1. Who we are
Perkival ("we", "us") provides a browser extension and the required account service that track credit-card benefits, credits, and signup bonuses. Operator and legal entity: [entity name and address — to be completed before launch]. Contact: [privacy contact address — to be confirmed].
2. The short version of the architecture
The extension captures your card benefits on your device, by reading the responses your own browser receives while you are signed in to your bank's website. We never receive, store, or transmit your bank credentials or session, and we never log in to your bank from our systems. This is an architectural property of the product, not just a policy statement — see the trust & security page for the full technical description.
3. What data we process, and why
| Data | Where it lives | Purpose |
|---|---|---|
| Your benefits wallet — cards you hold (product name, masked card number, account-owner label), credits and benefits (amounts, used/remaining, cycles, reset dates), usage history, loyalty point balances, your settings | Our servers, encrypted in transit (TLS) and at rest, isolated per user. Captured on your device, then sent to your account. | Showing your benefits dashboard, reminders, and exports. |
| Account identity — your sign-in email or Apple/Google identity | Our servers, encrypted in transit (TLS) and at rest, isolated per user. | Authenticating you and showing the same wallet on any device you sign in from. |
| Waitlist email (only if you submit it on this site) | Our servers. | Contacting you about beta access. Nothing else. |
| This website | — | perkival.com is a static site. It sets no cookies and runs no analytics or third-party trackers. |
4. What we never collect
- Your bank or card-issuer username, password, or one-time codes.
- Your bank session cookies or tokens.
- Your full card numbers (only the last digits are parsed, to tell cards apart).
- Your bank transactions or statements.
5. Telemetry and diagnostics
The extension includes an opt-in diagnostics channel that is off by default. You control it in Settings → Privacy (“Share anonymous diagnostics”). While it is off, the extension collects and sends nothing — no diagnostics are even stored on your device.
If you turn it on, the extension sends us anonymous, aggregate counts that help us catch card-issuer page changes early: how often a sync starts, succeeds, or fails (including signed-out syncs and per-card-issuer failures), how long syncs take, and a signal when an issuer page loads with nothing to read, and one-per-install counts of the setup milestones you reach (installed, first sync, first credit found, issuer connected, annual review opened). These carry no account data and no identifiers — no names, card numbers, balances, amounts, dates, or account tokens.
You can turn diagnostics off at any time; when you do, we stop collecting and any counts buffered on your device are discarded. The diagnostics endpoint is our own backend (the same service that hosts your account) — a real, live production endpoint. While diagnostics are off, nothing is sent; we only receive the anonymous, aggregate counts described above once you turn diagnostics on.
6. Sharing
We do not sell personal data, we do not run advertising, and we do not share your data with data brokers. Your account data is processed by the infrastructure providers that host our service (e.g., database and server hosting) under data-processing agreements; they process it on our instructions only. We would disclose data if legally compelled to, and would tell you unless prohibited.
7. Retention
- Device-local app settings: stay on your device until you clear them (Settings → clear data) or uninstall the extension. Our servers never receive them.
- Your account data: kept while your account exists. When you delete your account, your user record and all synced data are deleted; deletion is implemented as a first-class operation in our backend (idempotent and confirmation-protected). Residual copies in encrypted backups expire on the backup rotation schedule of [retention window — to be set before launch].
- Waitlist emails: kept until you're onboarded or you ask to be removed, whichever is first.
8. Your rights (access, export, deletion)
- Export: your data is exportable from the product itself — CSV or Excel (.xlsx).
- Deletion: delete your Perkival account and all its data with the in-product account-deletion control; you can also request deletion by contacting us. Clearing your device's local app settings is a separate control in Settings.
- Access & correction: contact [privacy contact address] and we will respond within 30 days.
Depending on where you live (e.g., EEA/UK GDPR, California CPRA), you may have additional statutory rights; we honor deletion and access requests regardless of jurisdiction. [Counsel: confirm jurisdictional language, legal bases, and international-transfer wording before launch.]
9. Security
Synced data is treated as sensitive financial information: TLS in transit, encryption at rest, per-user row isolation, least-privilege access, and identifiers masked out of logs and metrics. The deepest security control remains architectural: the most damaging secrets — your bank credentials — are never in our systems at all.
10. Children
Perkival is a financial tool for adults who hold credit cards. It is not directed at children, and we do not knowingly collect data from anyone under 18.
11. Changes to this policy
This is a draft and will change at least once before launch (see the banner). Once in force, material changes will be announced in the product and on this page with a new effective date, before they take effect.