Privacy Policy
PerpBrief · https://perpbrief.com Operated by PerpBrief · Effective date: September 1, 2026 · Last updated: September 1, 2026
This Privacy Policy explains what personal data we collect when you use PerpBrief (the "Service"), why we collect it, who we share it with, how long we keep it, and the rights you have over it. It applies whenever you visit our website or use the Service, whether or not you hold an account. Please read it together with our Terms of Use and our Risk & No-Advice Disclaimer, which govern your use of the Service itself.
1. Who We Are
PerpBrief is operated from the Cayman Islands. For the purposes of the Cayman Islands Data Protection Act (As Revised) (the "DPA"), and where the EU or UK General Data Protection Regulation ("GDPR") applies to you, we are the data controller of the personal data described in this Policy. For our full corporate details — legal entity name, company registration number, and registered office — contact legal@perpbrief.com.
You can reach us about anything in this Policy at privacy@perpbrief.com. For general questions about the Service, contact support@perpbrief.com.
2. Scope of This Policy
This Policy covers personal data we process through the PerpBrief website and Service. It does not cover:
- Public blockchains. Deposits made in connection with paid plans occur on public blockchain networks that no one, including us, controls. Section 7 explains what that means for you.
- Third-party services you choose to use with us. If you link Telegram for alerts, Telegram processes your data under its own privacy policy. The same goes for your email provider, browser, and wallet software.
- Market data. The Service is built on aggregated market data from independent third-party data providers. That data concerns markets, exchanges, and pseudonymous on-chain activity — it is not data about you, and it is not collected from you.
3. Information We Collect
We aim to collect the minimum needed to run the Service. We do not perform identity verification (KYC), and we deliberately never ask for the categories listed in section 3.4.
3.1 Information you give us
- Account data: your email address, a display name, and — only if you choose to set one — a password. We process your email address to send the single-use sign-in codes that create your account and log you in; a password is optional and set from your account settings. Any password you set is stored only as a cryptographic hash by our authentication provider; we never see or store it in plaintext. (Updated 2026-09-02.)
- Settings and preferences: your watchlist, theme, dashboard layouts, and other preferences you configure.
- Alert preferences: which alerts you enable and how you want them delivered.
- Telegram data (only if you link it): if you choose to connect a Telegram bot for alerts, we store your Telegram chat ID and username. You can disable or unlink Telegram at any time, and we delete or disable that channel data when you do.
- Support correspondence: messages you send us, and our replies.
3.2 Billing data (where paid plans are offered and you use them)
- The unique deposit addresses we assign to your account;
- transaction hashes and amounts observed on public blockchains that relate to your deposits;
- your prepaid credit balance and a ledger of charges; and
- your plan status and history.
3.3 Technical and usage data
- Log data: our hosting and delivery providers process technical data such as your IP address and browser user agent at the platform level in order to serve the site, keep it secure, and defend against abuse.
- Bot-defense data: requests that send an email to an address nobody has yet proven they control — a sign-in code, a new account, or a password reset — run a human-verification check operated by Cloudflare (Turnstile). Cloudflare receives your IP address and browser characteristics so it can decide whether a request is automated. The check runs on those endpoints only. Section 5 covers any storage it uses on your device. (Added 2026-09-02.)
- Analytics data: we use Google Analytics 4, deployed through Google Tag Manager, to understand how the Service is used in aggregate — pages visited, how you arrived, approximate region, and device and browser type. We do not tag individual features or in-app actions. Section 5 covers the cookies involved and your choices.
3.4 What we do not collect
We do not collect government identification documents (we currently perform no KYC), payment card data, precise geolocation, exchange API keys, or wallet private keys. The Service never asks for access to your wallets or exchange accounts. We do not sell personal data. We run no advertising technology; if we ever do, nothing will be stored on or read from your device for advertising until you have separately consented to it, and section 5.4 sets out what else has to happen first. (Updated 2026-09-02.)
4. How We Use Your Data and Our Legal Bases
We process personal data under the DPA and, where the GDPR applies to you, on the legal bases it recognizes. In summary:
| Purpose | Data used | Legal basis |
|---|---|---|
| Creating and operating your account; signing you in; providing the Service and its features | Account data, settings and preferences | Performance of a contract |
| Processing deposits, maintaining your prepaid credit ledger, operating plan activation, renewal, and lapse | Billing data | Performance of a contract; legal obligation (financial record-keeping) |
| Sending service and billing notices (renewal, low balance, grace period, security notices) | Account data, billing data | Performance of a contract |
| Delivering market alerts you have enabled, via Telegram | Alert preferences, Telegram chat ID and username | Performance of a contract; consent (for the Telegram channel you link) |
| Responding to support requests | Support correspondence, account data | Performance of a contract; legitimate interests |
| Securing the Service, preventing fraud and abuse, investigating misuse, and verifying that requests to the endpoints reachable without an account come from a person rather than a bot | Log data, bot-defense data, account data, billing data | Legitimate interests; legal obligation |
| Understanding aggregate usage to improve the Service | Analytics data | Consent (where required, such as in the EEA and UK); otherwise legitimate interests |
| Complying with law, responding to lawful requests, and establishing or defending legal claims | Any of the above, as relevant | Legal obligation; legitimate interests |
Transactional service messages — including renewal, low-balance, and grace-period notices — are part of operating your account. You cannot opt out of them while your account holds a paid plan or a prepaid credit balance. You can always opt out of non-essential communications.
5. Cookies, Analytics, and Advertising
Cookies are small text files a website stores in your browser to remember state between visits; browsers also offer local storage, which serves a similar purpose without being sent with every request. This section covers both.
5.1 What we use today
Here is everything stored on your device when you use the Service:
| Name | Set by | Purpose | Category | Duration |
|---|---|---|---|---|
| Sign-in session | Us, on our domain | Keeps you signed in to your account. Stored in your browser's local storage rather than as a cookie. | Strictly necessary | Until you sign out or the session expires |
| Your cookie choice | Us, through Google Tag Manager, on our domain | Remembers the choice you made in our cookie banner, so we do not ask again on every page. Stored in your browser's local storage, not as a cookie. | Strictly necessary | Until you change your choice or clear your browser storage; it does not expire |
_ga |
Google, on our domain | Google Analytics 4: distinguishes visitors for aggregate usage statistics | Analytics | 2 years from your most recent visit |
_ga_0349G5F5PP |
Google, on our domain | Google Analytics 4: maintains session state for our property | Analytics | 2 years from your most recent visit |
| Turnstile challenge storage | Cloudflare, on challenges.cloudflare.com |
Runs and records the human-verification check on our sign-in-code, signup and password-reset requests. Cloudflare sets this in its own domain's storage, not ours | Strictly necessary | Short-lived; see Cloudflare's Turnstile privacy notice |
That is the whole list.
We deploy analytics through Google Tag Manager (container GTM-NC3DNLLM). Tag Manager is a loading mechanism and sets no cookies of its own; everything it loads is in the table above.
Turnstile loads a script from challenges.cloudflare.com, so Cloudflare receives your IP address and browser characteristics for that request. It is a security control, not a measurement one.
5.2 Consent
Consent. Where the law requires consent for analytics cookies — including in the EEA and the UK — they load only after you have given it. The strictly necessary entries — the sign-in session, the record of your own cookie choice, and the human-verification check — do not require consent, because the Service does not work without them.
We ask before anything non-essential is stored or read. The choice is granular: you can accept one category and refuse another, and refusing is as easy as accepting. The Service is identical either way, and no part of it sits behind a cookie wall. Continuing to browse, scrolling, or ignoring the banner is not consent.
We pass your choice to Google through Google Consent Mode. Consent Mode carries separate signals for analytics storage and for three advertising categories. The banner offers you no advertising choice, because there is nothing to choose: the advertising signals are denied unconditionally, no choice available to you today can grant them, and accepting analytics does not and cannot set them.
Withdrawing. You can change or withdraw your choice at any time from the "Your Privacy Choices" link in the site footer, which stays as easy to reach as the banner that first asked. Withdrawal takes effect immediately. It does not undo processing that already happened.
5.3 Your choices
Beyond the consent controls in section 5.2, you can block or delete cookies through your browser controls and install Google's Analytics opt-out browser add-on. We have not enabled Google's advertising features inside Google Analytics, so nothing we collect feeds ad personalization.
Blocking analytics does not affect your use of the Service. Blocking the human-verification check does affect it: the check fails closed, so you will not be able to request a sign-in code, create an account, or reset your password until you allow challenges.cloudflare.com. Signing in with a password you have already set is unaffected.
Google describes its own processing at https://policies.google.com/privacy, and Cloudflare describes Turnstile's at https://www.cloudflare.com/turnstile-privacy-policy/.
5.4 Advertising and remarketing — not in use today
We run no advertising technology. There is no Google Ads tag, no Meta Pixel, no remarketing tag, no conversion tracking, and no advertising cookie of any kind on this site. Nothing in section 5.1 is read by an advertising network.
We may want to advertise the Service in future. This section names what we would use and what has to happen first. It describes nothing that is running now, and it is not consent you are giving now. Whatever we added would run on our public marketing pages. The one exception is the signup-completion step, where a conversion tag has to fire for an ad click to be attributed at all; if we used one there, it would report that a signup happened and nothing else. No advertising tag would run anywhere else behind sign-in, and none would ever carry a parameter describing your positions, balances, watchlist, plan, or account.
If we advertise, we expect to use Google's advertising products (conversion tracking and remarketing) and the Meta Pixel. Those set cookies of their own. None of the following are set today; this table is here so that switching one on is a disclosure, not a surprise:
| Name | Set by | Purpose | Category | Duration |
|---|---|---|---|---|
_gcl_au |
Google, on our domain | Conversion Linker: stores an ad-click identifier so a signup can be attributed to an ad | Advertising — not set | 90 days |
_gcl_aw |
Google, on our domain | Stores Google Ads click information | Advertising — not set | 90 days |
IDE |
Google, on doubleclick.net |
Ad targeting, frequency capping, and measurement | Advertising — not set | 13 months in the EEA and UK; up to 24 months elsewhere |
test_cookie |
Google, on doubleclick.net |
Checks whether your browser accepts cookies | Advertising — not set | 15 minutes |
_fbp, _fbc |
Meta, on our domain | Browser identifier and stored ad-click identifier, used to attribute a signup to a Meta ad | Advertising — not set | 90 days |
fr |
Meta, on facebook.com |
Ad delivery, measurement, and frequency capping | Advertising — not set | 90 days |
Before any of that is switched on, all of the following happen, in this order:
- This section and the table in section 5.1 are rewritten in the present tense, naming the contracting vendor entity, what each tag collects, and the transfer mechanism it relies on.
- The effective date at the top of this Policy changes.
- We notify you directly — by email to the address on your account, in a message about this change and nothing else — before it takes effect, because an advertising network is a new recipient of your personal data and, in most cases, a new transfer of it.
- The consent banner gains a separate advertising category, off by default, and we do not rely on legitimate interests for advertising in any jurisdiction. Every consent record that already exists is treated as carrying no choice for that category, whatever it says — including one created by an "accept all" button that predates the category — so the advertising signals stay denied for everyone until each person makes a new, affirmative choice on a control that names advertising. The tags fire only for people who have made that choice. Consent to analytics is not consent to advertising, and consent given to an earlier version of this Policy is not consent to this one.
Joint control. An advertising vendor is not a plain processor working to our instructions. With the Meta Pixel, Meta and we would be joint controllers for the data it captures and its transmission to Meta, and you could exercise your rights against either of us.
Google Signals. If we enabled Google's advertising features inside Google Analytics — remarketing audiences, Google Signals, demographics and interests — the first-party analytics cookies in section 5.1 would be read alongside Google's own advertising cookies, and data about you could be associated with your Google account. That is not the aggregate measurement described in section 3.3. It would go through the same four steps, and the consent you had already given to analytics would not carry it: we would ask again, for that specifically, and it would apply only from the day it was switched on, never to analytics data collected before.
We do not maintain a separate cookie policy; section 5 is our complete statement on cookies, analytics, and advertising technology. (Updated 2026-09-02.)
6. Who We Share Data With
We do not sell personal data. We share it only in the following cases.
6.1 Service providers (processors)
We use a small number of infrastructure providers that process personal data on our instructions:
| Provider | Role | Location |
|---|---|---|
| Cloud infrastructure provider | Database, authentication, and backend functions | United States |
| Web hosting provider | Web hosting and content delivery | United States / global |
| Analytics (Google Analytics 4) and tag management (Google Tag Manager) | United States / global | |
| Cloudflare | Turnstile human-verification checks on the endpoints reachable without an account | United States / global edge network |
| Telegram | Alert delivery — only if you link a Telegram bot to your account | Per Telegram's own infrastructure |
| Email delivery provider | Transactional email delivery (service and billing notices) | United States |
| Blockchain infrastructure API providers | Reading public blockchain data so we can detect deposits to the addresses we assign | Various |
Each provider is engaged under terms restricting its use of the data to the service it performs for us. Telegram is the exception: where you link it, Telegram acts under its own privacy policy rather than solely on our instructions, as section 2 explains. (Updated 2026-09-02.)
6.2 Legal and safety disclosures
We may disclose personal data where we reasonably believe it is required by law, regulation, legal process, or a governmental request; to enforce our Terms of Use; or to protect the rights, safety, or property of our users, the public, or ourselves.
6.3 Business transfers
If we are involved in a merger, acquisition, reorganization, or sale of assets, personal data may transfer as part of that transaction. We will require the recipient to honor commitments materially consistent with this Policy.
6.4 Access by our own personnel
Authorized personnel can view account, plan, deposit, and balance data where needed for support, operations, and fraud prevention. Access is restricted on a least-privilege basis, and any adjustment to an account balance is logged together with a recorded reason.
7. On-Chain Data Is Public
If you make deposits in connection with a paid plan, understand what a public blockchain means for your privacy:
- Blockchain transactions are recorded on public networks, permanently visible to anyone, and outside anyone's control — including ours. Nothing on a public blockchain can be edited, hidden, or deleted, by us or by anyone else.
- The deposit addresses we assign to your account are, once used, publicly and permanently linked to the transactions sent to them. Anyone observing the blockchain can connect those transactions to each other, and potentially to other addresses you have used.
- Our records associating a deposit address with your account are private and held by us; the on-chain activity itself is not.
The erasure and deletion rights described in section 10 apply to the data we hold. They cannot apply to data recorded on a public blockchain, because no one has the technical ability to erase it.
8. International Transfers
We are a Cayman Islands company, and our infrastructure providers host data primarily in the United States. Your personal data will therefore be transferred to, and processed in, countries other than the one you live in.
Where we transfer personal data internationally, we do so in accordance with the transfer provisions of the DPA. Where the GDPR applies to you, we rely on appropriate safeguards with the providers that process your data — the EU–US Data Privacy Framework where a provider is certified under it, and standard contractual clauses or an equivalent lawful mechanism otherwise or in addition. Google and Cloudflare are United States companies operating global networks, so data reaches them wherever you are. Adding an advertising vendor would add a recipient and, in most cases, a further transfer; section 5.4 sets out the notice you would get first. You can ask us about the safeguards applicable to your data at privacy@perpbrief.com. (Updated 2026-09-02.)
9. How Long We Keep Data
| Data | Retention |
|---|---|
| Account data, settings, preferences, alert configuration | For the life of your account. When you close your account, your settings, watchlists, saved layouts and alert configuration are deleted |
| Billing data: deposit addresses, observed on-chain transaction records, prepaid credit and charge ledger, plan history | At least 5 years after account closure, for financial record-keeping, audit, reconciliation, and legal purposes |
| Telegram chat ID and username | Deleted or disabled when you unlink Telegram, and deleted when you close your account |
| Support correspondence | For the life of your account, and afterwards as needed to resolve the matter and keep records of it |
| Analytics data | 14 months in Google Analytics 4, after which Google deletes the event-level records; aggregate reporting totals persist |
| Bot-defense data | Per Cloudflare's stated retention for Turnstile |
When retention ends, we delete the data or anonymize it so it no longer identifies you.
Analytics data is the one thing closing your account does not reach. It is keyed to a cookie in your browser, not to your account, so we cannot find it by looking you up. Withdrawing consent stops it being collected; clearing your browser's cookies severs it from you. (Added 2026-09-02.)
Closing your account. You can close your account yourself, from Account → Close account. You can also ask us to do it by emailing privacy@perpbrief.com from the address on the account, which is the route to use if you cannot sign in.
Closing works the same way either way:
- Access ends immediately, and any remaining Prepaid Credit is forfeited — see Terms of Use section 11.
- For 30 days nothing is deleted. The account is deactivated and you can reverse the closure in full during that window, either from the same screen or by contacting us.
- After 30 days the closure becomes permanent, and one of two things happens. If your account has no billing history, we delete it outright — the account, your settings, preferences, saved layouts, alert configuration and any support correspondence all go, and nothing about you remains. If your account does have billing history, we delete all of that same data but keep the financial and on-chain transaction records described above for the retention period, and we erase your email address and name so those records no longer identify you. Your support correspondence is kept in that case, because it may still be needed to resolve or evidence the matter it concerns.
We say this plainly because it limits the erasure right described in section 10: where we keep financial records, we keep them, and anonymizing them is what we do instead of deleting them.
10. Your Rights
Subject to the conditions and exemptions in applicable law, you have the right to:
- Access the personal data we hold about you and receive a copy;
- Correct data that is inaccurate or incomplete;
- Erase your data — you can do this yourself at any time by closing your account (section 9), subject to the retention limits in that section (financial and on-chain transaction records are retained after account closure) and the technical reality in section 7 (public blockchain records cannot be erased by anyone);
- Object to or restrict certain processing, including any processing based on legitimate interests;
- Port data you provided to us in a structured, commonly used, machine-readable format, where that right applies;
- Withdraw consent at any time where processing is based on consent (for example, analytics cookies or the Telegram alert channel), without affecting processing that happened before withdrawal. Withdrawing is as easy as giving — see section 5.2.
To exercise any of these rights, email privacy@perpbrief.com. We may need to verify that you control the account before acting. We respond within 30 days. Exercising your rights is free of charge, though the law permits us to decline or charge for requests that are manifestly unfounded or excessive.
Complaints. If you are unhappy with how we handle your data or your request, you can complain to the Office of the Ombudsman of the Cayman Islands, our supervisory authority under the DPA. If the GDPR applies to you, you can also complain to the data protection authority in the country where you live or work. We would appreciate the chance to address your concern first, but you are not required to contact us before complaining.
11. Security
We take reasonable technical and organizational measures to protect personal data, proportionate to what we hold:
- Data is encrypted in transit.
- Database access is governed by row-level access controls, so account data is segregated per user.
- Internal access follows least privilege, and balance adjustments are logged with a recorded reason.
- We handle no payment card data at all.
- Deposit detection uses a watch-only architecture: our servers can observe public blockchain activity at the addresses we assign, but hold no private keys capable of moving funds.
No system is perfectly secure, and we do not promise that ours is an exception. If a breach of security affects your personal data, we will notify you and the relevant authorities as required by applicable law.
You play a part too: keep your password confidential, use a password unique to this Service, and tell us promptly at support@perpbrief.com if you suspect unauthorized access to your account.
12. Automated Decision-Making
The Bias Score and the Service's other analytics are computed from market data — aggregated exchange and blockchain activity — not from your personal data. We do not use personal data to make automated decisions that produce legal effects or similarly significant effects about you, and we build no behavioral profiles. (Updated 2026-09-02.)
13. Additional Information for California Residents
This section applies if you live in California and uses the definitions of the California Consumer Privacy Act as amended (the "CCPA"). We honor these rights whether or not the CCPA's thresholds apply to us.
Sale and sharing. Under the CCPA, "sale" and "share" do not require money to change hands: disclosing personal data to a third party for cross-context behavioral advertising is a "share" even when nothing is paid for it. In the twelve months before the date at the top of this Policy we have not sold or shared personal data, and we do not sell or share it today. We do not knowingly sell or share the personal data of anyone under 16. If we ever add the advertising technology described in section 5.4, that would be a "share", and this paragraph would say so plainly.
Opt-out preference signals. Because we do not sell or share personal data, there is nothing today for a browser-level opt-out signal to switch off. If we ever added the advertising technology described in section 5.4, we would publish a "Do Not Sell or Share My Personal Information" control at the "Your Privacy Choices" link in the site footer and honor the Global Privacy Control and equivalent browser-level signals — both working before the first tag fired. Honoring a browser signal does not replace offering you the control, so we would do both.
Your rights. You have the right to know what personal data we collect and what we do with it, to receive a copy of it, to correct it, to delete it, to opt out of sale or sharing, and to limit the use of sensitive personal information. Exercising them changes nothing about the Service you receive, the price you pay, or the tier you are on. Use the route in section 10; an authorized agent may act for you, and we may ask you to confirm that you authorized them.
Sensitive personal information. We do not use or disclose sensitive personal information for any purpose beyond those the CCPA permits without a right to limit.
Categories. What we collect, why, who receives it, and how long we keep it are in sections 3, 4, 6, and 9.
14. Children
The Service is not directed at anyone under 18, and we do not knowingly collect personal data from anyone under that age. If we learn that we hold personal data of someone under 18, we will delete it. If you believe this has happened, contact privacy@perpbrief.com.
15. Changes to This Policy
We may update this Policy as the Service, our providers, or the law change. When we do, we post the updated version at https://perpbrief.com with a new "Last updated" date. Each version is dated so you can tell what changed and when.
A new date on this page is not how we tell you about a material change. For material changes — and specifically for a new recipient of your personal data, a new category of cookie or similar storage, or a new transfer of your data to another country — we notify you directly, by email to the address on your account or through the Service, in a message about that change and nothing else, far enough in advance that you can act on it before it takes effect. Your continued use of the Service after an update takes effect means the update applies to our processing from that point on — but anything that requires your consent still requires you to give it, and we will never read continued use as consent. (Updated 2026-09-02.)
16. Contact Us
Privacy questions and requests: privacy@perpbrief.com General contact: support@perpbrief.com
Corporate details — legal entity name, registered office, and company registration number: legal@perpbrief.com