Skip to main content
Percher is still being built and account creation is paused — get notified when it opens.

Percher — Privacy Policy

Effective date: 10 September 2026 Version: 1.0.1

This Privacy Policy explains how Kaizensu AB, company registration number 559595-6359, processes personal data as controller when you use percher.app, percher.run, the Percher CLI, MCP server, API and dashboard (the Service).

It covers processing for which Kaizensu AB determines the purposes and means. For personal data in a customer's hosted Application (App Data: source code, environment-variable values, databases, files, build and crash logs, visitor statistics produced for the app owner, and Crash Diagnostics input and output) the customer normally determines the purposes and means, and Percher acts as processor under the Data Processing Agreement. The limited Account, billing, security and service metadata that Percher uses for its own purposes is controller processing described below.

1. Controller and contact

Kaizensu AB Kulvertkonstens väg 12 422 60 Hisings Backa, Sweden Email: legal@percher.app Support: support@percher.app

2. Data, purposes and legal bases

ProcessingPersonal dataPurpose and legal basis
Account and authenticationEmail, password hash, session and authentication recordsCreate, secure and administer the Account; contract (Art. 6(1)(b)) and legitimate interests in security (Art. 6(1)(f))
Service metadataDeployment identifiers, timestamps and status; build/crash event status; technical performance and error metadata; configuration metadata and support communications, excluding customer-provided content in App DataDeliver and support the Service; contract and legitimate interests in reliable operation
Security and abuseIP address, audit events, rate-limit and Turnstile signals, the anonymous-publish network identifier (a value derived on our server from the publisher's network prefix — IPv4 /24, IPv6 /56, never the address itself — using a key generated for that UTC date), abuse reports, optional reporter name/contact details and reported URLs/contentPrevent, detect and handle misuse; legitimate interests and, where applicable, legal obligation
Transaction administrationAccount email, plan, subscription and transaction identifiers; no full card detailsAdminister paid access, accounting and disputes; contract and legal obligation
Consumer withdrawal noticeName, Account email, plan and purchase description, optional order/subscription identifier, declaration, confirmed durable receipt form and receipt/confirmation timestampsReceive, acknowledge and administer withdrawal notices; legal obligation and legitimate interests in legal claims
Transactional emailEmail address and message contentAccount, security, deployment and service messages; contract and legitimate interests
CLI and local MCP telemetryClient and Bun version, CLI command or MCP tool name, success/error outcome, error type and operating-system/architecture family. MCP events can also contain a random per-process session identifier, a bounded schema-derived option summary, duration and a bounded outcome detailImprove compatibility, tool selection and reliability; legitimate interests. Opt out from either client with PERCHER_NO_TELEMETRY=1 (or true) or DO_NOT_TRACK=1
First-party Service statisticsCountry derived locally from IP; daily salted visitor identifier; device/browser/OS family; referrer hostname; reduced route shape; request method, status, response time and sizeMeasure aggregate traffic on Percher's own service hosts (percher.app, percher.run, api.percher.run, docs.percher.app and mcp.percher.app) for service operation and improvement, without tracking cookies; legitimate interests
WaitlistEmail and short-lived IP used for rate limitingSend the requested reopening notice: consent for email; legitimate interests for form security
Legal complianceRecords required for accounting, tax, legal claims or lawful authority requestsLegal obligation (Art. 6(1)(c)) and legitimate interests in legal claims

The Account email and the authentication data marked as required at registration are needed to enter into and perform the agreement; without them an Account cannot be created or used. Billing and transaction identifiers are required only for a paid plan. Other data is provided voluntarily or generated through use of the Service; without data needed for an optional feature or a support request, that feature or support may not be available.

Percher processes App Data only on the customer's documented instructions under the DPA. External AI crash analysis is currently switched off for the whole Service, and an Application's opt-in setting alone sends nothing to an external provider. If it is switched on again, Percher sends, for an Application whose owner has enabled Crash Diagnostics, a secret-scrubbed excerpt of the last 200 crash-log lines and technical context to Anthropic and returns the AI-generated output; the customer is then controller or processor, Percher processor or subprocessor, and Anthropic the next subprocessor in the chain. Environment-variable values are encrypted at rest. Passwords are stored only as hashes.

For hosted-Application statistics and first-party Service statistics, an IP address is used transiently on our server to derive a country and a daily salted identifier; the statistics record does not contain the IP. Query strings are discarded, identifiers and email-like path segments are replaced, and only the referrer hostname is kept; ordinary readable route segments can still contain data chosen by the app owner. For hosted-Application statistics the customer is controller or processor and Percher processor or subprocessor; for statistics on Percher's own service hosts, Kaizensu AB is controller.

We do not sell personal data, use it for targeted advertising or use customer source code to train AI models.

3. Recipients

ProviderUse and dataRole/location
Hetzner Online GmbHCore hosting, storage, network and backupsProcessor; Germany/Finland
Anthropic Ireland, Limited (Anthropic)Secret-scrubbed crash excerpt and technical context, only if external crash analysis is switched on again for the Service and enabled for the Application; nothing is sent while it is offSub-processor for App Data when active; contracting entity in Ireland, processing in the United States
Cloudflare, Inc.Turnstile interaction and network signals at sign-up, password reset and the public support-access form; DNS metadata for DNS-only authoritative DNS for percher.runProcessor for Turnstile protection and separate controller for improving its bot detection; DNS under its applicable terms; United States/global
Spaceship, Inc.Authoritative DNS metadata for percher.app; sender/recipient addresses and message content when you email our company contact addressesProcessor for hosted correspondence; separate account/registrar purposes under its Privacy Policy; United States/global
Plus Five Five, Inc. (Resend)Email address and transactional message, including withdrawal notices and receiptsProcessor or sub-processor, depending on message content; United States
Polar Software, Inc.Checkout, subscription, tax, invoicing and transaction dataMerchant of Record and independent controller for the sale; processor for limited Account Data where its DPA applies; United States
GitHub, Inc.Optional GitHub App/OAuth, repository and webhook data selected by the userIndependent user-selected service; United States/global

The current providers that may process customer App Data are listed in the Subprocessor Notice. We may also disclose data when required by law, to establish or defend legal claims, or as part of a corporate transaction subject to appropriate confidentiality and notice where required.

4. International transfers

Core application hosting is in the EEA. Some providers process limited data in the United States or globally. Where Chapter V GDPR applies, a provider is used only if the transfer is covered by an adequacy decision or by the European Commission's Standard Contractual Clauses in the provider's data-processing terms, with supplementary measures where required. Anthropic and Resend are used for transfers subject to Chapter V only while the terms or DPA applicable to Kaizensu AB's account incorporate the appropriate SCC module. We do not rely on a provider's general certification unless it covers the actual recipient and processing. Data is encrypted in transit.

The Standard Contractual Clauses are published by the European Commission, and each provider's data-processing terms are published on that provider's website. Contact legal@percher.app for information about the mechanism for a particular transfer.

5. Retention

DataNormal retention
Primary Account record and password hashUntil Account deletion and completion of the deletion process; residual backups up to 30 days
Source code, configuration, environment variables and deployment historyUntil the relevant Application or Account is deleted; residual backups up to 30 days
Crash logs and Crash Diagnostics90 days
Daily salted visitor identifier and saltNo more than 48 hours in the live database
Anonymous-publish network identifier and its daily keyIdentifier until the anonymous Application is claimed or removed, normally within 73 hours of creation; key until its UTC date is more than three days old and no anonymous Application still carries that date, normally four days; residual backups up to 30 days
Aggregate daily Application and first-party Service statistics400 days
CLI and local MCP telemetry365 days
Audit and authentication-security logs, which may contain limited Account identifiers90 days
Web-server access logs containing IPAt most 7 days
Waitlist emailUntil the notice is sent, consent is withdrawn or deletion is requested
Waitlist rate-limit IPAt most 2 hours
Abuse reportWhile the report is open, including under a documented legal hold. Reporter contact details, IP address, free-text details and the reported URL are removed 90 days after the report is dismissed or actioned, later only while a reporter notice is still pending or the reported Application remains suspended by us; the anonymised decision record is kept for transparency statistics; residual backups up to 30 days
Support case and attachmentsCase 24 months after resolution; attachments 90 days after resolution; residual backups up to 30 days
Dashboard Account sessionUp to 7 days per session, renewed during continued activity
Private-Application access sessionUp to 14 days; invalidated earlier if the Account or access is no longer valid
Accounting and transaction recordsFor the period required by law
Consumer withdrawal notice and receipt evidence10 years after receipt; longer only under an explicit time-bounded legal hold; residual backups up to 30 days

Deletion from backups occurs through the normal backup cycle. We may retain limited data where law requires it or a legal claim needs it. Account deletion removes a withdrawal notice's Account link but does not erase its contents before that retention period ends; download your receipt before deleting the Account.

6. Your rights

Subject to the GDPR, you may request access, correction, deletion, restriction, portability and objection. Where processing is based on consent, you may withdraw it without affecting earlier processing. You may object at any time to processing based on legitimate interests; we then stop unless we demonstrate overriding legitimate grounds or need the data for legal claims.

Send requests to legal@percher.app, from the Account email where possible. We may request proportionate identity verification and respond within the time the GDPR requires, normally one month.

You may complain to the Swedish Authority for Privacy Protection, Integritetsskyddsmyndigheten (IMY), imy.se, or the supervisory authority where you live or work.

7. Security and incidents

We use access controls, least privilege, TLS, encryption of stored environment-variable values and backups, tenant, container and network isolation, logging, secret scrubbing, rate limits and vulnerability management. No service is completely secure; customers remain responsible for their application code, credentials, access rules and lawful processing. We assess personal-data breaches and notify IMY and affected individuals where the GDPR requires it.

8. AI and automated decisions

Crash Diagnostics is optional AI-generated troubleshooting output that can be wrong and must be reviewed by the Account holder. External AI analysis is currently switched off for the whole Service; the active provider, if any, is shown in the Service. Percher does not use Crash Diagnostics or other automated processing to make decisions about individuals that produce legal or similarly significant effects.

9. Children

The Service is intended for persons aged 18 or over. Contact legal@percher.app if you believe a child has provided Account Data.

10. Cookies

We use authentication, security and access cookies and functional local storage, and no advertising cookies. See the Cookie Policy.

11. Changes and language

We may update this policy, give notice before a material change where required and show the current date above.

The English and Swedish versions are intended to have the same meaning. If they differ, the English version prevails. This does not limit rights under mandatory data-protection or consumer law.


*Last updated: 22 September 2026* *© 2026 Kaizensu AB — Percher, percher.app*