Trust & security
You're trusting a tool with a view of your financial life. You deserve specifics, not a badge that says "bank-grade encryption." This page is the specifics: what data exists, where it lives, what crosses the network, what happens when things go wrong, and the one risk we'd rather disclose than bury.
A free Perkival account is required to use the product — there's no account-free mode. Your derived benefit data lives in your account so it's available on any device you sign in from; your bank credentials and session stay on your device — always.
Signing in to your Perkival account is required to use the product; diagnostics are a separate, opt-in channel that stays off by default — while it's off, nothing about your app usage leaves your device.
Sign out and syncing stops. Delete your account and the data goes with it — see below.
We never log in as you, from anywhere. There is no server-side login code, no credential vault, and no "background refresh from our cloud." A tracker that stores your bank login on its servers is a breach honeypot; we chose an architecture where that class of breach is impossible for us to have.
There are no bank credentials or sessions to steal — nobody can log in to your bank with anything we hold. Your derived benefit data (cards, credits, history) could be exposed; that's still personal financial information, which is why it's encrypted at rest, isolated per user, and kept out of logs.
Your signed-in browser session lives on that machine. Protect it the way you protect the rest of your digital life: an OS account password and full-disk encryption (FileVault/BitLocker). You can also sign out of your Perkival account, or clear your device's local app settings, any time from Settings.
Perkival requires our servers and your account to show your dashboard — there's no offline-only mode. What we can promise instead: your data is exportable to open formats — CSV and Excel — any time, so it's never locked in and never hostage, even if you decide to leave.
The https://*.chase.com/* permission lets Perkival run on Chase pages the user opens. This describes site access, not card or feature coverage.
It cannot read your email, your other tabs, or any other site. Remote-config for parser fixes is data-only (selectors, never code), so an update of logic always goes through a store-reviewed release.
Perkival works by riding the authenticated session you opened with your bank — it reads data from your own browsing, on your own device. We think that is the most defensible way to build this category: no stored credentials, no server-side logins, no impersonating you from a data center. But we owe you the caveats:
On your device: Settings has a clear-data control that clears your local app settings in one click. On our servers: deleting your Perkival account removes your user record and every row of your synced wallet — deletion is implemented in the backend as a first-class, tested operation (idempotent, confirmation-protected), not a support-ticket promise. Details, retention periods, and your rights are in the privacy policy.