Privacy
Privacy policy
The short version: financial data stays on our infrastructure, and no financial value or personal detail is ever sent to a third party - analytics included.
Read this alongside Data & deletion, which covers what is stored and how to get it out or have it erased, and Security, which covers how it is held.
What holds today
- No third-party financial data sharing. Statement contents, balances, categories and projections are never transmitted to an analytics provider, an advertising network or a data broker.
- Analytics are usage-only and self-hosted. Umami runs on our own infrastructure and records events such as
imported_statementorviewed_goal- that an action happened, never the amounts involved. - No bank credentials, ever. There is no bank login field and no aggregation feed, so there is no standing access to hold.
- Sign-in providers. Where Google or Apple sign-in is used, the provider learns that you signed in to Perpetory. It receives no financial data.
Who processes your data on our behalf
These are our sub-processors: the companies that handle data for us so the product can work. Naming them, and where they are, is the point of the list - a policy that says “trusted third parties” tells you nothing.
| Provider | What it does | Where |
|---|---|---|
| Microsoft Azure | Application hosting and the managed database holding your data | United States |
| Azure OpenAI | Categorization and the written analysis. Runs in our own Azure subscription and receives transaction text stripped of anything that identifies you | United States |
| Cloudflare | DNS, TLS termination and denial-of-service protection | Global edge; nothing is stored there |
| Stripe | Card payments and billing. Holds your card; we never see it | United States |
Cloudflare is listed as global on purpose. It terminates TLS at whichever edge is nearest you, so a connection from Europe is decrypted in Europe before reaching a US origin. Nothing is stored there; everything we keep is kept in the United States.
To confirm before publishing
OPEN-02Transactional email: which provider, and where?
Categorization, and what the model sees
Some categorization and the written analysis use a language model. It runs in our own Azure subscription in the United States - not a third-party API, and not a shared service. Your prompts are never training data for anyone’s model.
The model is not given anything that identifies you. It receives the text of a transaction and the figures it needs to reason about, with the identity stripped out first: no name, no email address, no account or card number, no bank, no entity name, no balances that could be matched back to you. It sees “AWS · infrastructure” and a number. It does not see whose.
That design is deliberate rather than incidental. Azure may briefly retain a prompt for abuse monitoring, as any hosted model service does, which is precisely why the identity is removed before anything is sent - so the most that could ever sit in such a store is a merchant name, detached from any person.
Your California privacy rights
If you are a California resident, the CCPA as amended by the CPRA gives you the rights below. We honor them for every customer rather than checking which state you are in first, because the mechanics are the same either way and asking would be sillier than just doing it.
- Know and access. See what we hold and get a copy. That is the export described in Data & deletion - all of it, in CSV and JSON, on demand and without asking us.
- Delete. Have it erased, from your account settings or by email. The timings, including what happens to backups, are on the same page.
- Correct. Fix anything inaccurate. Most of it is editable in the app directly; write to us for anything that is not.
- Non-discrimination. Exercising any of these does not change your price or degrade the product. There is one plan and one price.
We do not sell your personal information, and we do not share it in the sense the CPRA uses that word - no cross-context behavioral advertising, no data brokers, no advertising networks. There is no opt-out to offer you because there is nothing to opt out of.
Financial information is treated as sensitive, because it is. We use it only to provide the product you are paying for - importing, categorizing, and computing the figures you asked for - and never for any secondary purpose, profiling for someone else’s benefit, or inference we then sell.
To exercise any of these, use the app or write to [email protected]. An authorized agent may act for you; we will ask for reasonable proof that they are authorized.
Where the service is offered
Perpetory is offered to residents of the United States. The product is built around US banks, US entity structures and dollar amounts, and it is not directed at the European Union or the United Kingdom.
We say this plainly rather than staying quiet about it, because a policy that implies a GDPR posture nobody has built is worse than one that states its limits. If that changes, this policy changes first.
OPEN-02Retention period for account and transaction data on an active account.
Contact
Privacy questions and data requests go to[email protected].