Data & deletion
Getting everything out, and having it erased
Full export is a permanent feature, not a retention tactic. A product whose entry story is “files in, no bank login” has to be able to say files out too.
This page is part of the Terms of service.
The product promise is no lock-in. That closes the loop the landing page opens: statements go in as files you control, and they come out the same way.
What is stored
Specifically, rather than as a category. A vague inventory reads as evasion on a product that asks for complete bank statements.
- Entities you create, and the accounts mapped to them.
- Transactions imported from statements: date, description, counterparty, amount, category, and whether the line was recognized as an internal transfer.
- Loans, leases and invoices, with the payments recorded against them.
- Goal inputs: age, invested capital, target withdrawal rate, logged deposits.
- Account details: email address, and a password hash where email sign-in is used.
What is not stored
The statement files themselves. A CSV is read, the transactions in it are written to your account, and the file is discarded. It is not archived, not kept for a retention period, and not held in a second storage service. The list above is the whole of what exists in your account, rather than the part of it we chose to describe.
That matters more than it sounds. A bank export usually carries more than the transactions: the full account number, the account holder’s name and address, sometimes a balance history the parser never looks at. Keeping the file would mean holding the richest version of your data indefinitely to save ourselves occasional work.
The cost is ours to state: if an import goes wrong because we read your bank’s format badly, we cannot re-run it from our side. We will ask you to upload the file again. Duplicates are detected, so doing that is harmless.
What we keep after your account is gone
One category, because the law requires it. Billing records: your name and email, the dates and amounts of charges and refunds, the sales tax on them, and the invoices and receipts we issued. Tax and accounting law requires us to keep these for a set number of years, so they are not deleted with your account; they are kept for as long as that law requires, and no longer. They contain nothing from your statements, entities, transactions or Goal. Your card details are held by Stripe, not by us, under Stripe’s own retention rules.
One thing is outside our hands, so it is stated rather than left out. The AI analyst runs on Azure OpenAI, in our own Azure subscription. Microsoft does not train models on what it is sent, but its abuse monitoring can store a prompt that its systems flag, for review, and Microsoft does not publish how long it is kept. That is why a prompt carries no identity: as the Privacy policy sets out, the model sees the text of a transaction and a figure, never your name, email address, account numbers or entity names.
Export
Two formats, because they are for two different things.
- CSV, one file per entity. Transactions with their dates, descriptions, counterparties, amounts, categories and internal-transfer flags. This is the one that opens in Excel or Numbers, which is where most people go to check our arithmetic against their own.
- JSON, one file for the whole account. Everything, with the structure intact: entities and the accounts mapped to them, every transaction, loans and leases with their recorded payments, invoices, and the Goal inputs, including your age, invested capital, target withdrawal rate and the full deposit ledger.
The Goal inputs are named on purpose. They are the part of your account that is your work rather than your bank’s, they are what another tool would make you re-enter, and they are the first thing an export usually drops. If you leave, you leave with all of it, in a format you can open.
When export works. At any time while your account is active, and for 30 days after it ends, whatever the reason it ended. The only exception is when you ask us to delete everything outright: that skips the 30 days, so export first if you want a copy.
When an account ends, and what happens next
An account ends in one of five ways. In every case except the first, it is kept for 30 days after it ends, so you can still export, and an accidental ending is recoverable. Then it is deleted.
| How it ends | When it ends | Then |
|---|---|---|
| You delete it | The day you ask | Live data is deleted that day. No 30-day window. |
| You cancel | At the end of the period you have already paid for. You keep full access until then. | Kept 30 days, export works, then deleted. |
| You cancel during a free trial | At the end of the trial | Kept 30 days, export works, then deleted. |
| A payment fails | We retry for up to 14 days. If it still fails, the account becomes read-only: you can see and export your data, but not add to it. | Kept read-only for 30 days. Paying in that time restores it. Then deleted. |
| We close it, or discontinue Perpetory | On the date in our notice. Except in urgent cases we tell you first, and if we discontinue Perpetory we give at least 60 days’ notice. | Kept 30 days, export works, then deleted, unless the law requires us to keep it longer. |
If you get a refund for a payment (for example within 30 days of your first yearly charge), the paid period ends on the day of the refund, and the account then follows the “you cancel” row.
Deletion
Delete your account from your account settings. It does not go through us, it does not need a reason, and there is no retention conversation, the same way canceling is one click. If you would rather ask a person, email contact@perpetory.com and we will do it.
Deleting your account also ends your subscription. It is not a refund: the unused part of a paid period is refunded only in the cases listed in section 8 of the Terms, such as within 30 days of your first yearly charge. If that applies to you, ask for the refund before you delete.
Deletion happens when you ask. The live data is gone that day, not at the end of a window.
The one lag is backups, and here is the arithmetic rather than a reassuring adjective. Azure keeps encrypted automated backups for 30 days. Deleting your account removes the live record immediately; the backups that still contain it then age out over the following 30 days. After that, nothing from your account remains anywhere, apart from the billing records described above and, at most, a flagged prompt that carries no identity.
The longest it can take, in days:
- You ask for deletion: up to 30 days until nothing remains (the backup window).
- Your account ends any other way: up to 60 days from the day it ends (30 days kept, then the backup window).
- With a yearly plan, “the day it ends” is the end of the paid year, not the day you clicked cancel.