Privacy
Privacy policy
The short version: financial data stays on our infrastructure, and no financial value or personal detail is ever sent to a third party — analytics included.
Read this alongside Data & deletion, which covers what is stored and how to get it out or have it erased, andSecurity, which covers how it is held.
What holds today
- No third-party financial data sharing. Statement contents, balances, categories and projections are never transmitted to an analytics provider, an advertising network or a data broker.
- Analytics are usage-only and self-hosted. Umami runs on our own infrastructure and records events such as
imported_statementorviewed_goal— that an action happened, never the amounts involved. - No bank credentials, ever. There is no bank login field and no aggregation feed, so there is no standing access to hold.
- Sign-in providers. Where Google or Apple sign-in is used, the provider learns that you signed in to Perpetory. It receives no financial data.
To confirm before publishing
OPEN-02Which sub-processors are in scope, and where is each located?
Hosting, managed database, transactional email, payment processor, and the AI
provider if categorisation runs through a model. Each needs naming, and the
AI one needs care: the product privacy promise rests on prompts staying
inside our own tenant.
OPEN-02Does statement content ever reach a model for categorisation, and if so which and where?
This is the sharpest question on the page. If categorisation is rules-only
today, say so. If a model is involved, say whose, in which tenant, and
whether it is aggregates or raw rows.
OPEN-02CCPA/CPRA applicability, and whether a GDPR position is needed at launch.
The stated market is US owner-operators. If EU users are not accepted at
launch, saying so is simpler than claiming a compliance posture that has not
been built.
OPEN-02Retention period for account and transaction data on an active account.
Contact
Privacy questions and data requests go tohello@perpetory.com.