AI providers & data processing
The PICHI platform is flexibly configured to meet each client's security requirements. The set of language models used is defined by the project configuration. At the client's request we can limit processing exclusively to Russian models (Yandex, Aspirity's own model) or deploy the platform in an isolated on-premise environment — with no transfer of data outside the client's infrastructure. The chosen configuration is fixed by a separate addendum to the contract.
Last updated: 01.08.2026
How we handle data
- Only the text content of the dialogue from a training session — what is needed to produce a response — is sent to language models.
- Account personal data (email, name) is not included in requests to the LLM — this is enforced by technical measures.
- Stored recordings of training sessions are kept in infrastructure located in Russia and are not passed to language models.
- Speech recognition (STT) runs in Russia by default (on-prem or Yandex SpeechKit); foreign STT (Deepgram, USA) may be used at the client's choice in the standard cloud configuration.
- The standard configuration may use a real-time voice model (Google Gemini Live): the audio of the conversation is sent to the model directly, with no intermediate transcription and with no storage on the provider's side. Such models are disabled in the RU-only and on-premise configurations.
- Dialogue analytics is performed on de-identified data.
Processing configurations
| Configuration | What it is | For whom |
|---|---|---|
| Standard (mixed) | Optimal quality: both Russian and foreign models may be used (see the table below). | Clients with no restrictions on foreign services. |
| RU-only | Processing exclusively by Russian services: YandexGPT, GigaChat (Sber), Aspirity's own model; STT — on-prem or Yandex SpeechKit (Deepgram disabled); TTS — Yandex SpeechKit (ElevenLabs disabled). Foreign models, including real-time voice models, are turned off. | Clients with a policy prohibiting cross-border transfer. |
| On-premise | Fully isolated environment within the client's infrastructure. No external data transfer. | Banks, pharma, public sector, maximum security requirements. |
The chosen configuration may be fixed by a separate addendum to the contract.
AI providers (language models)
| Provider | Jurisdiction | What is transferred | Role / note | Policy link |
|---|---|---|---|---|
| Aspirity LLC (own model) | Russia | Dialogue text | Available in RU-only and on-prem | Privacy Policy |
| Yandex LLC (YandexGPT) | Russia | Dialogue text | Available in RU-only | yandex.ru/legal/confidential |
| Sber (GigaChat) | Russia | Dialogue text | Available in RU-only | |
| OpenAI | USA | Dialogue text without identifiers | Disabled in RU-only / on-prem | openai.com/policies/privacy-policy |
| Anthropic | USA | Dialogue text without identifiers | Disabled in RU-only / on-prem | anthropic.com/legal/privacy |
| Google (Gemini) | USA | Dialogue text without identifiers | Disabled in RU-only / on-prem | policies.google.com/privacy |
| Z.ai (Zhipu AI, GLM models) | China | Dialogue text without identifiers | Disabled in RU-only / on-prem | docs.z.ai — privacy policy |
| Alibaba Cloud (Qwen) | China | Dialogue text without identifiers | Disabled in RU-only / on-prem | alibabacloud.com — privacy policy |
The set of providers depends on the project configuration and may be limited by contract. The table reflects the full list of technically supported providers.
Speech recognition (STT)
| STT provider | Jurisdiction | Note | Policy link |
|---|---|---|---|
| On-premise | Within the client's environment | Voice does not leave the client's infrastructure. For maximum security requirements. | |
| Yandex SpeechKit | Russia | Russian STT, the default option for the Russia-based cloud configuration. | yandex.ru/legal/confidential |
| Deepgram | USA | Voice transfer. Used at the client's choice; disabled in RU-only / on-prem. | deepgram.com/privacy |
Speech synthesis (TTS)
| TTS provider | Jurisdiction | Note | Policy link |
|---|---|---|---|
| Yandex SpeechKit | Russia | The AI counterpart's reply text is transferred. Default option for the Russia-based configuration. | yandex.ru/legal/confidential |
| ElevenLabs | USA | The AI counterpart's reply text is transferred (the user's speech is not). Disabled in RU-only / on-prem. | elevenlabs.io/privacy-policy |
Real-time voice models
A separate mode in which recognition, response generation and speech synthesis are handled by a single model — the audio of the conversation is sent to it directly, with no intermediate STT step.
| Provider | Jurisdiction | What is transferred | Policy link |
|---|---|---|---|
| Google (Gemini Live) | USA | Conversation audio without user identifiers. Processed in real time, not stored. Disabled in RU-only / on-prem. | policies.google.com/privacy |
Other subprocessors
| Subprocessor | Purpose | What is transferred | Jurisdiction | Policy link |
|---|---|---|---|---|
| Selectel | Platform hosting, data storage | All platform data | Russia | selectel.ru/about/documents |
| Yandex (email delivery) | Transactional emails (training notifications) | email, recipient name | Russia | yandex.ru/legal/confidential |
| Yandex SmartCaptcha | Form protection against bots | IP, behavioural data | Russia | yandex.ru/legal/confidential |
| Stripe | Subscription payments | Payment details and the payer's email. Card data is handled by the payment provider and is not stored on the platform. | USA / EU | stripe.com/privacy |
| PostHog | Product analytics (with consent). Tracking can be disabled — see the Cookie Policy . | De-identified events | EU | posthog.com/privacy |
| Yandex Metrica | Web analytics (with consent). Tracking can be disabled — see the Cookie Policy . | De-identified events | Russia | yandex.ru/legal/confidential |
Cross-border transfer
In the standard configuration, the infrastructure of foreign language-model providers may be used to generate AI responses. In that case only the de-identified text content of the dialogue is transferred — content that contains no user identifiers and does not constitute personal data. Users' personal data (email, name) is not transferred outside Russia, and stored recordings of training sessions are kept in Russia and are not transferred abroad. If the client has opted for foreign speech recognition (Deepgram) or a real-time voice model (Gemini Live), the audio of the conversation is processed by that provider during the call — with no storage on its side. For clients whose internal policies do not allow the use of foreign services, the RU-only and on-premise configurations are available.
Contacts and fixing the configuration
For security and data-processing enquiries: hi@aspirity.com
On request we are ready to provide a DPA / addendum to the contract, fix the chosen processing configuration and complete the client's security questionnaire.
Change log
- 01.08.2026 — version 1.1: the list of subprocessors has been brought up to date. Added Z.ai (GLM), the Gemini Live real-time voice model and payment processing (Stripe); speech synthesis moved into its own section (Yandex SpeechKit, ElevenLabs). DeepSeek removed — the model is no longer in use.
- 01.07.2026 — page published, version 1.0.
Last updated: 01.08.2026