PerpBrief ← Back to app

Privacy Policy

PerpBrief · https://perpbrief.com Operated by PerpBrief · Effective date: September 1, 2026 · Last updated: September 1, 2026

This Privacy Policy explains what personal data we collect when you use PerpBrief (the "Service"), why we collect it, who we share it with, how long we keep it, and the rights you have over it. It applies whenever you visit our website or use the Service, whether or not you hold an account. Please read it together with our Terms of Use and our Risk & No-Advice Disclaimer, which govern your use of the Service itself.

1. Who We Are

PerpBrief is operated from the Cayman Islands. For the purposes of the Cayman Islands Data Protection Act (As Revised) (the "DPA"), and where the EU or UK General Data Protection Regulation ("GDPR") applies to you, we are the data controller of the personal data described in this Policy. For our full corporate details — legal entity name, company registration number, and registered office — contact legal@perpbrief.com.

You can reach us about anything in this Policy at privacy@perpbrief.com. For general questions about the Service, contact support@perpbrief.com.

2. Scope of This Policy

This Policy covers personal data we process through the PerpBrief website and Service. It does not cover:

3. Information We Collect

We aim to collect the minimum needed to run the Service. We do not perform identity verification (KYC), and we deliberately never ask for the categories listed in section 3.4.

3.1 Information you give us

3.2 Billing data (where paid plans are offered and you use them)

3.3 Technical and usage data

3.4 What we do not collect

We do not collect government identification documents (we currently perform no KYC), payment card data, precise geolocation, exchange API keys, or wallet private keys. The Service never asks for access to your wallets or exchange accounts. We do not sell personal data. We run no advertising technology; if we ever do, nothing will be stored on or read from your device for advertising until you have separately consented to it, and section 5.4 sets out what else has to happen first. (Updated 2026-09-02.)

4. How We Use Your Data and Our Legal Bases

We process personal data under the DPA and, where the GDPR applies to you, on the legal bases it recognizes. In summary:

Purpose Data used Legal basis
Creating and operating your account; signing you in; providing the Service and its features Account data, settings and preferences Performance of a contract
Processing deposits, maintaining your prepaid credit ledger, operating plan activation, renewal, and lapse Billing data Performance of a contract; legal obligation (financial record-keeping)
Sending service and billing notices (renewal, low balance, grace period, security notices) Account data, billing data Performance of a contract
Delivering market alerts you have enabled, via Telegram Alert preferences, Telegram chat ID and username Performance of a contract; consent (for the Telegram channel you link)
Responding to support requests Support correspondence, account data Performance of a contract; legitimate interests
Securing the Service, preventing fraud and abuse, investigating misuse, and verifying that requests to the endpoints reachable without an account come from a person rather than a bot Log data, bot-defense data, account data, billing data Legitimate interests; legal obligation
Understanding aggregate usage to improve the Service Analytics data Consent (where required, such as in the EEA and UK); otherwise legitimate interests
Complying with law, responding to lawful requests, and establishing or defending legal claims Any of the above, as relevant Legal obligation; legitimate interests

Transactional service messages — including renewal, low-balance, and grace-period notices — are part of operating your account. You cannot opt out of them while your account holds a paid plan or a prepaid credit balance. You can always opt out of non-essential communications.

5. Cookies, Analytics, and Advertising

Cookies are small text files a website stores in your browser to remember state between visits; browsers also offer local storage, which serves a similar purpose without being sent with every request. This section covers both.

5.1 What we use today

Here is everything stored on your device when you use the Service:

Name Set by Purpose Category Duration
Sign-in session Us, on our domain Keeps you signed in to your account. Stored in your browser's local storage rather than as a cookie. Strictly necessary Until you sign out or the session expires
Your cookie choice Us, through Google Tag Manager, on our domain Remembers the choice you made in our cookie banner, so we do not ask again on every page. Stored in your browser's local storage, not as a cookie. Strictly necessary Until you change your choice or clear your browser storage; it does not expire
_ga Google, on our domain Google Analytics 4: distinguishes visitors for aggregate usage statistics Analytics 2 years from your most recent visit
_ga_0349G5F5PP Google, on our domain Google Analytics 4: maintains session state for our property Analytics 2 years from your most recent visit
Turnstile challenge storage Cloudflare, on challenges.cloudflare.com Runs and records the human-verification check on our sign-in-code, signup and password-reset requests. Cloudflare sets this in its own domain's storage, not ours Strictly necessary Short-lived; see Cloudflare's Turnstile privacy notice

That is the whole list.

We deploy analytics through Google Tag Manager (container GTM-NC3DNLLM). Tag Manager is a loading mechanism and sets no cookies of its own; everything it loads is in the table above.

Turnstile loads a script from challenges.cloudflare.com, so Cloudflare receives your IP address and browser characteristics for that request. It is a security control, not a measurement one.

5.2 Consent

Consent. Where the law requires consent for analytics cookies — including in the EEA and the UK — they load only after you have given it. The strictly necessary entries — the sign-in session, the record of your own cookie choice, and the human-verification check — do not require consent, because the Service does not work without them.

We ask before anything non-essential is stored or read. The choice is granular: you can accept one category and refuse another, and refusing is as easy as accepting. The Service is identical either way, and no part of it sits behind a cookie wall. Continuing to browse, scrolling, or ignoring the banner is not consent.

We pass your choice to Google through Google Consent Mode. Consent Mode carries separate signals for analytics storage and for three advertising categories. The banner offers you no advertising choice, because there is nothing to choose: the advertising signals are denied unconditionally, no choice available to you today can grant them, and accepting analytics does not and cannot set them.

Withdrawing. You can change or withdraw your choice at any time from the "Your Privacy Choices" link in the site footer, which stays as easy to reach as the banner that first asked. Withdrawal takes effect immediately. It does not undo processing that already happened.

5.3 Your choices

Beyond the consent controls in section 5.2, you can block or delete cookies through your browser controls and install Google's Analytics opt-out browser add-on. We have not enabled Google's advertising features inside Google Analytics, so nothing we collect feeds ad personalization.

Blocking analytics does not affect your use of the Service. Blocking the human-verification check does affect it: the check fails closed, so you will not be able to request a sign-in code, create an account, or reset your password until you allow challenges.cloudflare.com. Signing in with a password you have already set is unaffected.

Google describes its own processing at https://policies.google.com/privacy, and Cloudflare describes Turnstile's at https://www.cloudflare.com/turnstile-privacy-policy/.

5.4 Advertising and remarketing — not in use today

We run no advertising technology. There is no Google Ads tag, no Meta Pixel, no remarketing tag, no conversion tracking, and no advertising cookie of any kind on this site. Nothing in section 5.1 is read by an advertising network.

We may want to advertise the Service in future. This section names what we would use and what has to happen first. It describes nothing that is running now, and it is not consent you are giving now. Whatever we added would run on our public marketing pages. The one exception is the signup-completion step, where a conversion tag has to fire for an ad click to be attributed at all; if we used one there, it would report that a signup happened and nothing else. No advertising tag would run anywhere else behind sign-in, and none would ever carry a parameter describing your positions, balances, watchlist, plan, or account.

If we advertise, we expect to use Google's advertising products (conversion tracking and remarketing) and the Meta Pixel. Those set cookies of their own. None of the following are set today; this table is here so that switching one on is a disclosure, not a surprise:

Name Set by Purpose Category Duration
_gcl_au Google, on our domain Conversion Linker: stores an ad-click identifier so a signup can be attributed to an ad Advertising — not set 90 days
_gcl_aw Google, on our domain Stores Google Ads click information Advertising — not set 90 days
IDE Google, on doubleclick.net Ad targeting, frequency capping, and measurement Advertising — not set 13 months in the EEA and UK; up to 24 months elsewhere
test_cookie Google, on doubleclick.net Checks whether your browser accepts cookies Advertising — not set 15 minutes
_fbp, _fbc Meta, on our domain Browser identifier and stored ad-click identifier, used to attribute a signup to a Meta ad Advertising — not set 90 days
fr Meta, on facebook.com Ad delivery, measurement, and frequency capping Advertising — not set 90 days

Before any of that is switched on, all of the following happen, in this order:

  1. This section and the table in section 5.1 are rewritten in the present tense, naming the contracting vendor entity, what each tag collects, and the transfer mechanism it relies on.
  2. The effective date at the top of this Policy changes.
  3. We notify you directly — by email to the address on your account, in a message about this change and nothing else — before it takes effect, because an advertising network is a new recipient of your personal data and, in most cases, a new transfer of it.
  4. The consent banner gains a separate advertising category, off by default, and we do not rely on legitimate interests for advertising in any jurisdiction. Every consent record that already exists is treated as carrying no choice for that category, whatever it says — including one created by an "accept all" button that predates the category — so the advertising signals stay denied for everyone until each person makes a new, affirmative choice on a control that names advertising. The tags fire only for people who have made that choice. Consent to analytics is not consent to advertising, and consent given to an earlier version of this Policy is not consent to this one.

Joint control. An advertising vendor is not a plain processor working to our instructions. With the Meta Pixel, Meta and we would be joint controllers for the data it captures and its transmission to Meta, and you could exercise your rights against either of us.

Google Signals. If we enabled Google's advertising features inside Google Analytics — remarketing audiences, Google Signals, demographics and interests — the first-party analytics cookies in section 5.1 would be read alongside Google's own advertising cookies, and data about you could be associated with your Google account. That is not the aggregate measurement described in section 3.3. It would go through the same four steps, and the consent you had already given to analytics would not carry it: we would ask again, for that specifically, and it would apply only from the day it was switched on, never to analytics data collected before.

We do not maintain a separate cookie policy; section 5 is our complete statement on cookies, analytics, and advertising technology. (Updated 2026-09-02.)

6. Who We Share Data With

We do not sell personal data. We share it only in the following cases.

6.1 Service providers (processors)

We use a small number of infrastructure providers that process personal data on our instructions:

Provider Role Location
Cloud infrastructure provider Database, authentication, and backend functions United States
Web hosting provider Web hosting and content delivery United States / global
Google Analytics (Google Analytics 4) and tag management (Google Tag Manager) United States / global
Cloudflare Turnstile human-verification checks on the endpoints reachable without an account United States / global edge network
Telegram Alert delivery — only if you link a Telegram bot to your account Per Telegram's own infrastructure
Email delivery provider Transactional email delivery (service and billing notices) United States
Blockchain infrastructure API providers Reading public blockchain data so we can detect deposits to the addresses we assign Various

Each provider is engaged under terms restricting its use of the data to the service it performs for us. Telegram is the exception: where you link it, Telegram acts under its own privacy policy rather than solely on our instructions, as section 2 explains. (Updated 2026-09-02.)

6.2 Legal and safety disclosures

We may disclose personal data where we reasonably believe it is required by law, regulation, legal process, or a governmental request; to enforce our Terms of Use; or to protect the rights, safety, or property of our users, the public, or ourselves.

6.3 Business transfers

If we are involved in a merger, acquisition, reorganization, or sale of assets, personal data may transfer as part of that transaction. We will require the recipient to honor commitments materially consistent with this Policy.

6.4 Access by our own personnel

Authorized personnel can view account, plan, deposit, and balance data where needed for support, operations, and fraud prevention. Access is restricted on a least-privilege basis, and any adjustment to an account balance is logged together with a recorded reason.

7. On-Chain Data Is Public

If you make deposits in connection with a paid plan, understand what a public blockchain means for your privacy:

The erasure and deletion rights described in section 10 apply to the data we hold. They cannot apply to data recorded on a public blockchain, because no one has the technical ability to erase it.

8. International Transfers

We are a Cayman Islands company, and our infrastructure providers host data primarily in the United States. Your personal data will therefore be transferred to, and processed in, countries other than the one you live in.

Where we transfer personal data internationally, we do so in accordance with the transfer provisions of the DPA. Where the GDPR applies to you, we rely on appropriate safeguards with the providers that process your data — the EU–US Data Privacy Framework where a provider is certified under it, and standard contractual clauses or an equivalent lawful mechanism otherwise or in addition. Google and Cloudflare are United States companies operating global networks, so data reaches them wherever you are. Adding an advertising vendor would add a recipient and, in most cases, a further transfer; section 5.4 sets out the notice you would get first. You can ask us about the safeguards applicable to your data at privacy@perpbrief.com. (Updated 2026-09-02.)

9. How Long We Keep Data

Data Retention
Account data, settings, preferences, alert configuration For the life of your account. When you close your account, your settings, watchlists, saved layouts and alert configuration are deleted
Billing data: deposit addresses, observed on-chain transaction records, prepaid credit and charge ledger, plan history At least 5 years after account closure, for financial record-keeping, audit, reconciliation, and legal purposes
Telegram chat ID and username Deleted or disabled when you unlink Telegram, and deleted when you close your account
Support correspondence For the life of your account, and afterwards as needed to resolve the matter and keep records of it
Analytics data 14 months in Google Analytics 4, after which Google deletes the event-level records; aggregate reporting totals persist
Bot-defense data Per Cloudflare's stated retention for Turnstile

When retention ends, we delete the data or anonymize it so it no longer identifies you.

Analytics data is the one thing closing your account does not reach. It is keyed to a cookie in your browser, not to your account, so we cannot find it by looking you up. Withdrawing consent stops it being collected; clearing your browser's cookies severs it from you. (Added 2026-09-02.)

Closing your account. You can close your account yourself, from Account → Close account. You can also ask us to do it by emailing privacy@perpbrief.com from the address on the account, which is the route to use if you cannot sign in.

Closing works the same way either way:

We say this plainly because it limits the erasure right described in section 10: where we keep financial records, we keep them, and anonymizing them is what we do instead of deleting them.

10. Your Rights

Subject to the conditions and exemptions in applicable law, you have the right to:

To exercise any of these rights, email privacy@perpbrief.com. We may need to verify that you control the account before acting. We respond within 30 days. Exercising your rights is free of charge, though the law permits us to decline or charge for requests that are manifestly unfounded or excessive.

Complaints. If you are unhappy with how we handle your data or your request, you can complain to the Office of the Ombudsman of the Cayman Islands, our supervisory authority under the DPA. If the GDPR applies to you, you can also complain to the data protection authority in the country where you live or work. We would appreciate the chance to address your concern first, but you are not required to contact us before complaining.

11. Security

We take reasonable technical and organizational measures to protect personal data, proportionate to what we hold:

No system is perfectly secure, and we do not promise that ours is an exception. If a breach of security affects your personal data, we will notify you and the relevant authorities as required by applicable law.

You play a part too: keep your password confidential, use a password unique to this Service, and tell us promptly at support@perpbrief.com if you suspect unauthorized access to your account.

12. Automated Decision-Making

The Bias Score and the Service's other analytics are computed from market data — aggregated exchange and blockchain activity — not from your personal data. We do not use personal data to make automated decisions that produce legal effects or similarly significant effects about you, and we build no behavioral profiles. (Updated 2026-09-02.)

13. Additional Information for California Residents

This section applies if you live in California and uses the definitions of the California Consumer Privacy Act as amended (the "CCPA"). We honor these rights whether or not the CCPA's thresholds apply to us.

Sale and sharing. Under the CCPA, "sale" and "share" do not require money to change hands: disclosing personal data to a third party for cross-context behavioral advertising is a "share" even when nothing is paid for it. In the twelve months before the date at the top of this Policy we have not sold or shared personal data, and we do not sell or share it today. We do not knowingly sell or share the personal data of anyone under 16. If we ever add the advertising technology described in section 5.4, that would be a "share", and this paragraph would say so plainly.

Opt-out preference signals. Because we do not sell or share personal data, there is nothing today for a browser-level opt-out signal to switch off. If we ever added the advertising technology described in section 5.4, we would publish a "Do Not Sell or Share My Personal Information" control at the "Your Privacy Choices" link in the site footer and honor the Global Privacy Control and equivalent browser-level signals — both working before the first tag fired. Honoring a browser signal does not replace offering you the control, so we would do both.

Your rights. You have the right to know what personal data we collect and what we do with it, to receive a copy of it, to correct it, to delete it, to opt out of sale or sharing, and to limit the use of sensitive personal information. Exercising them changes nothing about the Service you receive, the price you pay, or the tier you are on. Use the route in section 10; an authorized agent may act for you, and we may ask you to confirm that you authorized them.

Sensitive personal information. We do not use or disclose sensitive personal information for any purpose beyond those the CCPA permits without a right to limit.

Categories. What we collect, why, who receives it, and how long we keep it are in sections 3, 4, 6, and 9.

14. Children

The Service is not directed at anyone under 18, and we do not knowingly collect personal data from anyone under that age. If we learn that we hold personal data of someone under 18, we will delete it. If you believe this has happened, contact privacy@perpbrief.com.

15. Changes to This Policy

We may update this Policy as the Service, our providers, or the law change. When we do, we post the updated version at https://perpbrief.com with a new "Last updated" date. Each version is dated so you can tell what changed and when.

A new date on this page is not how we tell you about a material change. For material changes — and specifically for a new recipient of your personal data, a new category of cookie or similar storage, or a new transfer of your data to another country — we notify you directly, by email to the address on your account or through the Service, in a message about that change and nothing else, far enough in advance that you can act on it before it takes effect. Your continued use of the Service after an update takes effect means the update applies to our processing from that point on — but anything that requires your consent still requires you to give it, and we will never read continued use as consent. (Updated 2026-09-02.)

16. Contact Us

Privacy questions and requests: privacy@perpbrief.com General contact: support@perpbrief.com

Corporate details — legal entity name, registered office, and company registration number: legal@perpbrief.com