Privacy
Privacy policy
The short version: financial data stays on our infrastructure, and no financial value is ever sent to a third party outside the providers listed below - analytics included.
Read this alongside Data & deletion, which covers what is stored and how to get it out or have it erased, and Security, which covers how it is held.
What holds today
- No third-party financial data sharing. Statement contents, balances, categories and projections are never transmitted to an analytics provider, an advertising network or a data broker.
- Your email address goes only to the providers that need it, all named in the table below: Azure, which stores it with your account or your early-access entry; our mail server, which delivers our email; and Stripe, once you pay. The mail server receives an address and nothing else, and Stripe sees what you are charged. Neither is sent a balance, a category or a figure from your statements.
- Analytics are usage-only and self-hosted. Umami runs on our own infrastructure and records events such as
imported_statementorviewed_goal- that an action happened, never the amounts involved. - No bank credentials, ever. There is no bank login field and no aggregation feed, so there is no standing access to hold.
- Sign-in providers. Where Google or Apple sign-in is used, the provider learns that you signed in to Perpetory. It receives no financial data.
The early-access list
Perpetory has not launched. The form on the home page joins a pre-launch list, and it is the only thing on this site that collects anything about someone who is not a customer - so it is set out here in full rather than folded into the paragraphs above.
What is stored
- Your email address. That is the point of the list.
- How many companies you run, if you answer the optional question after joining - as one of four ranges, never a name or a figure.
- Which button you joined from (the hero, the demo, the pricing section), so we know which part of the page is doing the work.
Not your browser, and not your IP address alongside your entry. Nothing in the row above identifies a machine. “We needed it to stop abuse” is how a short list of stored data stops being short, so here is exactly what abuse control does instead, rather than a claim that it costs nothing:
- A hidden field that only automated software fills. It keeps nothing.
- A rate limit, counted against a one-way hash of your IP address in a separate table from the list. The counter is a number, it cannot be turned back into an address, it is not linked to your entry, and it is deleted within the hour.
- A bot check on the form, which sends your IP address to Cloudflare to score and gets back a yes or no. Your email address is never part of that request. It is listed in the table below.
What we do with it
We send you one confirmation email, and then one email when your spot opens. That is the whole plan. If it ever becomes more than that - a note before launch, say - it will be something you can decline in the email itself, and this paragraph will change before the first one is sent rather than after.
The confirmation exists so the list is made of addresses whose owners asked for them. Until you click it, nothing else is ever sent.
Getting off it
Every email carries an unsubscribe link and our postal address. You can also write to contact@perpetory.com and ask us to delete the entry; there is one row, and deleting it is immediate and complete. Joining the list does not create an account, and the list is not connected to the account you might later open.
Who processes your data on our behalf
These are our sub-processors: the companies that handle data for us so the product can work. Naming them, and where they are, is the point of the list - a policy that says “trusted third parties” tells you nothing.
| Provider | What it does | Where |
|---|---|---|
| Microsoft Azure | Application hosting and the managed database holding your data | United States |
| Azure OpenAI | Categorization and the written analysis. Runs in our own Azure subscription and receives transaction text stripped of anything that identifies you | United States |
| Cloudflare | DNS, TLS termination and denial-of-service protection | Global edge; nothing is stored there |
| Stripe | Card payments and billing. Holds your card; we never see it | United States |
| Microsoft Azure (Functions, Table Storage) | Runs the early-access list and stores it. Holds an email address, an optional company-count range and which button you joined from - no financial data ever reaches it | United States |
| Our mail server | Sends the confirmation email for the early-access list, and the one message when a spot opens. Receives an email address and nothing else | United States |
| Cloudflare Turnstile | Checks that the early-access form was submitted by a person. Receives your IP address and a token from the widget - not your email address | Global edge |
Cloudflare is listed as global on purpose. It terminates TLS at whichever edge is nearest you, so a connection from Europe is decrypted in Europe before reaching a US origin. Nothing is stored there; everything we keep is kept in the United States.
Categorization, and what the model sees
Some categorization and the written analysis use a language model. It runs in our own Azure subscription in the United States - not a third-party API, and not a shared service. Your prompts are never training data for anyone’s model.
The model is not given anything that identifies you. It receives the text of a transaction and the figures it needs to reason about, with the identity stripped out first: no name, no email address, no account or card number, no bank, no entity name, no balances that could be matched back to you. It sees “AWS · infrastructure” and a number. It does not see whose.
That design is deliberate rather than incidental. Microsoft’s abuse monitoring can store a prompt that its systems flag, for review, and Microsoft does not publish how long it is kept. That is precisely why the identity is removed before anything is sent - so the most that could ever sit in such a store is a merchant name, detached from any person.
How long we keep it
While your account is open we keep what you put into it, in full. There is no rolling window that quietly discards last year’s transactions - a multi-year view of real cash flow is the product, so trimming history to shorten a retention line would break the thing you are paying for.
Retention ends when the account does. However the account ends, that starts the clock, and Data & deletion states the exact timings, including how far the encrypted backups lag behind the live record.
The one exception is billing records: charges, refunds, the sales tax on them and the receipts we issued, with the name and email they were issued to. Tax and accounting law requires us to keep these after the account is gone, for as long as that law requires. They hold nothing from your statements.
Your California privacy rights
If you are a California resident, the CCPA as amended by the CPRA gives you the rights below. We honor them for every customer rather than checking which state you are in first, because the mechanics are the same either way and asking would be sillier than just doing it.
- Know and access. See what we hold and get a copy. That is the export described in Data & deletion - all of it, in CSV and JSON, on demand and without asking us.
- Delete. Have it erased, from your account settings or by email. The timings, including what happens to backups, are on the same page.
- Correct. Fix anything inaccurate. Most of it is editable in the app directly; write to us for anything that is not.
- Non-discrimination. Exercising any of these does not change your price or degrade the product. There is one plan and one price.
We do not sell your personal information, and we do not share it in the sense the CPRA uses that word - no cross-context behavioral advertising, no data brokers, no advertising networks. There is no opt-out to offer you because there is nothing to opt out of.
Financial information is treated as sensitive, because it is. We use it only to provide the product you are paying for - importing, categorizing, and computing the figures you asked for - and never for any secondary purpose, profiling for someone else’s benefit, or inference we then sell.
To exercise any of these, use the app or write to contact@perpetory.com. An authorized agent may act for you; we will ask for reasonable proof that they are authorized.
Where the service is offered
Perpetory is offered to residents of the United States. The product is built around US banks, US entity structures and dollar amounts, and it is not directed at the European Union, the European Economic Area or the United Kingdom.
We say this plainly rather than staying quiet about it, because a policy that implies a GDPR posture nobody has built is worse than one that states its limits. If that changes, this policy changes first.
Contact
Privacy questions and data requests go to contact@perpetory.com.