Privacy

Privacy policy

The short version: financial data stays on our infrastructure, and no financial value or personal detail is ever sent to a third party — analytics included.

Read this alongside Data & deletion, which covers what is stored and how to get it out or have it erased, andSecurity, which covers how it is held.

What holds today

  • No third-party financial data sharing. Statement contents, balances, categories and projections are never transmitted to an analytics provider, an advertising network or a data broker.
  • Analytics are usage-only and self-hosted. Umami runs on our own infrastructure and records events such asimported_statement or viewed_goal — that an action happened, never the amounts involved.
  • No bank credentials, ever. There is no bank login field and no aggregation feed, so there is no standing access to hold.
  • Sign-in providers. Where Google or Apple sign-in is used, the provider learns that you signed in to Perpetory. It receives no financial data.

To confirm before publishing

OPEN-02Which sub-processors are in scope, and where is each located?

Hosting, managed database, transactional email, payment processor, and the AI provider if categorisation runs through a model. Each needs naming, and the AI one needs care: the product privacy promise rests on prompts staying inside our own tenant.

OPEN-02Does statement content ever reach a model for categorisation, and if so which and where?

This is the sharpest question on the page. If categorisation is rules-only today, say so. If a model is involved, say whose, in which tenant, and whether it is aggregates or raw rows.

OPEN-02CCPA/CPRA applicability, and whether a GDPR position is needed at launch.

The stated market is US owner-operators. If EU users are not accepted at launch, saying so is simpler than claiming a compliance posture that has not been built.

OPEN-02Retention period for account and transaction data on an active account.

Contact

Privacy questions and data requests go tohello@perpetory.com.