specific consent captured at the start of the session — on the file itself — that tells you plainly what the audio is for: training and evaluating AI systems, for Perit and for the customers who commission the work.

We never enrol a voice for identification or verification, never build a speaker-recognition profile from contributor audio, and never license a recording as a standalone identity artefact. Sessions are prompt-led — we ask you to read or improvise scripted material, not to talk about your own life — and we ask you not to include names, account numbers or health details that identify a real person.

Video, images and the rooms they are recorded in

Physical Intelligence capture and task video put a camera on a person — on the chest, the head, a wrist gripper, or in a hand — and record them doing real tasks in real kitchens, offices, shops and workplaces. That footage can show a face, a home, a colleague, a customer, a document on a desk. So the rules are stricter than for audio.

  • The person wearing or holding the camera consents on the file, before the first take, to exactly this use.
  • Anyone else who appears recognisably in frame has to consent too, and the contributor is trained to obtain it or to keep them out of frame. Footage with an unconsented, identifiable bystander fails QC and is deleted.
  • Sites are recorded with the permission of whoever controls them. Screens, documents, name badges and anything else that carries a third party's personal data are kept out of frame or redacted before delivery.
  • We never build a face-recognition profile from contributor footage, never license footage for identifying individuals, and never use it to map or surveil a private premises.
  • Teleoperation and gripper episodes carry robot state, action and pose logs. Those are machine data, not personal data, and are delivered alongside the video.

How we use it

Our lawful bases are consent for recordings and footage, contract for payment, platform access and hiring, and legitimate interests for security, fraud prevention and product improvement. Under India's Digital Personal Data Protection Act, contributor consent is taken through a plain-language notice before capture and can be withdrawn as described below.

  • To run the platforms: matching you to sessions and tasks, reviewing submissions, paying you.
  • To build, annotate and license datasets, benchmarks and environments, as described at the point of collection.
  • To maintain quality: calibration, QA sampling, agreement and drift checks on submitted work, and fraud checks on accounts.
  • To hire: reviewing applications and issuing Foundry test credentials.
  • To meet legal, tax and accounting obligations on payments we make and invoices we issue.

Who we share it with

Delivered datasets go to the customer who commissioned or licensed them, under terms that forbid re-identification, voice or face enrolment, and onward sale of the raw corpus. Benchmark audio is held out and is not delivered to any model provider.

Beyond that, personal data reaches only the vendors that make the platforms work — regional cloud hosting, payment providers for bank and UPI payouts, identity checks, email, and Google for the application form and the scheduling page you see when you book a call — each under a written processing agreement. The current sub-processor list, with the region each operates in, is attached to every data processing agreement and available on request. We do not sell personal data.

Where it lives

Every collection is pinned to one region at kickoff — Frankfurt, Northern Virginia or Mumbai — and the recordings, footage, transcripts and labels for it stay there. Account, billing, applicant and support records are global systems and hold no audio or video. The full picture, including how transfers are handled, is on the data residency page.

How long we keep it

  • Approved recordings, footage and labels: for the life of the dataset they belong to; the collection notice states the period.
  • Rejected submissions: deleted within 30 days.
  • Account and payment records: as long as the law requires, typically seven years.
  • Applications: up to twelve months after the role closes, then deleted unless you were hired.
  • Withdrawn sessions: deleted, not archived.

Your rights

You can ask for a copy of your data, correct it, delete it, restrict or object to processing, and withdraw consent. Contributors can export every recording and clip they have submitted from the workspace. Withdrawal before payout deletes the session; withdrawal after payout stops future use and removes your material from datasets we still control. Copies already delivered under licence to a customer cannot be recalled, which is why consent is taken before you record rather than after.

Write to us and we answer within 30 days. If you are in the EEA or UK you may also complain to your supervisory authority; California residents have the rights the CCPA and CPRA give them, including the right to know that we do not sell personal data. We would rather you told us first.

Security

Audio, video and labels are encrypted in transit and at rest. Access is role-scoped and logged; a reviewer streams the one clip they are working on and cannot download it; bucket handovers use time-boxed credentials. We hold a SOC 2 report, ISO 27001:2022 for information security, ISO 27701:2019 for privacy management and TPN Gold for content security; we operate under GDPR, CCPA and HIPAA, and offer a Business Associate Agreement where recordings may carry protected health information. Report a vulnerability to us — we will not pursue good-faith research, and we will tell you when it is fixed.

Children

The platforms are for adults. We do not knowingly collect data from anyone under 18, and child-voice or child-video datasets are only ever collected under a separate guardian-consent protocol agreed in writing before the work starts.

Changes

We will post any change here and, where it affects how your recordings or footage are used, tell contributors by email before it takes effect.

Questions about this page?

One address for privacy requests, security reports and anything contractual. We answer within 30 days, usually the same week.

Email support@perit.ai