Effective date: 10 September 2026 Version: 1.0.1
This Privacy Policy explains how Kaizensu AB, company registration number 559595-6359, processes personal data as controller when you use percher.app, percher.run, the Percher CLI, MCP server, API and dashboard (the Service).
It covers processing for which Kaizensu AB determines the purposes and means. For personal data in a customer's hosted Application (App Data: source code, environment-variable values, databases, files, build and crash logs, visitor statistics produced for the app owner, and Crash Diagnostics input and output) the customer normally determines the purposes and means, and Percher acts as processor under the Data Processing Agreement. The limited Account, billing, security and service metadata that Percher uses for its own purposes is controller processing described below.
Kaizensu AB Kulvertkonstens väg 12 422 60 Hisings Backa, Sweden Email: legal@percher.app Support: support@percher.app
| Processing | Personal data | Purpose and legal basis |
|---|---|---|
| Account and authentication | Email, password hash, session and authentication records | Create, secure and administer the Account; contract (Art. 6(1)(b)) and legitimate interests in security (Art. 6(1)(f)) |
| Service metadata | Deployment identifiers, timestamps and status; build/crash event status; technical performance and error metadata; configuration metadata and support communications, excluding customer-provided content in App Data | Deliver and support the Service; contract and legitimate interests in reliable operation |
| Security and abuse | IP address, audit events, rate-limit and Turnstile signals, the anonymous-publish network identifier (a value derived on our server from the publisher's network prefix — IPv4 /24, IPv6 /56, never the address itself — using a key generated for that UTC date), abuse reports, optional reporter name/contact details and reported URLs/content | Prevent, detect and handle misuse; legitimate interests and, where applicable, legal obligation |
| Transaction administration | Account email, plan, subscription and transaction identifiers; no full card details | Administer paid access, accounting and disputes; contract and legal obligation |
| Consumer withdrawal notice | Name, Account email, plan and purchase description, optional order/subscription identifier, declaration, confirmed durable receipt form and receipt/confirmation timestamps | Receive, acknowledge and administer withdrawal notices; legal obligation and legitimate interests in legal claims |
| Transactional email | Email address and message content | Account, security, deployment and service messages; contract and legitimate interests |
| CLI and local MCP telemetry | Client and Bun version, CLI command or MCP tool name, success/error outcome, error type and operating-system/architecture family. MCP events can also contain a random per-process session identifier, a bounded schema-derived option summary, duration and a bounded outcome detail | Improve compatibility, tool selection and reliability; legitimate interests. Opt out from either client with PERCHER_NO_TELEMETRY=1 (or true) or DO_NOT_TRACK=1 |
| First-party Service statistics | Country derived locally from IP; daily salted visitor identifier; device/browser/OS family; referrer hostname; reduced route shape; request method, status, response time and size | Measure aggregate traffic on Percher's own service hosts (percher.app, percher.run, api.percher.run, docs.percher.app and mcp.percher.app) for service operation and improvement, without tracking cookies; legitimate interests |
| Waitlist | Email and short-lived IP used for rate limiting | Send the requested reopening notice: consent for email; legitimate interests for form security |
| Legal compliance | Records required for accounting, tax, legal claims or lawful authority requests | Legal obligation (Art. 6(1)(c)) and legitimate interests in legal claims |
The Account email and the authentication data marked as required at registration are needed to enter into and perform the agreement; without them an Account cannot be created or used. Billing and transaction identifiers are required only for a paid plan. Other data is provided voluntarily or generated through use of the Service; without data needed for an optional feature or a support request, that feature or support may not be available.
Percher processes App Data only on the customer's documented instructions under the DPA. External AI crash analysis is currently switched off for the whole Service, and an Application's opt-in setting alone sends nothing to an external provider. If it is switched on again, Percher sends, for an Application whose owner has enabled Crash Diagnostics, a secret-scrubbed excerpt of the last 200 crash-log lines and technical context to Anthropic and returns the AI-generated output; the customer is then controller or processor, Percher processor or subprocessor, and Anthropic the next subprocessor in the chain. Environment-variable values are encrypted at rest. Passwords are stored only as hashes.
For hosted-Application statistics and first-party Service statistics, an IP address is used transiently on our server to derive a country and a daily salted identifier; the statistics record does not contain the IP. Query strings are discarded, identifiers and email-like path segments are replaced, and only the referrer hostname is kept; ordinary readable route segments can still contain data chosen by the app owner. For hosted-Application statistics the customer is controller or processor and Percher processor or subprocessor; for statistics on Percher's own service hosts, Kaizensu AB is controller.
We do not sell personal data, use it for targeted advertising or use customer source code to train AI models.
| Provider | Use and data | Role/location |
|---|---|---|
| Hetzner Online GmbH | Core hosting, storage, network and backups | Processor; Germany/Finland |
| Anthropic Ireland, Limited (Anthropic) | Secret-scrubbed crash excerpt and technical context, only if external crash analysis is switched on again for the Service and enabled for the Application; nothing is sent while it is off | Sub-processor for App Data when active; contracting entity in Ireland, processing in the United States |
| Cloudflare, Inc. | Turnstile interaction and network signals at sign-up, password reset and the public support-access form; DNS metadata for DNS-only authoritative DNS for percher.run | Processor for Turnstile protection and separate controller for improving its bot detection; DNS under its applicable terms; United States/global |
| Spaceship, Inc. | Authoritative DNS metadata for percher.app; sender/recipient addresses and message content when you email our company contact addresses | Processor for hosted correspondence; separate account/registrar purposes under its Privacy Policy; United States/global |
| Plus Five Five, Inc. (Resend) | Email address and transactional message, including withdrawal notices and receipts | Processor or sub-processor, depending on message content; United States |
| Polar Software, Inc. | Checkout, subscription, tax, invoicing and transaction data | Merchant of Record and independent controller for the sale; processor for limited Account Data where its DPA applies; United States |
| GitHub, Inc. | Optional GitHub App/OAuth, repository and webhook data selected by the user | Independent user-selected service; United States/global |
The current providers that may process customer App Data are listed in the Subprocessor Notice. We may also disclose data when required by law, to establish or defend legal claims, or as part of a corporate transaction subject to appropriate confidentiality and notice where required.
Core application hosting is in the EEA. Some providers process limited data in the United States or globally. Where Chapter V GDPR applies, a provider is used only if the transfer is covered by an adequacy decision or by the European Commission's Standard Contractual Clauses in the provider's data-processing terms, with supplementary measures where required. Anthropic and Resend are used for transfers subject to Chapter V only while the terms or DPA applicable to Kaizensu AB's account incorporate the appropriate SCC module. We do not rely on a provider's general certification unless it covers the actual recipient and processing. Data is encrypted in transit.
The Standard Contractual Clauses are published by the European Commission, and each provider's data-processing terms are published on that provider's website. Contact legal@percher.app for information about the mechanism for a particular transfer.
| Data | Normal retention |
|---|---|
| Primary Account record and password hash | Until Account deletion and completion of the deletion process; residual backups up to 30 days |
| Source code, configuration, environment variables and deployment history | Until the relevant Application or Account is deleted; residual backups up to 30 days |
| Crash logs and Crash Diagnostics | 90 days |
| Daily salted visitor identifier and salt | No more than 48 hours in the live database |
| Anonymous-publish network identifier and its daily key | Identifier until the anonymous Application is claimed or removed, normally within 73 hours of creation; key until its UTC date is more than three days old and no anonymous Application still carries that date, normally four days; residual backups up to 30 days |
| Aggregate daily Application and first-party Service statistics | 400 days |
| CLI and local MCP telemetry | 365 days |
| Audit and authentication-security logs, which may contain limited Account identifiers | 90 days |
| Web-server access logs containing IP | At most 7 days |
| Waitlist email | Until the notice is sent, consent is withdrawn or deletion is requested |
| Waitlist rate-limit IP | At most 2 hours |
| Abuse report | While the report is open, including under a documented legal hold. Reporter contact details, IP address, free-text details and the reported URL are removed 90 days after the report is dismissed or actioned, later only while a reporter notice is still pending or the reported Application remains suspended by us; the anonymised decision record is kept for transparency statistics; residual backups up to 30 days |
| Support case and attachments | Case 24 months after resolution; attachments 90 days after resolution; residual backups up to 30 days |
| Dashboard Account session | Up to 7 days per session, renewed during continued activity |
| Private-Application access session | Up to 14 days; invalidated earlier if the Account or access is no longer valid |
| Accounting and transaction records | For the period required by law |
| Consumer withdrawal notice and receipt evidence | 10 years after receipt; longer only under an explicit time-bounded legal hold; residual backups up to 30 days |
Deletion from backups occurs through the normal backup cycle. We may retain limited data where law requires it or a legal claim needs it. Account deletion removes a withdrawal notice's Account link but does not erase its contents before that retention period ends; download your receipt before deleting the Account.
Subject to the GDPR, you may request access, correction, deletion, restriction, portability and objection. Where processing is based on consent, you may withdraw it without affecting earlier processing. You may object at any time to processing based on legitimate interests; we then stop unless we demonstrate overriding legitimate grounds or need the data for legal claims.
Send requests to legal@percher.app, from the Account email where possible. We may request proportionate identity verification and respond within the time the GDPR requires, normally one month.
You may complain to the Swedish Authority for Privacy Protection, Integritetsskyddsmyndigheten (IMY), imy.se, or the supervisory authority where you live or work.
We use access controls, least privilege, TLS, encryption of stored environment-variable values and backups, tenant, container and network isolation, logging, secret scrubbing, rate limits and vulnerability management. No service is completely secure; customers remain responsible for their application code, credentials, access rules and lawful processing. We assess personal-data breaches and notify IMY and affected individuals where the GDPR requires it.
Crash Diagnostics is optional AI-generated troubleshooting output that can be wrong and must be reviewed by the Account holder. External AI analysis is currently switched off for the whole Service; the active provider, if any, is shown in the Service. Percher does not use Crash Diagnostics or other automated processing to make decisions about individuals that produce legal or similarly significant effects.
The Service is intended for persons aged 18 or over. Contact legal@percher.app if you believe a child has provided Account Data.
We use authentication, security and access cookies and functional local storage, and no advertising cookies. See the Cookie Policy.
We may update this policy, give notice before a material change where required and show the current date above.
The English and Swedish versions are intended to have the same meaning. If they differ, the English version prevails. This does not limit rights under mandatory data-protection or consumer law.
*Last updated: 22 September 2026* *© 2026 Kaizensu AB — Percher, percher.app*